Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-25745 — OpenEMR's Message Update Ignores Patient id

OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the message/note update endpoint (e.g. PUT or POST) upd…

openemr | Remote | Authorization
Mar 18, 2026 Mar 20, 2026
Mar 18, 2026
Mar 20, 2026
8.3 HIGH
CVE-2026-4396 — Devolutions Hub Reporting Service TLS Certificate Verification Bypass

Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.

| Cryptography
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.1 HIGH
CVE-2026-31971 — HTSlib CRAM decoder vulnerable to buffer overflow

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compression methods. Whe…

htslib | Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.1 HIGH
CVE-2026-31970 — HTSlib BGZF index file reader has a heap buffer overflow

HTSlib is a library for reading and writing bioinformatics file formats. GZI files are used to index block-compressed GZIP [BGZF] files. In the GZI loading function, `bgzf_index_load_hfile()`, it wa…

htslib | Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.1 HIGH
CVE-2026-31969 — HTSlib CRAM decoder has a heap buffer overflow

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compression methods. Wh…

htslib | Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.8 HIGH
CVE-2026-31968 — HTSlib CRAM decoder vulnerable to buffer overflow

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compression methods. For…

htslib | Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
9.1 CRITICAL
CVE-2026-31967 — HTSlib CRAM reader has out-of-bounds read due to improper validation of input

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the `cram_decode_slice()` function called while readi…

htslib | Remote | Information Disclosure
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
9.1 CRITICAL
CVE-2026-31966 — HTSlib CRAM reader has out-of-bounds read due to improper validation of input

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one method of removing redundant data, CRAM uses refe…

htslib | Remote | Information Disclosure
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
2.1 LOW
CVE-2026-3479 — pkgutil.get_data() does not enforce documented restrictions

pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.

python | Path Traversal
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.2 HIGH
CVE-2026-31965 — HTSlib CRAM reader has out-of-bounds reads due to improper validation of input

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the `cram_decode_slice()` function called while readi…

htslib | Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
7.5 HIGH
CVE-2026-31964 — HTSlib CRAM decoder has a NULL Pointer Dereference

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compression methods. Wh…

htslib | Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.8 HIGH
CVE-2026-31963 — HTSlib CRAM reader has heap buffer overflow due to improper validation of input

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one method of removing redundant data, CRAM uses refe…

htslib | Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.8 HIGH
CVE-2025-58112 — Microsoft Dynamics 365 Customer Engagement SQL Injection

Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an upload of a .rdl (Report Definition Language) file; th…

Remote | Injection
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.1 HIGH
CVE-2026-32634 — Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Serv…

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised server name and the discovered IP address…

glances | Authentication
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
9.1 CRITICAL
CVE-2026-32633 — Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint returns raw server objects from `GlancesServersList…

glances | Remote | Information Disclosure
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
5.9 MEDIUM
CVE-2026-32632 — Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding

Glances is an open-source system cross-platform monitoring tool. Glances recently added DNS rebinding protection for the MCP endpoint, but prior to version 4.5.2, the main REST/WebUI FastAPI applicat…

glances | Remote | Misconfiguration
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
9.1 CRITICAL
CVE-2026-32611 — Glances has a SQL Injection in DuckDB Export via Unparameterized DDL Statements

Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL injection in the TimescaleDB export module by converting all SQL operations to use pa…

glances | Remote | Injection
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.8 HIGH
CVE-2026-31962 — HTSlib CRAM reader has heap buffer overflow due to improper validation of input

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. While most alignment records store DNA sequence and qual…

htslib | Remote | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
9.1 CRITICAL
CVE-2026-30704 — "WDR201A WiFi Extender UART Interface Information Disclosure Vulnerability"

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCB

Remote | Misconfiguration
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
0.0 NA
CVE-2026-30703 — WiFi Extender WDR201A Command Injection Vulnerability

A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02). The adm.cgi endpoint improperly sanitizes user-supplied input p…

| Injection
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
Showing 20 of 5697 Results