Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-3381 — Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of …

Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib includes a copy of the zlib library. Compress::Raw::Zlib version 2.220 includes zli…

Remote | Supply Chain
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2026-3257 — UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite…

UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl embeds the UnQLite library. Version 0.06 and earlier of the Perl module uses a ve…

Remote | Memory Corruption
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
8.5 HIGH
CVE-2026-29126 — World-Writable, Root Owned/Run `/etc/udhcpc/default.script` in IDC SFX2100 Satellite Rece…

Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) SFX2100 Satellite Receiver allows a local unprivileged attacker to potentially …

| Authorization
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
7.1 HIGH
CVE-2026-29125 — IDC SFX2100 Satellite Receiver allows unprivileged modification of DNS configuration due …

IDC SFX2100 Satalite Recievers set the `/etc/resolv.conf` file to be world-writable by any local user, allowing DNS resolver tampering that can redirect network communications, facilitate man-in-the-…

| Misconfiguration
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
8.6 HIGH
CVE-2026-29124 — Multiple SUID Root Binaries in `monitor` User Home Directory Leading to Potential Local P…

Multiple SUID root-owned binaries are found in /home/monitor/terminal, /home/monitor/kore-terminal, /home/monitor/IDE-DPack/terminal-dpack, and /home/monitor/IDE-DPack/terminal-dpack2 in Internationa…

| Authorization
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
8.6 HIGH
CVE-2026-29123 — Multiple SUID Root Binaries in `xd` User Home Directory Leading to Potential Local Privil…

A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a local actor to potentially preform local privilege escalation depending on condi…

| Path Traversal
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
8.3 HIGH
CVE-2026-29122 — `/bin/date` Binary given SETUID Permissions on IDC SFX2100 Leading to Potential LPE

International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who c…

| Misconfiguration
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
9.1 CRITICAL
CVE-2025-40931 — Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id

Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD5 generates session ids insecurely. The default session id generator returns a …

Remote | Cryptography
Mar 05, 2026 Mar 06, 2026
Mar 05, 2026
Mar 06, 2026
9.8 CRITICAL
CVE-2025-40926 — Plack::Middleware::Session::Simple versions through 0.04 for Perl generates session ids i…

Plack::Middleware::Session::Simple versions through 0.04 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the …

Remote | Cryptography
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
8.4 HIGH
CVE-2026-29121 — `/sbin/ip` Binary given SETUID Permissions on IDC SFX2100 Leading to Potential LPE

International Data Casting (IDC) SFX2100 satellite receiver comes with the `/sbin/ip` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who ca…

| Misconfiguration
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
8.4 HIGH
CVE-2026-2836 — Cache poisoning via insecure-by-default cache key

A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the default HTTP cache key implementation generates cache…

pingora | Remote | Misconfiguration
Mar 05, 2026 Mar 06, 2026
Mar 05, 2026
Mar 06, 2026
9.3 CRITICAL
CVE-2026-2835 — HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing

An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs due to improperly allowing HTTP/1.0 request bodies t…

pingora | Remote | Misconfiguration
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
9.3 CRITICAL
CVE-2026-2833 — HTTP Request Smuggling via Premature Upgrade

An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora proxy reads a request containing an Upgrade header, …

pingora | Remote | Misconfiguration
Mar 05, 2026 Mar 05, 2026
Mar 05, 2026
Mar 05, 2026
5.3 MEDIUM
CVE-2026-22052 — NetApp ONTAP S3 NAS Bucket Information Disclosure Vulnerability

ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the cont…

Remote | Information Disclosure
Mar 05, 2026 Mar 06, 2026
Mar 05, 2026
Mar 06, 2026
5.7 MEDIUM
CVE-2026-2297 — SourcelessFileLoader does not use io.open_code()

The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.au…

python | Misconfiguration
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
5.4 MEDIUM
CVE-2026-29086 — Hono: Cookie Attribute Injection via Unsanitized domain and path in setCookie()

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCookie() utility did not validate semicolons (;), carriage returns (\r), or newli…

hono | Remote | Injection
Mar 04, 2026 Mar 06, 2026
Mar 04, 2026
Mar 06, 2026
6.5 MEDIUM
CVE-2026-29085 — Hono: SSE Control Field Injection via CR/LF in writeSSE()

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming Helper, the event, id, and retry fields were not val…

hono | Remote | Injection
Mar 04, 2026 Mar 06, 2026
Mar 04, 2026
Mar 06, 2026
9.8 CRITICAL
CVE-2026-29045 — Hono: Arbitrary file access via serveStatic vulnerability

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/…

hono | Remote | Authorization
Mar 04, 2026 Mar 06, 2026
Mar 04, 2026
Mar 06, 2026
6.3 MEDIUM
CVE-2026-26002 — OnDemand susceptible to malicious input when navigating to a directory.

Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible to malicious input when navigating to a directory…

open_ondemand | Remote | Path Traversal
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
4.8 MEDIUM
CVE-2025-41257 — Suprema BioStar 2 Insecure Password Change

Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account a…

Remote | Authentication
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
Showing 20 of 5122 Results