Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.4 CRITICAL
CVE-2026-28697 — Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templates

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injecti…

craft_cms | Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
8.7 HIGH
CVE-2026-28696 — Craft affected by IDOR via GraphQL @parseRefs

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal reference tags (e.g., {user:1:email}), can be abused …

craft_cms | Remote | Authorization
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-28695 — Craft affected by authenticated RCE via Twig SSTI - create() function + Symfony Process g…

Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Template Injection using the create() Twig function combined with a Symfony Process…

craft_cms | Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
4.3 MEDIUM
CVE-2026-23812 — Security Boundary Bypass via Routing Node Impersonation

A vulnerability has been identified where an attacker connecting to an access point as a standard wired or wireless client can impersonate a gateway by leveraging an address-based spoofing technique.…

| Misconfiguration
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
4.3 MEDIUM
CVE-2026-23811 — Unauthorized Bi-Directional Traffic Interception via L2/L3 Manipulation

A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restrictions between clients and redirect traffic at Layer 3 (L3). In addition to bypassin…

| Misconfiguration
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
4.3 MEDIUM
CVE-2026-23810 — Cross-BSSID GTK Re-encryption and Traffic Injection

A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-Fi frame that causes an Access Point (AP) to classify the frame as group-addres…

| Injection
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
5.4 MEDIUM
CVE-2026-23809 — MAC Address Spoofing leads to Inter-BSSID Isolation Bypass Resulting in Traffic Redirecti…

A technique has been identified that adapts a known port-stealing method to Wi-Fi environments that use multiple BSSIDs. By leveraging the relationship between BSSIDs and their associated virtual por…

| Misconfiguration
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
5.4 MEDIUM
CVE-2026-23808 — Client Isolation Bypass via GTK Manipulation

A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled Group Temporal Key (GTK) on a client device. Succ…

| Authentication
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
5.4 MEDIUM
CVE-2026-23601 — Frame Injection via Shared GTK Allows Traffic Spoofing and Client Compromise

A vulnerability has been identified in the wireless encryption handling of Wi-Fi transmissions. A malicious actor can generate shared-key authenticated transmissions containing targeted payloads whil…

| Cryptography
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
3.3 LOW
CVE-2026-22760 — Dell Device Management Agent (DDMA) Improper Check for Unusual or Exceptional Conditions …

Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Improper Check for Unusual or Exceptional Conditions vulnerability. A low privileged attacker with local access could potentia…

device_management_agent | Denial of Service
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
5.8 MEDIUM
CVE-2026-20005 — Multiple Cisco Products Snort 3 SSL Denial of Service Vulnerability

Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resultin…

cyber_vision_center | Remote | Denial of Service
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
9.6 CRITICAL
CVE-2025-69969 — "SRK Powertech Pvt Ltd Pebble Prism Ultra BLE Authentication Bypass"

A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer …

| Authentication
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
9.8 CRITICAL
CVE-2025-66944 — Apache Vran SQL Injection

SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in the search API endpoint

Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2025-66678 — Nil Hardware Editor HwRwDrv.sys Arbitrary Read/Write Vulnerability

An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allows attackers to execute arbitrary read and write operations via a crafted reques…

Remote | Misconfiguration
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
7.0 HIGH
CVE-2025-15558 — Docker Desktop Docker Plugins Uncontrolled Search Path Element Local Privilege Escalation…

Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place mal…

| Misconfiguration
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
7.5 HIGH
CVE-2026-26673 — "DJI Mavic Denial of Service Vulnerability"

An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via the DJI Enhanced-WiFi transmission subsystem

Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-26514 — Bird LG Go Argument Injection Denial of Service

An Argument Injection vulnerability exists in bird-lg-go before commit 6187a4e. The traceroute module uses shlex.Split to parse user input without validation, allowing remote attackers to inject arbi…

bird-lg-go | Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-26478 — Mobvoi Tichome Mini Shell Command Injection

A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially crafted UDP datagram and execute arbitrary shell code …

tichome_mini_firmware tichome_mini | Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
4.4 MEDIUM
CVE-2026-22285 — Dell Device Management Agent Plaintext Storage of Password Vulnerability

Dell Device Management Agent (DDMA), versions prior to 26.02, contain a Plaintext Storage of Password vulnerability. A high privileged attacker with local access could potentially exploit this vulner…

device_management_agent | Cryptography
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.8 MEDIUM
CVE-2025-62879 — Rancher Backup Operator pod's logs leak S3 tokens

A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs.

rancher rancher_backup_and_restore_operator | Remote | Information Disclosure
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
Showing 20 of 5090 Results