Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-28435 — Payload size limit bypass via gzip decompression in ContentReader (streaming) allows over…

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, cpp-httplib (httplib.h) does not enforce Server::set_payload_max_length() on the decompressed reques…

cpp-httplib | Remote | Denial of Service
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
5.3 MEDIUM
CVE-2026-28434 — cpp-httplib's default exception handler leaks e.what() to clients via EXCEPTION_WHAT resp…

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, when a request handler throws a C++ exception and the application has not registered a custom except…

cpp-httplib | Remote | Information Disclosure
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
5.9 MEDIUM
CVE-2026-28427 — OpenDeck affected by path traversal allows arbitrary file read

OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1, the service listening on port 57118 serves static files for installed plugins but does not properly sanitize path components. B…

Remote | Path Traversal
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2025-70219 — D-Link DIR-513 Stack Buffer Overflow Vulnerability

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the goform/formDeviceReboot.

dir-513_firmware dir-513 | Remote | Memory Corruption
Mar 04, 2026 Mar 06, 2026
Mar 04, 2026
Mar 06, 2026
7.7 HIGH
CVE-2026-3125 — SSRF vulnerability in opennextjs-cloudflare via /cdn-cgi/ path normalization bypass

A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package, resulting from a path normalization bypass in the /cdn-cgi/image/ handler.The @opennextjs/clou…

Remote | Server-Side Request Forgery
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.5 MEDIUM
CVE-2026-20064 — Cisco Secure Firewall Threat Defense (FTD) Software CLI Command Injection Vulnerability

A vulnerability in of Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to cause the device to unexpectedly reload, causing a denial of service (DoS) co…

| Denial of Service
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.8 MEDIUM
CVE-2026-20025 — Cisco Secure Firewall ASA Software and Cisco Secure FTD Software OSPF LSU Packet Heap Cor…

A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpect…

| Denial of Service
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.8 MEDIUM
CVE-2026-20024 — "Cisco OSPF Heap Corruption Remote DoS Vulnerability"

A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpect…

| Memory Corruption
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.1 MEDIUM
CVE-2026-20023 — Cisco OSPF Protocol Memory Corruption Denial of Service Vulnerability

A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjace…

| Memory Corruption
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.1 MEDIUM
CVE-2026-20022 — Cisco Secure Firewall ASA/Cisco Secure FTD OSPF LSU Packet Buffer Overflow Denial of Serv…

A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpe…

| Denial of Service
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
4.3 MEDIUM
CVE-2026-20021 — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) OSPF Pro…

A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, adjacent…

| Denial of Service
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.8 MEDIUM
CVE-2026-20020 — Cisco Secure Firewall ASA Software and Cisco Secure FTD Software OSPF Buffer Overflow DoS…

A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpe…

| Denial of Service
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.0 MEDIUM
CVE-2026-20016 — "Cisco FXOS Software CLI Command Injection Vulnerability"

A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Secure FTD Software could allow an authenticated, local attacker to execute arbitrary commands on the…

| Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
8.6 HIGH
CVE-2026-0847 — Path Traversal in nltk/nltk

A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and Brac…

nltk | Remote | Path Traversal
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2025-70226 — D-Link DIR-513 Stack Buffer Overflow

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formEasySetupWizard.

dir-513_firmware dir-513 | Remote | Memory Corruption
Mar 04, 2026 Mar 06, 2026
Mar 04, 2026
Mar 06, 2026
9.8 CRITICAL
CVE-2025-70223 — D-Link DIR-513 Buffer Overflow Vulnerability

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAdvNetwork.

dir-513_firmware dir-513 | Remote | Memory Corruption
Mar 04, 2026 Mar 06, 2026
Mar 04, 2026
Mar 06, 2026
7.8 HIGH
CVE-2026-26949 — Dell Device Management Agent DDMA Incorrect Authorization Elevation of Privilege

Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerabilit…

device_management_agent | Authorization
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.1 MEDIUM
CVE-2026-20149 — Cisco Webex Cross-Site Scripting Vulnerability

A vulnerability in Cisco Webex could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability, and no customer action is…

webex_meetings | Remote | Cross-Site Scripting
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
10.0 CRITICAL
CVE-2026-20131 — "Cisco Secure Firewall Management Center Java Deserialization Root RCE"

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root …

Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
5.3 MEDIUM
CVE-2026-20106 — Cisco Secure Firewall ASA/FTD Unauthenticated Remote Memory Exhaustion DoS

A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Softw…

Remote | Denial of Service
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
Showing 20 of 5096 Results