Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-2458 — Unauthorized channel enumeration in private teams after member removal

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membership when searching channels which allows a removed team member to enumerate all publi…

Remote | Authorization
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
4.3 MEDIUM
CVE-2026-2457 — WebSocket Message Spoofing via Permalink Embed Manipulation

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metadata which allows an authenticated attacker to spoof permalink embeds impersonati…

Remote | Authentication
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
5.3 MEDIUM
CVE-2026-2456 — Denial of Service via Unbounded Memory Allocation in Integration Actions

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of responses from integration action endpoints, which allows an authenticated attacker t…

Remote | Denial of Service
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
5.3 MEDIUM
CVE-2026-2233 — User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Re…

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi…

Remote | Authorization
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
7.1 HIGH
CVE-2026-28522 — arduino-TuyaOpen WiFiUDP Null Pointer Dereference Denial of Service

arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An attacker on the same local area network can send a large volume of malicious UDP p…

| Denial of Service
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
7.7 HIGH
CVE-2026-28521 — arduino-TuyaOpen TuyaIoT Out-of-Bounds Memory Read Information Disclosure

arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An attacker who hijacks or controls the Tuya cloud service can issue malicious DP e…

| Memory Corruption
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
8.6 HIGH
CVE-2026-28520 — arduino-TuyaOpen WiFiMulti Single-Byte Buffer Overflow Remote Code Execution

arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. When the victim's smart hardware connects to an attacker-controlled AP hotspot, …

| Memory Corruption
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
8.8 HIGH
CVE-2026-28519 — arduino-TuyaOpen DnsServer Heap-Based Buffer Overflow Remote Code Execution

arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area network who controls the LAN DNS server can se…

| Memory Corruption
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
4.3 MEDIUM
CVE-2026-26246 — Memory Exhaustion via Malformed PSD File Upload

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing PSD image files which allows an authenticated attacker to cause server memo…

Remote | Denial of Service
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
7.1 HIGH
CVE-2026-26133 — M365 Copilot Information Disclosure Vulnerability

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
4.3 MEDIUM
CVE-2026-25783 — Denial of service via malformed User-Agent header in getBrowserVersion

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header tokens which allows an authenticated attacker to cause a request panic via a sp…

Remote | Denial of Service
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
4.3 MEDIUM
CVE-2026-25780 — Memory Exhaustion via Malformed DOC File Upload

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing DOC files which allows an authenticated attacker to cause server memory exh…

Remote | Denial of Service
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
8.7 HIGH
CVE-2026-25083 — GROWI OpenAI Authorization Bypass

GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logged-in user who knows a shared AI assistant's identifier may view and/or tamper …

| Authorization
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
7.5 HIGH
CVE-2026-24458 — DoS attack via login attempts with multi-megabyte passwords

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to overload the server CPU and memory via executing l…

Remote | Denial of Service
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
7.1 HIGH
CVE-2026-21005 — Cisco Smart Switch Path Traversal Vulnerability

Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.

| Path Traversal
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
6.9 MEDIUM
CVE-2026-21004 — Cisco Smart Switch Authentication Bypass Denial of Service Vulnerability

Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.

| Authentication
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
5.9 MEDIUM
CVE-2026-21002 — Galaxy Store Cryptographic Signature Verification Vulnerability

Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.

| Cryptography
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
5.9 MEDIUM
CVE-2026-21001 — Galaxy Store Path Traversal File Creation Vulnerability

Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.

| Path Traversal
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
7.0 HIGH
CVE-2026-21000 — Galaxy Store Privilege Escalation Vulnerability

Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.

| Authorization
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
7.1 HIGH
CVE-2026-20999 — Smart Switch Authentication Bypass by Replay Vulnerability

Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.

Remote | Authentication
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
Showing 20 of 5304 Results