CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2026-3833

    Last Modified: 14 Sept 2026

    A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.

    Published: 30 Apr 2026
    8.7
    High

    CVE-2025-51846

    Last Modified: 4 May 2026

    CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed in 2026.2.2.

    Published: 30 Apr 2026
    8.7
    High

    CVE-2022-50992

    Last Modified: 15 Jul 2026

    Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying file paths to the WorkflowService.getAttachment and WorkflowService.LoadTemplateProp methods. Attackers can exploit these methods without authentication to retrieve sensitive files including system configuration files and database credentials from the server. Exploitation evidence was first observed by the Shadowserver Foundation on 2022-12-14 (UTC).

    Published: 30 Apr 2026
    9.3
    Critical

    CVE-2022-50993

    Last Modified: 15 Jul 2026

    Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpoint that allows remote attackers to upload malicious files by sending multipart POST requests with arbitrary filenames and disguised content types. Attackers can upload PHP webshells to the Document directory and execute them via HTTP GET requests to achieve remote code execution as the web server user. Exploitation evidence was first observed by the Shadowserver Foundation on 2022-10-10 (UTC).

    Published: 30 Apr 2026
    9.3
    Critical

    CVE-2025-71284

    Last Modified: 5 May 2026

    Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoint at /en/9-2radius.php where the radius_address POST parameter is split and interpolated directly into a sed command without sanitization. An unauthenticated remote attacker can inject arbitrary shell commands by submitting a POST request with crafted radius_address, radius_address2, shared_secret2, source_ip, timeout, or retry parameters along with save=1 and enable_radius=1 to achieve remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-07-11 (UTC).

    Published: 30 Apr 2026
    8.8
    High

    CVE-2025-14543

    Last Modified: 17 Jun 2026

    Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 4.3x before 5.2.*.

    Published: 30 Apr 2026
    7.7
    High

    CVE-2026-5174

    Last Modified: 4 May 2026

    Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

    Published: 30 Apr 2026
    9.8
    Critical

    CVE-2026-4670

    Last Modified: 4 May 2026

    Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

    Published: 30 Apr 2026
    7.5
    High

    CVE-2026-2892

    Last Modified: 1 May 2026

    The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3.1.4. This is due to the 'get_customer_data' method relying on an unsigned 'o_stripe_data' cookie to determine Stripe product ownership for unauthenticated users. The 'check_purchase' method trusts this cookie data without performing server-side verification against the Stripe API for one-time 'payment' mode purchases. This makes it possible for unauthenticated attackers to bypass Stripe purchase-gated content visibility conditions by forging the 'o_stripe_data' cookie with a target product ID, which is publicly exposed in the checkout block's HTML source.

    Published: 30 Apr 2026
    7.2
    High

    CVE-2026-7246

    Last Modified: 18 Aug 2026

    This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below: Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

    Published: 30 Apr 2026
    8.1
    High

    CVE-2026-7402

    Last Modified: 6 Jun 2026

    Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

    Published: 30 Apr 2026
    7.4
    High

    CVE-2025-14576

    Last Modified: 29 Jul 2026

    Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.

    Published: 30 Apr 2026
    8.1
    High

    CVE-2026-7399

    Last Modified: 6 Jun 2026

    Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege Abuse. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

    Published: 30 Apr 2026
    6.5
    Medium

    CVE-2026-7382

    Last Modified: 6 Jun 2026

    Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows Excavation. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

    Published: 30 Apr 2026
    7.7
    High

    CVE-2024-13971

    Last Modified: 17 May 2026

    Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.

    Published: 30 Apr 2026
    6.1
    Medium

    CVE-2026-7163

    Last Modified: 19 May 2026

    A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters provisioned through the hub. The credentials download endpoint (GET /v2/clusters/{cluster_id}/credentials, which returns the kubeadmin password) and the kubeconfig download endpoint are operational in AUTH_TYPE=local mode, the only authentication mode available in on-premises ACM/MCE hub deployments. The local authenticator unconditionally grants full administrative access to any request bearing a valid JWT, with no per-endpoint restrictions. A valid local JWT is embedded as a plaintext query parameter in InfraEnvStatus.ISODownloadURL and is readable by any user who has get rights on an InfraEnv object in their own namespace. The affected components ship as part of Multicluster Engine (MCE). The Red Hat Advanced Cluster Management (ACM) deployments that include MCE are equally affected. This issue does not affect the hosted SaaS offering (console.redhat.com), which uses a different authentication mode. Successful exploitation gives the attacker the kubeadmin password and kubeconfig for any OpenShift cluster provisioned through the affected hub, granting unrestricted root-level administrative access to those spoke clusters.

    Published: 30 Apr 2026
    5.9
    Medium

    CVE-2026-5080

    Last Modified: 5 May 2026

    Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generated from summing the character codepoints of the absolute pathname with the process id, the epoch time and calls to the built-in rand() function to return a number between 0 and 999-billion, and concatenating that result three times. The path name might be known or guessed by an attacker, especially for applications known to be written using Dancer with standard installation locations. The epoch time can be guessed by an attacker, and may be leaked in the HTTP header. The process id comes from a small set of numbers, and workers may have sequential process ids. The built-in rand() function is seeded with 32-bits and is considered unsuitable for security applications. Predictable session ids could allow an attacker to gain access to systems.

