Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.3 HIGH
CVE-2026-32805 — Romeo is vulnerable to Archive Slip due to missing checks in sanitization

Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests within GitHub Actions. Prior to version 0.2.2, the `sa…

Remote | Path Traversal
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
7.9 HIGH
CVE-2026-32737 — Romeo's invalid NetworkPolicy enables a malicious actor to pivot into another namespace

Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests within GitHub Actions. Prior to version 0.2.1, due to …

Remote | Misconfiguration
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
4.3 MEDIUM
CVE-2026-32736 — Hytale Modding Wiki has Insecure Direct Object Reference / GDPR PII Exposure

The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. An Insecure Direct Object Reference (IDOR) vulnerability in versions of the wiki prior to 1.0.0 exposes …

Remote | Information Disclosure
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
2.3 LOW
CVE-2026-32735 — Unpacking Arbitrary Mustache Template Files via `maven-dependency-plugin`

openapi-to-java-records-mustache-templates allows users to generate Java Records from OpenAPI specifications. Starting in version 5.1.1 and prior to version 5.5.1, the parent POM file of this project…

Remote | Supply Chain
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
9.9 CRITICAL
CVE-2026-32731 — ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip …

ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `gzip.js` constructs file-write paths using `fs.cre…

Remote | Path Traversal
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.1 HIGH
CVE-2026-32730 — ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware

ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/express/index.js` (lines 386-389) contains an inco…

apostrophecms | Remote | Authentication
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.1 HIGH
CVE-2025-15031 — Path Traversal Vulnerability in mlflow/mlflow

A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically, the use of `tarfile.extractall` without path vali…

mlflow | Path Traversal
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
2.1 LOW
CVE-2026-4407 — Out-of-bounds array write in Xpdf 4.06 due to missing validation

Out-of-bounds array write in Xpdf 4.06 and earlier, due to incorrect validation of the "N" field in ICCBased color spaces.

xpdf | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.2 HIGH
CVE-2026-33163 — Parse Server leaks protected fields via LiveQuery afterEvent trigger

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.35 and 8.6.50, when a `Parse.Cloud.afterLiveQueryEvent` trigger is registe…

parse-server | Remote | Information Disclosure
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
6.9 MEDIUM
CVE-2026-33042 — Parse Server affected by empty authData bypassing credential requirement on signup

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.29 and 8.6.49, a user can sign up without providing credentials by sending…

parse-server | Remote | Authentication
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.7 HIGH
CVE-2026-32944 — Parse Server crash via deeply nested query condition operators

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.21 and 8.6.45, an unauthenticated attacker can crash the Parse Server proc…

parse-server | Remote | Denial of Service
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
3.1 LOW
CVE-2026-32943 — Parse Server has a password reset token single-use bypass via concurrent requests

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.28 and 8.6.48, the password reset mechanism does not enforce single-use gu…

parse-server | Remote | Race Condition
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.2 HIGH
CVE-2026-32886 — Parse Server's Cloud function dispatch crashes server via prototype chain traversal

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.24 and 8.6.47, remote clients can crash the Parse Server process by callin…

parse-server | Remote | Denial of Service
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
7.5 HIGH
CVE-2026-32878 — Parse Server vulnerable to schema poisoning via prototype pollution in deep copy

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.20 and 8.6.44, an attacker can bypass the default request keyword denylist…

parse-server | Remote | Misconfiguration
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
7.5 HIGH
CVE-2026-32770 — Parse Server: LiveQuery subscription with invalid regular expression crashes server

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.19 and 8.6.43, a remote attacker can crash the Parse Server by subscribing…

parse-server | Remote | Denial of Service
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
4.3 MEDIUM
CVE-2026-32742 — Parse Server session creation endpoint allows overwriting server-generated session fields

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.17 and 8.6.42, an authenticated user can overwrite server-generated sessio…

parse-server | Remote | Authentication
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.3 HIGH
CVE-2026-32728 — Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing X…

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.15 and 8.6.41, an attacker who is allowed to upload files can bypass the f…

parse-server | Remote | Cross-Site Scripting
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
4.8 MEDIUM
CVE-2026-32723 — SandboxJS timers have an execution-quota bypass (cross-sandbox currentTicks race)

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.35, SandboxJS timers have an execution-quota bypass. A global tick state (`currentTicks.current`) is shared between sandboxes. Timer string …

sandboxjs | Misconfiguration
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
6.1 MEDIUM
CVE-2026-32722 — Memray-generated HTML reports vulnerable to Stored XSS via unescaped command-line metadata

Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no esc…

memray | Remote | Cross-Site Scripting
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
9.0 CRITICAL
CVE-2026-32703 — OpenProject's repository files are served with the MIME type allowing them to be used to …

OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not properly escape filenames displayed from…

openproject | Remote | Cross-Site Scripting
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
Showing 20 of 5710 Results