Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.1 MEDIUM
CVE-2026-27740 — Discourse has Stored XSS in AI Triage Automation

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerability that arises because the system trusts the raw ou…

discourse | Remote | Cross-Site Scripting
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
5.1 MEDIUM
CVE-2026-27570 — Discourse Vulnerable to Stored XSS via Shared AI Conversation Onebox

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox method in the SharedAiConversation model renders the conversation title direct…

discourse | Remote | Cross-Site Scripting
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
6.9 MEDIUM
CVE-2026-27491 — Discourse has a bypass of official warnings messages by non-staff users

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coercion issue in a post actions API endpoint allowed non-staff users to issue war…

discourse | Remote | Authorization
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
5.3 MEDIUM
CVE-2026-27454 — Discourse has check revision visibility on posts endpoint

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting /posts/:id.json?version=X bypassed authorization checks on post revisions. The…

discourse | Remote | Authorization
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
4.1 MEDIUM
CVE-2026-27166 — Discourse vulnerable to HTML injection via prohibited iframe URLs

Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficient cleanup in the default Codepen allowed iframes value allows an attacker to t…

discourse | Remote | Cross-Site Scripting
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
8.6 HIGH
CVE-2026-26139 — Microsoft Purview Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
8.6 HIGH
CVE-2026-26138 — Microsoft Purview Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
8.9 HIGH
CVE-2026-26137 — Microsoft 365 Copilot BizChat Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft 365 Copilot's Business Chat allows an authorized attacker to elevate privileges over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
6.5 MEDIUM
CVE-2026-26136 — Microsoft Copilot Information Disclosure Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
6.5 MEDIUM
CVE-2026-26120 — Microsoft Bing Tampering Vulnerability

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
5.3 MEDIUM
CVE-2026-24299 — M365 Copilot Information Disclosure Vulnerability

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
8.6 HIGH
CVE-2026-23659 — Azure Data Factory Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
8.6 HIGH
CVE-2026-23658 — Azure DevOps: msazure Elevation of Privilege Vulnerability

Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
2.1 LOW
CVE-2026-3580 — Compiler-induced timing leak in sp_256_get_entry_256_9 on RISC-V

In wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bnez) by GCC when targeting RISC-V RV32I with -O3. This transformation breaks the side-…

wolfssl | Cryptography
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
2.1 LOW
CVE-2026-3579 — Non-constant time multiplication subroutine __muldi3 on RISC-V RV32I

wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication. The compiler-inserted __muldi3 subroutine executes in variable time based on opera…

wolfssl | Cryptography
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
9.1 CRITICAL
CVE-2026-32238 — OpenEMR has Remote Code Execution in backup functionality

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command injection vulnerability in the backup functionalit…

openemr | Remote | Injection
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
4.4 MEDIUM
CVE-2026-32119 — OpenEMR has Stored DOM XSS via SearchHighlight text-node reconstruction on Custom Report …

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, DOM-based stored XSS in the jQuery SearchHighlight plugin (`library/js/Searc…

openemr | Remote | Cross-Site Scripting
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
6.5 MEDIUM
CVE-2026-25928 — OpenEMR Vulnerable to Path Traversal When Zipping DICOM Folders

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the DICOM zip/export feature uses a user-supplied destination or path compon…

openemr | Remote | Path Traversal
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
6.5 MEDIUM
CVE-2026-25744 — OpenEMR: POST /api/.../vital Accepts Attacker-Supplied id and Overwrites Arbitrary Vitals

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the encounter vitals API accepts an `id` in the request body and treats it a…

openemr | Remote | Authorization
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
4.3 MEDIUM
CVE-2026-3503 — Fault injection attack with ML-DSA and ML-KEM on ARM

Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex-M microcontrollers allows a physical attacker to compromise key material and/or cry…

| Memory Corruption
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
Showing 20 of 5747 Results