Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-30048 — NotChatbot WebChat Widget Stored XSS Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in the NotChatbot WebChat widget thru 1.4.4. User-supplied input is not properly sanitized before being stored and rendered in the chat conver…

Remote | Cross-Site Scripting
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
9.8 CRITICAL
CVE-2026-29859 — aaPanel Arbitrary File Upload Remote Code Execution Vulnerability

An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file.

aapanel | Remote | Misconfiguration
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
7.5 HIGH
CVE-2026-29858 — aaPanel Local File Inclusion Vulnerability

A lack of path validation in aaPanel v7.57.0 allows attackers to execute a local file inclusion (LFI), leadingot sensitive information exposure.

aapanel | Remote | Path Traversal
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
7.5 HIGH
CVE-2026-29856 — aaPanel Regular Expression Denial of Service (ReDoS) in VirtualHost Configuration Handlin…

An issue in the VirtualHost configuration handling/parser component of aaPanel v7.57.0 allows attackers to cause a Regular Expression Denial of Service (ReDoS) via a crafted input.

aapanel | Remote | Denial of Service
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
7.5 HIGH
CVE-2026-27135 — nghttp2 Denial of service: Assertion failure due to the missing state validation

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_sessi…

nghttp2 | Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
4.9 MEDIUM
CVE-2026-26948 — "Dell Integrated Dell Remote Access Controller Debug Information Disclosure"

Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G versions prior to 7.10.90.00, contain an Exposure of Sensitive System Information Due to Uncleared Debu…

Remote | Information Disclosure
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
5.3 MEDIUM
CVE-2026-26945 — Dell Integrated Dell Remote Access Controller Privilege Escalation Vulnerability

Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior t…

| Misconfiguration
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.2 HIGH
CVE-2026-26740 — GIFlib Buffer Overflow Denial of Service

Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without valida…

Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
0.0 NA
CVE-2026-23270 — net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks

In the Linux kernel, the following vulnerability has been resolved: net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks As Paolo said earlier [1]: "Since the blamed com…

linux_kernel | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
0.0 NA
CVE-2026-23269 — apparmor: validate DFA start states are in bounds in unpack_pdb

In the Linux kernel, the following vulnerability has been resolved: apparmor: validate DFA start states are in bounds in unpack_pdb Start states are read from untrusted data and used as indexes int…

linux_kernel | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
0.0 NA
CVE-2026-23268 — apparmor: fix unprivileged local user can do privileged policy management

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix unprivileged local user can do privileged policy management An unprivileged local user can load, replace, and remov…

linux_kernel | Authorization
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
0.0 NA
CVE-2026-23267 — f2fs: fix IS_CHECKPOINTED flag inconsistency issue caused by concurrent atomic commit and…

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix IS_CHECKPOINTED flag inconsistency issue caused by concurrent atomic commit and checkpoint writes During SPO tests, whe…

linux_kernel | Race Condition
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
0.0 NA
CVE-2026-23266 — fbdev: rivafb: fix divide error in nv3_arb()

In the Linux kernel, the following vulnerability has been resolved: fbdev: rivafb: fix divide error in nv3_arb() A userspace program can trigger the RIVA NV3 arbitration code by calling the FBIOPUT…

linux_kernel | Denial of Service
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
0.0 NA
CVE-2026-23265 — f2fs: fix to do sanity check on node footer in {read,write}_end_io

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on node footer in {read,write}_end_io -----------[ cut here ]------------ kernel BUG at fs/f2fs/data…

linux_kernel | Misconfiguration
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
0.0 NA
CVE-2026-23264 — Revert "drm/amd: Check if ASPM is enabled from PCIe subsystem"

In the Linux kernel, the following vulnerability has been resolved: Revert "drm/amd: Check if ASPM is enabled from PCIe subsystem" This reverts commit 7294863a6f01248d72b61d38478978d638641bee. Thi…

Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
0.0 NA
CVE-2026-23263 — io_uring/zcrx: fix page array leak

In the Linux kernel, the following vulnerability has been resolved: io_uring/zcrx: fix page array leak d9f595b9a65e ("io_uring/zcrx: fix leaking pages on sg init fail") fixed a page leakage but did…

linux_kernel | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
0.0 NA
CVE-2026-23262 — gve: Fix stats report corruption on queue count change

In the Linux kernel, the following vulnerability has been resolved: gve: Fix stats report corruption on queue count change The driver and the NIC share a region in memory for stats reporting. The N…

linux_kernel | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
0.0 NA
CVE-2026-23261 — nvme-fc: release admin tagset if init fails

In the Linux kernel, the following vulnerability has been resolved: nvme-fc: release admin tagset if init fails nvme_fabrics creates an NVMe/FC controller in following path: nvmf_dev_write() …

linux_kernel | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
0.0 NA
CVE-2026-23260 — regmap: maple: free entry on mas_store_gfp() failure

In the Linux kernel, the following vulnerability has been resolved: regmap: maple: free entry on mas_store_gfp() failure regcache_maple_write() allocates a new block ('entry') to merge adjacent ran…

linux_kernel | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
0.0 NA
CVE-2026-23259 — io_uring/rw: free potentially allocated iovec on cache put failure

In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: free potentially allocated iovec on cache put failure If a read/write request goes through io_req_rw_cleanup() and h…

linux_kernel | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
Showing 20 of 5609 Results