Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-32611 — Glances has a SQL Injection in DuckDB Export via Unparameterized DDL Statements

Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL injection in the TimescaleDB export module by converting all SQL operations to use pa…

| Injection
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
8.1 HIGH
CVE-2026-32610 — Glances's Default CORS Configuration Allows Cross-Origin Credential Theft

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server ships with a default CORS configuration that sets `allow_origins=["*"]` combin…

Remote | Misconfiguration
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
0.0 NA
CVE-2026-30695 — Zucchetti Axess Cross-Site Scripting (XSS)

A Cross-Site Scripting (XSS) vulnerability exists in the web-based configuration interface of Zucchetti Axess access control devices, including XA4, X3/X3BIO, X4, X7, and XIO / i-door / i-door+. The …

| Cross-Site Scripting
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
0.0 NA
CVE-2026-30345 — CTFd Zip Slip File Write Vulnerability

A zip slip vulnerability in the Admin import functionality of CTFd v3.8.1-18-gdb5a18c4 allows attackers to write arbitrary files outside the intended directories via supplying a crafted import.

| Path Traversal
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
8.8 HIGH
CVE-2026-1463 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery <= 4.0.4 - Authenticated (A…

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.3 via the 'template' parameter i…

Remote | Path Traversal
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
0.0 NA
CVE-2025-67830 — Mura SQL Injection Vulnerability

Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.

| Injection
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
0.0 NA
CVE-2026-23253 — media: dvb-core: fix wrong reinitialization of ringbuffer on reopen

In the Linux kernel, the following vulnerability has been resolved: media: dvb-core: fix wrong reinitialization of ringbuffer on reopen dvb_dvr_open() calls dvb_ringbuffer_init() when a new reader …

| Race Condition
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
0.0 NA
CVE-2026-23252 — xfs: get rid of the xchk_xfile_*_descr calls

In the Linux kernel, the following vulnerability has been resolved: xfs: get rid of the xchk_xfile_*_descr calls The xchk_xfile_*_descr macros call kasprintf, which can fail to allocate memory if t…

| Memory Corruption
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
0.0 NA
CVE-2026-23251 — xfs: only call xf{array,blob}_destroy if we have a valid pointer

In the Linux kernel, the following vulnerability has been resolved: xfs: only call xf{array,blob}_destroy if we have a valid pointer Only call the xfarray and xfblob destructor if we have a valid p…

| Memory Corruption
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
0.0 NA
CVE-2026-23250 — xfs: check return value of xchk_scrub_create_subord

In the Linux kernel, the following vulnerability has been resolved: xfs: check return value of xchk_scrub_create_subord Fix this function to return NULL instead of a mangled ENOMEM, then fix the ca…

| Memory Corruption
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
0.0 NA
CVE-2026-23249 — xfs: check for deleted cursors when revalidating two btrees

In the Linux kernel, the following vulnerability has been resolved: xfs: check for deleted cursors when revalidating two btrees The free space and inode btree repair functions will rebuild both btr…

| Misconfiguration
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
7.2 HIGH
CVE-2026-3090 — Post SMTP <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'event_type'

The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘event_type…

Remote | Cross-Site Scripting
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
0.0 NA
CVE-2026-33004 — Jenkins LoadNinja Plugin API Key Exposure Vulnerability

Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

| Information Disclosure
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
4.3 MEDIUM
CVE-2026-33003 — Jenkins LoadNinja Plugin Unencrypted API Key Storage Vulnerability

Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission o…

Remote | Information Disclosure
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
0.0 NA
CVE-2026-33002 — Jenkins Origin Validation DNS Rebinding Vulnerability

Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected…

| Misconfiguration
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
0.0 NA
CVE-2026-33001 — Jenkins Symbolic Link Archive Extraction Vulnerability (Path Traversal)

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary loca…

| Path Traversal
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
8.2 HIGH
CVE-2026-2992 — KiviCare <= 4.1.2 - Missing Authorization to Unauthenticated Privilege Escalation via Set…

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST …

Remote | Authorization
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
9.8 CRITICAL
CVE-2026-2991 — KiviCare – Clinic & Patient Management System (EHR) <= 4.1.2 - Unauthenticated Authentica…

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patientSocialLogin…

Remote | Authentication
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
5.3 MEDIUM
CVE-2026-2559 — Post SMTP <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Office 365 OAut…

The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oauth_redirect()` function in all versions up to, and …

Remote | Authorization
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
6.4 MEDIUM
CVE-2026-2512 — Code Embed <= 2.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom…

The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field meta values in all versions up to, and including, 2.5.1. This is due to the plugin's sanitization fun…

Remote | Cross-Site Scripting
Mar 18, 2026 Mar 18, 2026
Mar 18, 2026
Mar 18, 2026
Showing 20 of 5443 Results