Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-35056 — XenForo Remote Code Execution via Authenticated Admin

XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.

xenforo | Remote | Authentication
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
6.1 MEDIUM
CVE-2026-35055 — XenForo Cross-Site Scripting via Lightbox in Posts

XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with p…

xenforo | Remote | Cross-Site Scripting
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
6.4 MEDIUM
CVE-2026-35054 — XenForo Stored Cross-Site Scripting via BB Code Rendering

XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other …

xenforo | Remote | Cross-Site Scripting
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
6.3 MEDIUM
CVE-2026-2394 — Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overre…

Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6…

connext_professional | Remote | Memory Corruption
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
8.7 HIGH
CVE-2025-71282 — XenForo Path Disclosure via open_basedir Exceptions

XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure.

xenforo | Remote | Information Disclosure
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
9.8 CRITICAL
CVE-2025-71281 — XenForo Template Method Call Restriction Bypass

XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for methods accessible through callbacks a…

xenforo | Remote | Authorization
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
6.9 MEDIUM
CVE-2025-71280 — XenForo Local Account Page Caching Information Disclosure

XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached account pages could expose sens…

xenforo | Information Disclosure
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
9.8 CRITICAL
CVE-2025-71279 — XenForo Passkey Security Bypass

XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication.

xenforo | Remote | Authentication
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
8.8 HIGH
CVE-2025-71278 — XenForo OAuth2 Unauthorized Scope Request

XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior to 2.3.5, potentially allowin…

xenforo | Remote | Authorization
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
7.6 HIGH
CVE-2025-13855 — IBM Storage Protect Server is affected by a vulnerability that could allow authenticated …

IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view,…

storage_protect_server | Remote | Injection
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
6.3 MEDIUM
CVE-2024-58342 — XenForo Open Redirect via getDynamicRedirect

XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the redirect target, allowing attackers to redirect us…

xenforo | Remote | Misconfiguration
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
5.3 MEDIUM
CVE-2026-5240 — code-projects BloodBank Managing System admin_state.php cross site scripting

A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. This affects an unknown part of the file /admin_state.php. The manipulation of the argument statename leads …

Remote | Cross-Site Scripting
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
7.5 HIGH
CVE-2026-5238 — itsourcecode Payroll Management System Parameter view_employee.php sql injection

A weakness has been identified in itsourcecode Payroll Management System 1.0. Affected by this issue is some unknown functionality of the file /view_employee.php of the component Parameter Handler. E…

payroll_management_system | Remote | Injection
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
6.5 MEDIUM
CVE-2026-4668 — Amelia <= 2.1.2 - Authenticated (Manager+) SQL Injection via 'sort' Parameter

The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and incl…

amelia | Remote | Injection
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
0.0 NA
CVE-2025-66442 — Mbed TLS and TF-PSA-Crypto RSA Timing Side Channel

In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also af…

| Cryptography
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
0.0 NA
CVE-2026-34872 — Mbed TLS Finite-Field Diffie-Hellman Lack of Contributory Behavior Vulnerability

An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-H…

| Cryptography
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
7.5 HIGH
CVE-2026-5237 — itsourcecode Payroll Management System Parameter manage_user.php sql injection

A security flaw has been discovered in itsourcecode Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /manage_user.php of the component Parameter H…

payroll_management_system | Remote | Injection
Mar 31, 2026 Apr 01, 2026
Mar 31, 2026
Apr 01, 2026
5.3 MEDIUM
CVE-2026-5236 — Axiomatic Bento4 DSI v1 Ap4Dac4Atom.cpp SkipBits heap-based overflow

A vulnerability was identified in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_BitReader::SkipBits of the file Ap4Dac4Atom.cpp of the component DSI v1 Parser. Such manipulation of t…

bento4 | Memory Corruption
Mar 31, 2026 Apr 01, 2026
Mar 31, 2026
Apr 01, 2026
5.3 MEDIUM
CVE-2026-5235 — Axiomatic Bento4 MP4 File Ap4Dac4Atom.cpp ReadCache heap-based overflow

A vulnerability was determined in Axiomatic Bento4 up to 1.6.0-641. This impacts the function AP4_BitReader::ReadCache of the file Ap4Dac4Atom.cpp of the component MP4 File Parser. This manipulation …

bento4 | Memory Corruption
Mar 31, 2026 Apr 01, 2026
Mar 31, 2026
Apr 01, 2026
6.2 MEDIUM
CVE-2026-34556 — iccDEV: HBO in icAnsiToUtf8()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a heap-buffer-overflow (HBO) in icAnsiToUtf8() in the XML conversion pa…

iccdev | Memory Corruption
Mar 31, 2026 Apr 01, 2026
Mar 31, 2026
Apr 01, 2026
Showing 20 of 6193 Results