Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.1 LOW
CVE-2026-0115 — Intel Trusted Execution Environment (TEE) Physical Key Leak

In Trusted Execution Environment, there is a possible key leak due to side channel information disclosure. This could lead to physical information disclosure with no additional execution privileges n…

| Information Disclosure
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
9.8 CRITICAL
CVE-2026-0114 — Cisco Modem Out-of-Bounds Write Remote Code Execution Vulnerability

In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not ne…

Remote | Memory Corruption
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
9.8 CRITICAL
CVE-2026-0113 — Mozilla Firefox Out-of-Bounds Write Vulnerability

In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution priv…

Remote | Memory Corruption
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
7.4 HIGH
CVE-2026-0112 — "VPU Use After Free Privilege Escalation"

In vpu_open_inst of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User inte…

| Race Condition
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
9.8 CRITICAL
CVE-2026-0111 — Mozilla Firefox Stack-Based Buffer Overflow

In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution priv…

Remote | Memory Corruption
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
9.8 CRITICAL
CVE-2026-0110 — Vulnerability in Siemens SIMATIC S7-1200 EoP

In MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible EoP due to memory corruption. This could lead to remote escalation of privilege with no additional execution privileges needed. User in…

Remote | Memory Corruption
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
7.5 HIGH
CVE-2026-0109 — "TP-Link Wireless Router TCP Data Info Get Denial of Service Vulnerability"

In dhd_tcpdata_info_get of dhd_ip.c, there is a possible Denial of Service due to a precondition check failure. This could lead to remote denial of service with no additional execution privileges nee…

Remote | Denial of Service
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
4.0 MEDIUM
CVE-2026-0108 — PowerVR GPU Information Disclosure Vulnerability

The register protection of the PowerVR GPU is incorrectly configured. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo…

| Misconfiguration
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
8.4 HIGH
CVE-2026-0107 — GMC Confused Deputy Privilege Escalation

In gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a possible escalation of privileges due to a confused deputy. This could lead to local escalation of privilege with no additional execution pri…

| Authorization
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
0.0 NA
CVE-2025-70802 — Tenda G1V3.1si Hardcoded Password Vulnerability

Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.

| Authentication
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
0.0 NA
CVE-2025-70798 — Tenda i24V3.0si Hardcoded Password Vulnerability

Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.

| Authentication
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
7.5 HIGH
CVE-2025-70244 — D-Link DIR-513 Stack Buffer Overflow Vulnerability

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanSetup.

Remote | Memory Corruption
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
7.4 HIGH
CVE-2025-66413 — Git for Windows leaks NTLM hash when cloning from an attacker-controlled server

Git for Windows is the Windows port of Git. Prior to 2.53.0(2), it is possible to obtain a user's NTLM hash by tricking them into cloning from a malicious server. Since NTLM hashing is weak, it is po…

Remote | Authentication
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
8.4 HIGH
CVE-2025-36920 — KVM ARM64 Hypervisor Out-of-Bounds Write Vulnerability

In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional executio…

| Memory Corruption
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
5.4 MEDIUM
CVE-2025-13213 — Multiple vulnerabilities in IBM Aspera Orchestrator

IBM Aspera Orchestrator 3.0.0 through 4.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks…

Remote | Injection
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
5.3 MEDIUM
CVE-2026-3582 — Incorrect Authorization in GitHub Enterprise Server allows access to issue and commit sea…

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with a classic personal access token (PAT) lacking the repo scope to retrieve is…

Remote | Authorization
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
7.4 HIGH
CVE-2026-2713 — IBM Trusteer Rapport installer affected by uncontrolled search path element vulnerability

IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code on the system, caused by DLL uncontrolled search path element vulnerability. By…

| Misconfiguration
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
7.4 HIGH
CVE-2026-2266 — Improper neutralization of input vulnerability was identified in GitHub Enterprise Server…

An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed DOM-based cross-site scripting via task list content. The task list content extraction logic …

Remote | Cross-Site Scripting
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
9.3 CRITICAL
CVE-2026-29793 — NoSQL Injection via WebSocket id Parameter in MongoDB Adapter

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42, Socket.IO clients can send arbitrary JavaScript objects as the …

Remote | Injection
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
9.3 CRITICAL
CVE-2026-29792 — Feathersjs has an OAuth Callback Account Takeover

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42, an unauthenticated attacker can send a crafted GET request direc…

Remote | Authentication
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
Showing 20 of 5430 Results