Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-31860 — Unhead has a XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive …

Unhead is a document head and template manager. Prior to 2.1.11, useHeadSafe() can be bypassed to inject arbitrary HTML attributes, including event handlers, into SSR-rendered <head> tags. This is th…

Remote | Cross-Site Scripting
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
6.9 MEDIUM
CVE-2026-28256 — Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Co…

A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.

Remote | Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
8.2 HIGH
CVE-2026-28255 — Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Co…

A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.

Remote | Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
6.9 MEDIUM
CVE-2026-28254 — Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge

A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.

Remote | Authorization
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
8.7 HIGH
CVE-2026-28253 — Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+,…

A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to cause a denial-of-service condition

Remote | Denial of Service
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.2 CRITICAL
CVE-2026-28252 — Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer…

A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to th…

Remote | Cryptography
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-26795 — GL-iNet GL-AR300M16 Command Injection Vulnerability

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. This vulnerability allows attackers to execute arbit…

| Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-26794 — GL-iNet GL-AR300M16 SQL Injection Vulnerability

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execute arbitrary SQL database operations via …

| Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-26792 — GL-iNet GL-AR300M16 Command Injection Vulnerability

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_version, firmware_upload, hash_…

| Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-26791 — GL-iNet GL-AR300M16 Command Injection Vulnerability

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server function. This vulnerability allows attackers to execut…

| Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
2.0 LOW
CVE-2025-13462 — tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result i…

| Misconfiguration
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
6.3 MEDIUM
CVE-2026-4045 — projectsend Auth.php response discrepancy

A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php. Executing a manipulation of the argument ldap_email can lead to observable re…

Remote | Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
6.5 MEDIUM
CVE-2026-31841 — Raw exposure of database statements in Hyperterse MCP search tool

Hyperterse is a tool-first MCP framework for building AI-ready backend surfaces from declarative config. Prior to v2.2.0, the search tool allows LLMs to search for tools using natural language. While…

Remote | Information Disclosure
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
6.2 MEDIUM
CVE-2026-29066 — Arbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLI

Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite's built-in filesystem access restriction. Th…

| Misconfiguration
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
8.4 HIGH
CVE-2026-28793 — Path Traversal Leading to Arbitrary File Read, Write and Delete in TinaCMS

Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path traversal, allowing attackers to read and write ar…

| Path Traversal
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.6 CRITICAL
CVE-2026-28792 — Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS

Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Allow-Origin: *) with the path traversal vulnerabili…

Remote | Path Traversal
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
7.4 HIGH
CVE-2026-28791 — Path Traversal in Media Upload Handle in Tina

Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS development server's media upload handler. The code at media.ts joins user-controlle…

Remote | Path Traversal
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
7.5 HIGH
CVE-2026-28356 — ReDoS in multipart 1.3.0 - `parse_options_header()`

multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alterna…

Remote | Denial of Service
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
7.8 HIGH
CVE-2026-27940 — llama.cpp has a Heap Buffer Overflow via Integer Overflow in `mem_size` Calculation — Byp…

llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is vulnerable to an Integer overflow, leading to an undersized heap allocation. Us…

| Memory Corruption
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
8.1 HIGH
CVE-2026-25529 — Postal has HTML injection / XSS in message view

Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed unescaped data to be included in the admin interface. The primary way for unescap…

Remote | Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
Showing 20 of 5431 Results