Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.5 LOW
CVE-2026-4243 — La Nacion App app.lanacion.activity BuildConfig.java credentials storage

A weakness has been identified in La Nacion App 10.2.25 on Android. This impacts an unknown function of the file source/app/lanacion/clublanacion/BuildConfig.java of the component app.lanacion.activi…

| Misconfiguration
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
2.5 LOW
CVE-2026-4242 — BabyChakra Pregnancy & Parenting App app.babychakra.babychakra Configuration.java credent…

A security flaw has been discovered in BabyChakra Pregnancy & Parenting App up to 5.4.3.0 on Android. This affects an unknown function of the file file app/babychakra/babychakra/Configuration.java of…

| Misconfiguration
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
4.3 MEDIUM
CVE-2026-2455 — SSRF bypass via IPv4-mapped IPv6 literals

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation which allows an attacker to perform SSRF atta…

Remote | Server-Side Request Forgery
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
7.1 HIGH
CVE-2026-25369 — WordPress Flexmls® IDX plugin <= 3.15.9 - Reflected Cross Site Scripting (XSS) vulnerabil…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Flexmls Flexmls® IDX allows Reflected XSS.This issue affects Flexmls® IDX: from n/a through 3.15.…

Remote | Cross-Site Scripting
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
4.3 MEDIUM
CVE-2026-24692 — Guest users can bypass read permissions via search API

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissions in search API endpoints which allows guest users without read permissions to acce…

Remote | Authorization
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
3.1 LOW
CVE-2026-22545 — Password Change Bypass via Auth Switch Endpoint

Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth type switch which allows an authenticated attacker to change account password withou…

Remote | Authentication
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
4.3 MEDIUM
CVE-2026-21386 — Private channel enumeration via /mute slash command

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows an authenticated team member to enumera…

Remote | Information Disclosure
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
1.8 LOW
CVE-2025-52649 — HCL AION is affected by a vulnerability where certain identifiers may be predictable in n…

HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers may allow an attacker to infer or guess system-generated values, potentially le…

| Information Disclosure
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
2.2 LOW
CVE-2025-52646 — HCL AION is affected by a vulnerability where certain offering configurations may permit …

HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could exp…

| Injection
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
1.9 LOW
CVE-2025-52645 — HCL AION is affected by a vulnerability where model packaging and distribution mechanisms…

HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This may allow the possibility of unverified or modifie…

| Supply Chain
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
5.8 MEDIUM
CVE-2025-52644 — HCL AION is affected by a vulnerability where certain user actions are not adequately aud…

HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user activities and could…

| Information Disclosure
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
4.7 MEDIUM
CVE-2025-52643 — HCL AION is affected by a vulnerability where untrusted file parsing operations are not e…

HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to potential security …

| Misconfiguration
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
3.3 LOW
CVE-2025-52642 — HCL AION is affected by an internal filesystem paths disloser vulnerability

HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or system behaviour. Exposure of internal paths may reveal environment structure d…

| Path Traversal
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
1.8 LOW
CVE-2025-52636 — HCL AION is affected by a improper handling of uploads files Size

HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of upload sizes may allow excessive resource consumption, which could potentially…

| Denial of Service
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
4.8 MEDIUM
CVE-2025-2274 — Stored Cross Site Scripting in Forcepoint Web Security

Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Stored XSS.This issue affects Web Security through 8.5.6.

| Cross-Site Scripting
Mar 16, 2026 Mar 17, 2026
Mar 16, 2026
Mar 17, 2026
4.3 MEDIUM
CVE-2026-4265 — Guest user can upload files without permission across teams

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file permissions which allows a guest user to post files in channels where they lack …

Remote | Authorization
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
8.4 HIGH
CVE-2026-4255 — DLL Injection Privilege Escalation

A DLL search order hijacking vulnerability in Thermalright TR-VISION HOME on Windows (64-bit) allows a local attacker to escalate privileges via DLL side-loading. The application loads certain dynami…

| Misconfiguration
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
6.5 MEDIUM
CVE-2026-4241 — itsourcecode College Management System time-table.php sql injection

A vulnerability was identified in itsourcecode College Management System 1.0. The impacted element is an unknown function of the file /admin/time-table.php. Such manipulation of the argument course_c…

Remote | Injection
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
5.5 MEDIUM
CVE-2026-4240 — Open5GS CCA smf_s6b_sta_cb denial of service

A vulnerability was determined in Open5GS up to 2.7.6. The affected element is the function smf_gx_cca_cb/smf_gy_cca_cb/smf_s6b_aaa_cb/smf_s6b_sta_cb of the component CCA Handler. This manipulation c…

Remote | Denial of Service
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
5.1 MEDIUM
CVE-2026-4239 — Lagom WHMCS Template Datatables prototype pollution

A vulnerability was found in Lagom WHMCS Template up to 2.3.7. Impacted is an unknown function of the component Datatables. The manipulation results in improperly controlled modification of object pr…

Remote | Misconfiguration
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
Showing 20 of 5359 Results