Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-31958 — Tornado has a DoS due to too many multipart parts

Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting…

tornado | Remote | Denial of Service
Mar 11, 2026 Apr 01, 2026
Mar 11, 2026
Apr 01, 2026
10.0 CRITICAL
CVE-2026-31957 — Himmelblau unset domain configuration can allow any-tenant authentication at first login …

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed without a configured tenant domain in himmelblau.conf, authentic…

himmelblau | Remote | Authentication
Mar 11, 2026 Mar 16, 2026
Mar 11, 2026
Mar 16, 2026
7.3 HIGH
CVE-2026-31954 — Emlog asynchronous media file deletion missing CSRF protection

Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::checkToken(), enabling CSRF attacks.

emlog | Remote | Cross-Site Request Forgery
Mar 11, 2026 Mar 17, 2026
Mar 11, 2026
Mar 17, 2026
6.3 MEDIUM
CVE-2026-31901 — Parse Server has user enumeration via email verification endpoint

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34 and 9.6.0-alpha.8, the email verification endpoint (/verificationEmailRequest) …

parse-server | Remote | Information Disclosure
Mar 11, 2026 Mar 13, 2026
Mar 11, 2026
Mar 13, 2026
9.8 CRITICAL
CVE-2026-31900 — Black's vulnerable version parsing leads to RCE in GitHub Action

Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use fro…

black | Remote | Supply Chain
Mar 11, 2026 Mar 16, 2026
Mar 11, 2026
Mar 16, 2026
9.8 CRITICAL
CVE-2026-31896 — WeGIA has a Time-Based Blind SQL Injection in remover_produto_ocultar.php

WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application. The remover_produto_ocultar.php script uses extract…

wegia | Remote | Injection
Mar 11, 2026 Mar 13, 2026
Mar 11, 2026
Mar 13, 2026
8.8 HIGH
CVE-2026-31895 — WeGIA has a SQL Injection via Direct Query Interpolation in restaurar_produto.php

WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection vulnerability in html/matPat/restaurar_pro…

wegia | Remote | Injection
Mar 11, 2026 Mar 13, 2026
Mar 11, 2026
Mar 13, 2026
7.5 HIGH
CVE-2026-31894 — WeGIA affected by arbitrary file read via symlink in backup restore

WeGIA is a web manager for charitable institutions. In 3.6.5, The patched loadBackupDB() extracts tar.gz archives to a temporary directory using PHP's PharData class, then uses glob() and file_get_co…

wegia | Remote | Path Traversal
Mar 11, 2026 Mar 13, 2026
Mar 11, 2026
Mar 13, 2026
8.9 HIGH
CVE-2026-31889 — Shopware has a potential take over of app credentials

Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the co…

shopware | Remote | Authentication
Mar 11, 2026 Mar 16, 2026
Mar 11, 2026
Mar 16, 2026
9.8 CRITICAL
CVE-2026-27703 — RIOT has an Out-of-Bounds Write in nanoCoAP Handler

RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. In 2026.01 and earlier, the default handler…

riot | Remote | Memory Corruption
Mar 11, 2026 Mar 16, 2026
Mar 11, 2026
Mar 16, 2026
9.1 CRITICAL
CVE-2026-27478 — Unity Catalog has a JWT Issuer Validation Bypass Allows Complete User Impersonation

Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vulnerability exists in the Unity Catalog token exchange endpoint (/api/1.0/unity…

unitycatalog | Remote | Authentication
Mar 11, 2026 Mar 16, 2026
Mar 11, 2026
Mar 16, 2026
7.8 HIGH
CVE-2026-24510 — Dell Alienware Command Center AWCC Improper Privilege Management Elevation of Privilege

Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this v…

alienware_command_center | Authorization
Mar 11, 2026 Mar 16, 2026
Mar 11, 2026
Mar 16, 2026
5.5 MEDIUM
CVE-2026-24508 — Dell Alienware Command Center AWCC Improper Certificate Validation Information Exposure

Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this…

alienware_command_center | Information Disclosure
Mar 11, 2026 Mar 16, 2026
Mar 11, 2026
Mar 16, 2026
Showing 20 of 6453 Results