Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-3538 — Google Chrome Skia Integer Overflow

Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Cr…

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
8.8 HIGH
CVE-2026-3537 — Google Chrome PowerVR Heap Corruption Vulnerability

Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security seve…

linux_kernel chrome macos windows | Remote | Memory Corruption
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
8.8 HIGH
CVE-2026-3536 — Google Chrome ANGLE Integer Overflow Vulnerability

Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: C…

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
7.5 HIGH
CVE-2026-28435 — Payload size limit bypass via gzip decompression in ContentReader (streaming) allows over…

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, cpp-httplib (httplib.h) does not enforce Server::set_payload_max_length() on the decompressed reques…

cpp-httplib | Remote | Denial of Service
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
5.3 MEDIUM
CVE-2026-28434 — cpp-httplib's default exception handler leaks e.what() to clients via EXCEPTION_WHAT resp…

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, when a request handler throws a C++ exception and the application has not registered a custom except…

cpp-httplib | Remote | Information Disclosure
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
5.9 MEDIUM
CVE-2026-28427 — OpenDeck affected by path traversal allows arbitrary file read

OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1, the service listening on port 57118 serves static files for installed plugins but does not properly sanitize path components. B…

Remote | Path Traversal
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2025-70219 — D-Link DIR-513 Stack Buffer Overflow Vulnerability

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the goform/formDeviceReboot.

dir-513_firmware dir-513 | Remote | Memory Corruption
Mar 04, 2026 Mar 06, 2026
Mar 04, 2026
Mar 06, 2026
7.7 HIGH
CVE-2026-3125 — SSRF vulnerability in opennextjs-cloudflare via /cdn-cgi/ path normalization bypass

A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package, resulting from a path normalization bypass in the /cdn-cgi/image/ handler.The @opennextjs/clou…

Remote | Server-Side Request Forgery
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.5 MEDIUM
CVE-2026-20064 — Cisco Secure Firewall Threat Defense (FTD) Software CLI Command Injection Vulnerability

A vulnerability in of Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to cause the device to unexpectedly reload, causing a denial of service (DoS) co…

| Denial of Service
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.8 MEDIUM
CVE-2026-20025 — Cisco Secure Firewall ASA Software and Cisco Secure FTD Software OSPF LSU Packet Heap Cor…

A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpect…

| Denial of Service
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.8 MEDIUM
CVE-2026-20024 — "Cisco OSPF Heap Corruption Remote DoS Vulnerability"

A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpect…

| Memory Corruption
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.1 MEDIUM
CVE-2026-20023 — Cisco OSPF Protocol Memory Corruption Denial of Service Vulnerability

A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjace…

| Memory Corruption
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.1 MEDIUM
CVE-2026-20022 — Cisco Secure Firewall ASA/Cisco Secure FTD OSPF LSU Packet Buffer Overflow Denial of Serv…

A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpe…

| Denial of Service
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
4.3 MEDIUM
CVE-2026-20021 — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) OSPF Pro…

A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, adjacent…

| Denial of Service
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.8 MEDIUM
CVE-2026-20020 — Cisco Secure Firewall ASA Software and Cisco Secure FTD Software OSPF Buffer Overflow DoS…

A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpe…

| Denial of Service
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.0 MEDIUM
CVE-2026-20016 — "Cisco FXOS Software CLI Command Injection Vulnerability"

A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Secure FTD Software could allow an authenticated, local attacker to execute arbitrary commands on the…

| Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
8.6 HIGH
CVE-2026-0847 — Path Traversal in nltk/nltk

A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and Brac…

nltk | Remote | Path Traversal
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
9.8 CRITICAL
CVE-2025-70226 — D-Link DIR-513 Stack Buffer Overflow

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formEasySetupWizard.

dir-513_firmware dir-513 | Remote | Memory Corruption
Mar 04, 2026 Mar 06, 2026
Mar 04, 2026
Mar 06, 2026
9.8 CRITICAL
CVE-2025-70223 — D-Link DIR-513 Buffer Overflow Vulnerability

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAdvNetwork.

dir-513_firmware dir-513 | Remote | Memory Corruption
Mar 04, 2026 Mar 06, 2026
Mar 04, 2026
Mar 06, 2026
7.8 HIGH
CVE-2026-26949 — Dell Device Management Agent DDMA Incorrect Authorization Elevation of Privilege

Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerabilit…

device_management_agent | Authorization
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
Showing 20 of 5122 Results