Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-30573 — SourceCodester Pharmacy Product Management System Business Logic Injection

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is located in the add-sales.php file. The application fails to validate the "txtprice…

| Injection
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
0.0 NA
CVE-2026-30526 — SourceCodester Zoo Management System Reflected Cross-Site Scripting (XSS)

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Zoo Management System v1.0. The vulnerability is located in the login page, specifically within the msg parameter. The ap…

| Cross-Site Scripting
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
0.0 NA
CVE-2026-30523 — SourceCodester Loan Management System Integer Overflow

A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input validation. The application allows administrators to define "Loan Plans" which dete…

| Misconfiguration
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
0.0 NA
CVE-2026-30292 — Docudepot PDF Reader File Overwrite Vulnerability

An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code …

| Information Disclosure
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
0.0 NA
CVE-2026-30291 — Ora Tools PDF Reader File Overwrite Vulnerability

An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary c…

| Path Traversal
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
0.0 NA
CVE-2026-29598 — DDSN Interactive Acora CMS Stored XSS

Multiple stored cross-site scripting (XSS) vulnerabilities in the submit_add_user.asp endpoint of DDSN Interactive Acora CMS v10.7.1 allow attackers to execute arbitrary web scripts or HTML via injec…

| Cross-Site Scripting
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
6.4 MEDIUM
CVE-2025-13535 — King Addons for Elementor <= 51.1.38 - Authenticated (Contributor+) DOM-Based Stored Cros…

The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is …

Remote | Cross-Site Scripting
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
0.0 NA
CVE-2026-4989 — Devolutions Server SSRF Vulnerability

Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticated user to perform server-side request forgery (SSRF), potentially leading to in…

| Server-Side Request Forgery
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
0.0 NA
CVE-2026-5175 — Devolutions Server MFA Access Control Vulnerability

Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to delete their own configured MFA factors and reduce account pr…

| Authentication
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
0.0 NA
CVE-2026-4925 — Devolutions Server MFA Access Bypass Vulnerability

Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and remove their own multi-factor authentication (MFA…

| Authorization
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
0.0 NA
CVE-2026-4927 — Devolutions Server Information Disclosure

Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This …

| Information Disclosure
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
0.0 NA
CVE-2026-4924 — Devolutions Server Two-Factor Authentication Bypass

Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multifactor authenticat…

| Authentication
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
0.0 NA
CVE-2026-4828 — Devolutions Server OAuth Authentication Bypass

Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multi-factor authentication via a crafte…

| Authentication
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
0.0 NA
CVE-2026-4829 — Devolutions Server OAuth Authentication Bypass

Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, vi…

| Authentication
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
5.6 MEDIUM
CVE-2026-5271 — Possible to hijack modules in current working directory

pymanager included the current working directory in sys.path meaning modules could be shadowed by modules in the current working directory. This could lead to modules getting shadowed

| Misconfiguration
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
7.3 HIGH
CVE-2026-3877 — Reflected Cross-Site Scripting in Dashboard Search

A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution allows attackers to craft a malicious URL, that if visited by an authenticated v…

Remote | Cross-Site Scripting
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
3.3 LOW
CVE-2026-35094 — Libinput: libinput: information disclosure via dangling pointer in lua plugin handling

A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cle…

| Memory Corruption
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
8.8 HIGH
CVE-2026-35093 — Libinput: libinput: unauthorized code execution and information disclosure through lua by…

A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows th…

| Injection
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
7.5 HIGH
CVE-2026-35092 — Corosync: corosync: denial of service via integer overflow in join message validation

A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) pac…

Remote | Denial of Service
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
8.2 HIGH
CVE-2026-35091 — Corosync: corosync: denial of service and information disclosure via crafted udp packet

A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User…

Remote | Denial of Service
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
Showing 20 of 6261 Results