    Published: 30 Apr 2026
    4.6
    Medium

    CVE-2026-1493

    Last Modified: 5 May 2026

    LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely processes the parameter on the client side, allowing an attacker to execute arbitrary JavaScript in the context of the victim's browser. An attacker with ability to set a cookie can perform a more severe attack, so we evaluate the impact and risk of exploitation as minimal. However, the vendor considered this a vulnerability and released a security patch. This issue was fixed in version 1.3.4.

    Published: 30 Apr 2026
    7.4
    High

    CVE-2026-41882

    Last Modified: 5 May 2026

    In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server

    Published: 30 Apr 2026
    5.3
    Medium

    CVE-2026-6498

    Last Modified: 1 May 2026

    The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 This is due to the valid_payment() function using a PHP loose comparison (==) between the attacker-controlled payment_id POST parameter and the booking's stripe_payment_intent_id property. When an unauthenticated attacker submits a request to the nopriv AJAX handler rtb_stripe_pmt_succeed before the Stripe payment intent has been created for a booking (i.e., before the JavaScript-triggered create_stripe_pmtIntnt() call has stored an intent ID in post meta), the stripe_payment_intent_id property on the booking object remains null. The comparison sanitize_text_field('') == null evaluates to TRUE in PHP loose comparison, causing the payment verification check to pass with zero actual payment. This makes it possible for unauthenticated attackers to mark any existing payment_pending booking as paid without completing a Stripe payment by submitting an empty payment_id parameter.

    Published: 30 Apr 2026
    5.9
    Medium

    CVE-2026-41016

    Last Modified: 1 May 2026

    Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between the Airflow worker and the SMTP server could present a self-signed certificate, complete the STARTTLS upgrade, and capture the SMTP credentials sent during the subsequent `login()` call. Users are advised to upgrade to the `apache-airflow-providers-smtp` version that contains the fix.

    Published: 30 Apr 2026
    7.4
    High

    CVE-2026-42800

    Last Modified: 5 May 2026

    NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/sipuri.c.

    Published: 30 Apr 2026
    7.4
    High

    CVE-2026-42799

    Last Modified: 5 May 2026

    Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects Kestrel: before 2026/02/10.

    Published: 30 Apr 2026
    7.1
    High

    CVE-2026-22070

    Last Modified: 5 May 2026

    ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.

    Published: 30 Apr 2026
    8.1
    High

    CVE-2026-35547

    Last Modified: 1 May 2026

    When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to write outside the bounds of a heap allocation. This can trigger a crash or system panic, and it may be possible for an unprivileged user to exploit the bug to elevate their privileges.

    Published: 30 Apr 2026
    7.8
    High

    CVE-2026-39457

    Last Modified: 1 May 2026

    When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whether the provided socket descriptor fits in select(2)'s file descriptor set size limit of FD_SETSIZE (1024). An attacker who is able to force a libnv application to allocate large file descriptors, e.g., by opening many descriptors and executing a program which is not careful to close them upon startup, can trigger stack corruption. If the target application is setuid-root, then this could be used to elevate local privileges.

    Published: 30 Apr 2026
    8.1
    High

    CVE-2026-42512

    Last Modified: 1 May 2026

    As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the array incorrectly calculates its new size when requesting memory, resulting in a heap buffer overrun. A specially crafted packet can cause dhclient to overrun its buffer of environment entries. This can result in a crash, but it may be possible to leverage this bug to achieve remote code execution.

    Published: 30 Apr 2026
    7.5
    High

    CVE-2026-7164

    Last Modified: 1 May 2026

    Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic. Remote attackers can craft packets which cause affected systems to panic. This affects any system where pf is configured to process traffic, independent of the configured ruleset.

    Published: 30 Apr 2026
    8.7
    High

    CVE-2024-39847

    Last Modified: 17 May 2026

    Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.

    Published: 30 Apr 2026
    7.8
    High

    CVE-2026-7270

    Last Modified: 10 May 2026

    An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers. The bug may be exploitable by an unprivileged user to obtain superuser privileges.

    Published: 30 Apr 2026
    8.1
    High

    CVE-2026-42511

    Last Modified: 1 May 2026

    The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by dhclient, e.g., after a system restart, an attacker-controlled field from the lease is passed to dhclient-script(8), which evaluates it. A rogue DHCP server may be able to execute arbirary code as root on a system running dhclient.

    Published: 30 Apr 2026
    4
    Medium

    CVE-2026-42798

    Last Modified: 30 Apr 2026

    Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.

    Published: 30 Apr 2026
    5.1
    Medium

    CVE-2026-41226

    Last Modified: 31 Aug 2026

    Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may be redirected to an arbitrary website. As a result, the user may become a victim of a phishing attack.

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-5409

    Last Modified: 1 May 2026

    Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-5408

    Last Modified: 1 May 2026

    BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-5406

    Last Modified: 1 May 2026

    FC-SWILS protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-5407

    Last Modified: 1 May 2026

    SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-5299

    Last Modified: 1 May 2026

    ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    8.8
    High

    CVE-2026-5402

    Last Modified: 1 May 2026

    TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-5401

    Last Modified: 1 May 2026

    AFP Spotlight protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-5654

    Last Modified: 1 May 2026

    AMR-NB codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-5655

    Last Modified: 1 May 2026

    SDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-5657

    Last Modified: 1 May 2026

    iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-5653

    Last Modified: 1 May 2026

    DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6538

    Last Modified: 1 May 2026

    BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6537

    Last Modified: 1 May 2026

    ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6536

    Last Modified: 1 May 2026

    DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6535

    Last Modified: 1 May 2026

    Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6534

    Last Modified: 1 May 2026

    USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6533

    Last Modified: 1 May 2026

    Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026