Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.3 LOW
CVE-2025-70330 — Easy Grade Pro Uninitialized Memory Read Vulnerability

Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files. By modifying specific fields at precise offsets within an otherwise valid .EGP file, an …

| Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
7.5 HIGH
CVE-2025-70027 — SunbirdEd Server-Side Request Forgery Vulnerability

An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. This allows attackers to obtain sensitive information

sunbirded-portal | Remote | Server-Side Request Forgery
Mar 11, 2026 Apr 02, 2026
Mar 11, 2026
Apr 02, 2026
8.1 HIGH
CVE-2025-67298 — ClasroomIO Privilege Escalation Vulnerability

An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and /rest/v1/profile

classroomio | Remote | Authentication
Mar 11, 2026 Apr 07, 2026
Mar 11, 2026
Apr 07, 2026
6.2 MEDIUM
CVE-2026-3904 — GNU C Library NSS-Backed Functions Concurrent Modification Crash

Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under high load on x86_64 systems, the client may call memcmp on …

glibc | Memory Corruption
Mar 11, 2026 Apr 09, 2026
Mar 11, 2026
Apr 09, 2026
7.5 HIGH
CVE-2026-3496 — JetBooking <= 4.0.3 - Unauthenticated SQL Injection via 'check_in_date' Parameter

The JetBooking plugin for WordPress is vulnerable to SQL Injection via the 'check_in_date' parameter in all versions up to, and including, 4.0.3. This is due to insufficient escaping on the user supp…

Remote | Injection
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
7.8 HIGH
CVE-2026-32063 — OpenClaw 2026.2.19-2 < 2026.2.21 - Command Injection via Newline in systemd Unit Generati…

OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injection vulnerability in systemd unit file generation where attacker-controlled environment values are not validated for CR/LF cha…

openclaw | Injection
Mar 11, 2026 Mar 16, 2026
Mar 11, 2026
Mar 16, 2026
8.7 HIGH
CVE-2026-32062 — OpenClaw 2026.2.21-2 < 2026.2.22 - Unauthenticated WebSocket Resource Exhaustion via Medi…

OpenClaw versions2026.2.21-2 prior to 2026.2.22 and @openclaw/voice-call versions 2026.2.21 prior to 2026.2.22 accept media-stream WebSocket upgrades before stream validation, allowing unauthenticate…

openclaw openclaw\/voice-call | Remote | Authentication
Mar 11, 2026 Mar 26, 2026
Mar 11, 2026
Mar 26, 2026
6.7 MEDIUM
CVE-2026-32061 — OpenClaw < 2026.2.17 - Arbitrary File Read via $include Directive Path Traversal

OpenClaw versions prior to 2026.2.17 contain a path traversal vulnerability in the $include directive resolution that allows reading arbitrary local files outside the config directory boundary. Attac…

openclaw | Path Traversal
Mar 11, 2026 Mar 16, 2026
Mar 11, 2026
Mar 16, 2026
8.8 HIGH
CVE-2026-32060 — OpenClaw < 2026.2.14 - Path Traversal in apply_patch via Crafted Paths

OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the configured workspace directory. When apply_patch …

openclaw | Remote | Path Traversal
Mar 11, 2026 Mar 16, 2026
Mar 11, 2026
Mar 16, 2026
8.8 HIGH
CVE-2026-32059 — OpenClaw 2026.2.22-2 < 2026.2.23 - Allowlist Bypass via sort Long-Option Abbreviation in …

OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviations, allowing attackers to bypass denied-flag chec…

openclaw | Remote | Authentication
Mar 11, 2026 Mar 16, 2026
Mar 11, 2026
Mar 16, 2026
9.8 CRITICAL
CVE-2026-3944 — itsourcecode University Management System att_add.php sql injection

A vulnerability was determined in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /att_add.php. This manipulation of the argument Name causes sql in…

university_management_system | Remote | Injection
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
7.5 HIGH
CVE-2026-3943 — H3C ACG1000-AK230 aaa_portal_auth_local_submit command injection

A vulnerability was found in H3C ACG1000-AK230 up to 20260227. This affects an unknown part of the file /webui/?aaa_portal_auth_local_submit. The manipulation of the argument suffix results in comman…

Remote | Injection
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
Showing 20 of 6452 Results