Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-32842 — Edimax GS-5008PL <= 1.00.54 Admin Credentials Stored in Cleartext

Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows attackers to obtain administrator credentials by accessing configuration backup fi…

Remote | Information Disclosure
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
8.1 HIGH
CVE-2026-32841 — Edimax GS-5008PL <= 1.00.54 Global Authentication State Across All Clients

Edimax GS-5008PL firmware version 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the management interface. Attackers can exploit the …

Remote | Authentication
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
5.4 MEDIUM
CVE-2026-32840 — Edimax GS-5008PL <= 1.00.54 Stored XSS via Device Name

Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_name_set.cgi script that allows attackers to inject arbitrary script code by mani…

Remote | Cross-Site Scripting
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
4.3 MEDIUM
CVE-2026-32839 — Edimax GS-5008PL <= 1.00.54 CSRF via Management CGI Endpoints

Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remote attackers to perform unauthorized administrative actions by inducing logged-i…

Remote | Cross-Site Request Forgery
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
7.5 HIGH
CVE-2026-32838 — Edimax GS-5008PL <= 1.00.54 Transmits Credentials Over Cleartext HTTP

Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. Attackers on the same network can intercept managem…

Remote | Misconfiguration
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
7.5 HIGH
CVE-2026-1376 — IBM i Denial of Service

IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to improper allocation of resources.

Remote | Denial of Service
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
6.5 MEDIUM
CVE-2026-1267 — IBM Planning Analytics Information Disclosure

IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and administrative functionalities due to lack of proper access controls.

Remote | Authorization
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
5.7 MEDIUM
CVE-2025-14806 — IBM Planning Analytics Information Disclosure

IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing and serving sensitive, user-specific responses as publicly cacheable resources.

Remote | Misconfiguration
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
6.7 MEDIUM
CVE-2026-2809 — Endpoint DLP Driver DLL

Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow a privileged user to trigge…

| Memory Corruption
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
2.0 LOW
CVE-2026-4359 — Heap-buffer-over-read in _mongoc_http_send via strstr on non-null-terminated buffer

A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

Remote | Denial of Service
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
6.4 MEDIUM
CVE-2026-4358 — Memory safety issues in slot-based execution hash table spill

A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when …

Remote | Memory Corruption
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
8.5 HIGH
CVE-2026-4295 — Arbitrary code execution via crafted project files in Kiro IDE

Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote unauthenticated threat actor to execute arbitrary code via maliciously crafted pro…

| Misconfiguration
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
8.3 HIGH
CVE-2026-4064 — PowerShell Universal gRPC Authorization Bypass

Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perf…

Remote | Authorization
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
5.5 MEDIUM
CVE-2026-3563 — PowerShell Universal Route Hijacking and Denial of Service Vulnerability

Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to overri…

Remote | Misconfiguration
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
8.7 HIGH
CVE-2026-32981 — Ray Dashboard <= 2.8.0 Path Traversal Leading to Local File Disclosure

A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static fil…

Remote | Path Traversal
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
5.1 MEDIUM
CVE-2026-32837 — mackron / miniaudio Out-of-Bounds Read in BEXT Coding History Parsing

miniaudio version 0.11.25 and earlier contain a heap out-of-bounds read vulnerability in the WAV BEXT metadata parser that allows attackers to trigger memory access violations by processing crafted W…

| Memory Corruption
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
6.9 MEDIUM
CVE-2026-32836 — mackron / dr_libs Excessive Memory Allocation in PICTURE Metadata Parsing

dr_libs version 0.13.3 and earlier contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger excessive memory allocation by supply…

| Memory Corruption
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
0.0 NA
CVE-2026-30707 — SpeedExam Online Examination System Broken Access Control Vulnerability

An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails ASP.NET PageMethod. Authenticated attackers can bypa…

| Authorization
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
6.5 MEDIUM
CVE-2026-25936 — GLPI Vulnerable to Authenticated SQL Injection

GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a SQL injection. Version 11.0.6 fixes the issue.

Remote | Injection
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
6.8 MEDIUM
CVE-2025-15584 — Endpoint DLP Driver Filter Communication Port Integer Overflow

Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to tri…

| Denial of Service
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
Showing 20 of 5428 Results