Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-28490 — Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a cryptographic padding oracle vulnerability was identified in the Authlib Python library concerning…

| Cryptography
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
6.0 MEDIUM
CVE-2026-3644 — Incomplete control character validation in http.cookies

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characte…

Remote | Misconfiguration
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
0.0 NA
CVE-2026-27962 — Authlib JWS JWK Header Injection: Signature Verification Bypass

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attac…

| Authentication
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
0.0 NA
CVE-2026-4254 — Tenda AC8 HTTP Endpoint SysToolChangePwd doSystemCmd stack-based overflow

A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of the file /goform/SysToolChangePwd of the component HTTP Endpoint. This manipulati…

| Memory Corruption
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
7.8 HIGH
CVE-2026-23862 — Dell ThinOS Command Injection Vulnerability

Dell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with loca…

| Injection
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
6.8 MEDIUM
CVE-2026-4270 — AWS API MCP File Access Restriction Bypass

Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file acces…

| Path Traversal
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
10.0 HIGH
CVE-2026-4252 — Tenda AC8 IPv6 check_is_ipv6 ip address for authentication

A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The manipulation leads to reliance on ip address for authe…

Remote | Authentication
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
2.5 LOW
CVE-2026-4251 — CityData CityChat ai.citydata.citychat credentials.json credentials storage

A vulnerability was determined in CityData CityChat up to 0.12.6 on Android. Affected by this vulnerability is an unknown functionality of the file resources/assets/flutter_assets/assets/credentials.…

| Information Disclosure
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
0.0 NA
CVE-2026-30405 — GoBGP Denial of Service Vulnerability

An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attribute

| Denial of Service
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
0.0 NA
CVE-2025-65734 — Gunet Open eClass SVG File Upload Code Execution Vulnerability

An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, and fixed in v3.13, allows attackers to execute arbitrary code via uploading a …

| Misconfiguration
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
0.0 NA
CVE-2026-23489 — Fields GLPI plugin vulnerable to RCE in dropdown generation

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdow…

| Injection
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
0.0 NA
CVE-2026-4253 — Tenda AC8 Web UploadCfg route_set_user_policy_rule os command injection

A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route_set_user_policy_rule of the file /cgi-bin/UploadCfg of the component Web Interface. The manipulation of t…

| Injection
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
5.1 MEDIUM
CVE-2026-29510 — Hereta ETH-IMC408M Stored XSS via Device Name

Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by manipulating the Device …

Remote | Cross-Site Scripting
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
5.1 MEDIUM
CVE-2026-29513 — Hereta ETH-IMC408M Stored XSS via Device Location

Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by manipulating the Device …

Remote | Cross-Site Scripting
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
5.1 MEDIUM
CVE-2026-29520 — Hereta ETH-IMC408M Reflected XSS via ping_ipaddr Parameter

Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a reflected cross-site scripting vulnerability in the Network Diagnosis ping function that allows attackers to execute arbitrary JavaScrip…

Remote | Cross-Site Scripting
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
5.1 MEDIUM
CVE-2026-29521 — Hereta ETH-IMC408M CSRF via Configuration Setup

Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a cross-site request forgery vulnerability that allows attackers to modify device configuration by exploiting missing CSRF protections in …

Remote | Cross-Site Request Forgery
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
0.0 NA
CVE-2026-4276 — LibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows atta…

LibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows attackers to forge log entries.

| Injection
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
2.5 LOW
CVE-2026-4250 — Albert Sağlık Hizmetleri ve Ticaret Albert Health Google Cloud Service Account Key servic…

A vulnerability was found in Albert Sağlık Hizmetleri ve Ticaret Albert Health up to 1.7.3 on Android. Affected is an unknown function of the file resources/assets/service-account.json of the compone…

| Misconfiguration
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
5.4 MEDIUM
CVE-2026-32587 — WordPress WP EasyPay plugin <= 4.2.11 - Broken Access Control vulnerability

Missing Authorization vulnerability in Saad Iqbal WP EasyPay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP EasyPay: from n/a through 4.2.11.

Remote | Authorization
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
5.3 MEDIUM
CVE-2026-32583 — WordPress Modern Events Calendar plugin <= 7.29.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Webnus Inc. Modern Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Modern Events Calendar: from n/a t…

Remote | Authorization
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
Showing 20 of 5274 Results