Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-4288 — Tiandy Easy7 Integrated Management Platform Endpoint getDevDetailedInfo sql injection

A weakness has been identified in Tiandy Easy7 Integrated Management Platform 7.17.0. The impacted element is an unknown function of the file /rest/devStatus/getDevDetailedInfo of the component Endpo…

Remote | Injection
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
7.5 HIGH
CVE-2026-4287 — Tiandy Easy7 Integrated Management Platform Endpoint queryResources sql injection

A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The affected element is an unknown function of the file /rest/devStatus/queryResources of the component Endp…

Remote | Injection
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
5.1 MEDIUM
CVE-2026-4285 — taoofagi easegen-admin Pdf2MdUtil.java recognizeMarkdown path traversal

A vulnerability was identified in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. Impacted is the function recognizeMarkdown of the file yudao-module-digitalcourse/yudao-module…

Remote | Path Traversal
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
0.0 NA
CVE-2026-30707 — SpeedExam Online Examination System Broken Access Control Vulnerability

An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails ASP.NET PageMethod. Authenticated attackers can bypa…

| Authorization
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
5.8 MEDIUM
CVE-2026-4284 — taoofagi easegen-admin PPT File PPTUtil.java downloadFile server-side request forgery

A vulnerability was determined in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. This issue affects the function downloadFile of the file - yudao-module-digitalcourse/yudao-mo…

Remote | Server-Side Request Forgery
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
9.1 CRITICAL
CVE-2026-4177 — YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities …

YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names…

Remote | Memory Corruption
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
5.5 MEDIUM
CVE-2026-21991 — "Sun DTrace dtprobed Arbitrary File Creation Vulnerability"

A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.

| Path Traversal
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
5.8 MEDIUM
CVE-2026-2454 — DoS in Calls plugin via malformed msgpack in websocket request.

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array lengths which allows malicious user to cause OOM errors and crash the server via …

Remote | Denial of Service
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
8.7 HIGH
CVE-2026-29522 — ZwickRoell Test Data Management < 3.0.8 Path Traversal LFI

ZwickRoell Test Data Management versions prior to 3.0.8 contain a local file inclusion (LFI) vulnerability in the /server/node_upgrade_srv.js endpoint. An unauthenticated attacker can supply director…

Remote | Path Traversal
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
3.8 LOW
CVE-2026-26230 — Team Admin Privilege Escalation to Demote Members to Guest

Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles API endpoint which allows team administrators to demote members to guest role. Matte…

Remote | Authorization
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
4.3 MEDIUM
CVE-2026-1629 — Permalink Preview Information Disclosure After Permission Revocation

Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel access which allows the user to continue viewing private channel content via previou…

Remote | Information Disclosure
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
9.8 CRITICAL
CVE-2025-69902 — Kubectl-MCP-Server Command Injection Vulnerability

A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via injecting arbitrary shell metacharacters.

Remote | Injection
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
8.8 HIGH
CVE-2025-50881 — Use It Flow Remote Code Execution Vulnerability

The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Execution. When handling GET requests, the script takes user-supplied input from …

Remote | Injection
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
9.8 CRITICAL
CVE-2026-32267 — Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpers…

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user w…

craft_cms | Remote | Authentication
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
8.6 HIGH
CVE-2026-32264 — Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsControl…

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, there is a Behavior injection RCE vulnerability in…

craft_cms | Remote | Injection
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
8.6 HIGH
CVE-2026-32263 — Craft CMS vulnerable to behavior injection RCE via EntryTypesController

Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTypesController.php, the $settings array from parse_str is passed directly to Craf…

craft_cms | Remote | Injection
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
5.3 MEDIUM
CVE-2026-32262 — Craft CMS has a Path Traversal Vulnerability in AssetsController

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, the AssetsController->replaceFile() method has a t…

craft_cms | Remote | Path Traversal
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
6.1 MEDIUM
CVE-2026-30882 — Chamilo LMS: Reflected XSS in the session category listing page

Chamilo LMS is a learning management system. Chamilo LMS version 1.11.34 and prior contains a Reflected Cross-Site Scripting (XSS) vulnerability in the session category listing page. The keyword para…

chamilo_lms | Remote | Cross-Site Scripting
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
8.8 HIGH
CVE-2026-30881 — Chamilo LMS: SQL Injection in the statistics AJAX endpoint

Chamilo LMS is a learning management system. Version 1.11.34 and prior contains a SQL Injection vulnerability in the statistics AJAX endpoint. The parameters date_start and date_end from $_REQUEST ar…

chamilo_lms | Remote | Injection
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
6.3 MEDIUM
CVE-2026-30876 — Chamilo LMS: User enumeration vulnerability via response

Chamilo LMS is a learning management system. Prior to version 1.11.36, Chamilo is vulnerable to user enumeration with valid/invalid username. This issue has been patched in version 1.11.36.

chamilo_lms | Remote | Authentication
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
Showing 20 of 5359 Results