Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2025-71269 — btrfs: do not free data reservation in fallback from inline due to -ENOSPC

In the Linux kernel, the following vulnerability has been resolved: btrfs: do not free data reservation in fallback from inline due to -ENOSPC If we fail to create an inline extent due to -ENOSPC, …

linux_kernel | Denial of Service
Mar 18, 2026 Apr 11, 2026
Mar 18, 2026
Apr 11, 2026
0.0 NA
CVE-2025-71268 — btrfs: fix reservation leak in some error paths when inserting inline extent

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix reservation leak in some error paths when inserting inline extent If we fail to allocate a path or join a transaction,…

linux_kernel | Memory Corruption
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.1 HIGH
CVE-2026-32610 — Glances's Default CORS Configuration Allows Cross-Origin Credential Theft

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server ships with a default CORS configuration that sets `allow_origins=["*"]` combin…

glances | Remote | Misconfiguration
Mar 18, 2026 Mar 21, 2026
Mar 18, 2026
Mar 21, 2026
6.1 MEDIUM
CVE-2026-30695 — Zucchetti Axess Cross-Site Scripting (XSS)

A Cross-Site Scripting (XSS) vulnerability exists in the web-based configuration interface of Zucchetti Axess access control devices, including XA4, X3/X3BIO, X4, X7, and XIO / i-door / i-door+. The …

Remote | Cross-Site Scripting
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
7.5 HIGH
CVE-2026-30345 — CTFd Zip Slip File Write Vulnerability

A zip slip vulnerability in the Admin import functionality of CTFd v3.8.1-18-gdb5a18c4 allows attackers to write arbitrary files outside the intended directories via supplying a crafted import.

Remote | Path Traversal
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
8.8 HIGH
CVE-2026-1463 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery <= 4.0.4 - Authenticated (A…

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.3 via the 'template' parameter i…

nextgen_gallery | Remote | Path Traversal
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
9.8 CRITICAL
CVE-2025-67830 — Mura SQL Injection Vulnerability

Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.

mura_cms | Remote | Injection
Mar 18, 2026 Mar 21, 2026
Mar 18, 2026
Mar 21, 2026
Showing 20 of 6507 Results