Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2025-47378 — Exposure of Sensitive System Information to an Unauthorized Control Sphere in HLOS

Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.

Mar 02, 2026 Mar 05, 2026
Mar 02, 2026
Mar 05, 2026
7.8 HIGH
CVE-2025-47377 — Use After Free in Automotive Audio

Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls.

Mar 02, 2026 Mar 04, 2026
Mar 02, 2026
Mar 04, 2026
7.8 HIGH
CVE-2025-47376 — Use After Free in Automotive Audio

Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.

Mar 02, 2026 Mar 04, 2026
Mar 02, 2026
Mar 04, 2026
7.8 HIGH
CVE-2025-47375 — Use After Free in Automotive Audio

Memory corruption while handling different IOCTL calls from the user-space simultaneously.

Mar 02, 2026 Mar 04, 2026
Mar 02, 2026
Mar 04, 2026
7.8 HIGH
CVE-2025-47373 — Out-of-bounds Write in Automotive

Memory Corruption when accessing buffers with invalid length during TA invocation.

Mar 02, 2026 Mar 04, 2026
Mar 02, 2026
Mar 04, 2026
6.5 MEDIUM
CVE-2025-47371 — Reachable Assertion in Modem

Transient DOS when an LTE RLC packet with invalid TB is received by UE.

Mar 02, 2026 Mar 04, 2026
Mar 02, 2026
Mar 04, 2026
7.5 HIGH
CVE-2026-28412 — Textream Vulnerable to Uncontrolled Resource Consumption (Denial of Service)

Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limit on concurrent connections. Combined with a broadcast timer that sends state t…

textream | Remote | Denial of Service
Mar 02, 2026 Mar 04, 2026
Mar 02, 2026
Mar 04, 2026
8.6 HIGH
CVE-2026-28403 — Textream Cross-Site WebSocket Hijacking (CSWSH) vulnerability

Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server (`ws://127.0.0.1:<httpPort+1>`) accepts connections from any origin without validating the HTT…

textream | Remote | Misconfiguration
Mar 02, 2026 Mar 04, 2026
Mar 02, 2026
Mar 04, 2026
9.8 CRITICAL
CVE-2026-26720 — Twenty CRM TypeScript Injection Vulnerability

An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.

twenty | Remote | Injection
Mar 02, 2026 Mar 04, 2026
Mar 02, 2026
Mar 04, 2026
9.8 CRITICAL
CVE-2026-26701 — Sourcecodester Personnel Property Equipment System SQL Injection Vulnerability

sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_tecnical_user.php.

Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
8.8 HIGH
CVE-2026-26699 — Sourcecodester Personnel Property Equipment System File Upload Code Execution Vulnerabili…

sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin_change_picture.php.

Mar 02, 2026 Mar 04, 2026
Mar 02, 2026
Mar 04, 2026
9.8 CRITICAL
CVE-2026-24112 — Tenda W20E Buffer Overflow Vulnerability

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInfo` is passed into the `addWewifiWhiteUser` functio…

w20e_firmware w20e | Remote | Memory Corruption
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-24110 — Tenda W20E Buffer Overflow

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may send overly long `addDhcpRules` data. When these rules enter the `addDhcpRule` function and are processed by `ret = sscanf(pRule…

w20e_firmware w20e | Remote | Memory Corruption
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-24101 — Tenda AC15V1.0 Command Injection Vulnerability

An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, concatenated into `doSystemCmd`. The value of s1_1…

ac15_firmware ac15 | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
6.0 MEDIUM
CVE-2026-0689 — XIQ‑SE NAC Admin Credential Exposure via HTTP Response

In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an authenticated NAC administrator to retrieve masked sensitive parameters from HT…

Remote | Information Disclosure
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
6.1 MEDIUM
CVE-2025-66880 — Wethink Technology Inc 720yun Pano-sdk Cross Site Scripting Vulnerability

Cross Site Scripting vulnerability in Wethink Technology Inc 720yun pano-sdk 0.5.877 allows a remote attacker to execute arbitrary code via the LoginComp (Module 2093) and SignupComp (Module 2094) mo…

Remote | Cross-Site Scripting
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
9.8 CRITICAL
CVE-2025-52998 — Chamilo: PHAR deserialization bypass

Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is performed, the data can be spoofed. An attacker can create objects of arbitrary class…

chamilo_lms | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
6.9 MEDIUM
CVE-2025-52564 — Chamilo: HTML injection via open parameter

Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sanitize user input. This allows an attacker to inject arbitrary HTML, such as unde…

chamilo_lms | Remote | Cross-Site Scripting
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
6.1 MEDIUM
CVE-2025-52563 — Chamilo: Reflected XSS via page parameter

Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to insufficient sanitization of the page parameter in the session/…

chamilo_lms | Remote | Cross-Site Scripting
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
6.1 MEDIUM
CVE-2025-52476 — Chamilo: Reflected XSS via keyword_active parameter

Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to improper sanitization of the keyword_active parameter in admin/…

chamilo_lms | Remote | Cross-Site Scripting
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
Showing 20 of 5087 Results