Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-4044 — projectsend Delete import-orphans.php realpath path traversal

A vulnerability was detected in projectsend up to r1945. This affects the function realpath of the file /import-orphans.php of the component Delete Handler. Performing a manipulation of the argument …

| Path Traversal
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-4043 — Tenda i12 wifiSSIDget formwrlSSIDget stack-based overflow

A security vulnerability has been detected in Tenda i12 1.0.0.6(2204). The impacted element is the function formwrlSSIDget of the file /goform/wifiSSIDget. Such manipulation of the argument index lea…

| Memory Corruption
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.0 HIGH
CVE-2026-4042 — Tenda i12 WifiMacFilterGet formWifiMacFilterGet stack-based overflow

A weakness has been identified in Tenda i12 1.0.0.6(2204). The affected element is the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet. This manipulation of the argument index caus…

Remote | Memory Corruption
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.0 HIGH
CVE-2026-4041 — Tenda i12 exeCommand vos_strcpy stack-based overflow

A security flaw has been discovered in Tenda i12 1.0.0.6(2204). Impacted is the function vos_strcpy of the file /goform/exeCommand. The manipulation of the argument cmdinput results in stack-based bu…

Remote | Memory Corruption
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.4 CRITICAL
CVE-2026-28384 — Authenticated RCE via unsanitized compression_algorithm

An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to th…

Remote | Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.1 CRITICAL
CVE-2026-21671 — Veeam Backup & Replication HA Remote Code Execution (RCE) as Backup Administrator

A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.

Remote | Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
7.7 HIGH
CVE-2026-21670 — Apache SSH Credentials Extraction Vulnerability

A vulnerability allowing a low-privileged user to extract saved SSH credentials.

Remote | Information Disclosure
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.9 CRITICAL
CVE-2026-21669 — Citrix Backup Server Remote Code Execution Vulnerability

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

Remote | Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
8.8 HIGH
CVE-2026-21668 — Acronis Backup Arbitrary File Manipulation Vulnerability

A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.

Remote | Path Traversal
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.9 CRITICAL
CVE-2026-21667 — Backup Server Domain User RCE

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

Remote | Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.9 CRITICAL
CVE-2026-21666 — Apache Backup Server Remote Code Execution Vulnerability

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

Remote | Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
5.8 MEDIUM
CVE-2026-3099 — Libsoup: libsoup: authentication bypass via digest authentication replay attack

A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required incrementing nonce-co…

Remote | Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
6.1 MEDIUM
CVE-2026-2987 — Simple Ajax Chat <= 20260217 - Unauthenticated Stored Cross-Site Scripting via 'c'

The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'c' parameter in versions up to, and including, 20260217 due to insufficient input sanitization and outp…

Remote | Cross-Site Scripting
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
8.6 HIGH
CVE-2026-2514 — Possibility of unintended actions when viewing maliciously crafted network data in Progre…

In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed …

| Cross-Site Scripting
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
8.6 HIGH
CVE-2026-2513 — Possibility of unintended actions when an administrator clicks a malicious link in the Pr…

A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended a…

Remote | Cross-Site Request Forgery
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
6.3 MEDIUM
CVE-2026-0809 — Weak KSeF token encoding in Streamsoft Prestiż

Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-Faktur) token to be guessed after analyzing how tokens with know values are enco…

Remote | Cryptography
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
4.8 MEDIUM
CVE-2026-4040 — OpenClaw File Existence tools.exec.safeBins information exposure

A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the component File Existence Handler. The manipulation leads to information exposure…

| Information Disclosure
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
6.5 MEDIUM
CVE-2026-4039 — OpenClaw Skill Env applySkillConfigenvOverrides code injection

A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverrides of the component Skill Env Handler. Executing a manipulation can lead to c…

Remote | Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-3989 — CVE-2026-3989

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which wil…

| Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.8 CRITICAL
CVE-2026-3060 — CVE-2026-3060

SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without…

Remote | Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
Showing 20 of 5511 Results