Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-31971 — HTSlib CRAM decoder vulnerable to buffer overflow

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compression methods. Whe…

htslib | Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.1 HIGH
CVE-2026-31970 — HTSlib BGZF index file reader has a heap buffer overflow

HTSlib is a library for reading and writing bioinformatics file formats. GZI files are used to index block-compressed GZIP [BGZF] files. In the GZI loading function, `bgzf_index_load_hfile()`, it wa…

htslib | Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.1 HIGH
CVE-2026-31969 — HTSlib CRAM decoder has a heap buffer overflow

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compression methods. Wh…

htslib | Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.8 HIGH
CVE-2026-31968 — HTSlib CRAM decoder vulnerable to buffer overflow

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compression methods. For…

htslib | Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
9.1 CRITICAL
CVE-2026-31967 — HTSlib CRAM reader has out-of-bounds read due to improper validation of input

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the `cram_decode_slice()` function called while readi…

htslib | Remote | Information Disclosure
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
9.1 CRITICAL
CVE-2026-31966 — HTSlib CRAM reader has out-of-bounds read due to improper validation of input

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one method of removing redundant data, CRAM uses refe…

htslib | Remote | Information Disclosure
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
2.1 LOW
CVE-2026-3479 — pkgutil.get_data() does not enforce documented restrictions

pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.

python | Path Traversal
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.2 HIGH
CVE-2026-31965 — HTSlib CRAM reader has out-of-bounds reads due to improper validation of input

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the `cram_decode_slice()` function called while readi…

htslib | Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
7.5 HIGH
CVE-2026-31964 — HTSlib CRAM decoder has a NULL Pointer Dereference

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compression methods. Wh…

htslib | Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.8 HIGH
CVE-2026-31963 — HTSlib CRAM reader has heap buffer overflow due to improper validation of input

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one method of removing redundant data, CRAM uses refe…

htslib | Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.8 HIGH
CVE-2025-58112 — Microsoft Dynamics 365 Customer Engagement SQL Injection

Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an upload of a .rdl (Report Definition Language) file; th…

Remote | Injection
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.1 HIGH
CVE-2026-32634 — Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Serv…

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised server name and the discovered IP address…

glances | Authentication
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
9.1 CRITICAL
CVE-2026-32633 — Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint returns raw server objects from `GlancesServersList…

glances | Remote | Information Disclosure
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
5.9 MEDIUM
CVE-2026-32632 — Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding

Glances is an open-source system cross-platform monitoring tool. Glances recently added DNS rebinding protection for the MCP endpoint, but prior to version 4.5.2, the main REST/WebUI FastAPI applicat…

glances | Remote | Misconfiguration
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
9.1 CRITICAL
CVE-2026-32611 — Glances has a SQL Injection in DuckDB Export via Unparameterized DDL Statements

Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL injection in the TimescaleDB export module by converting all SQL operations to use pa…

glances | Remote | Injection
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.8 HIGH
CVE-2026-31962 — HTSlib CRAM reader has heap buffer overflow due to improper validation of input

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. While most alignment records store DNA sequence and qual…

htslib | Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
9.1 CRITICAL
CVE-2026-30704 — "WDR201A WiFi Extender UART Interface Information Disclosure Vulnerability"

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCB

Remote | Misconfiguration
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
0.0 NA
CVE-2026-30703 — WiFi Extender WDR201A Command Injection Vulnerability

A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02). The adm.cgi endpoint improperly sanitizes user-supplied input p…

| Injection
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
0.0 NA
CVE-2026-30702 — "TP-Link WiFi Extender WDR201A Authentication Bypass"

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login page does not properly enforce session validation, a…

| Authentication
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
0.0 NA
CVE-2026-30701 — "WiFi Extender WDR201A Hardcoded Credential Disclosure Vulnerability"

The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the form of Server Side Include) within multiple server-side we…

| Information Disclosure
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
Showing 20 of 5604 Results