Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2026-21628 — Extension - astroidframe.work - Unauthenticated Remote Code Execution in Astroid Framewor…

A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.

astroid_framework | Remote | Authentication
Mar 05, 2026 Mar 13, 2026
Mar 05, 2026
Mar 13, 2026
7.5 HIGH
CVE-2026-1605 — Eclipse Jetty JDK Inflater Memory Leak

In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding …

jetty | Remote | Denial of Service
Mar 05, 2026 Mar 06, 2026
Mar 05, 2026
Mar 06, 2026
6.5 MEDIUM
CVE-2025-11143 — Jetty URI Parser Differential Parsing Vulnerability

The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security…

jetty | Remote | Misconfiguration
Mar 05, 2026 Mar 06, 2026
Mar 05, 2026
Mar 06, 2026
4.7 MEDIUM
CVE-2026-28551 — Cisco Device Security Management Module Race Condition Vulnerability

Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Race Condition
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
6.6 MEDIUM
CVE-2026-28549 — Apache Permission Service Race Condition

Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Race Condition
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
7.1 HIGH
CVE-2026-28548 — Apache Email Confidentiality Bypass

Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

emui harmonyos | Authentication
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
6.8 MEDIUM
CVE-2026-28547 — Cisco Scanning Module Pointer Uninitialized Access Vulnerability

Vulnerability of uninitialized pointer access in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
5.9 MEDIUM
CVE-2026-28546 — Cisco ASA Buffer Overflow

Buffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
7.3 HIGH
CVE-2026-28542 — Apache System Service Framework Privilege Escalation

Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Authorization
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
Showing 20 of 6089 Results