Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.8 LOW
CVE-2026-0849 — crypto: ATAES132A response length allows stack buffer overflow

Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver, allowing a compromised device or bus attacker to corrupt kernel memory and po…

| Memory Corruption
Mar 14, 2026 Mar 14, 2026
Mar 14, 2026
Mar 14, 2026
5.3 MEDIUM
CVE-2026-1870 — Thim Kit for Elementor <= 1.3.7 - Missing Authorization to Unauthenticated Private Course…

The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing validation checks on the 'thim-ekit/archive…

Remote | Authorization
Mar 14, 2026 Mar 14, 2026
Mar 14, 2026
Mar 14, 2026
0.0 NA
CVE-2025-54920 — Apache Spark: Spark History Server Code Execution Vulnerability

This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.5.4 and earlier vers…

| Injection
Mar 14, 2026 Mar 14, 2026
Mar 14, 2026
Mar 14, 2026
4.3 MEDIUM
CVE-2026-1948 — NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Authe…

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_license() function in a…

Remote | Authorization
Mar 14, 2026 Mar 14, 2026
Mar 14, 2026
Mar 14, 2026
5.0 MEDIUM
CVE-2026-0385 — Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability

None

Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
0.0 NA
CVE-2026-32732 — XSS in @leanprover/unicode-input-component

Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the packa…

| Cross-Site Scripting
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
8.1 HIGH
CVE-2026-32729 — Runtipi has a TOTP two-factor authentication bypass via unrestricted brute-force on `/api…

Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting, or account lockout mechanism. An attack…

Remote | Authentication
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
5.3 MEDIUM
CVE-2026-32724 — PX4 autopilot has a heap Use-After-Free in MavlinkShell::available() via SERIAL_CONTROL R…

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc1, a heap-use-after-free is detected in the MavlinkShell::available() function. The issue is caused by a race condition betwee…

| Race Condition
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
8.5 HIGH
CVE-2026-3227 — Authenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840N

A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router conf…

| Injection
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
0.0 NA
CVE-2026-32720 — Improper Access Control in github.com/ctfer-io/monitoring

The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). Prior to 0.2.1, due to a mis-written NetworkPolic…

| Misconfiguration
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
4.2 MEDIUM
CVE-2026-32719 — AnythingLLM has a Zip Slip Path Traversal and Code Execution via Community Hub Plugin Imp…

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The ImportedPlugin.importCommunityItemFromUrl() func…

Remote | Path Traversal
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
2.7 LOW
CVE-2026-32717 — AnythingLLM access control bypass: suspended users can continue using Browser Extension A…

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, in multi-user mode, AnythingLLM blocks suspended use…

Remote | Authentication
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
3.8 LOW
CVE-2026-32715 — AnythingLLM Manager Privilege Bypass Allows Access to Admin-Only System Preferences

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The two generic system-preferences endpoints allow m…

Remote | Authorization
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
4.3 MEDIUM
CVE-2026-32713 — PX4 Autopilot MAVLink FTP Session Validation Logic Error Allows Operations on Invalid Fil…

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, A logic error in the PX4 Autopilot MAVLink FTP session validation uses incorrect boolean logic (&& instead of ||), allowing…

| Misconfiguration
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
5.4 MEDIUM
CVE-2026-32709 — PX4 Autopilot MAVLink FTP Unauthenticated Path Traversal (Arbitrary File Read/Write/Delet…

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, An unauthenticated path traversal vulnerability in the PX4 Autopilot MAVLink FTP implementation allows any MAVLink peer to …

| Path Traversal
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
7.8 HIGH
CVE-2026-32708 — Zenoh uORB Subscriber Allows Arbitrary Stack Allocation (PX4/PX4-Autopilot)

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack VLA directly from the incoming payload length without bounds. A remote Zenoh pu…

| Memory Corruption
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
5.2 MEDIUM
CVE-2026-32707 — PX4 autopilot has a stack buffer overflow in tattu_can due to unbounded memcpy in frame a…

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, tattu_can contains an unbounded memcpy in its multi-frame assembly loop, allowing stack memory overwrite when crafted CAN f…

| Memory Corruption
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
7.1 HIGH
CVE-2026-32706 — PX4 autopilot has a global buffer overflow in crsf_rc via oversized variable-length known…

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized variable-length known packet and copies it into a fixed 64-byte global buffer witho…

| Memory Corruption
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
6.8 MEDIUM
CVE-2026-32705 — PX4 autopilot BST Device Name Length Can Overflow Driver Buffer

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the BST telemetry probe writes a string terminator using a device-provided length without bounds. A malicious BST device ca…

| Memory Corruption
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
8.2 HIGH
CVE-2026-32616 — Pigeon has a Host Header Injection in email verification flow

Pigeon is a message board/notepad/social system/blog. Prior to 1.0.201, the application uses $_SERVER['HTTP_HOST'] without validation to construct email verification URLs in the register and resendma…

Remote | Server-Side Request Forgery
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
Showing 20 of 5314 Results