Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.0 HIGH
CVE-2026-4318 — UTT HiPER 810G formApLbConfig strcpy buffer overflow

A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. Affected is the function strcpy of the file /goform/formApLbConfig. This manipulation of the argument loadBalanceNameOld causes bu…

Remote | Memory Corruption
Mar 17, 2026 Mar 18, 2026
Mar 17, 2026
Mar 18, 2026
9.0 CRITICAL
CVE-2026-3564 — ScreenConnect Instance Level Cryptographic Material Exposure

A condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain sce…

screenconnect | Remote | Cryptography
Mar 17, 2026 Mar 18, 2026
Mar 17, 2026
Mar 18, 2026
6.8 MEDIUM
CVE-2025-13406 — Scanning for higher HART revision device leads into NULL pointer dereference in live list

NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT (Webserver modules) allows HTTP DoS.This issue affects smartLink SW-HT: 1.43.

smartlink_sw-ht | Remote | Denial of Service
Mar 17, 2026 Mar 18, 2026
Mar 17, 2026
Mar 18, 2026
5.4 MEDIUM
CVE-2026-4324 — Rubygem-katello: katello: denial of service and potential information disclosure via sql …

A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of user-provided input, allows a remote attacker to inject arbitrary SQL commands int…

subscription_asset_manager | Remote | Injection
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
7.8 HIGH
CVE-2026-3888 — Local Privilege Escalation in snapd

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up th…

| Race Condition
Mar 17, 2026 Mar 18, 2026
Mar 17, 2026
Mar 18, 2026
4.7 MEDIUM
CVE-2025-62320 — HTML Injection Leading to Data Exfiltration to External Server vulnerability affects HCL …

HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML c…

Remote | Cross-Site Scripting
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
5.3 MEDIUM
CVE-2026-4271 — Libsoup: libsoup: denial of service via use-after-free in http/2 server

A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sen…

Remote | Memory Corruption
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
2.7 LOW
CVE-2025-31966 — Boolean-Based SQL Injection in Multiple Unica Components

HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An attacker can bypass these restrictio…

Remote | Injection
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
8.1 HIGH
CVE-2026-30911 — Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization

Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve,…

airflow | Remote | Authorization
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
7.5 HIGH
CVE-2026-28779 — Apache Airflow: Path of session token in cookie does not consider base_url - session hija…

Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url. This allows any application co-host…

airflow | Remote | Authentication
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
4.3 MEDIUM
CVE-2026-28563 — Apache Airflow: DAG authorization bypass

Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filtering by authorized DAG IDs. This allows an authenticated user with only DAG De…

airflow | Remote | Authorization
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
7.5 HIGH
CVE-2026-26929 — Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata

Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filtering when the request is made with dag_id set to "~" (wildcard for all DAGs). As a…

airflow | Remote | Authorization
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
3.9 LOW
CVE-2026-3634 — Libsoup: libsoup: http header injection and response splitting via crlf injection in cont…

A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in the `so…

Remote | Injection
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
3.9 LOW
CVE-2026-3633 — Libsoup: libsoup: header and http request injection via crlf injection

A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request data. This vulnerabilit…

Remote | Injection
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
3.9 LOW
CVE-2026-3632 — Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames

A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be…

Remote | Server-Side Request Forgery
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
0.0 NA
CVE-2026-23241 — audit: add missing syscalls to read class

In the Linux kernel, the following vulnerability has been resolved: audit: add missing syscalls to read class The "at" variant of getxattr() and listxattr() are missing from the audit read class. C…

linux_kernel | Misconfiguration
Mar 17, 2026 Mar 18, 2026
Mar 17, 2026
Mar 18, 2026
0.0 NA
CVE-2025-71239 — audit: add fchmodat2() to change attributes class

In the Linux kernel, the following vulnerability has been resolved: audit: add fchmodat2() to change attributes class fchmodat2(), introduced in version 6.6 is currently not in the change attribute…

linux_kernel | Misconfiguration
Mar 17, 2026 Mar 18, 2026
Mar 17, 2026
Mar 18, 2026
7.7 HIGH
CVE-2026-4208 — Authentication Bypass in extension "E-Mail MFA Provider" (mfa_email)

The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to…

Remote | Authentication
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
2.3 LOW
CVE-2026-4202 — Broken Access Control in extension "Redirect Tab"

The extension fails to verify, if an authenticated user has permissions to access to redirects resulting in exposure of redirect records when editing a page.

Remote | Authorization
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
5.3 MEDIUM
CVE-2026-32586 — WordPress Booster for WooCommerce plugin < 7.11.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Pluggabl Booster for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booster for WooCommerce: from n/a be…

booster_for_woocommerce | Remote | Authorization
Mar 17, 2026 Mar 17, 2026
Mar 17, 2026
Mar 17, 2026
Showing 20 of 5553 Results