Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-31857 — CraftCMS has an RCE vulnerability via relational conditionals in the control panel

Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions system. The BaseElementSelectConditionRule::getElemen…

| Injection
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
0.0 NA
CVE-2026-31975 — Cloud CLI WebSocket shell injection

Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.25.0, OS Command Injection via WebSocket Shell. Both projectPath and initialCo…

| Injection
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
0.0 NA
CVE-2026-31861 — Shell Command Injection in Git Routes [CloudCLI UI]

Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, The /api/user/git-config endpoint constructs shell commands by interpola…

| Injection
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
0.0 NA
CVE-2026-31862 — Cloud CLI has Command Injection via Multiple Parameters

Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, multiple Git-related API endpoints use execAsync() with string interpola…

| Injection
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
4.2 MEDIUM
CVE-2026-3429 — Org.keycloak.services.resources.account: improper access control leading to mfa deletion …

A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specific…

Remote | Authentication
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
8.7 HIGH
CVE-2026-31854 — Cursor Affected by Arbitrary Code Execution via Prompt Injection and Whitelist Bypass

Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted instructions, the model may attempt to follow them in order to “assist” the user…

Remote | Injection
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
5.7 MEDIUM
CVE-2026-31853 — ImageMagick has a heap buffer over-write on 32-bit systems in SFW decoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, an overflow on 32-bit systems can cause a crash in the SFW decoder when…

| Memory Corruption
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
10.0 CRITICAL
CVE-2026-31852 — Jellyfin Possible Organization/Secret Compromise from dangerous CI implementation

Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requests from forked repositories. Du…

Remote | Supply Chain
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
9.3 CRITICAL
CVE-2026-31840 — Parse Server has a SQL injection via dot-notation field name in PostgreSQL

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacker can use a dot-notation field name in combination…

Remote | Injection
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
8.2 HIGH
CVE-2026-31839 — Striae has a hash validation utility vulnerability

Striae is a firearms examiner's comparison companion. A high-severity integrity bypass vulnerability existed in Striae's digital confirmation workflow prior to v3.0.0. Hash-only validation trusted ma…

| Supply Chain
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
4.8 MEDIUM
CVE-2026-31813 — Supabase Auth has insecure Apple and Azure authentication with ID tokens

Supabase Auth is a JWT based API for managing users and issuing JWT tokens. Prior to 2.185.0, a vulnerability has been identified that allows an attacker to issue sessions for arbitrary users using s…

Remote | Authentication
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
6.3 MEDIUM
CVE-2026-30868 — Cross-Site Request Forgery (CSRF) in opnsense/core

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, multiple OPNsense MVC API endpoints perform state‑changing operations but are accessible via HTTP GET requests without CSRF…

Remote | Cross-Site Request Forgery
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
6.5 MEDIUM
CVE-2026-30239 — OpenProject has a Permission Check bypass on Budget deletion allows reassignment of WorkP…

OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the work packages that were assigned to this budget need to be moved to a different bu…

Remote | Authorization
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
4.3 MEDIUM
CVE-2026-30236 — OpenProject users that are not project members can be used to calculate Labor Budget, lea…

OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when editing a project budget and planning the labor cost, it was not checked that the user that was planned in …

Remote | Authorization
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
6.5 MEDIUM
CVE-2026-30235 — Business Logic Error on OpenProject through hyperlinks in markdown using DOM clobbering

OpenProject is an open-source, web-based project management software. Prior to 17.2.0, this vulnerability occurs due to improper validation of OpenProject’s Markdown rendering, specifically in the hy…

Remote | Cross-Site Scripting
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
5.4 MEDIUM
CVE-2026-20166 — Sensitive Information Disclosure in Discover Splunk Observability Cloud app for Splunk En…

In Splunk Enterprise versions below 10.2.1 and 10.0.4, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.16, and 10.0.2503.12, a low-privileged user that does not hold the "admin" or "p…

| Authorization
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
6.3 MEDIUM
CVE-2026-20165 — Sensitive Information Disclosure in MongoClient logging channel in Splunk Enterprise

In Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.7, 10.1.2507.17, 10.0.2503.12, and 9.3.2411.124, a low-privileged user that d…

| Information Disclosure
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
6.5 MEDIUM
CVE-2026-20164 — Sensitive Information Disclosure through Improper Access Control in Splunk Enterprise

In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.16, 10.0.2503.11, and 9.3.2411.123, a low-privileged user that d…

| Information Disclosure
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
8.0 HIGH
CVE-2026-20163 — Remote Command Execution (RCE) through the '/splunkd/__upload/indexing/preview' REST endp…

In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.0.2503.12, 10.1.2507.16, and 9.3.2411.124, a user who holds a role that…

| Authorization
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
6.3 MEDIUM
CVE-2026-20162 — Stored Cross-Site Scripting (XSS) through Path Traversal in Splunk Enterprise

In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.9, and Splunk Cloud Platform versions below 10.2.2510.4, 10.1.2507.15, 10.0.2503.11, and 9.3.2411.123, a low-privileged user who doe…

| Cross-Site Scripting
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
Showing 20 of 5449 Results