Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-28253 — Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+,…

A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to cause a denial-of-service condition

Remote | Denial of Service
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.2 CRITICAL
CVE-2026-28252 — Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer…

A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to th…

Remote | Cryptography
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-26795 — GL-iNet GL-AR300M16 Command Injection Vulnerability

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. This vulnerability allows attackers to execute arbit…

| Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-26794 — GL-iNet GL-AR300M16 SQL Injection Vulnerability

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execute arbitrary SQL database operations via …

| Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-26792 — GL-iNet GL-AR300M16 Command Injection Vulnerability

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_version, firmware_upload, hash_…

| Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-26791 — GL-iNet GL-AR300M16 Command Injection Vulnerability

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server function. This vulnerability allows attackers to execut…

| Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
2.0 LOW
CVE-2025-13462 — tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result i…

| Misconfiguration
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
6.3 MEDIUM
CVE-2026-4045 — projectsend Auth.php response discrepancy

A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php. Executing a manipulation of the argument ldap_email can lead to observable re…

Remote | Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
6.5 MEDIUM
CVE-2026-31841 — Raw exposure of database statements in Hyperterse MCP search tool

Hyperterse is a tool-first MCP framework for building AI-ready backend surfaces from declarative config. Prior to v2.2.0, the search tool allows LLMs to search for tools using natural language. While…

Remote | Information Disclosure
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
6.2 MEDIUM
CVE-2026-29066 — Arbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLI

Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite's built-in filesystem access restriction. Th…

| Misconfiguration
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
8.4 HIGH
CVE-2026-28793 — Path Traversal Leading to Arbitrary File Read, Write and Delete in TinaCMS

Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path traversal, allowing attackers to read and write ar…

| Path Traversal
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.6 CRITICAL
CVE-2026-28792 — Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS

Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Allow-Origin: *) with the path traversal vulnerabili…

Remote | Path Traversal
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
7.4 HIGH
CVE-2026-28791 — Path Traversal in Media Upload Handle in Tina

Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS development server's media upload handler. The code at media.ts joins user-controlle…

Remote | Path Traversal
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
7.5 HIGH
CVE-2026-28356 — ReDoS in multipart 1.3.0 - `parse_options_header()`

multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alterna…

Remote | Denial of Service
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
7.8 HIGH
CVE-2026-27940 — llama.cpp has a Heap Buffer Overflow via Integer Overflow in `mem_size` Calculation — Byp…

llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is vulnerable to an Integer overflow, leading to an undersized heap allocation. Us…

| Memory Corruption
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
8.1 HIGH
CVE-2026-25529 — Postal has HTML injection / XSS in message view

Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed unescaped data to be included in the admin interface. The primary way for unescap…

Remote | Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
6.3 MEDIUM
CVE-2026-24125 — Path Traversal in @tinacms/graphql

Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content documents using relative file paths (relativePath, newRelativePath) via GraphQ…

Remote | Path Traversal
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
7.7 HIGH
CVE-2026-21887 — OpenCTI has a Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.8.16, the OpenCTI platform’s data ingestion feature accepts user-supplied URLs without …

Remote | Server-Side Request Forgery
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.9 CRITICAL
CVE-2026-21708 — Postgres Backup Viewer Remote Code Execution (RCE)

A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.

Remote | Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
8.8 HIGH
CVE-2026-21672 — Veeam Backup & Replication Windows Local Privilege Escalation Vulnerability

A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.

| Authorization
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
Showing 20 of 5435 Results