Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.7 LOW
CVE-2025-66487 — Multiple vulnerabilities have been addressed in IBM Aspera Shares

IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.

aspera_shares | Remote | Denial of Service
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
4.8 MEDIUM
CVE-2025-66486 — Multiple vulnerabilities have been addressed in IBM Aspera Shares

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the…

aspera_shares | Remote | Cross-Site Scripting
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
5.4 MEDIUM
CVE-2025-66485 — Multiple vulnerabilities have been addressed in IBM Aspera Shares

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.  This could allow an attacker to conduct various attacks aga…

aspera_shares | Remote | Misconfiguration
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
5.5 MEDIUM
CVE-2025-66484 — Multiple vulnerabilities have been addressed in IBM Aspera Shares

IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functi…

aspera_shares | Remote | Cross-Site Scripting
Apr 01, 2026 Apr 02, 2026
Apr 01, 2026
Apr 02, 2026
6.3 MEDIUM
CVE-2025-66483 — Multiple vulnerabilities have been addressed in IBM Aspera Shares

IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.

aspera_shares | Remote | Authentication
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
6.5 MEDIUM
CVE-2025-36375 — IBM DataPower Gateway vulnerable to CSRF

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is …

Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
5.3 MEDIUM
CVE-2026-5313 — Nothings stb GIF Decoder stb_image.h stbi__gif_load_next denial of service

A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the library stb_image.h of the component GIF Decoder. Such manipulation leads to deni…

stb_image.h | Remote | Denial of Service
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
8.6 HIGH
CVE-2026-3987 — WatchGuard Firebox Arbitrary File Write vis Path Traversal in Fireware Web UI

A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated sys…

fireware_os | Remote | Path Traversal
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
8.8 HIGH
CVE-2026-34572 — CI4MS: Account Deactivation Module Full Persistent Unauthorized Access for All‑Roles via …

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to immed…

ci4ms | Remote | Authorization
Apr 01, 2026 Apr 02, 2026
Apr 01, 2026
Apr 02, 2026
9.9 CRITICAL
CVE-2026-34571 — CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session…

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, a Stored Cross-Site Scripting …

ci4ms | Remote | Cross-Site Scripting
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
10.0 CRITICAL
CVE-2026-34570 — CI4MS: Account Deletion Module Full Persistent Unauthorized Access for All‑Roles via Impr…

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to immed…

ci4ms | Remote | Authorization
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
9.9 CRITICAL
CVE-2026-34569 — CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via St…

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to prope…

ci4ms | Remote | Cross-Site Scripting
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
9.1 CRITICAL
CVE-2026-34568 — CI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored …

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to prope…

ci4ms | Remote | Cross-Site Scripting
Apr 01, 2026 Apr 02, 2026
Apr 01, 2026
Apr 02, 2026
9.1 CRITICAL
CVE-2026-34567 — CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalatio…

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to prope…

ci4ms | Remote | Cross-Site Scripting
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
9.1 CRITICAL
CVE-2026-34566 — CI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via St…

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to prope…

ci4ms | Remote | Cross-Site Scripting
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
9.1 CRITICAL
CVE-2026-34565 — CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation…

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to prope…

ci4ms | Remote | Cross-Site Scripting
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
9.1 CRITICAL
CVE-2026-34564 — CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation…

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to prope…

ci4ms | Remote | Cross-Site Scripting
Apr 01, 2026 Apr 02, 2026
Apr 01, 2026
Apr 02, 2026
9.1 CRITICAL
CVE-2026-34563 — CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via S…

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to prope…

ci4ms | Remote | Cross-Site Scripting
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
4.7 MEDIUM
CVE-2026-34562 — CI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Take…

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to prope…

ci4ms | Remote | Cross-Site Scripting
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
4.7 MEDIUM
CVE-2026-34561 — CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account …

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to prope…

ci4ms | Remote | Cross-Site Scripting
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
Showing 20 of 6330 Results