Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-30863 — Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authenticatio…

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, the Google, Apple, and Facebook authentication ada…

Remote | Authentication
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
9.9 CRITICAL
CVE-2026-30861 — WeKnora: Remote Code Execution (RCE) via Command Injection in MCP Stdio Configuration Val…

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 to before version 0.2.10, an unauthenticated remote code execution (RCE) vulner…

Remote | Injection
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
9.9 CRITICAL
CVE-2026-30860 — WeKnora: Remote Code Execution via SQL Injection Bypass in AI Database Query Tool

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution (RCE) vulnerability exists in the application's d…

Remote | Injection
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
5.3 MEDIUM
CVE-2026-30859 — WeKnora: Broken Access Control - Cross-Tenant Data Exposure

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a broken access control vulnerability in the database query tool allows a…

Remote | Authorization
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
6.5 MEDIUM
CVE-2026-30858 — WeKnora: DNS Rebinding Vulnerability in web_fetch Tool Allows SSRF to Internal Resources

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a DNS rebinding vulnerability in the web_fetch tool allows an unauthentica…

Remote | Server-Side Request Forgery
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
5.3 MEDIUM
CVE-2026-30857 — WeKnora: Unauthorized Cross‑Tenant Knowledge Base Cloning

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a cross-tenant authorization bypass in the knowledge base copy endpoint al…

Remote | Authorization
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
5.9 MEDIUM
CVE-2026-30856 — WeKnora: Tool Execution Hijacking via Ambigous Naming Convention In MCP client and Indire…

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a vulnerability involving tool name collision and indirect prompt injecti…

Remote | Injection
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
8.8 HIGH
CVE-2026-30855 — WeKnora: Broken Access Control in Tenant Management

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass in tenant management endpoints of WeKnora applicat…

Remote | Authorization
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
6.9 MEDIUM
CVE-2026-30854 — Parse Server: GraphQL `__type` introspection bypass via inline fragments when public intr…

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.3.1-alpha.3 to before version 9.5.0-alpha.10, when graphQLPublicIntrospection is…

Remote | Information Disclosure
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
5.5 MEDIUM
CVE-2026-30852 — Caddy: vars_regexp double-expands user input, leaking env vars and files

Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_regexp matcher in vars.go:337 double-expands user-controlled input through the C…

Remote | Information Disclosure
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
8.1 HIGH
CVE-2026-30851 — Caddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity…

Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplied headers, allowing identity inje…

Remote | Authentication
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
6.3 MEDIUM
CVE-2026-30850 — Parse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authoriz…

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.9 and 9.5.0-alpha.9, the file metadata endpoint (GET /files/:appId/metada…

Remote | Authorization
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
6.3 MEDIUM
CVE-2026-30848 — Parse Server: `PagesRouter` path traversal allows reading files outside configured pages …

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.8 and 9.5.0-alpha.8, the PagesRouter static file serving route is vulnera…

Remote | Path Traversal
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
8.7 HIGH
CVE-2026-29196 — Netmaker: Service User with Network Access Can Access config files with WireGuard Private…

Netmaker makes networks with WireGuard. Prior to version 1.5.0, a user assigned the platform-user role can retrieve WireGuard private keys of all wireguard configs in a network by calling GET /api/ex…

Remote | Information Disclosure
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
6.9 MEDIUM
CVE-2026-29195 — Netmaker: Privilege Escalation from Admin to Super-Admin via User Update

Netmaker makes networks with WireGuard. Prior to version 1.5.0, the user update handler (PUT /api/users/{username}) lacks validation to prevent an admin-role user from assigning the super-admin role …

Remote | Authorization
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
3.1 LOW
CVE-2026-3668 — Freedom Factory dGEN1 org.ethosmobile.webpwaemul AndroidEthereum access control

A weakness has been identified in Freedom Factory dGEN1 up to 20260221. This affects the function AndroidEthereum of the component org.ethosmobile.webpwaemul. This manipulation causes improper access…

Remote | Authorization
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
5.3 MEDIUM
CVE-2026-3667 — Freedom Factory dGEN1 org.ethosmobile.ethoslauncher FakeAppService improper authorization

A security flaw has been discovered in Freedom Factory dGEN1 up to 20260221. The impacted element is the function FakeAppService of the component org.ethosmobile.ethoslauncher. The manipulation resul…

| Authorization
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
4.8 MEDIUM
CVE-2026-3665 — xlnt-community xlnt XLSX File xlsx_consumer.cpp read_office_document null pointer derefer…

A vulnerability was identified in xlnt-community xlnt up to 1.6.1. The affected element is the function xlnt::detail::xlsx_consumer::read_office_document of the file source/detail/serialization/xlsx_…

| Memory Corruption
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
5.1 MEDIUM
CVE-2026-30838 — league/commonmark: DisallowedRawHtml extension bypass via whitespace in HTML tag names

league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallow…

commonmark | Remote | Cross-Site Scripting
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
7.5 HIGH
CVE-2026-30834 — PinchTab: SSRF with Full Response Exfiltration via Download Handler

PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Prior to version 0.7.7, a Server-Side Request Forgery (SSRF) vulnerability in the /download endpoint al…

Remote | Server-Side Request Forgery
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
Showing 20 of 5121 Results