Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-28789 — OliveTin: Unauthenticated DoS via concurrent map writes in OAuth2 state handling

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated denial-of-service vulnerability exists in OliveTin’s OAuth2 login flow. Concurr…

olivetin | Remote | Race Condition
Mar 05, 2026 Mar 06, 2026
Mar 05, 2026
Mar 06, 2026
10.0 CRITICAL
CVE-2026-28353 — Trivy Vulnerability Scanner: Unauthorized AI Agent Execution Code Included in OpenVSX Ext…

Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX marketplace was compromised and contain…

Remote | Supply Chain
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
6.1 MEDIUM
CVE-2026-28350 — lxml_html_clean: <base> tag injection through default Cleaner configuration

lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the <base> tag passes through the default Cleaner configuration. While page_struc…

lxml_html_clean | Remote | Misconfiguration
Mar 05, 2026 Mar 06, 2026
Mar 05, 2026
Mar 06, 2026
6.1 MEDIUM
CVE-2026-28348 — lxml_html_clean: CSS @import Filter Bypass via Unicode Escapes

lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the _has_sneaky_javascript() method strips backslashes before checking for danger…

lxml_html_clean | Remote | Cross-Site Scripting
Mar 05, 2026 Mar 06, 2026
Mar 05, 2026
Mar 06, 2026
6.4 MEDIUM
CVE-2026-28343 — CKEditor: Cross-site scripting (XSS) in the HTML Support package

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support featur…

ckeditor5 | Remote | Cross-Site Scripting
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-28342 — OliveTin: Unauthenticated Denial of Service via Memory Exhaustion in PasswordHash API End…

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash API endpoint allows unauthenticated users to trigger excessive memory allocation …

olivetin | Remote | Denial of Service
Mar 05, 2026 Mar 06, 2026
Mar 05, 2026
Mar 06, 2026
6.8 MEDIUM
CVE-2026-28277 — LangGraph: Unsafe msgpack deserialization in LangGraph checkpoint loading

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, LangGraph checkpointers can load ms…

| Injection
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
6.1 MEDIUM
CVE-2026-28223 — Wagtail: Improper escaping of HTML (Cross-site Scripting) in simple_translation admin int…

Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on confirmation message…

wagtail | Remote | Cross-Site Scripting
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
6.1 MEDIUM
CVE-2026-28222 — Wagtail: Improper escaping of HTML (Cross-site Scripting) on TableBlock class attributes

Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a stored cross-site scripting (XSS) vulnerability exists on rendering TableBlock…

wagtail | Remote | Cross-Site Scripting
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
7.0 HIGH
CVE-2026-21621 — Improper Scope Enforcement in OAuth client_credentials Flow Allows Read-Only API Key to E…

Incorrect Authorization vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.API.OAuthController' module) allows Privilege Escalation. An API key created with read-only permissions (domain: "api", r…

hexpm | Remote | Authorization
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2025-29165 — D-Link DIR-1253 Privilege Escalation Vulnerability

An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component

Remote | Authentication
Mar 05, 2026 Mar 06, 2026
Mar 05, 2026
Mar 06, 2026
7.1 HIGH
CVE-2025-13350 — Use-after-free of orphaned AF_UNIX in Ubuntu builds of Linux kernel

Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d9b85c07 ("af_unix: Don’t call skb_get() for OOB skb"). When orphaned MSG_OOB sockets hit unix_gc(),…

| Memory Corruption
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
5.8 MEDIUM
CVE-2024-43035 — Fonoster File Traversal Vulnerability

Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file VoiceServer endpoint. This occurs in serveFiles in mods/voice/src/utils.ts. NOTE…

Remote | Path Traversal
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
8.1 HIGH
CVE-2026-3459 — Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.5 - Unauthenticated Arbitr…

The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function i…

Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
8.8 HIGH
CVE-2026-3047 — Org.keycloak.broker.saml: keycloak saml broker: authentication bypass due to disabled sam…

A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can stil…

keycloak | Remote | Authentication
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
8.1 HIGH
CVE-2026-3009 — Org.keycloak/keycloak-services: improper enforcement of disabled identity provider in ide…

A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. A…

Remote | Authentication
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-29054 — Traefik: lowercase `Connection` tokens can delete traefik-managed forwarded identity head…

Traefik is an HTTP reverse proxy and load balancer. From version 2.11.9 to 2.11.37 and from version 3.1.3 to 3.6.8, there is a potential vulnerability in Traefik managing the Connection header with X…

traefik | Remote | Misconfiguration
Mar 05, 2026 Mar 06, 2026
Mar 05, 2026
Mar 06, 2026
8.8 HIGH
CVE-2026-28287 — FreePBX: Authenticated Remote Code Execution via Recordings Module AJAX Endpoints

FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, multiple command injection vulnerabilities exist in the recordings module. This…

freepbx | Remote | Injection
Mar 05, 2026 Mar 06, 2026
Mar 05, 2026
Mar 06, 2026
8.8 HIGH
CVE-2026-28284 — FreePBX: Authenticated SQL Injection Vulnerabilities in FreePBX Logfiles Module

FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several authenticated SQL injection vulnerabilities. This issue has been patched in versio…

freepbx | Remote | Injection
Mar 05, 2026 Mar 06, 2026
Mar 05, 2026
Mar 06, 2026
8.8 HIGH
CVE-2026-28210 — FreePBX: Authenticated SQL Injection in CDR (Call Data Record) Reports

FreePBX is an open source IP PBX. Prior to versions 16.0.49 and 17.0.7, FreePBX module cdr (Call Data Record) is vulnerable to SQL query injection. This issue has been patched in versions 16.0.49 and…

freepbx cdr | Remote | Injection
Mar 05, 2026 Mar 06, 2026
Mar 05, 2026
Mar 06, 2026
Showing 20 of 5122 Results