Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.0 MEDIUM
CVE-2026-26060 — Fleet: Password reset tokens remain valid after password change for 24 hours

Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password reset tokens to remain valid after a user…

Remote | Authentication
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
6.3 MEDIUM
CVE-2025-15612 — Wazuh Provisioning Scripts / Build Infrastructure Improper Certificate Validation leading…

Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with netw…

Remote | Misconfiguration
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.3 MEDIUM
CVE-2026-4968 — SourceCodester Diary App diary.php cross-site request forgery

A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an unknown function of the file diary.php. Executing a manipulation can lead to cross-site request forgery. The…

Remote | Cross-Site Request Forgery
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
6.5 MEDIUM
CVE-2026-4966 — itsourcecode Free Hotel Reservation System index.php sql injection

A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. Impacted is an unknown function of the file /admin/mod_room/index.php?view=edit. Executing a manipulation of the argument ID c…

Remote | Injection
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
7.5 HIGH
CVE-2026-4965 — letta-ai letta Incomplete Fix CVE-2025-6101 ast_parsers.py resolve_type eval injection

A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the component Incomplete Fix CVE-2025-6101. Performin…

Remote | Injection
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.3 MEDIUM
CVE-2026-34368 — AVideo Vulnerable to Wallet Balance Double-Spend via TOCTOU Race Condition in transferBal…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `plugin/YPTWallet/YPTWallet.php` contains a Time-of-Check-Time-of-Use (TOCTOU) ra…

Remote | Race Condition
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.3 MEDIUM
CVE-2026-34364 — AVideo has User Group-Based Category Access Control Bypass via Missing and Broken Group F…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint, which serves the category listing API, fails to enforce user group-based access…

Remote | Authorization
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
0.0 NA
CVE-2026-30568 — SourceCodester Inventory System Cross-Site Scripting (XSS)

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Inventory System 1.0 in in the view_purchase.php file via the "limit" parameter. The application fails to sanitize the in…

| Cross-Site Scripting
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
0.0 NA
CVE-2026-30567 — SourceCodester Inventory System Reflected XSS

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Inventory System 1.0 in the view_product.php file via the "limit" parameter. The application fails to sanitize the input,…

| Cross-Site Scripting
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
8.3 HIGH
CVE-2025-15617 — Wazuh GitHub Actions Workflow Exposure of Sensitive Credentials

Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to extract the GITHUB_TOKEN from uploaded artifacts. Attackers can use the exposed t…

Remote | Information Disclosure
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
6.5 MEDIUM
CVE-2026-4964 — letta-ai letta File URL message_helper.py _convert_message_create_to_message server-side …

A security vulnerability has been detected in letta-ai letta 0.16.4. This vulnerability affects the function _convert_message_create_to_message of the file letta/helpers/message_helper.py of the comp…

Remote | Server-Side Request Forgery
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
7.5 HIGH
CVE-2026-4963 — huggingface smolagents Incomplete Fix CVE-2025-9959 local_python_executor.py evaluate_wit…

A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evaluate_call/evaluate_with of the file src/smolagents/local_python_executor.py of t…

Remote | Injection
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
7.3 HIGH
CVE-2026-4962 — UltraVNC Service version.dll uncontrolled search path

A security flaw has been discovered in UltraVNC up to 1.6.4.0. Affected by this issue is some unknown functionality in the library version.dll of the component Service. The manipulation results in un…

| Path Traversal
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
9.0 HIGH
CVE-2026-4961 — Tenda AC6 POST Request QuickIndex formQuickIndex stack-based overflow

A vulnerability was identified in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. The manipu…

ac6_firmware | Remote | Memory Corruption
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
9.0 HIGH
CVE-2026-4960 — Tenda AC6 POST Request WizardHandle fromWizardHandle stack-based overflow

A vulnerability was determined in Tenda AC6 15.03.05.16. Affected is the function fromWizardHandle of the file /goform/WizardHandle of the component POST Request Handler. Executing a manipulation of …

ac6_firmware | Remote | Memory Corruption
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
6.9 MEDIUM
CVE-2026-34411 — Appsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIs

Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoints like /api/v1/consolidated-api/view and /api/v1…

appsmith | Remote | Authentication
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.4 MEDIUM
CVE-2026-34362 — AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyT…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function in `plugin/YPTSocket/functions.php` has its token timeout validation commented o…

avideo | Remote | Authentication
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.4 MEDIUM
CVE-2026-34247 — AVideo's IDOR in uploadPoster.php Allows Any Authenticated User to Overwrite Scheduled Li…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live/uploadPoster.php` endpoint allows any authenticated user to overwrite the poster image for any sch…

avideo | Remote | Authorization
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
6.3 MEDIUM
CVE-2026-34245 — AVideo's Missing Authorization in Playlist Schedule Creation Allows Cross-User Broadcast …

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists_schedules/add.json.php` endpoint allows any authenticated user with streaming …

avideo | Remote | Authorization
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
9.1 CRITICAL
CVE-2026-33867 — AVideo has Plaintext Video Password Storage

WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to password-protect individual videos. The video password is stored in the database in…

avideo | Remote | Cryptography
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
Showing 20 of 6111 Results