Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.6 LOW
CVE-2026-31863 — Improper Restriction of Excessive Authentication Attempts in github.com/anyproto/anytype-…

Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API can be bypassed, allowing an attacker to gain access without the 4-digit code. Th…

| Authentication
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
9.1 CRITICAL
CVE-2026-31862 — Cloud CLI has Command Injection via Multiple Parameters

Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, multiple Git-related API endpoints use execAsync() with string interpola…

Remote | Injection
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
8.7 HIGH
CVE-2026-31861 — Shell Command Injection in Git Routes [CloudCLI UI]

Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, The /api/user/git-config endpoint constructs shell commands by interpola…

Remote | Injection
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
6.9 MEDIUM
CVE-2026-31859 — Craft has Reflective XSS via incomplete return URL sanitization

Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in src/web/User.php to sanitize return URLs before they are stored in the session…

Remote | Cross-Site Scripting
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
8.7 HIGH
CVE-2026-31858 — CraftCMS's `ElementSearchController` Affected by Blind SQL Injection

Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() protection that was added to ElementIndexesController in CVE-2026-25495. The ex…

Remote | Injection
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
8.1 HIGH
CVE-2026-31857 — CraftCMS has an RCE vulnerability via relational conditionals in the control panel

Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions system. The BaseElementSelectConditionRule::getElemen…

Remote | Injection
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
9.3 CRITICAL
CVE-2026-31856 — Parse Server has a SQL injection via `Increment` operation on nested object field in Post…

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Incremen…

Remote | Injection
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
6.3 MEDIUM
CVE-2026-30226 — devalue has prototype pollution in devalue.parse and devalue.unflatten

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In devalue v5.6.3 and earlier, devalue.parse and devalue.unflatten were su…

Remote | Misconfiguration
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
5.7 MEDIUM
CVE-2026-0231 — Cortex XDR Broker VM: Sensitive Information Disclosure Vulnerability

An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obtain and modify sensitive information by triggering live terminal session via Cor…

| Information Disclosure
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
4.0 MEDIUM
CVE-2026-0230 — Cortex XDR Agent: Local Administrator can disable the agent on macOS

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malici…

| Authorization
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
4.2 MEDIUM
CVE-2026-3429 — Org.keycloak.services.resources.account: improper access control leading to mfa deletion …

A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specific…

Remote | Authentication
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
8.7 HIGH
CVE-2026-31854 — Cursor Affected by Arbitrary Code Execution via Prompt Injection and Whitelist Bypass

Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted instructions, the model may attempt to follow them in order to “assist” the user…

Remote | Injection
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
5.7 MEDIUM
CVE-2026-31853 — ImageMagick has a heap buffer over-write on 32-bit systems in SFW decoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, an overflow on 32-bit systems can cause a crash in the SFW decoder when…

| Memory Corruption
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
10.0 CRITICAL
CVE-2026-31852 — Jellyfin Possible Organization/Secret Compromise from dangerous CI implementation

Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requests from forked repositories. Du…

Remote | Supply Chain
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
9.3 CRITICAL
CVE-2026-31840 — Parse Server has a SQL injection via dot-notation field name in PostgreSQL

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacker can use a dot-notation field name in combination…

Remote | Injection
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
8.2 HIGH
CVE-2026-31839 — Striae has a hash validation utility vulnerability

Striae is a firearms examiner's comparison companion. A high-severity integrity bypass vulnerability existed in Striae's digital confirmation workflow prior to v3.0.0. Hash-only validation trusted ma…

| Supply Chain
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
4.8 MEDIUM
CVE-2026-31813 — Supabase Auth has insecure Apple and Azure authentication with ID tokens

Supabase Auth is a JWT based API for managing users and issuing JWT tokens. Prior to 2.185.0, a vulnerability has been identified that allows an attacker to issue sessions for arbitrary users using s…

Remote | Authentication
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
6.3 MEDIUM
CVE-2026-30868 — Cross-Site Request Forgery (CSRF) in opnsense/core

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, multiple OPNsense MVC API endpoints perform state‑changing operations but are accessible via HTTP GET requests without CSRF…

Remote | Cross-Site Request Forgery
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
6.5 MEDIUM
CVE-2026-30239 — OpenProject has a Permission Check bypass on Budget deletion allows reassignment of WorkP…

OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the work packages that were assigned to this budget need to be moved to a different bu…

Remote | Authorization
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
4.3 MEDIUM
CVE-2026-30236 — OpenProject users that are not project members can be used to calculate Labor Budget, lea…

OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when editing a project budget and planning the labor cost, it was not checked that the user that was planned in …

Remote | Authorization
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
Showing 20 of 5525 Results