Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-32191 — Microsoft Bing Images Remote Code Execution Vulnerability

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
10.0 CRITICAL
CVE-2026-32169 — Azure Cloud Shell Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
9.0 CRITICAL
CVE-2026-30924 — qui CORS Misconfiguration: Arbitrary Origins Trusted

qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that reflects arbitrary origins while also returning Access-Control-Allow-Credentials…

Remote | Cross-Site Request Forgery
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
10.0 CRITICAL
CVE-2026-30836 — Step CA: Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through…

Remote | Authentication
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
7.1 HIGH
CVE-2026-27953 — ormar has a Pydantic Validation Bypass via Kwargs Injection in Model Constructor

ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the model constructor, allowing any unauthenticated user to skip all field validat…

Remote | Authentication
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
5.1 MEDIUM
CVE-2026-27740 — Discourse has Stored XSS in AI Triage Automation

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerability that arises because the system trusts the raw ou…

Remote | Cross-Site Scripting
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
5.1 MEDIUM
CVE-2026-27570 — Discourse Vulnerable to Stored XSS via Shared AI Conversation Onebox

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox method in the SharedAiConversation model renders the conversation title direct…

Remote | Cross-Site Scripting
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
6.9 MEDIUM
CVE-2026-27491 — Discourse has a bypass of official warnings messages by non-staff users

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coercion issue in a post actions API endpoint allowed non-staff users to issue war…

Remote | Authorization
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
5.3 MEDIUM
CVE-2026-27454 — Discourse has check revision visibility on posts endpoint

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting /posts/:id.json?version=X bypassed authorization checks on post revisions. The…

Remote | Authorization
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
4.1 MEDIUM
CVE-2026-27166 — Discourse vulnerable to HTML injection via prohibited iframe URLs

Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficient cleanup in the default Codepen allowed iframes value allows an attacker to t…

Remote | Cross-Site Scripting
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
8.6 HIGH
CVE-2026-26139 — Microsoft Purview Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
8.6 HIGH
CVE-2026-26138 — Microsoft Purview Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
8.9 HIGH
CVE-2026-26137 — Microsoft 365 Copilot BizChat Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft 365 Copilot's Business Chat allows an authorized attacker to elevate privileges over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
6.5 MEDIUM
CVE-2026-26136 — Microsoft Copilot Information Disclosure Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
6.5 MEDIUM
CVE-2026-26120 — Microsoft Bing Tampering Vulnerability

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
5.3 MEDIUM
CVE-2026-24299 — M365 Copilot Information Disclosure Vulnerability

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
8.6 HIGH
CVE-2026-23659 — Azure Data Factory Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
8.6 HIGH
CVE-2026-23658 — Azure DevOps: msazure Elevation of Privilege Vulnerability

Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
2.1 LOW
CVE-2026-3580 — Compiler-induced timing leak in sp_256_get_entry_256_9 on RISC-V

In wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bnez) by GCC when targeting RISC-V RV32I with -O3. This transformation breaks the side-…

| Cryptography
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
2.1 LOW
CVE-2026-3579 — Non-constant time multiplication subroutine __muldi3 on RISC-V RV32I

wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication. The compiler-inserted __muldi3 subroutine executes in variable time based on opera…

| Cryptography
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
Showing 20 of 5609 Results