Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2025-63910 — Cohesity TranZman Migration Appliance File Upload Code Execution Vulnerability

An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers with Administrator privileges to execute arbitrary code via uplo…

Remote | Authentication
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
7.2 HIGH
CVE-2025-63909 — Cohesity TranZman Migration Appliance Privilege Escalation (Arbitrary File Access)

Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers to escalate privileges to root and read and writ…

Remote | Authorization
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
6.1 MEDIUM
CVE-2025-15599 — DOMPurify XSS via Textarea Rawtext Bypass in SAFE_FOR_XML

DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext elemen…

Remote | Cross-Site Scripting
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
2.0 LOW
CVE-2023-31044 — Nokia Impact Cross-Site Scripting (XSS) Vulnerability

An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the …

Remote | Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2021-35486 — Nokia IMPACT CSRF Vulnerability Allows Remote Configuration Overwrite

A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwrite the entire application configuration. Specifica…

| Cross-Site Request Forgery
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2021-35485 — Nokia IMPACT Remote File Upload Vulnerability

The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-side executable files via the /ui/rest-proxy/applicat…

| Authentication
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2021-35484 — Nokia IMPACT Time-based Boolean Blind SQL Injection

Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the Vi…

| Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2021-35483 — Nokia IMPACT Cross-Site Scripting (XSS) Vulnerability

The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload JavaScript files via the /ui/rest-proxy/application fileuplo…

| Cross-Site Scripting
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
5.3 MEDIUM
CVE-2026-3494 — MariaDB Server Audit Plugin Comment Handling Bypass

In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated datab…

Remote | Information Disclosure
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
8.6 HIGH
CVE-2026-3136 — Google Cloud Build Comment Control Bypass

An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execute arbitrary code in the build environment. This v…

Remote | Authorization
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2026-26886 — Sourcecodester Simple Online Men's Salon Management System SQL Injection

Sourcecodester Simple Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /admin/services/manage_service.php.

| Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2026-26885 — Sourcecodester Simple Online Men's Salon Management System SQL Injection

Sourcecodester Simple Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /classes/Master.php?f=delete_service.

| Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2026-26884 — Sourcecodester Simple Online Men's Salon Management System SQL Injection

Sourcecodester Simple Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/admin/appointments/view_appointment.php.

| Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2026-26883 — Sourcecodester Simple Online Men's Salon Management System SQL Injection Vulnerability

Sourcecodester Simple Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/classes/Master.php?f=delete_appointment.

| Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2025-62817 — Samsung Exynos NULL Pointer Dereference Denial of Service

An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of session->ncp_hdr_buf in __pilot_parsing_ncp() causes a denial of…

| Denial of Service
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2025-62816 — Samsung Mobile Processor Exynos Denial of Service Vulnerability

An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4L_VERTEXIOC_BOOTUP input leads to a denial of service.

| Denial of Service
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2025-66680 — WiseCleaner Wise Force Deleter Arbitrary File Deletion Vulnerability

An issue in the WiseDelfile64.sys component of WiseCleaner Wise Force Deleter 7.3.2 and earlier allows attackers to delete arbitrary files via a crafted request.

| Path Traversal
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2025-66363 — Samsung Exynos 2200 LBS Memory Initialization Vulnerability

An issue was discovered in LBS in Samsung Mobile Processor Exynos 2200. There was no check for memory initialization within DL NAS Transport messages.

| Memory Corruption
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2025-62815 — Samsung Exynos NULL Pointer Dereference Denial of Service

An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of npu_proto_drv.ast.thread_ref in set_cpu_affinity() causes a denial of servic…

| Denial of Service
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2025-62814 — Samsung Exynos Denial of Service Vulnerability

An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, and 2400. A NULL pointer dereference of ft_handle in load_fw_utc_vector() causes a denial of service.

| Denial of Service
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
Showing 20 of 4924 Results