Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-33498 — Parse Server: Query condition depth bypass via pre-validation transform pipeline

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.55 and 9.6.0-alpha.44, an attacker can send an unauthenticated HTTP reque…

parse-server | Remote | Denial of Service
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
6.3 MEDIUM
CVE-2026-33429 — Parse Server: Protected field change detection oracle via LiveQuery watch parameter

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.54 and 9.6.0-alpha.43, an attacker can subscribe to LiveQuery with a watc…

parse-server | Remote | Information Disclosure
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.1 HIGH
CVE-2026-33421 — Parse Server: LiveQuery bypasses CLP pointer permission enforcement

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.53 and 9.6.0-alpha.42, Parse Server's LiveQuery WebSocket interface does …

parse-server | Remote | Authorization
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
6.5 MEDIUM
CVE-2026-33417 — Wallos: Password Reset Tokens Never Expire

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in Wallos never expire. The password_resets table includes a created_at timestamp …

wallos | Remote | Authentication
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.0 HIGH
CVE-2026-33409 — Parse Server: Auth provider validation bypass on login via partial authData

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.52 and 9.6.0-alpha.41, an authentication bypass vulnerability allows an a…

parse-server | Remote | Authentication
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
6.3 MEDIUM
CVE-2026-33323 — Parse Server: Email verification resend page leaks user existence

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.51 and 9.6.0-alpha.40, the Pages route and legacy PublicAPI route for res…

parse-server | Remote | Information Disclosure
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
8.6 HIGH
CVE-2026-30932 — Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in D…

Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the content field for seve…

froxlor | Remote | Injection
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
9.3 CRITICAL
CVE-2026-2417 — Missing Authentication for Critical Function in Pharos Controls Mosaic Show Controller

A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthenticated attacker to bypass authentication and exe…

Remote | Authentication
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
5.9 MEDIUM
CVE-2026-29772 — Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands

Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full request body as JSON without enforcing a size limit. Because JSON.parse() allocates …

\@astrojs\/node | Remote | Denial of Service
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
6.1 MEDIUM
CVE-2026-23924 — Agent 2 Docker plugin arbitrary file read via Docker API injection

Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary fi…

zabbix | Remote | Information Disclosure
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
6.9 MEDIUM
CVE-2026-23923 — Unauthenticated arbitrary PHP class instantiation

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.

zabbix | Remote | Authentication
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
8.7 HIGH
CVE-2026-23921 — Blind, read-only SQL injection in Zabbix API via sortfield parameter

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Althou…

zabbix | Remote | Injection
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.7 HIGH
CVE-2026-23920 — Host and event action script regex validation can be bypassed in certain situations, lead…

Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected n…

zabbix | Remote | Injection
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.1 HIGH
CVE-2026-23919 — Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Server

For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-…

zabbix | Information Disclosure
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.8 HIGH
CVE-2026-1995 — IDrive Cloud Backup Client for Windows contains a privilege escalation vulnerability

IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded contents of these files are used …

| Authentication
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
8.3 HIGH
CVE-2026-33407 — Wallos: SSRF via HTTP Proxy Environment Variable

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY and HTTPS_PROXY environment variables without valid…

wallos | Remote | Server-Side Request Forgery
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.1 HIGH
CVE-2026-33401 — Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass …

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the patch introduced in commit e8a513591 (CVE-2026-30840) added SSRF protection to notification test end…

wallos | Remote | Server-Side Request Forgery
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
5.4 MEDIUM
CVE-2026-33400 — Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endp…

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, a stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint allows any authe…

wallos | Remote | Cross-Site Scripting
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.7 HIGH
CVE-2026-33399 — Wallos: SSRF Bypass - Incomplete Fix for CVE-2026-30839/30840

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in version 4.6.2 for CVE-2026-30839 and CVE-2026-30840 is incomplete. The validate_…

wallos | Remote | Server-Side Request Forgery
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
4.9 MEDIUM
CVE-2026-33162 — Craft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to…

Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp can move entries across sections via POST /actions/…

craft_cms | Remote | Authorization
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
Showing 20 of 5732 Results