Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-34376 — PdfDing: Password-protected share bypass via direct serve endpoint

PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. Prior to version 1.7.0, an access-control vulnerability allows unauthenticated users to…

Remote | Authorization
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
8.2 HIGH
CVE-2026-34236 — Auth0 PHP SDK Insufficient Entropy in Cookie Encryption

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth0 PHP SDK, cookies are encrypted with insufficient…

Remote | Cryptography
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
7.7 HIGH
CVE-2026-34222 — Open WebUI has Broken Access Control in Tool Valves

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.11, there is a broken access control vulnerability in tool values. This issue h…

Remote | Authorization
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
9.8 CRITICAL
CVE-2026-34159 — llama.cpp: Unauthenticated RCE via GRAPH_COMPUTE buffer=0 bypass in llama.cpp RPC backend

llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation when a tensor's buffer field is 0. An unauthentica…

Remote | Memory Corruption
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
7.4 HIGH
CVE-2026-34076 — Clerk JavaScript: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys t…

Clerk JavaScript is the official JavaScript repository for Clerk authentication. In @clerk/hono from versions 0.1.0 to before 0.1.5, @clerk/express from versions 2.0.0 to before 2.0.7, @clerk/backend…

javascript | Remote | Server-Side Request Forgery
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
8.3 HIGH
CVE-2026-34072 — cronmaster: Middleware authentication bypass enabling unauthorized page access and server…

Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs. Prior to version 2.2.0, an authentication bypass in middleware allows unauthe…

| Authentication
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
8.7 HIGH
CVE-2026-27489 — ONNX: Path Traversal via Symlink

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outsi…

onnx | Remote | Path Traversal
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
0.0 NA
CVE-2026-25834 — Mbed TLS Algorithm Downgrade Vulnerability

Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.

| Cryptography
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
2.5 LOW
CVE-2026-5310 — Enter Software Iperius Backup IperiusAccounts.ini hard-coded key

A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the file IperiusAccounts.ini. Such manipulation leads to use of hard-coded cryptograph…

| Cryptography
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
7.1 HIGH
CVE-2026-34604 — @tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Jun…

Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge. That blocks plain ../ traversal, but it does not …

tinacms\/cli | Remote | Path Traversal
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
7.1 HIGH
CVE-2026-34603 — @tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions

Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal checks to the dev media routes, but the implementation still validates only th…

tinacms\/cli | Remote | Path Traversal
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
6.8 MEDIUM
CVE-2026-33990 — Docker Model Runner OCI Registry Client Vulnerable to Server-Side Request Forgery (SSRF)

Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Prior to version 1.1.25, Docker Model Runner contains an SSRF vulnerability in its OCI registry token exc…

| Server-Side Request Forgery
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
5.4 MEDIUM
CVE-2026-33978 — Notesnook: Stored XSS in mobile share editor via unescaped web clip title metadata

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerability exists in the mobile share / web clip flow because attacker-controlled clip m…

Remote | Cross-Site Scripting
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
8.1 HIGH
CVE-2026-33949 — @tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files

Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the…

tinacms\/cli | Remote | Path Traversal
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
9.8 CRITICAL
CVE-2026-30643 — DedeCMS Remote Code Execution Vulnerability

An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.

Remote | Injection
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
7.3 HIGH
CVE-2026-30273 — Pandas-AI SQL Injection Vulnerability

pandas-ai v3.0.0 was discovered to contain a SQL injection vulnerability via the pandasai.agent.base._execute_sql_query component.

Remote | Injection
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
0.0 NA
CVE-2026-2265 — Replicator 1.0.5 is vulnerable to Remote Code Execution through Insecure Deserialization

An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package manager (npm) version 1.0.5 to deserialize untrusted user input and execute th…

| Injection
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
4.9 MEDIUM
CVE-2026-20174 — Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability

A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is…

Remote | Path Traversal
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
9.8 CRITICAL
CVE-2026-20160 — Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected S…

Remote | Injection
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
8.0 HIGH
CVE-2026-20155 — Cisco Evolved Programmable Network Manager Improper Authorization Vulnerability

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive inform…

Remote | Authorization
Apr 01, 2026 Apr 01, 2026
Apr 01, 2026
Apr 01, 2026
Showing 20 of 6189 Results