Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.0 HIGH
CVE-2026-3698 — UTT HiPER 810G NTP strcpy buffer overflow

A vulnerability was identified in UTT HiPER 810G up to 1.7.7-171114. This affects the function strcpy of the file /goform/NTP. The manipulation leads to buffer overflow. The attack may be initiated r…

Remote | Memory Corruption
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
6.5 MEDIUM
CVE-2026-3697 — Planet ICG-2510 Language Package Configuration httpd sub_40C8E4 stack-based overflow

A vulnerability was determined in Planet ICG-2510 1.0_20250811. The impacted element is the function sub_40C8E4 of the file /usr/sbin/httpd of the component Language Package Configuration Handler. Ex…

Remote | Memory Corruption
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
0.0 NA
CVE-2026-30910 — Crypt::Sodium::XS versions through 0.001000 for Perl has potential integer overflows

Crypt::Sodium::XS versions through 0.001000 for Perl has potential integer overflows. Combined aead encryption, combined signature creation, and bin2hex functions do not check that output size will …

| Memory Corruption
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
7.5 HIGH
CVE-2026-3696 — Totolink N300RH CGI cstecgi.cgi setWiFiWpsConfig os command injection

A vulnerability was found in Totolink N300RH 6..1c.1353_B20190305. The affected element is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a ma…

n300rh_firmware | Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
6.9 MEDIUM
CVE-2026-3695 — SourceCodester Modern Image Gallery App delete.php path traversal

A vulnerability has been found in SourceCodester Modern Image Gallery App 1.0. Impacted is an unknown function of the file /delete.php. Such manipulation of the argument filename leads to path traver…

modern_image_gallery_app | Remote | Path Traversal
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
7.5 HIGH
CVE-2026-3693 — Shy2593666979 AgentChat User Endpoint user.py update_user_info resource injection

A flaw has been found in Shy2593666979 AgentChat up to 2.3.0. This issue affects the function get_user_info/update_user_info of the file /src/backend/agentchat/api/v1/user.py of the component User En…

Remote | Authorization
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
0.0 NA
CVE-2026-30909 — Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows

Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows. bin2hex, encrypt, aes256gcm_encrypt_afternm and seal functions do not check that output size will be less than SI…

crypt\ | Memory Corruption
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
6.5 MEDIUM
CVE-2026-3683 — bufanyun HotGo Endpoint upload.go ImageTransferStorage server-side request forgery

A vulnerability was detected in bufanyun HotGo up to 2.0. This issue affects the function ImageTransferStorage of the file /server/internal/logic/common/upload.go of the component Endpoint. The manip…

Remote | Server-Side Request Forgery
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
6.5 MEDIUM
CVE-2026-3682 — welovemedia FFmate ffmpeg.go Execute argument injection

A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. This vulnerability affects the function Execute of the file /internal/service/ffmpeg/ffmpeg.go. The manipulation leads t…

Remote | Injection
Mar 08, 2026 Mar 08, 2026
Mar 08, 2026
Mar 08, 2026
6.5 MEDIUM
CVE-2026-3681 — welovemedia FFmate webhook.go fireWebhook server-side request forgery

A weakness has been identified in welovemedia FFmate up to 2.0.15. This affects the function fireWebhook of the file /internal/service/webhook/webhook.go. Executing a manipulation can lead to server-…

Remote | Server-Side Request Forgery
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
6.5 MEDIUM
CVE-2026-3680 — RyuzakiShinji biome-mcp-server biome-mcp-server.ts command injection

A security flaw has been discovered in RyuzakiShinji biome-mcp-server up to 1.0.0. Affected by this issue is some unknown functionality of the file biome-mcp-server.ts. Performing a manipulation resu…

Remote | Injection
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
9.0 HIGH
CVE-2026-3679 — Tenda FH451 QuickIndex formQuickIndex stack-based overflow

A vulnerability was identified in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function formQuickIndex of the file /goform/QuickIndex. Such manipulation of the argument mit_linktype/PPP…

fh451_firmware | Remote | Memory Corruption
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
9.0 HIGH
CVE-2026-3678 — Tenda FH451 AdvSetWan sub_3C434 stack-based overflow

A vulnerability was determined in Tenda FH451 1.0.0.9. Affected is the function sub_3C434 of the file /goform/AdvSetWan. This manipulation of the argument wanmode/PPPOEPassword causes stack-based buf…

fh451_firmware | Remote | Memory Corruption
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
9.0 HIGH
CVE-2026-3677 — Tenda FH451 setcfm fromSetCfm stack-based overflow

A vulnerability was found in Tenda FH451 1.0.0.9. This impacts the function fromSetCfm of the file /goform/setcfm. The manipulation of the argument funcname/funcpara1 results in stack-based buffer ov…

fh451_firmware | Remote | Memory Corruption
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
5.3 MEDIUM
CVE-2026-3675 — Freedom Factory dGEN1 org.ethosmobile.ethoslauncher FakeAppReceiver improper authorization

A vulnerability was determined in Freedom Factory dGEN1 up to 20260221. Affected by this issue is the function FakeAppReceiver of the component org.ethosmobile.ethoslauncher. Executing a manipulation…

| Authorization
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
5.3 MEDIUM
CVE-2026-3674 — Freedom Factory dGEN1 org.ethosmobile.ethoslauncher FakeAppProvider improper authorization

A vulnerability was found in Freedom Factory dGEN1 up to 20260221. Affected by this vulnerability is the function FakeAppProvider of the component org.ethosmobile.ethoslauncher. Performing a manipula…

| Authorization
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
6.5 MEDIUM
CVE-2026-3672 — JeecgBoot getDictItems isExistSqlInjectKeyword sql injection

A vulnerability has been found in JeecgBoot up to 3.9.1. Affected is the function isExistSqlInjectKeyword of the file /jeecg-boot/sys/api/getDictItems. Such manipulation leads to sql injection. The a…

jeecg_boot | Remote | Injection
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
3.3 LOW
CVE-2026-3671 — Freedom Factory dGEN1 org.ethereumphone.walletmanager.testing123 TokenBalanceContentProvi…

A flaw has been found in Freedom Factory dGEN1 up to 20260221. Affected by this vulnerability is the function TokenBalanceContentProvider of the component org.ethereumphone.walletmanager.testing123. …

| Authorization
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
5.3 MEDIUM
CVE-2026-3670 — Freedom Factory dGEN1 com.dgen.alarm improper authorization

A vulnerability was detected in Freedom Factory dGEN1 up to 20260221. Affected is an unknown function of the component com.dgen.alarm. Performing a manipulation results in improper authorization. The…

| Authorization
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
5.3 MEDIUM
CVE-2026-3669 — Freedom Factory dGEN1 com.dgen.alarm AlarmService improper authorization

A security vulnerability has been detected in Freedom Factory dGEN1 up to 20260221. This impacts the function AlarmService of the component com.dgen.alarm. Such manipulation leads to improper authori…

| Authorization
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
Showing 20 of 5087 Results