Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-5102 — Totolink A3300R Parameter cstecgi.cgi setSmartQosCfg command injection

A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. This vulnerability affects the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handl…

a3300r_firmware a3300r | Remote | Injection
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
8.8 HIGH
CVE-2026-2370 — Improper Handling of Parameters in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowe…

gitlab | Remote | Authorization
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
2.1 LOW
CVE-2025-7741 — CENTUM Hardcoded Password Remote Authentication Bypass

Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user account (PROG) used for CENTUM Authentication Mode within the system. Under the…

centum_vp_firmware | Authentication
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
0.0 NA
CVE-2026-30305 — Syntx Command Auto-Approval OS Command Injection Vulnerability

Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular …

| Injection
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
0.0 NA
CVE-2026-30307 — Roo Code Shell Command Injection Vulnerability

Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regul…

| Injection
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
8.8 HIGH
CVE-2026-5101 — Totolink A3300R Parameter cstecgi.cgi setLanCfg command injection

A vulnerability was identified in Totolink A3300R 17.0.0cu.557_b20221024. This affects the function setLanCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of …

a3300r_firmware a3300r | Remote | Injection
Mar 29, 2026 Mar 30, 2026
Mar 29, 2026
Mar 30, 2026
9.8 CRITICAL
CVE-2026-4176 — Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 be…

Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl …

Remote | Supply Chain
Mar 29, 2026 Mar 30, 2026
Mar 29, 2026
Mar 30, 2026
8.8 HIGH
CVE-2026-4946 — NSA Ghidra Auto-Analysis Annotation Command Execution

Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when an analyst interacts with the U…

ghidra | Remote | Misconfiguration
Mar 29, 2026 Mar 30, 2026
Mar 29, 2026
Mar 30, 2026
8.3 HIGH
CVE-2026-0562 — Insecure Direct Object Reference (IDOR) in parisneo/lollms

A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging to other users. The `respond_request()` function …

lollms_web_ui | Remote | Authorization
Mar 29, 2026 Mar 30, 2026
Mar 29, 2026
Mar 30, 2026
7.5 HIGH
CVE-2026-0560 — Server-Side Request Forgery (SSRF) in parisneo/lollms

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` functio…

lollms_web_ui | Remote | Server-Side Request Forgery
Mar 29, 2026 Mar 30, 2026
Mar 29, 2026
Mar 30, 2026
7.5 HIGH
CVE-2026-0558 — Unauthenticated File Upload in parisneo/lollms

A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not …

lollms_web_ui | Remote | Authentication
Mar 29, 2026 Mar 30, 2026
Mar 29, 2026
Mar 30, 2026
8.8 HIGH
CVE-2026-34005 — Xiongmai DVR/NVR Command Injection Vulnerability

In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the HostName value via an authenticated DVRIP protocol (…

Remote | Injection
Mar 29, 2026 Mar 30, 2026
Mar 29, 2026
Mar 30, 2026
9.0 HIGH
CVE-2026-5046 — Tenda FH1201 Parameter WrlExtraSet formWrlExtraSet stack-based overflow

A flaw has been found in Tenda FH1201 1.2.0.14(408). Affected is the function formWrlExtraSet of the file /goform/WrlExtraSet of the component Parameter Handler. Executing a manipulation of the argum…

fh1201_firmware fh1201 | Remote | Memory Corruption
Mar 29, 2026 Mar 30, 2026
Mar 29, 2026
Mar 30, 2026
9.0 HIGH
CVE-2026-5045 — Tenda FH1201 Parameter WrlclientSet stack-based overflow

A vulnerability was detected in Tenda FH1201 1.2.0.14(408). This impacts the function WrlclientSet of the file /goform/WrlclientSet of the component Parameter Handler. Performing a manipulation of th…

fh1201_firmware fh1201 | Remote | Memory Corruption
Mar 29, 2026 Mar 30, 2026
Mar 29, 2026
Mar 30, 2026
9.0 HIGH
CVE-2026-5044 — Belkin F9K1122 Setting formSetSystemSettings stack-based overflow

A security vulnerability has been detected in Belkin F9K1122 1.00.33. This affects the function formSetSystemSettings of the file /goform/formSetSystemSettings of the component Setting Handler. Such …

f9k1122_firmware f9k1122 | Remote | Memory Corruption
Mar 29, 2026 Mar 30, 2026
Mar 29, 2026
Mar 30, 2026
8.6 HIGH
CVE-2026-33575 — OpenClaw < 2026.3.12 - Long-lived Credential Exposure in Pairing Setup Codes

OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pair endpoint and OpenClaw qr command. Attackers with access to leaked setup codes…

openclaw | Remote | Authentication
Mar 29, 2026 Mar 30, 2026
Mar 29, 2026
Mar 30, 2026
6.2 MEDIUM
CVE-2026-33574 — OpenClaw < 2026.3.8 - Path Traversal via Tools Root Rebinding in Skills Download

OpenClaw before 2026.3.8 contains a path traversal vulnerability in the skills download installer that validates the tools root lexically but reuses the mutable path during archive download and copy …

openclaw | Path Traversal
Mar 29, 2026 Mar 30, 2026
Mar 29, 2026
Mar 30, 2026
8.8 HIGH
CVE-2026-33573 — OpenClaw < 2026.3.11 - Workspace Boundary Bypass via Agent RPC Parameters

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the gateway agent RPC that allows authenticated operators with operator.write permission to override workspace boundaries b…

openclaw | Remote | Authorization
Mar 29, 2026 Mar 30, 2026
Mar 29, 2026
Mar 30, 2026
8.4 HIGH
CVE-2026-33572 — OpenClaw < 2026.2.17 - Insufficient File Permissions in Session Transcript Files

OpenClaw before 2026.2.17 creates session transcript JSONL files with overly broad default permissions, allowing local users to read transcript contents. Attackers with local access can read transcri…

openclaw | Information Disclosure
Mar 29, 2026 Mar 30, 2026
Mar 29, 2026
Mar 30, 2026
9.8 CRITICAL
CVE-2026-32987 — OpenClaw < 2026.3.13 - Bootstrap Setup Code Replay via Device Pairing

OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers can verify a valid bootstrap code multiple times b…

openclaw | Remote | Authentication
Mar 29, 2026 Mar 30, 2026
Mar 29, 2026
Mar 30, 2026
Showing 20 of 5950 Results