Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-32586 — WordPress Booster for WooCommerce plugin < 7.11.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Pluggabl Booster for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booster for WooCommerce: from n/a be…

Remote | Authorization
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
9.8 CRITICAL
CVE-2026-4312 — DrangSoft|GCB/FCB Audit Software - Missing Authentication

GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to create a new administrative acco…

Remote | Authentication
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
2.3 LOW
CVE-2026-3237 — Octopus Server Key Manipulation Vulnerability

In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiration and revocation time frames via an API endpoint that …

Remote | Authorization
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
7.7 HIGH
CVE-2026-4258 — Apache Sjcl ECDSA Signature Verification Vulnerability

All versions of the package sjcl are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover …

Remote | Cryptography
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
6.5 MEDIUM
CVE-2026-4308 — frdel/agent0ai agent-zero document_query.py handle_pdf_document server-side request forge…

A weakness has been identified in frdel/agent0ai agent-zero 0.9.7. This affects the function handle_pdf_document of the file python/helpers/document_query.py. This manipulation causes server-side req…

Remote | Server-Side Request Forgery
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
5.3 MEDIUM
CVE-2026-4307 — frdel/agent0ai agent-zero files.py get_abs_path path traversal

A security flaw has been discovered in frdel/agent0ai agent-zero 0.9.7-10. The impacted element is the function get_abs_path of the file python/helpers/files.py. The manipulation results in path trav…

Remote | Path Traversal
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
5.3 MEDIUM
CVE-2026-2373 — Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1049 - Missing…

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1049 via the get_main_quer…

Remote | Information Disclosure
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
8.3 HIGH
CVE-2026-0708 — Libucl: libucl: denial of service via embedded null byte in ucl input

A flaw was found in libucl. A remote attacker could exploit this by providing a specially crafted Universal Configuration Language (UCL) input that contains a key with an embedded null byte. This can…

Remote | Denial of Service
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
7.5 HIGH
CVE-2026-2579 — WowStore – Store Builder & Product Blocks for WooCommerce <= 4.4.3 - Unauthenticated SQL …

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 4.4.3 due to insuffi…

Remote | Injection
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
7.5 HIGH
CVE-2026-4289 — Tiandy Easy7 Integrated Management Platform getRecByTemplateId sql injection

A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This affects an unknown function of the file /rest/preSetTemplate/getRecByTemplateId. The manip…

Remote | Injection
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
7.5 HIGH
CVE-2026-4288 — Tiandy Easy7 Integrated Management Platform Endpoint getDevDetailedInfo sql injection

A weakness has been identified in Tiandy Easy7 Integrated Management Platform 7.17.0. The impacted element is an unknown function of the file /rest/devStatus/getDevDetailedInfo of the component Endpo…

Remote | Injection
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
7.5 HIGH
CVE-2026-4287 — Tiandy Easy7 Integrated Management Platform Endpoint queryResources sql injection

A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The affected element is an unknown function of the file /rest/devStatus/queryResources of the component Endp…

Remote | Injection
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
5.1 MEDIUM
CVE-2026-4285 — taoofagi easegen-admin Pdf2MdUtil.java recognizeMarkdown path traversal

A vulnerability was identified in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. Impacted is the function recognizeMarkdown of the file yudao-module-digitalcourse/yudao-module…

Remote | Path Traversal
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
5.8 MEDIUM
CVE-2026-4284 — taoofagi easegen-admin PPT File PPTUtil.java downloadFile server-side request forgery

A vulnerability was determined in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. This issue affects the function downloadFile of the file - yudao-module-digitalcourse/yudao-mo…

Remote | Server-Side Request Forgery
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
0.0 NA
CVE-2026-4177 — YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities …

YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names…

| Memory Corruption
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
5.5 MEDIUM
CVE-2026-21991 — "Sun DTrace dtprobed Arbitrary File Creation Vulnerability"

A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.

| Path Traversal
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
5.8 MEDIUM
CVE-2026-2454 — DoS in Calls plugin via malformed msgpack in websocket request.

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array lengths which allows malicious user to cause OOM errors and crash the server via …

Remote | Denial of Service
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
8.7 HIGH
CVE-2026-29522 — ZwickRoell Test Data Management < 3.0.8 Path Traversal LFI

ZwickRoell Test Data Management versions prior to 3.0.8 contain a local file inclusion (LFI) vulnerability in the /server/node_upgrade_srv.js endpoint. An unauthenticated attacker can supply director…

Remote | Path Traversal
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
3.8 LOW
CVE-2026-26230 — Team Admin Privilege Escalation to Demote Members to Guest

Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles API endpoint which allows team administrators to demote members to guest role. Matte…

Remote | Authorization
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
4.3 MEDIUM
CVE-2026-1629 — Permalink Preview Information Disclosure After Permission Revocation

Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel access which allows the user to continue viewing private channel content via previou…

Remote | Information Disclosure
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
Showing 20 of 5314 Results