Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-25667 — Microsoft .NET Kestrel QUIC Denial of Service

ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorre…

| Denial of Service
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
7.2 HIGH
CVE-2026-3548 — Buffer overflow in CRL number parsing in wolfSSL

Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer overflow could occur when improperly storing the CRL number as a hexadecimal string…

wolfssl | Remote | Memory Corruption
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
0.0 NA
CVE-2026-30694 — DedeCMS Code Execution Vulnerability

An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component

| Injection
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
5.0 MEDIUM
CVE-2026-2646 — Heap buffer overflow in session parsing with wolfSSL_d2i_SSL_SESSION() function

A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. When deserializing session data with SESSION_CERTS enabled, certificate and session id lengths are read fr…

wolfssl | Memory Corruption
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
5.5 MEDIUM
CVE-2026-2645 — Acceptance of CertificateVerify Message before ClientKeyExchange in TLS 1.2

In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. The server could incorrectly accept the CertificateVerify message before the ClientKeyExchange m…

wolfssl | Remote | Authentication
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
6.5 MEDIUM
CVE-2026-26940 — Improper Validation of Specified Quantity in Input in Kibana Leading to Denial of Service

Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead Denial of Service via Excessive Allocation (CAPEC-130). The vulnerability allows …

kibana | Remote | Denial of Service
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
6.5 MEDIUM
CVE-2026-26939 — Missing Authorization in Kibana Leading to Unauthorized Endpoint Response Action Configur…

Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Response Action Configuration (host isolation, process termination, and process sus…

kibana | Remote | Authorization
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
5.7 MEDIUM
CVE-2026-26933 — Improper Validation of Array Index in Packetbeat Leading to Denial of Service

Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker with the ability to s…

packetbeat | Memory Corruption
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
0.0 NA
CVE-2025-67115 — Sercomm Small Cell Path Traversal Vulnerability

A path traversal vulnerability in /ftl/web/setup.cgi in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote authenticated users to read arbitrary files…

| Path Traversal
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
0.0 NA
CVE-2025-67114 — Sercomm Small Cell FreedomFi Englewood Deterministic Credential Generation Algorithm Vuln…

Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers to derive v…

| Authentication
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
0.0 NA
CVE-2025-67113 — Sercomm Small Cell CWMP Command Injection Vulnerability

OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers controlling the ACS endpoint t…

| Injection
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
0.0 NA
CVE-2025-67112 — Small Cell Sercomm SCE4255W FreedomFi Englewood Hard-Coded AES-256-CBC Key Vulnerability

Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote authentic…

| Cryptography
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
0.0 NA
CVE-2026-30403 — wgcloud Arbitrary File Read Vulnerability

There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud v3.6.3 and before, which can be used to read any file on the victim's server.

| Path Traversal
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
5.7 MEDIUM
CVE-2026-26931 — Memory Allocation with Excessive Size Value in Metricbeat Leading to Denial of Service

Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).

| Denial of Service
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
2.1 LOW
CVE-2026-1005 — Integer underflow leads to out-of-bounds access in sniffer AES-GCM/CCM/ARIA-GCM decrypt p…

Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer overflow in the AEAD decryption path by injecting a TLS record shorter than the explicit IV plus authenticati…

wolfssl | Remote | Memory Corruption
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
2.2 LOW
CVE-2026-0819 — Stack buffer overflow in PKCS7 SignedData encoding with custom signed attributes

A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. In wc_PKCS7_BuildSignedAttributes(), when adding custom signed attributes, the code passes an incorr…

wolfssl | Memory Corruption
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
0.0 NA
CVE-2026-3029 — CVE-2026-3029

A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF version, 1.26.5.

| Path Traversal
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
5.5 MEDIUM
CVE-2026-32869 — OPEXUS eComplaint and eCASE XSS via Name of Organization field

OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field when filling out case information. An authenticated attacker can inject an XSS p…

ecase_ecomplaint | Remote | Cross-Site Scripting
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
5.5 MEDIUM
CVE-2026-32868 — OPEXUS eComplaint and eCASE XSS via my information

OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the 'My Information' screen. An authenticated attacker can inject parts of an XSS p…

ecase_ecomplaint | Remote | Cross-Site Scripting
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
5.4 MEDIUM
CVE-2026-32867 — OPEXUS eComplaint unauthenticated file upload

OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files via 'Portal/EEOC/DocumentUploadPub.aspx'. Users woul…

ecase_ecomplaint | Remote | Authentication
Mar 19, 2026 Mar 19, 2026
Mar 19, 2026
Mar 19, 2026
Showing 20 of 5743 Results