cve.li

Recent

CVE-2026-45152CWE-78

uniget: Command Injection in tool.Check Leading to Arbitrary Code Execution

Published 2026-05-27 by GitHub_M

CVE-2026-44720CWE-287CWE-347

OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover

Published 2026-05-27 by GitHub_M

CVE-2026-45083CWE-306

Goobi viewer: Unauthenticated Solr Streaming Expression Proxy

Published 2026-05-27 by GitHub_M

CVE-2026-9208CWE-78

Tanium addressed an unauthorized code execution vulnerability in Connect.

Published 2026-05-27 by Tanium

CVE-2026-44247CWE-400CWE-770

Volcano: Webhook server vulnerable to OOM due to unbounded HTTP request body size

Published 2026-05-27 by GitHub_M

CVE-2026-45137CWE-20

Anchor: Program<'info, System> is not properly validated

Published 2026-05-27 by GitHub_M

CVE-2026-45136CWE-78CWE-94

claude-code-cache-fix: Local code execution via Python triple-quote injection in tools/quota-statusline.sh

Published 2026-05-27 by GitHub_M

CVE-2026-44660CWE-401

UltraJSON: Memory Leak in ujson.dump() on Write Failure

Published 2026-05-27 by GitHub_M

CVE-2026-44712CWE-78CWE-88

pam_usb: Shell injection via device UUID and username in pamusb-conf and pamusb-agent

Published 2026-05-27 by GitHub_M

CVE-2026-44709CWE-78

pam_usb: PINENTRY_FALLBACK_APP environment variable allows arbitrary command execution

Published 2026-05-27 by GitHub_M

Load more ↓