Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-5352 — Trendnet TEW-657BRM setup.cgi edit os command injection

A security vulnerability has been detected in Trendnet TEW-657BRM 1.00.1. This impacts the function Edit of the file /setup.cgi. Such manipulation of the argument pcdb_list leads to os command inject…

Remote | Injection
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
2.5 LOW
CVE-2026-35388 — OpenSSH Proxy Mode Connection Multiplexing Authentication Bypass

OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.

| Misconfiguration
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
3.1 LOW
CVE-2026-35387 — OpenSSH ECDSA Algorithm Misinterpretation Vulnerability

OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.

Remote | Cryptography
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
3.6 LOW
CVE-2026-35386 — OpenSSH Shell Injection Vulnerability

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and als…

| Injection
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
7.5 HIGH
CVE-2026-35385 — OpenSSH Setuid/Setgid Vulnerability

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol)…

Remote | Misconfiguration
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
5.3 MEDIUM
CVE-2026-35038 — signalk-server: Arbitrary Prototype Read via `from` Field Bypass

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. This vulnerability a…

Remote | Information Disclosure
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
0.0 NA

An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the ser…

| Memory Corruption
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
4.8 MEDIUM
CVE-2026-34831 — Rack: Content-Length mismatch in Rack::Files error responses

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Files#fail sets the Content-Length response header using String#size instead of String#bytesize. When t…

Remote | Misconfiguration
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
5.9 MEDIUM
CVE-2026-34830 — Rack: Rack::Sendfile regex injection via HTTP_X_ACCEL_MAPPING header allows arbitrary fil…

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path interpolates the value of the X-Accel-Mapping request header directly into a re…

Remote | Injection
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
7.5 HIGH
CVE-2026-34829 — Rack: Denial of Service via Unbounded Multipart File Upload Without Content-Length

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only wraps the request body in a BoundedIO when CONTENT_LENGTH is present. When a mul…

Remote | Denial of Service
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
5.3 MEDIUM
CVE-2026-34826 — Rack: Unbounded Range Count in get_byte_ranges Enables DoS

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges parses the HTTP Range header without limiting the number of individual byte range…

Remote | Denial of Service
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
5.3 MEDIUM
CVE-2026-34786 — Rack: Rack::Static header_rules bypass via URL-encoded paths

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static#applicable_rules evaluates several header_rules types against the raw URL-encoded PATH_INFO, whi…

Remote | Misconfiguration
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
7.5 HIGH
CVE-2026-34785 — Rack: Local file inclusion in `Rack::Static` via URL Prefix Matching

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix chec…

Remote | Path Traversal
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
5.3 MEDIUM
CVE-2026-34763 — Rack: Rack::Directory info disclosure and DoS via unescaped regex interpolation

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Directory interpolates the configured root path directly into a regular expression when deriving the di…

Remote | Information Disclosure
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
5.3 MEDIUM
CVE-2026-34230 — Rack: Quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encodi…

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.select_best_encoding processes Accept-Encoding values with quadratic time complexity when the hea…

Remote | Denial of Service
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
6.1 MEDIUM
CVE-2026-34083 — signalk-server: OAuth Authorization Code Theft via Unvalidated Host Header in OIDC Flow

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, SignalK Server contains a code-level vulnerability in its OIDC login and logout handlers where t…

Remote | Authentication
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
6.9 MEDIUM
CVE-2026-33951 — signalk-server: Unauthenticated Source Priorities Manipulation

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the SignalK Server exposes an unauthenticated HTTP endpoint that allows remote attackers …

Remote | Authorization
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
9.4 CRITICAL
CVE-2026-33950 — signalk-server: Privilege Escalation by Admin Role Injection via /enableSecurity

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnerability by Admin Role Injection via /enableSecurity…

Remote | Authorization
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
0.0 NA
CVE-2026-30603 — Qianniao QN-L23PA0904 Firmware Update Mechanism Root Access Vulnerability

An issue in the firmware update mechanism of Qianniao QN-L23PA0904 v20250721.1640 allows attackers to gain root access, install backdoors, and exfiltrate data via supplying a crafted iu.sh script con…

| Authentication
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
3.7 LOW
CVE-2026-26961 — Rack: Multipart Boundary Parsing Ambiguity allowing WAF Bypass

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser extracts the boundary parameter from multipart/form-data using a greedy regular expre…

Remote | Misconfiguration
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
Showing 20 of 6379 Results