Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-4976 — Totolink LR350 cstecgi.cgi setWiFiGuestCfg buffer overflow

A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid resu…

| Memory Corruption
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
0.0 NA
CVE-2026-33875 — Authenticator Vulnerable to Authentication Flow Hijack

Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially allowing attackers t…

| Authentication
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
0.0 NA
CVE-2026-33874 — Authenticator vulnerable to Remote Code Execution

Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior to version 4.16.0, the Mac OS version of the Authenticator is vulnera…

| Authentication
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
9.0 HIGH
CVE-2026-4975 — Tenda AC15 POST Request setcfm formSetCfm memory corruption

A vulnerability has been found in Tenda AC15 15.03.05.19. This affects the function formSetCfm of the file /goform/setcfm of the component POST Request Handler. The manipulation of the argument funcp…

Remote | Memory Corruption
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
9.0 HIGH
CVE-2026-4974 — Tenda AC7 POST Request SetSysTimeCfg fromSetSysTime memory corruption

A flaw has been found in Tenda AC7 15.03.06.44. Affected by this issue is the function fromSetSysTime of the file /goform/SetSysTimeCfg of the component POST Request Handler. Executing a manipulation…

Remote | Memory Corruption
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.1 MEDIUM
CVE-2026-4973 — SourceCodester Online Quiz System add-question.php cross site scripting

A vulnerability was detected in SourceCodester Online Quiz System hasta 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-question.php. Performing a manipulatio…

Remote | Cross-Site Scripting
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
4.8 MEDIUM
CVE-2026-4972 — code-projects Online Reviewer System btn_functions.php cross site scripting

A security vulnerability has been detected in code-projects Online Reviewer System up to 1.0. Affected is an unknown function of the file /system/system/students/assessments/databank/btn_functions.ph…

Remote | Cross-Site Scripting
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.3 MEDIUM
CVE-2026-4971 — SourceCodester Note Taking App cross-site request forgery

A weakness has been identified in SourceCodester Note Taking App up to 1.0. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack is possible to be carried…

Remote | Cross-Site Request Forgery
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.4 MEDIUM
CVE-2026-34475 — Varnish Cache Authentication Bypass Cache Poisoning

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or aut…

Remote | Misconfiguration
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
6.6 MEDIUM
CVE-2026-34391 — Fleet Vulnerable to Windows MDM cross-device command disclosure

Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command processing allows a malicious enrolled device to access MDM commands intended for othe…

Remote | Authorization
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
4.9 MEDIUM
CVE-2026-34389 — Fleet's user account creation via invite does not enforce invited email address

Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow where the email address provided during invite acceptance was not validated agai…

Remote | Authentication
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
6.6 MEDIUM
CVE-2026-34388 — Fleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpoint

Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability in Fleet's gRPC Launcher endpoint allows an authenticated host to crash the entire Fleet server pro…

Remote | Denial of Service
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
9.6 CRITICAL
CVE-2026-34205 — Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host …

Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpo…

| Misconfiguration
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
7.1 HIGH
CVE-2026-33872 — elixir-nodejs has Cross-User Data Leakage or Information Disclosure due to Worker Protoco…

elixir-nodejs provides an Elixir API for calling Node.js functions. A vulnerability in versions prior to 3.1.4 results in Cross-User Data Leakage or Information Disclosure due to a race condition in …

Remote | Race Condition
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
8.7 HIGH
CVE-2026-33871 — Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 s…

Remote | Denial of Service
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
7.5 HIGH
CVE-2026-33870 — Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encodin…

Remote | Misconfiguration
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
4.8 MEDIUM
CVE-2026-33869 — Mastodon has a denial of service for quote authorization

Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5.8 and on the 4.4.x branch prior to 4.4.15, an attacker that knows of a quote b…

Remote | Denial of Service
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
4.3 MEDIUM
CVE-2026-33868 — Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>'

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauthenticated Open Redirect vulnerability (CWE-601) exists in the `/web/*…

Remote | Misconfiguration
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
8.9 HIGH
CVE-2026-33765 — Pi-hole Web Interface has a Command Injection Vulnerability

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 have a critical OS Command Injection vulnerability…

Remote | Injection
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.7 MEDIUM
CVE-2026-33739 — FOG has Stored XSS in Multiple Management Pages

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.1812, the listing tables on multiple management pages (Host, Storage, Group, Image, Printer, Snapin…

Remote | Cross-Site Scripting
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
Showing 20 of 6111 Results