Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.8 MEDIUM
CVE-2026-3463 — xlnt-community xlnt Compound Document binary.hpp append heap-based overflow

A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::binary_writer::append of the file source/detail/binary.hpp of the component Compound Document…

| Memory Corruption
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2025-59060 — Apache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClient

Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this …

| Misconfiguration
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2025-59059 — Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator

Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

| Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
7.2 HIGH
CVE-2026-2568 — WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.5 - …

The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission data in all versions up to, and…

Remote | Cross-Site Scripting
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-22886 — Apache OpenMQ Default Administrative Account Vulnerability

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforc…

Remote | Authentication
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
6.3 MEDIUM
CVE-2025-15598 — Dataease SQLBot JWT Token auth.py validateEmbedded signature verification

A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing …

Remote | Cryptography
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
8.7 HIGH
CVE-2026-1876 — Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series Ethernet…

Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a remote attacker to cause a deni…

Remote | Denial of Service
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
8.7 HIGH
CVE-2026-1875 — Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet…

Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP all versions allows a remote attacker to cause a denial-of…

Remote | Denial of Service
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
8.7 HIGH
CVE-2026-1874 — Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet…

Always-Incorrect Control Flow Implementation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP versions 1.106 and prior and Mitsubishi Electr…

Remote | Denial of Service
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
5.7 MEDIUM
CVE-2025-15595 — Privilege escalation via dll hijacking in Inno Setup

Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.

| Authentication
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
9.0 HIGH
CVE-2025-12345 — LLM-Claw Agent Deployment initiate.c agent_deploy_init buffer overflow

A security vulnerability has been detected in LLM-Claw 0.1.0/0.1.1/0.1.1a/0.1.1a-p1. The affected element is the function agent_deploy_init of the file /agents/deploy/initiate.c of the component Agen…

Remote | Memory Corruption
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
6.1 MEDIUM
CVE-2026-3455 — Mailparser Cross-site Scripting (XSS) Vulnerability

Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() function due to the improper sanitisation of URLs in the email content. An attacker c…

Remote | Cross-Site Scripting
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
4.8 MEDIUM
CVE-2026-3449 — "Once Package Incorrect Control Flow Scoping Vulnerability"

Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resolving when AbortSignal option is used. The Promise remains in a permanently pend…

| Misconfiguration
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-1492 — User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Member…

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privileg…

Remote | Authorization
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
5.6 MEDIUM
CVE-2026-20801 — Gallagher Hanwha VMS and Gallagher NxWitness VMS Unprivileged Access to Live Video Streams

Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations allows unprivileged users with local network access …

Remote | Cryptography
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
2.5 LOW
CVE-2026-20757 — Gallagher Morpho Command Centre Server Denial-of-Service Vulnerability

Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server. This issue affects Command …

| Race Condition
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
5.7 MEDIUM
CVE-2025-47147 — Command Centre Mobile Client Cleartext Storage of Sensitive Information

Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the …

| Cryptography
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-2628 — All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login <= 2.2.5 - Authentication Bypass

The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.2.5. This makes it possible for unauth…

Remote | Authentication
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
8.8 HIGH
CVE-2026-2448 — Page Builder by SiteOrigin <= 2.33.5 - Authenticated (Contributor+) Local File Inclusion

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.5 via the locate_template() function. This makes it possible for a…

page_builder | Remote | Path Traversal
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
7.2 HIGH
CVE-2026-2269 — Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7…

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.0.…

uncanny_automator | Remote | Server-Side Request Forgery
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
Showing 20 of 4881 Results