Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-30927 — Admidio: Event participation IDOR - non-leaders can register other users for events via u…

Admidio is an open-source user management solution. Prior to 5.0.6, in modules/events/events_function.php, the event participation logic allows any user who can participate in an event to register OT…

| Authorization
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-30925 — Parse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query …

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-alpha.14 and 8.6.11, a malicious client can subscribe to a LiveQuery with a craf…

| Denial of Service
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-30921 — OneUptime Synthetic Monitor RCE via exposed Playwright browser object

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project users to submit custom Playwright code that is execute…

| Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-30920 — OneUptime has broken access control in GitHub App installation flow that allows unauthori…

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.…

| Authorization
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-30919 — facileManager Affected by Stored Cross-Site Scripting (XSS)

facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as persistent or second-order XSS) occurs when an application receives data from …

| Cross-Site Scripting
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-30918 — facileManager Affected by Reflected Cross-Site Scripting (XSS)

facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs when an application receives data from an untrusted source and uses it in its HTT…

| Cross-Site Scripting
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-30917 — Stored XSS on Bucket namespace pages

Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to 2.1.1, a stored XSS can be inserted into any Bucket table field that has a PAGE type, which will execute wh…

| Cross-Site Scripting
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-30916 — Shescape has possible misidentification of shell due to link chains

Shescape is a simple shell escape library for JavaScript. Prior to 2.1.9, an attacker may be able to bypass escaping for the shell being used. This can result, for example, in exposure of sensitive i…

| Information Disclosure
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-30913 — flarum/nickname: Display name injection in notification emails (autolink & markdown)

Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their nickname to a string that email clients interpret as a hyperlink. The nickname is…

| Cross-Site Scripting
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-30887 — OneUptime Affected by Unsandboxed Code Execution in Probe Allows Any Project Member to Ac…

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/JavaScript code via Synthetic Monitors to test website…

| Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-30885 — WWBN AVideo - Unauthenticated IDOR - Playlist Information Disclosure

WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user without requiring authentication or authorization. An …

| Authorization
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-30870 — Some sync filters in PowerSync Service ignored using `config.edition: 3`

PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync streams with config.edition: 3, certain subquery filters were ignored when determin…

| Authorization
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
6.8 MEDIUM
CVE-2026-28267 — QNAP i-フィルター Privilege Escalation Vulnerability

Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwritten in the system directory or backup directory by a non-administrative user.

| Misconfiguration
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-30869 — SiYuan has a Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Lea…

SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read arbitrary files from the server filesystem. By exp…

| Path Traversal
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-30862 — Critical Stored XSS & Privilege Escalation in Appsmith

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table Widget (TableWidgetV2). The root cause is a lack o…

| Cross-Site Scripting
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-29773 — kubewarden-controller cross-namespace data exfiltration via deprecated host callback bind…

Kubewarden is a policy engine for Kubernetes. Kubewarden cluster operators can grant permissions to users to deploy namespaced AdmissionPolicies and AdmissionPolicyGroups in their Namespaces. One of …

| Authorization
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-28513 — Pocket ID: OIDC authorization code validation uses AND instead of OR, allowing cross-clie…

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, the OIDC token endpoint rejects an authorization code only when both the client I…

| Authentication
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-28512 — Pocket ID: OAuth redirect_uri validation bypass via userinfo/host confusion

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to before 2.4.0, a flaw in callback URL validation allowed crafted redirect_uri values…

| Authentication
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-28281 — InstantCMS has Multiple CSRF Vulnerabilities

InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF tokens, which allows attackers grant moderator privileges to users, execute schedule…

| Cross-Site Request Forgery
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
9.1 CRITICAL
CVE-2025-11158 — Hitachi Vantara Pentaho Data Integration & Analytics - Missing Authorization

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of …

Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
Showing 20 of 5070 Results