Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.1 MEDIUM
CVE-2025-12455 — Username Enumeration Observable Response Discrepancy vulnerability has been discovered in…

Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing.   The vulnerability could lead to Password Brute Forcing in Vertica management console application.Th…

Remote | Authentication
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
5.1 MEDIUM
CVE-2025-12454 — Improper neutralization of input during web page generation vulnerability has been discov…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS.  The vulnerability could lead to Reflected XSS attack of …

Remote | Cross-Site Scripting
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
5.1 MEDIUM
CVE-2025-12453 — Improper neutralization of input during web page generation vulnerability has been discov…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS.  The vulnerability could lead to Reflected XSS attack of …

Remote | Cross-Site Scripting
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
5.4 MEDIUM
CVE-2023-40693 — IBM Sterling B2B Integrator and IBM Sterling File Gateway Cross-Site Scripting

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1 are vulnerable to cross-site scripting. This vulnerabilit…

Remote | Cross-Site Scripting
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
0.0 NA
CVE-2026-32314 — Yamux remote Panic via malformed Data frame with SYN set and len = 262145

Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. Prior to 0.13.10, the Rust implementation of Yamux can panic when processing a crafted inbound Data frame that sets SY…

| Denial of Service
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
8.2 HIGH
CVE-2026-32313 — xmlseclibs is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for…

xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the …

Remote | Cryptography
Mar 13, 2026 Mar 13, 2026
Mar 13, 2026
Mar 13, 2026
10.0 CRITICAL
CVE-2026-3611 — Honeywell IQ4x BMS Controller Missing authentication for critical function

The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With no user module configured, security is disabled by …

Remote | Authentication
Mar 12, 2026 Mar 13, 2026
Mar 12, 2026
Mar 13, 2026
5.9 MEDIUM
CVE-2026-2581 — undici is vulnerable to Unbounded Memory Consumption in in Undici's DeduplicationHandler …

This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulnerable Undici versions, when interceptors.deduplicate() is enabled, response dat…

Remote | Denial of Service
Mar 12, 2026 Mar 13, 2026
Mar 12, 2026
Mar 13, 2026
7.5 HIGH
CVE-2026-2229 — undici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid ser…

ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket …

Remote | Denial of Service
Mar 12, 2026 Mar 13, 2026
Mar 12, 2026
Mar 13, 2026
7.5 HIGH
CVE-2026-1528 — undici is vulnerable to Malicious WebSocket 64-bit length overflows undici parser and cra…

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fata…

Remote | Denial of Service
Mar 12, 2026 Mar 13, 2026
Mar 12, 2026
Mar 13, 2026
4.6 MEDIUM
CVE-2026-1527 — undici is vulnerable to CRLF Injection via upgrade option

ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences (\r\n) to: * Inject arbitrary HTTP headers * Terminate t…

Remote | Injection
Mar 12, 2026 Mar 13, 2026
Mar 12, 2026
Mar 13, 2026
7.5 HIGH
CVE-2026-1526 — undici is vulnerable to Unbounded Memory Consumption in undici WebSocket permessage-defla…

The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage…

Remote | Denial of Service
Mar 12, 2026 Mar 13, 2026
Mar 12, 2026
Mar 13, 2026
8.7 HIGH
CVE-2026-32274 — Black: Arbitrary file writes from unsanitized user input in cache file name

Black is the uncompromising Python code formatter. Prior to 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics opt…

Remote | Misconfiguration
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
6.5 MEDIUM
CVE-2026-32269 — Parse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.13 and 8.6.39, the OAuth2 authentication adapter does not correctly valida…

parse-server | Remote | Authentication
Mar 12, 2026 Mar 13, 2026
Mar 12, 2026
Mar 13, 2026
8.1 HIGH
CVE-2026-32260 — Command Injection via incomplete shell metacharacter blocklist in node:child_process (byp…

Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.7.0 to 2.7.1, A command injection vulnerability exists in Deno's node:child_process polyfill (shell: true mode) that bypasses the fi…

Remote | Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
6.7 MEDIUM
CVE-2026-32259 — ImageMagick has a possible stack buffer overflow in sixel encoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, when a memory allocation fails in the sixel encoder it would be possibl…

| Memory Corruption
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.3 CRITICAL
CVE-2026-32251 — Tolgee has an XXE Injection in Translation Import

Tolgee is an open-source localization platform. Prior to 3.166.3, the XML parsers used for importing Android XML resources (.xml) and .resx files don't disable external entity processing. An authenti…

Remote | XML External Entity
Mar 12, 2026 Mar 13, 2026
Mar 12, 2026
Mar 13, 2026
5.3 MEDIUM
CVE-2026-32249 — NFA regex engine NULL pointer dereference affects Vim < 9.2.0137

Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a chara…

| Memory Corruption
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.8 CRITICAL
CVE-2026-32248 — Parse Server: Account takeover via operator injection in authentication data identifier

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account …

parse-server | Remote | Authentication
Mar 12, 2026 Mar 13, 2026
Mar 12, 2026
Mar 13, 2026
6.3 MEDIUM
CVE-2026-32240 — Cap'n Proto: Integer overflow in KJ-HTTP chunk size

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a chunk's size parsed to a value of 2^64 or larger, it would be tru…

Remote | Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
Showing 20 of 5479 Results