Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2026-28289 — FreeScout 1.8.206 Patch Bypass for CVE-2026-27636 via Zero-Width Space Character Leads to…

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with …

freescout | Remote | Misconfiguration
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
7.4 HIGH
CVE-2026-27981 — HomeBox has an Auth Rate Limit Bypass via IP Spoofing

HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) tracks failed attempts per client IP. It determines the client IP by reading, 1…

homebox | Remote | Authentication
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-27971 — Qwik affected by unauthenticated RCE via server$ Deserialization

Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user…

qwik | Remote | Injection
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-27932 — joserfc PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a resource exhaustion vulnerability in joserfc allows…

joserfc | Remote | Denial of Service
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
8.6 HIGH
CVE-2026-27905 — BentoML has an Arbitrary File Write via Symlink Path Traversal in Tar Extraction

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path i…

bentoml | Path Traversal
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
8.4 HIGH
CVE-2026-27622 — OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals…

openexr | Memory Corruption
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
8.2 HIGH
CVE-2026-27601 — Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack

Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an …

underscore | Remote | Denial of Service
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
5.0 MEDIUM
CVE-2026-27600 — HomeBox affected by Blind SSRF

HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticated users to specify arbitrary URLs to which the application sends HTTP POST req…

homebox | Remote | Server-Side Request Forgery
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
9.1 CRITICAL
CVE-2026-26279 — Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injec…

Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields de…

froxlor | Remote | Injection
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
5.4 MEDIUM
CVE-2026-26272 — HomeBox affected by Stored XSS via HTML/SVG Attachment Upload

HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerability exists in the item attachment upload functionality. The application does n…

homebox | Remote | Cross-Site Scripting
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
9.3 CRITICAL
CVE-2026-26266 — AliasVault affected by Cross-Site Scripting (XSS) via Email HTML Rendering

AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnerability was identified in the email rendering feature of AliasVault Web Client v…

aliasvault | Remote | Cross-Site Scripting
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
6.1 MEDIUM
CVE-2026-25590 — GLPI Inventory Plugin has Reflected XSS in task jobs

The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, there is a reflected XSS vulnerability in task jobs. This vul…

glpi_inventory | Remote | Cross-Site Scripting
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
7.2 HIGH
CVE-2026-3487 — itsourcecode College Management System class-result.php sql injection

A vulnerability was found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/class-result.php. Performing a manipulation of the argument cour…

college_management_system | Remote | Injection
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-3224 — Microsoft Entra ID Azure AD Authentication Bypass Vulnerability

Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID us…

devolutions_server | Remote | Authentication
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-3204 — Devolutions Server URL Spoofing Vulnerability

Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error message via a specially crafted URL.

devolutions_server | Remote | Information Disclosure
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-3130 — Devolutions Server PAM Account Deletion Vulnerability

Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked o…

devolutions_server | Remote | Authorization
Mar 03, 2026 Mar 04, 2026
Mar 03, 2026
Mar 04, 2026
9.8 CRITICAL
CVE-2026-2590 — Devolutions Remote Desktop Manager Password Persistence Vulnerability

Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and earlier allows an authenticated user to p…

remote_desktop_manager | Remote | Authentication
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-27012 — Unauthenticated privilege escalation in OpenSTAManager via modules/utenti/actions.php

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenSTAManager all…

openstamanager | Remote | Authentication
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
9.6 CRITICAL
CVE-2026-25146 — OpenEMR's payments gateway_api_key secret rendered into client JS code

OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret va…

openemr | Remote | Information Disclosure
Mar 03, 2026 Mar 04, 2026
Mar 03, 2026
Mar 04, 2026
10.0 CRITICAL
CVE-2026-24898 — OpenEMR has an Unauthenticated MedEx Token Disclosure

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerability in the MedEx callback endpoi…

openemr | Remote | Information Disclosure
Mar 03, 2026 Mar 04, 2026
Mar 03, 2026
Mar 04, 2026
Showing 20 of 5090 Results