Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28078
Total
2162
Critical
8456
High
8753
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-40068 | UNKNOWN | — | In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker … | May 05, 2026 |
| CVE-2026-39852 | UNKNOWN | — | Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between … | May 05, 2026 |
| CVE-2026-39849 | UNKNOWN | — | Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the `dns.interface` configuration field in Pi-hole FTL … | May 05, 2026 |
| CVE-2026-39402 | UNKNOWN | — | lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line() function that allows an … | May 05, 2026 |
| CVE-2026-39383 | UNKNOWN | — | Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make outbound HTTP POST … | May 05, 2026 |
| CVE-2026-35579 | UNKNOWN | — | CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. … | May 05, 2026 |
| CVE-2026-35527 | UNKNOWN | — | Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to … | May 05, 2026 |
| CVE-2026-7857 | HIGH | 7.2 | A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects the function sprintf of the file /user_group.asp of the component CGI Handler. The … | May 05, 2026 |
| CVE-2026-7856 | HIGH | 7.2 | A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the file /url_member.asp of the component Web Management Interface. Executing … | May 05, 2026 |
| CVE-2026-44331 | HIGH | 8.1 | In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap2_sql.c allows a remote attacker to inject arbitrary SQL commands via a … | May 05, 2026 |
| CVE-2026-40331 | UNKNOWN | — | Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7.5.2, the … | May 05, 2026 |
| CVE-2026-40330 | UNKNOWN | — | Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7.5.2, a … | May 05, 2026 |
| CVE-2026-40329 | UNKNOWN | — | Masa CMS is an open source content management system. In versions 7.5.2 and earlier, a SQL injection vulnerability exists in the beanFeed.cfc component within the … | May 05, 2026 |
| CVE-2026-40280 | UNKNOWN | — | Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists for the --webhook-deny-list and --api-download-from-deny-list flags use a case-sensitive … | May 05, 2026 |
| CVE-2026-38947 | MEDIUM | 6.1 | FluentCMS 1.2.3 is vulnerable to Cross Site Scripting (XSS) in TextHTML plugin. | May 05, 2026 |
| CVE-2026-35453 | UNKNOWN | — | PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.3 and earlier, 2.0.0 through 2.1.15, 2.2.0 through 2.4.4, 3.3.0 through 3.10.4, and … | May 05, 2026 |
| CVE-2026-35397 | UNKNOWN | — | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated … | May 05, 2026 |
| CVE-2026-34596 | UNKNOWN | — | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of-Check-to-Time-of-Use (TOCTOU) race condition exists during addon installation. When … | May 05, 2026 |
| CVE-2026-34527 | UNKNOWN | — | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, SbieIniServer::HashPassword converts a SHA-1 digest to hexadecimal incorrectly. The high … | May 05, 2026 |
| CVE-2026-34464 | UNKNOWN | — | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server field from NAMED_PIPE_OPEN_REQ into a fixed … | May 05, 2026 |
| CVE-2026-34462 | UNKNOWN | — | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several ProcessServer handlers (KillAllHandler, SuspendAllHandler, and RunSandboxedHandler) copy a WCHAR … | May 05, 2026 |
| CVE-2026-34461 | UNKNOWN | — | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieIniServer RunSbieCtrl handler contains a stack buffer overflow. The … | May 05, 2026 |
| CVE-2026-34459 | UNKNOWN | — | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc proxy service's GetRawInputDeviceInfoSlave handler contains two vulnerabilities that … | May 05, 2026 |
| CVE-2026-34458 | UNKNOWN | — | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard local user to … | May 05, 2026 |
| CVE-2026-34084 | UNKNOWN | — | PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and … | May 05, 2026 |