Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-33083 — DataEase has SQL Injection in Order By Clause

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the orderDirection parameter used in dataset-related endpoint…

dataease | Remote | Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
8.7 HIGH
CVE-2026-33082 — DataEase: SQL Injection in v2 Dataset Export

DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerability in the dataset export functionality. The expressionTree parameter in POST…

dataease | Remote | Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
8.7 HIGH
CVE-2026-2336 — Weak webstax_auth Cookie Authentication Allows Privilege Escalation

A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a…

Remote | Authentication
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
1.7 LOW
CVE-2026-27820 — zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corrupti…

zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The z…

zlib | Remote | Memory Corruption
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
5.3 MEDIUM
CVE-2026-24749 — Silverstripe Assets Module has a DBFile::getURL() permission bypass

The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile…

assets | Remote | Authorization
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
4.1 MEDIUM
CVE-2025-43883 — Dell PowerScale OneFS Denial of Service Vulnerability

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability. A high privileged attacker with local access could potentially explo…

powerscale_onefs | Denial of Service
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
2.9 LOW
CVE-2026-41080 — Oracle libexpat Hash Flooding Vulnerability

libexpat before 2.7.6 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

libexpat | Denial of Service
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
5.1 MEDIUM
CVE-2025-36579 — Dell Client Platform BIOS Authentication Bypass

Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leadi…

| Authentication
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
0.0 NA
CVE-2026-5426 — KnowledgeDeliver deployments before February 24, 2026 use a static ASP.NET/IIS machineKey…

Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remot…

| Misconfiguration
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
0.0 NA
CVE-2026-37100 — Yamaha SR-B30A BLE Authentication Bypass Vulnerability

An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: Sound Bar Remote / version: 2.40) allows remote attackers within BLE radio rang…

| Authentication
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
7.1 HIGH
CVE-2026-6409 — Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsi…

A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Maliciously structured messages—specifically those containing negative varints or dee…

protobuf | Remote | Denial of Service
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
8.2 HIGH
CVE-2026-3324 — Authentication Bypass

Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration.

manageengine_log360 | Remote | Authentication
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
9.1 CRITICAL
CVE-2026-37347 — SourceCodester Payroll Management and Information System SQL Injection Vulnerability

SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php.

Remote | Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
4.7 MEDIUM
CVE-2026-37346 — SourceCodester Payroll Management and Information System SQL Injection

SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_account.php?emp_id=.

Remote | Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
9.8 CRITICAL
CVE-2026-37345 — SourceCodester Vehicle Parking Area Management System SQL Injection

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php.

Remote | Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
0.0 NA
CVE-2026-37344 — SourceCodester Vehicle Parking Area Management System SQL Injection

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_location.php.

| Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
0.0 NA
CVE-2026-37343 — SourceCodester Vehicle Parking Area Management System SQL Injection Vulnerability

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_user.php.

| Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
0.0 NA
CVE-2026-37342 — SourceCodester Vehicle Parking Area Management System SQL Injection

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_parked_details.php.

| Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
0.0 NA
CVE-2026-37341 — SourceCodester Vehicle Parking Area Management System SQL Injection

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_category.php.

| Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
0.0 NA
CVE-2026-37340 — SourceCodester Simple Music Cloud Community System SQL Injection Vulnerability

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php.

| Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
Showing 20 of 6514 Results