Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.3 MEDIUM
CVE-2026-26227 — VLC for Android < 3.7.0 Remote Access OTP Authentication Bypass

VideoLAN VLC for Android prior to version 3.7.0 contains an authentication bypass in the Remote Access Server feature due to missing or insufficient rate limiting on one-time password (OTP) verificat…

vlc | Remote | Authentication
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.1 HIGH
CVE-2026-23750 — Golioth Pouch < [INSERT FIXED VERSION] BLE GATT Heap-based Buffer Overflow

Golioth Pouch version 0.1.0, prior to commit 1b2219a1, contains a heap-based buffer overflow in BLE GATT server certificate handling. server_cert_write() allocates a heap buffer of size CONFIG_POUCH_…

| Memory Corruption
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
2.9 LOW
CVE-2026-23749 — Golioth Firmware SDK < 0.22.0 Blockwise Transfer Path Out-of-Bounds Read

Golioth Firmware SDK version 0.19.1 prior to 0.22.0, fixed in commit 0e788217, contain an out-of-bounds read due to improper null termination of a blockwise transfer path. blockwise_transfer_init() a…

| Memory Corruption
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
6.3 MEDIUM
CVE-2026-23748 — Golioth Firmware SDK < 0.22.0 LightDB State Out-of-Bounds Read

Golioth Firmware SDK version 0.10.0 prior to 0.22.0, fixed in commit d7f55b38, contain an out-of-bounds read in LightDB State string parsing. When processing a string payload, a payload_size value le…

Remote | Memory Corruption
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
6.3 MEDIUM
CVE-2026-23747 — Golioth Firmware SDK < 0.22.0 Payload Utils Stack-based Buffer Overflow

Golioth Firmware SDK version 0.10.0 prior to 0.22.0, fixed in commit 48f521b, contain a stack-based buffer overflow in Payload Utils. The golioth_payload_as_int() and golioth_payload_as_float() helpe…

Remote | Memory Corruption
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
9.8 CRITICAL
CVE-2025-50857 — ZenTaoPMS Directory Traversal Vulnerability

ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attackers to execute arbitrary code via a crafted file upload

Remote | Path Traversal
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
4.3 MEDIUM
CVE-2026-28296 — Gvfs: ftp gvfs backend: arbitrary ftp command injection via crlf sequences in file paths

A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF)…

Remote | Injection
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
4.3 MEDIUM
CVE-2026-28295 — Gvfs: gvfs ftp backend: information disclosure via untrusted pasv responses

A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditi…

Remote | Server-Side Request Forgery
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.5 HIGH
CVE-2026-26265 — Discourse has IDOR vulnerability in the directory items endpoint

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerability in the directory items endpoint allows any user, including anonymous users,…

discourse | Remote | Authorization
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
4.9 MEDIUM
CVE-2026-26228 — VLC for Android < 3.7.0 Remote Access Path Traversal

VideoLAN VLC for Android prior to version 3.7.0 contains a path traversal vulnerability in the Remote Access Server routing for the authenticated endpoint GET /download. The file query parameter is c…

vlc | Remote | Path Traversal
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
5.4 MEDIUM
CVE-2026-26207 — DIscourse's discourse-policy plugin lacks post access check

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `discourse-policy` plugin allows any authenticated user to interact with policies on posts they d…

discourse | Remote | Authorization
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
7.5 HIGH
CVE-2026-26078 — Discourse has authentication bypass vulnerability in the Patreon plugin webhook endpoint

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_webhook_secret` site setting is blank, an attacker can forge valid webhook sign…

discourse | Remote | Authentication
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
8.2 HIGH
CVE-2025-71057 — D-Link Wireless N 300 ADSL2+ Modem Router Session Hijacking Vulnerability

Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a session hijacking attack via spoofing the IP address of an authenticated user.

Remote | Authentication
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
5.4 MEDIUM
CVE-2025-56605 — PuneethReddyHC Event Management System Reflected Cross-Site Scripting

A reflected Cross-Site Scripting (XSS) vulnerability exists in the register.php backend script of PuneethReddyHC Event Management System 1.0. The mobile POST parameter is improperly validated and ech…

Remote | Cross-Site Scripting
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.4 HIGH
CVE-2026-3071 — Flair LanguageModel Deserialization Remote Code Execution Vulnerability

Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when loading a malicious model.

| Injection
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.4 HIGH
CVE-2026-2244 — Sensitive Data Exposure in Google Cloud Vertex AI Workbench

A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid Google Cloud access tokens of other users via abuse of a built-in startup scrip…

Remote | Information Disclosure
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2026-26077 — Discourse doesn't ensure webhooks require a token

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook endpoints (SendGrid, Mailjet, Mandrill, Postmark, SparkPost) in the `WebhooksCont…

discourse | Remote | Authentication
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
6.1 MEDIUM
CVE-2026-2680 — Multiple vulnerabilities in A3factura software

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerVATNumber', in 'a3factura-app.wolterskluwer.es/#/incomes/salesDeliveryNotes' endpoint, which could allow an a…

a3factura a3factura | Remote | Cross-Site Scripting
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
6.1 MEDIUM
CVE-2026-2679 — Multiple vulnerabilities in A3factura software

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerName', in 'a3factura-app.wolterskluwer.es/#/incomes/salesInvoices' endpoint, which could allow an attacker to…

a3factura a3factura | Remote | Cross-Site Scripting
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
6.1 MEDIUM
CVE-2026-2678 — Multiple vulnerabilities in A3factura software

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', parameter 'name', in 'a3factura-app.wolterskluwer.es/#/incomes/customers' endpoint, which could allow an attac…

a3factura a3factura | Remote | Cross-Site Scripting
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
Showing 20 of 5068 Results