Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-32877 — Botan: Heap Buffer Over-read in SM2 Decryption via Undersized C3 Hash Field

Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that checked the authentication code value (C3) failed to check that the encoded valu…

| Memory Corruption
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
0.0 NA
CVE-2026-32883 — Botan: Missing OCSP Response Signature Verification Allows MitM Certificate Revocation By…

Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an appropriate status code, but critically omitted verif…

| Cryptography
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
0.0 NA
CVE-2026-32884 — Botan: Case-Insensitive CN Values Bypass DNS excludedSubtrees Name Constraints (RFC 5280 …

Botan is a C++ cryptography library. Prior to version 3.11.0, during processing of an X.509 certificate path using name constraints which restrict the set of allowable DNS names, if no subject altern…

| Cryptography
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
0.0 NA
CVE-2026-28228 — OpenOLAT: Server-Side Template Injection (SSTI) in Velocity templates allows Remote Code …

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. Prior to versions 19.1.31, 20.1.18, and 20.2.5, an authenticated user with the Author ro…

| Injection
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
0.0 NA
CVE-2026-31946 — OpenOLAT: Authentication bypass via forged JWT in OIDC implicit flow

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version 20.2.5, OpenOLAT's OpenID Connect implicit flow im…

| Cryptography
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
0.0 NA
CVE-2026-5152 — Tenda CH22 createFileName formCreateFileName stack-based overflow

A vulnerability was detected in Tenda CH22 1.0.0.1. Impacted is the function formCreateFileName of the file /goform/createFileName. Performing a manipulation of the argument fileNameMit results in st…

| Memory Corruption
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
0.0 NA
CVE-2026-34558 — CI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via …

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to prope…

| Cross-Site Scripting
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
0.0 NA
CVE-2026-34557 — CI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation …

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to prope…

| Cross-Site Scripting
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
0.0 NA
CVE-2026-27599 — CI4MS: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover f…

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to prope…

| Cross-Site Scripting
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
7.5 HIGH
CVE-2026-5150 — code-projects Accounting System Parameter viewin_costumer.php sql injection

A security vulnerability has been detected in code-projects Accounting System 1.0. This issue affects some unknown processing of the file /viewin_costumer.php of the component Parameter Handler. Such…

Remote | Injection
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
5.8 MEDIUM
CVE-2026-5148 — YunaiV yudao-cloud page sql injection

A weakness has been identified in YunaiV yudao-cloud up to 2026.01. This vulnerability affects unknown code of the file /admin-api/system/mail-log/page. This manipulation of the argument toMail cause…

Remote | Injection
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
9.4 CRITICAL
CVE-2026-33026 — nginx-ui Backup Restore Allows Tampering with Encrypted Backups

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious…

Remote | Injection
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
7.4 HIGH
CVE-2026-32275 — Tautulli: Unsanitized JSONP callback parameter allows cross-origin script injection and A…

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.17.0, an unsanitized JSONP callback parameter allows cross-origin script injecti…

Remote | Cross-Site Scripting
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
8.7 HIGH
CVE-2026-31831 — Tautulli: Unauthenticated Path Traversal in `/newsletter/image/images` endpoint

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/image/images API endpoint is vulnerable to path traversal, allowing unauthentic…

Remote | Path Traversal
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
4.0 MEDIUM
CVE-2026-31804 — Tautulli: Unauthenticated pms_image_proxy endpoint proxies arbitrary HTTP requests throug…

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_proxy endpoint accepts a user-supplied img parameter and forwards it to Plex Med…

Remote | Server-Side Request Forgery
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
4.9 MEDIUM
CVE-2026-31799 — Tautulli: SQL Injection in get_home_stats API endpoint via unsanitised filter parameters

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 2.14.2 to before version 2.17.0 for parameters "before" and "after" and from version 2.1.0-beta to before v…

Remote | Injection
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
0.0 NA
CVE-2026-30307 — Roo Code Shell Command Injection Vulnerability

Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regul…

| Injection
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
0.0 NA
CVE-2026-30305 — Syntx Command Auto-Approval OS Command Injection Vulnerability

Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular …

| Injection
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
7.5 HIGH
CVE-2026-28505 — Tautulli: RCE via eval() sandbox bypass using lambda nested scope to escape co_names whit…

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() function in notification_handler.py implements a sandboxed eval() for notificati…

Remote | Injection
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
5.9 MEDIUM
CVE-2026-21717 — Node.js V8 JSON.parse() String Hash Collision Vulnerability

A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such coll…

Remote | Misconfiguration
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
Showing 20 of 5969 Results