Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-21714 — Node.js HTTP2 Memory Leak Vulnerability

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The ser…

| Memory Corruption
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
6.5 MEDIUM
CVE-2026-5126 — SourceCodester RSS Feed Parser file_get_contents server-side request forgery

A flaw has been found in SourceCodester RSS Feed Parser 1.0. Affected by this issue is the function file_get_contents. This manipulation causes server-side request forgery. The attack is possible to …

Remote | Server-Side Request Forgery
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
5.3 MEDIUM
CVE-2026-5125 — raine consult-llm-mcp server.ts child_process.execSync os command injection

A vulnerability was detected in raine consult-llm-mcp up to 2.5.3. Affected by this vulnerability is the function child_process.execSync of the file src/server.ts. The manipulation of the argument gi…

| Injection
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
7.5 HIGH
CVE-2026-4046 — iconv crash due to assertion failure with untrusted input

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remot…

Remote | Denial of Service
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
9.8 CRITICAL
CVE-2026-33032 — Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While …

Remote | Authentication
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
8.8 HIGH
CVE-2026-33030 — Nginx UI: Unencrypted Storage of DNS API Tokens and ACME Private Keys

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user t…

| Authorization
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
6.9 MEDIUM
CVE-2026-33029 — Nginx UI: DoS via Negative Integer Input in Logrotate Interval

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in the logrotate configuration allows an authenticated user to cause a complete De…

Remote | Denial of Service
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
7.1 HIGH
CVE-2026-33028 — Nginx UI: Race Condition Leads to Persistent Data Corruption and Service Collapse

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to the complete absence of synchronization mechanism…

Remote | Race Condition
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
6.9 MEDIUM
CVE-2026-33027 — Nginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration D…

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supp…

Remote | Path Traversal
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
7.5 HIGH
CVE-2026-30077 — OpenAirInterface AMF Buffer Overflow

OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But the crash is consistent for particular inputs. An example input in hex stream i…

Remote | Denial of Service
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
8.2 HIGH
CVE-2026-29872 — GitHub MCP Agent Streamlit API Token Information Disclosure Vulnerability

A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19). The affected Streamlit-based GitHub MCP Ag…

Remote | Information Disclosure
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
3.8 LOW
CVE-2025-66215 — OpenSC: Stack-buffer-overflow WRITE in card-oberthur

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-bu…

| Memory Corruption
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
3.9 LOW
CVE-2025-66038 — OpenSC: `sc_compacttlv_find_tag` can return out-of-bounds pointers

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a single byte encodes the tag …

| Memory Corruption
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
3.9 LOW
CVE-2025-66037 — OpenSC: Out of Bounds vulnerability

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out-of-bounds heap read in the…

| Memory Corruption
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
3.8 LOW
CVE-2025-49010 — OpenSC: Stack-buffer-overflow WRITE in GET RESPONSE

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-bu…

| Memory Corruption
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
6.3 MEDIUM
CVE-2026-5124 — osrg GoBGP BGP Header bgp.go BGPHeader.DecodeFromBytes access control

A security vulnerability has been detected in osrg GoBGP up to 4.3.0. Affected is the function BGPHeader.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP Header Handler. The man…

Remote | Authorization
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
7.6 HIGH
CVE-2026-29954 — KubePlus SSRF/Arbitrary HTTP Header Injection

In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of ResourceComposition resources. The field is only URL-encode…

Remote | Server-Side Request Forgery
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
0.0 NA
CVE-2026-29909 — MRCMS Directory Enumeration Vulnerability

MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation,…

| Authentication
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
5.4 MEDIUM
CVE-2026-27508 — Smoothwall Express < 3.1 Update 13 Reflected XSS in redirect.cgi via url Parameter

Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improper sanitation of the url parameter. Attackers can …

Remote | Cross-Site Scripting
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
5.4 MEDIUM
CVE-2026-26352 — Smoothwall Express < 3.1 Update 13 Stored XSS in vpnmain.cgi via VPN_IP Parameter

Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to improper sanitation of the VPN_IP parameter. Authentic…

Remote | Cross-Site Scripting
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
Showing 20 of 5954 Results