Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-32242 — Parse Server OAuth2 adapter shares mutable state across providers via singleton instance

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.11 and 8.6.37, Parse Server's built-in OAuth2 auth adapter exports a singl…

| Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-32237 — @backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets usi…

Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to execute scaffolder dry-runs can gain access to server-configured environment secr…

| Information Disclosure
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-32236 — @backstage/plugin-auth-backend: SSRF in experimental CIMD metadata fetch

Backstage is an open framework for building developer portals. Prior to 0.27.1, a Server-Side Request Forgery (SSRF) vulnerability exists in @backstage/plugin-auth-backend when auth.experimentalClien…

| Server-Side Request Forgery
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-32235 — @backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass

Backstage is an open framework for building developer portals. Prior to 0.27.1, the experimental OIDC provider in @backstage/plugin-auth-backend is vulnerable to a redirect URI allowlist bypass. Inst…

| Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-32138 — NEXULEAN API Key Leak

NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. Prior to 2.0.0, a security vulnerability was identified where Firebase and Web3F…

| Misconfiguration
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
2.7 LOW
CVE-2026-3497 — Linux OpenSSH GSSAPI Memory Corruption

Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH u…

Remote | Memory Corruption
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-32232 — ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink

ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink Alias Bypass. This vulnerability is fixed in 0.7.6.

| Misconfiguration
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-32231 — ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is c…

ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields (sender, chat_id) from the request body and applies authorization checks to th…

| Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-32142 — shopware/commercial: `/api/_info/config` route exposes information about licenses

Shopware is an open commerce platform. /api/_info/config route exposes information about licenses. This vulnerability is fixed in 7.8.1 and 6.10.15.

| Information Disclosure
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
6.3 MEDIUM
CVE-2025-13913 — Inductive Automation Ignition Software Deserialization of Untrusted Data

Inductive Automation Ignition Software is vulnerable to an unauthenticated API endpoint exposure that may allow an attacker to remotely change the "forgot password" recovery email address.

| Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
8.5 HIGH
CVE-2026-3841 — Command Injection Vulnerability in Telnet CLI on TP-Link TL-MR6400

A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by insufficient sanitization of data processed during…

| Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
7.5 HIGH
CVE-2026-32141 — flatted: Unbounded recursion DoS in parse() revive phase

flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with de…

Remote | Denial of Service
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.3 CRITICAL
CVE-2026-32140 — Dataease: Redshift JDBC RCE Bypass

Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to load an attacker-controlled configuration…

Remote | Misconfiguration
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
5.3 MEDIUM
CVE-2026-32139 — Dataease: Unfiltered active SVG content leads to Stored XSS

Dataease is an open source data visualization analysis tool. In DataEase 2.10.19 and earlier, the static resource upload interface allows SVG uploads. However, backend validation only checks whether …

Remote | Cross-Site Scripting
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.3 CRITICAL
CVE-2026-32137 — DataEase SQL Injection Vulnerability

Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasource/previewData is directly concatenated into the SQL statement without any filte…

Remote | Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
8.7 HIGH
CVE-2026-32129 — Poseidon V1 variable-length input collision via implicit zero-padding

soroban-poseidon provides Poseidon and Poseidon2 cryptographic hash functions for Soroban smart contracts. Poseidon V1 (PoseidonSponge) accepts variable-length inputs without injective padding. When …

Remote | Cryptography
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
8.2 HIGH
CVE-2026-32116 — Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite

Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 to before 0.23.0, receiving a file (wormhole receive) from a malicious party co…

Remote | Path Traversal
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
5.3 MEDIUM
CVE-2026-32100 — swag/platform-security: `/api/_info/config` route exposes information about licenses and …

Shopware is an open commerce platform. /api/_info/config route exposes information about active security fixes. This vulnerability is fixed in 2.0.16, 3.0.12, and 4.0.7.

Remote | Information Disclosure
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
4.8 MEDIUM
CVE-2026-31890 — Inspektor Gadget: Tracing Denial of Service via Event Flooding

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. Prior to 0.50.1, in a situation where the ring-buffer of …

| Denial of Service
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NONE
CVE-2026-31873 — Unhead has a Bypass of URI Scheme Sanitization in makeTagSafe via Case-Sensitivity

Unhead is a document head and template manager. Prior to 2.1.11, The link.href check in makeTagSafe (safe.ts) uses String.includes(), which is case-sensitive. Browsers treat URI schemes case-insensit…

Remote | Cross-Site Scripting
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
Showing 20 of 5446 Results