Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2025-9497 — Hardcoded Upgrade Decryption Passwords

Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.

| Authentication
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
0.0 NA
CVE-2026-4995 — wandb OpenUI Window Message Event index.html cross site scripting

A vulnerability was determined in wandb OpenUI up to 1.0. Affected by this vulnerability is an unknown functionality of the file frontend/public/annotator/index.html of the component Window Message E…

| Cross-Site Scripting
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
5.1 MEDIUM
CVE-2026-4994 — wandb OpenUI APIStatusError server.py generic_exception_handler information exposure

A vulnerability was found in wandb OpenUI up to 1.0/3.5-turb. Affected is the function generic_exception_handler of the file backend/openui/server.py of the component APIStatusError Handler. The mani…

| Information Disclosure
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
3.3 LOW
CVE-2026-4993 — wandb OpenUI config.py hard-coded credentials

A vulnerability has been found in wandb OpenUI up to 0.0.0.0/1.0. This impacts an unknown function of the file backend/openui/config.py. The manipulation of the argument LITELLM_MASTER_KEY leads to h…

| Misconfiguration
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
5.3 MEDIUM
CVE-2026-2442 — Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email H…

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 2.…

Remote | Injection
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
0.0 NA
CVE-2026-23399 — nf_tables: nft_dynset: fix possible stateful expression memleak in error path

In the Linux kernel, the following vulnerability has been resolved: nf_tables: nft_dynset: fix possible stateful expression memleak in error path If cloning the second stateful expression in the el…

| Memory Corruption
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
6.5 MEDIUM
CVE-2026-1307 — Ninja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via…

The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.1 via a callback functio…

Remote | Information Disclosure
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
0.0 NA
CVE-2025-15445 — Restaurant Cafeteria <= 0.4.6 - Subscriber+ Arbitrary Plugin Installation/Activation

The Restaurant Cafeteria WordPress theme through 0.4.6 exposes insecure admin-ajax actions without nonce or capability checks, allowing any logged-in user, like subscriber, to perform privileged oper…

| Authorization
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
7.2 HIGH
CVE-2025-12886 — Oxygen <= 6.0.8 - Unauthenticated Server-Side Request Forgery via route_path

The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.8 via the laborator_calc_route AJAX action. This makes it possible for unau…

Remote | Server-Side Request Forgery
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
7.5 HIGH
CVE-2026-4987 — SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id'

The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up to, and including, 2.5.2. This is due to the crea…

Remote | Authorization
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
7.3 HIGH
CVE-2026-1679 — net: eswifi socket send payload length not bounded

The eswifi socket offload driver copies user-provided payloads into a fixed buffer without checking available space; oversized sends overflow `eswifi->buf`, corrupting kernel memory (CWE-120). Exploi…

zephyr | Memory Corruption
Mar 28, 2026 Mar 28, 2026
Mar 28, 2026
Mar 28, 2026
5.3 MEDIUM
CVE-2026-4992 — wandb OpenUI HTMLAnnotator server.py get_share HTML injection

A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/openui/server.py of the component HTMLAnnotator Component. Executing a manipulati…

Remote | Injection
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.1 MEDIUM
CVE-2026-4991 — QDOCS Smart School Management System Admission Enquiry enquiry cross site scripting

A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown function of the file /admin/enquiry of the component Admission Enquiry Module. Perfo…

smart_school | Remote | Cross-Site Scripting
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
8.0 HIGH
CVE-2026-4248 — Ultimate Member <= 2.11.2 - Authenticated (Contributor+) Sensitive Information Exposure t…

The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag…

ultimate_member | Remote | Information Disclosure
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.8 MEDIUM
CVE-2026-33996 — LibJWT has NULL/bounds validation in JWK octet and RSA PSS parsing

LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS did not protect against a NULL value when expecting to parse JSON string values…

| Misconfiguration
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
6.3 MEDIUM
CVE-2026-33994 — Locutus Prototype Pollution due to incomplete fix for CVE-2026-25521

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39 and prior to version 3.0.25, a prototype pollution vulnerability exists in the…

locutus | Remote | Misconfiguration
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
6.9 MEDIUM
CVE-2026-33993 — Locutus has Prototype Pollution via __proto__ Key Injection in unserialize()

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, the `unserialize()` function in `locutus/php/var/unserialize` assigns deserializ…

locutus | Remote | Misconfiguration
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
9.3 CRITICAL
CVE-2026-33992 — pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata E…

pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, PyLoad's download engine accepts arbitrary URLs without validation, enabling Server-Side Request F…

pyload | Remote | Server-Side Request Forgery
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
8.8 HIGH
CVE-2026-33991 — WeGIA has SQL Injection in deletar_tag.php

WeGIA is a web manager for charitable institutions. Prior to version 3.6.7, the file `html/socio/sistema/deletar_tag.php` uses `extract($_REQUEST)` on line 14 and directly concatenates the `$id_tag` …

wegia | Remote | Injection
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.3 MEDIUM
CVE-2026-33936 — python-ecdsa: Denial of Service via improper DER length validation in crafted private keys

The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signatu…

ecdsa | Remote | Cryptography
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
Showing 20 of 6047 Results