Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.7 MEDIUM
CVE-2026-28551 — Cisco Device Security Management Module Race Condition Vulnerability

Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Race Condition
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
6.6 MEDIUM
CVE-2026-28549 — Apache Permission Service Race Condition

Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Race Condition
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
7.1 HIGH
CVE-2026-28548 — Apache Email Confidentiality Bypass

Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

emui harmonyos | Authentication
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
6.8 MEDIUM
CVE-2026-28547 — Cisco Scanning Module Pointer Uninitialized Access Vulnerability

Vulnerability of uninitialized pointer access in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
5.9 MEDIUM
CVE-2026-28546 — Cisco ASA Buffer Overflow

Buffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
7.3 HIGH
CVE-2026-28542 — Apache System Service Framework Privilege Escalation

Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Authorization
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
6.5 MEDIUM
CVE-2026-2893 — Page and Post Clone <= 6.3 - Authenticated (Contributor+) SQL Injection via 'meta_key' Pa…

The Page and Post Clone plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' parameter in the content_clone() function in all versions up to, and including, 6.3. This is due to insu…

page_and_post_clone | Remote | Injection
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-28552 — Huawei IMS Out-of-Bounds Write Vulnerability

Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Remote | Memory Corruption
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
4.7 MEDIUM
CVE-2026-28550 — Cisco Security Control Module Race Condition Vulnerability

Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Race Condition
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
5.9 MEDIUM
CVE-2026-28545 — "HP Printing Module Race Condition Vulnerability"

Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Race Condition
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
6.2 MEDIUM
CVE-2026-28544 — Adobe Printing Module Race Condition Vulnerability

Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Race Condition
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
4.7 MEDIUM
CVE-2026-28543 — Cisco Maintenance and Diagnostics Module Race Condition Vulnerability

Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Race Condition
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
5.5 MEDIUM
CVE-2026-28541 — "Qualcomm Cellular Data Permission Control Vulnerability"

Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Authorization
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
4.0 MEDIUM
CVE-2026-28540 — Qualcomm Bluetooth Out-of-Bounds Character Read Vulnerability

Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

harmonyos | Memory Corruption
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
6.2 MEDIUM
CVE-2026-28539 — Apache Certificate Management Module Information Disclosure Vulnerability

Data processing vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

harmonyos | Cryptography
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
5.9 MEDIUM
CVE-2026-28538 — Apache Certificate Management Path Traversal Vulnerability

Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Path Traversal
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
5.5 MEDIUM
CVE-2026-28537 — Microsoft Windows Double Free Vulnerability

Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
3.3 LOW
CVE-2026-21786 — HCL Sametime for iOS is affected by sensitive information disclosure

HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs.

| Information Disclosure
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
8.1 HIGH
CVE-2026-1321 — Membership Plugin – Restrict Content <= 3.2.20 - Unauthenticated Privilege Escalation via…

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. This is due to the `rcp_setup_registration_init()` fu…

restrict_content | Remote | Authorization
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
5.5 MEDIUM
CVE-2025-66319 — Citrix Resource Scheduling Module Permission Bypass Vulnerability

Permission control vulnerability in the resource scheduling module. Impact: Successful exploitation of this vulnerability may affect service integrity.

harmonyos | Authorization
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
Showing 20 of 5096 Results