Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2025-13957 — PostgreSQL SOCKS Proxy Hard-coded Credentials Remote Code Execution

CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code execution when SOCKS Proxy is enabled, and administrator credentials and PostgreSQL…

Remote | Authentication
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
5.1 MEDIUM
CVE-2025-13902 — Apache Web Server Cross-site Scripting (XSS)

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated attackers can have a victim’s browser r…

Remote | Cross-Site Scripting
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
6.9 MEDIUM
CVE-2025-13901 — Machine Expert Protocol Resource Shutdown Weakness

CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unauthenticated attacker sends malicious payload to oc…

Remote | Denial of Service
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
8.5 HIGH
CVE-2025-11739 — Apache Java Deserialization Code Execution Vulnerability

CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data str…

| Injection
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
7.5 HIGH
CVE-2026-3585 — The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_cre…

The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_import' function. This makes it possible for authentica…

Remote | Path Traversal
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
5.4 MEDIUM
CVE-2026-30927 — Admidio: Event participation IDOR - non-leaders can register other users for events via u…

Admidio is an open-source user management solution. Prior to 5.0.6, in modules/events/events_function.php, the event participation logic allows any user who can participate in an event to register OT…

admidio | Remote | Authorization
Mar 10, 2026 Mar 13, 2026
Mar 10, 2026
Mar 13, 2026
8.2 HIGH
CVE-2026-30925 — Parse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query …

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-alpha.14 and 8.6.11, a malicious client can subscribe to a LiveQuery with a craf…

parse-server | Remote | Denial of Service
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
9.9 CRITICAL
CVE-2026-30921 — OneUptime Synthetic Monitor RCE via exposed Playwright browser object

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project users to submit custom Playwright code that is execute…

oneuptime | Remote | Injection
Mar 10, 2026 Mar 12, 2026
Mar 10, 2026
Mar 12, 2026
8.6 HIGH
CVE-2026-30920 — OneUptime has broken access control in GitHub App installation flow that allows unauthori…

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.…

oneuptime | Remote | Authorization
Mar 10, 2026 Mar 12, 2026
Mar 10, 2026
Mar 12, 2026
7.6 HIGH
CVE-2026-30919 — facileManager Affected by Stored Cross-Site Scripting (XSS)

facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as persistent or second-order XSS) occurs when an application receives data from …

facilemanager | Remote | Cross-Site Scripting
Mar 10, 2026 Mar 13, 2026
Mar 10, 2026
Mar 13, 2026
7.6 HIGH
CVE-2026-30918 — facileManager Affected by Reflected Cross-Site Scripting (XSS)

facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs when an application receives data from an untrusted source and uses it in its HTT…

facilemanager | Remote | Cross-Site Scripting
Mar 10, 2026 Mar 13, 2026
Mar 10, 2026
Mar 13, 2026
8.8 HIGH
CVE-2026-30917 — Stored XSS on Bucket namespace pages

Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to 2.1.1, a stored XSS can be inserted into any Bucket table field that has a PAGE type, which will execute wh…

Remote | Cross-Site Scripting
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
4.6 MEDIUM
CVE-2026-30913 — flarum/nickname: Display name injection in notification emails (autolink & markdown)

Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their nickname to a string that email clients interpret as a hyperlink. The nickname is…

flarum | Remote | Cross-Site Scripting
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
9.9 CRITICAL
CVE-2026-30887 — OneUptime Affected by Unsandboxed Code Execution in Probe Allows Any Project Member to Ac…

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/JavaScript code via Synthetic Monitors to test website…

oneuptime | Remote | Injection
Mar 10, 2026 Mar 12, 2026
Mar 10, 2026
Mar 12, 2026
5.5 MEDIUM
CVE-2026-30885 — WWBN AVideo - Unauthenticated IDOR - Playlist Information Disclosure

WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user without requiring authentication or authorization. An …

avideo | Remote | Authorization
Mar 10, 2026 Mar 13, 2026
Mar 10, 2026
Mar 13, 2026
6.5 MEDIUM
CVE-2026-30870 — Some sync filters in PowerSync Service ignored using `config.edition: 3`

PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync streams with config.edition: 3, certain subquery filters were ignored when determin…

Remote | Authorization
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
9.8 CRITICAL
CVE-2026-30869 — SiYuan has a Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Lea…

SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read arbitrary files from the server filesystem. By exp…

siyuan | Remote | Path Traversal
Mar 10, 2026 Mar 13, 2026
Mar 10, 2026
Mar 13, 2026
9.0 CRITICAL
CVE-2026-30862 — Critical Stored XSS & Privilege Escalation in Appsmith

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table Widget (TableWidgetV2). The root cause is a lack o…

appsmith | Remote | Cross-Site Scripting
Mar 10, 2026 Mar 13, 2026
Mar 10, 2026
Mar 13, 2026
7.3 HIGH
CVE-2026-2364 — CODESYS Installer TOCTOU Privilege Escalation

If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Development System, a low privileged local attacker can gain elevated rights due to a TOCTOU vulnerability …

| Race Condition
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
4.3 MEDIUM
CVE-2026-29773 — kubewarden-controller cross-namespace data exfiltration via deprecated host callback bind…

Kubewarden is a policy engine for Kubernetes. Kubewarden cluster operators can grant permissions to users to deploy namespaced AdmissionPolicies and AdmissionPolicyGroups in their Namespaces. One of …

Remote | Authorization
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
Showing 20 of 5702 Results