Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-24103 — Tenda AC15V1.0 Buffer Overflow Vulnerability

A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi.

ac15_firmware ac15 | Remote | Memory Corruption
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-22891 — The Biosig Project libbiosig Heap-Based Buffer Overflow Vulnerability

A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lea…

libbiosig | Remote | Memory Corruption
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
8.1 HIGH
CVE-2026-20777 — Biosig Project libbiosig Heap-Based Buffer Overflow Vulnerability

A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted .wft file can lead t…

libbiosig | Remote | Memory Corruption
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2025-70821 — Renren Security SQL Injection Vulnerability

renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component

renren-security | Remote | Injection
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
7.1 HIGH
CVE-2025-64736 — The Biosig Project libbiosig Out-of-Bounds Read Information Leak

An out-of-bounds read vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (5462afb0). A specially crafted .abf file can lead to an informatio…

libbiosig | Information Disclosure
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
0.0 NA
CVE-2025-57622 — Step-Video-T2V Deserialization Code Execution Vulnerability

An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature = pickle.loads(request.get_data()) component

| Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
7.8 HIGH
CVE-2025-52365 — Stabilizer szc Command Injection Vulnerability

A command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to execute arbitrary system commands via unsanitized user input passed to os.syste…

| Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
6.9 MEDIUM
CVE-2026-3344 — WatchGuard Firebox System Integrity Check Bypass

A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and maintain limited persistence via a maliciously-crafted firmware update package…

Mar 03, 2026 Mar 04, 2026
Mar 03, 2026
Mar 04, 2026
6.1 MEDIUM
CVE-2026-3343 — WatchGuard Firebox Reflected Cross-Site-Scripting (XSS) Vulnerability in Fireware Web UI

A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click o…

fireware firebox_m270 firebox_m290 firebox_m370 firebox_m390 firebox_m440 +32 more | Remote | Cross-Site Scripting
Mar 03, 2026 Mar 04, 2026
Mar 03, 2026
Mar 04, 2026
8.6 HIGH
CVE-2026-3342 — WatchGuard Firebox Out of Bounds Write Vulnerability

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to execute arbitrary code with root permissions via an exposed management interface.…

Mar 03, 2026 Mar 04, 2026
Mar 03, 2026
Mar 04, 2026
2.1 LOW
CVE-2026-3351 — Authorization Bypass in LXD GET /1.0/certificates Endpoint

Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd se…

lxd | Remote | Authorization
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
4.8 MEDIUM
CVE-2026-3463 — xlnt-community xlnt Compound Document binary.hpp append heap-based overflow

A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::binary_writer::append of the file source/detail/binary.hpp of the component Compound Document…

| Memory Corruption
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
5.3 MEDIUM
CVE-2025-59060 — Apache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClient

Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this …

ranger | Remote | Misconfiguration
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2025-59059 — Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator

Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

ranger | Remote | Injection
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
7.2 HIGH
CVE-2026-2568 — WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.5 - …

The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission data in all versions up to, and…

Remote | Cross-Site Scripting
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-22886 — Apache OpenMQ Default Administrative Account Vulnerability

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforc…

Remote | Authentication
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
6.3 MEDIUM
CVE-2025-15598 — Dataease SQLBot JWT Token auth.py validateEmbedded signature verification

A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing …

sqlbot | Remote | Cryptography
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
8.7 HIGH
CVE-2026-1876 — Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series Ethernet…

Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a remote attacker to cause a deni…

Remote | Denial of Service
Mar 03, 2026 Mar 04, 2026
Mar 03, 2026
Mar 04, 2026
8.7 HIGH
CVE-2026-1875 — Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet…

Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP all versions allows a remote attacker to cause a denial-of…

Remote | Denial of Service
Mar 03, 2026 Mar 04, 2026
Mar 03, 2026
Mar 04, 2026
8.7 HIGH
CVE-2026-1874 — Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet…

Always-Incorrect Control Flow Implementation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP versions 1.106 and prior and Mitsubishi Electr…

Remote | Denial of Service
Mar 03, 2026 Mar 04, 2026
Mar 03, 2026
Mar 04, 2026
Showing 20 of 5089 Results