Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.9 CRITICAL
CVE-2026-34717 — OpenProject: SQL Injection in Cost Reporting =n Operator via parse_number_string

OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operator.rb:177 embeds user input directly into SQL WHER…

openproject | Remote | Injection
Apr 02, 2026 Apr 03, 2026
Apr 02, 2026
Apr 03, 2026
5.3 MEDIUM
CVE-2026-34715 — ewe Has Improper Neutralization of CRLF Sequences in HTTP Headers (HTTP Request/Response …

ewe is a Gleam web server. Prior to version 3.0.6, the encode_headers function in src/ewe/internal/encoder.gleam directly interpolates response header keys and values into raw HTTP bytes without vali…

ewe | Remote | Injection
Apr 02, 2026 Apr 03, 2026
Apr 02, 2026
Apr 03, 2026
5.9 MEDIUM
CVE-2026-34610 — leancrypto: Integer truncation in X.509 name parser enables certificate identity imperson…

The leancrypto library is a cryptographic library that exclusively contains only PQC-resistant cryptographic algorithms. Prior to version 1.7.1, lc_x509_extract_name_segment() casts size_t vlen to ui…

Remote | Cryptography
Apr 02, 2026 Apr 03, 2026
Apr 02, 2026
Apr 03, 2026
4.9 MEDIUM
CVE-2026-34608 — nanomq: Heap-Buffer-Overflow in webhook_inproc.c via cJSON_Parse OOB Read

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inproc.c, the hook_work_cb() function processes nng messages by parsing the message…

nanomq | Remote | Memory Corruption
Apr 02, 2026 Apr 03, 2026
Apr 02, 2026
Apr 03, 2026
6.9 MEDIUM
CVE-2026-34606 — Stored XSS in Frappe LMS

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, Frappe LMS was vulnerable to stored XSS. This issu…

learning | Remote | Cross-Site Scripting
Apr 02, 2026 Apr 03, 2026
Apr 02, 2026
Apr 03, 2026
7.5 HIGH
CVE-2026-34601 — xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup in…

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In xmldom versions 0.6.0 and prior and @xmldom/xmldom prior to versions 0.8.12 and 0.9.9,…

xmldom | Remote | XML External Entity
Apr 02, 2026 Apr 03, 2026
Apr 02, 2026
Apr 03, 2026
7.1 HIGH
CVE-2026-34598 — YesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter"

YesWiki is a wiki system written in PHP. Prior to version 4.6.0, a stored and blind XSS vulnerability exists in the form title field. A malicious attacker can inject JavaScript without any authentica…

yeswiki | Remote | Cross-Site Scripting
Apr 02, 2026 Apr 03, 2026
Apr 02, 2026
Apr 03, 2026
8.2 HIGH
CVE-2026-34593 — Ash Framework: Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat a…

Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type.Module.cast_input/2 unconditionally creates a new Erlang atom via Module.conca…

ash | Remote | Denial of Service
Apr 02, 2026 Apr 03, 2026
Apr 02, 2026
Apr 03, 2026
7.1 HIGH
CVE-2026-34591 — Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write

Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, allowing arbitrary …

poetry | Remote | Path Traversal
Apr 02, 2026 Apr 03, 2026
Apr 02, 2026
Apr 03, 2026
5.4 MEDIUM
CVE-2026-34590 — Postiz: SSRF via Webhook Creation Endpoint Missing URL Safety Validation

Postiz is an AI social media scheduling tool. Prior to version 2.21.4, the POST /webhooks/ endpoint for creating webhooks uses WebhooksDto which validates the url field with only @IsUrl() (format che…

Remote | Server-Side Request Forgery
Apr 02, 2026 Apr 03, 2026
Apr 02, 2026
Apr 03, 2026
5.4 MEDIUM
CVE-2026-34584 — listmonk: Broken Access Control in CSV Import (Unauthorized List Assignment)

listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, bugs in list permission checks allows users in a multi-user environment to acce…

listmonk | Remote | Authorization
Apr 02, 2026 Apr 03, 2026
Apr 02, 2026
Apr 03, 2026
8.6 HIGH
CVE-2026-34577 — Postiz: Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassa…

Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the GET /public/stream endpoint in PublicController accepts a user-supplied url query parameter and proxies the full HTTP respon…

Remote | Server-Side Request Forgery
Apr 02, 2026 Apr 03, 2026
Apr 02, 2026
Apr 03, 2026
8.3 HIGH
CVE-2026-34576 — Postiz: SSRF in upload-from-url endpoint allows fetching internal resources and cloud met…

Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the POST /public/v1/upload-from-url endpoint accepts a user-supplied URL and fetches it server-side using axios.get() with no SS…

Remote | Server-Side Request Forgery
Apr 02, 2026 Apr 03, 2026
Apr 02, 2026
Apr 03, 2026
5.0 MEDIUM
CVE-2026-34526 — SillyTavern: Incomplete IP validation in /api/search/visit allows SSRF via localhost and …

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version…

sillytavern | Remote | Server-Side Request Forgery
Apr 02, 2026 Apr 03, 2026
Apr 02, 2026
Apr 03, 2026
8.3 HIGH
CVE-2026-34524 — SillyTavern: Path traversal in `/api/chats/export` and `/api/chats/delete` allows arbitra…

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version…

sillytavern | Remote | Path Traversal
Apr 02, 2026 Apr 03, 2026
Apr 02, 2026
Apr 03, 2026
5.3 MEDIUM
CVE-2026-34523 — SillyTavern: Path traversal allows file existence oracle

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version…

sillytavern | Remote | Path Traversal
Apr 02, 2026 Apr 03, 2026
Apr 02, 2026
Apr 03, 2026
8.1 HIGH
CVE-2026-34522 — SillyTavern: Path traversal in `/api/chats/import` allows arbitrary file write outside in…

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version…

sillytavern | Remote | Path Traversal
Apr 02, 2026 Apr 03, 2026
Apr 02, 2026
Apr 03, 2026
7.1 HIGH
CVE-2026-34124 — Denial of Service via Path Expansion Overflow in HTTP Service in TP-Link Tapo C520WS

A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic. The implementation enforces length restrictions on the raw request path but do…

tapo_c520ws_firmware tapo_c520ws | Memory Corruption
Apr 02, 2026 Apr 06, 2026
Apr 02, 2026
Apr 06, 2026
7.1 HIGH
CVE-2026-34122 — Stack-based Buffer Overflow Leading to Denial of Service in TP-Link Tapo C520WS

A stack-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within a configuration handling component due to insufficient input validation. An attacker can exploit this vu…

tapo_c520ws_firmware tapo_c520ws | Memory Corruption
Apr 02, 2026 Apr 06, 2026
Apr 02, 2026
Apr 06, 2026
8.8 HIGH
CVE-2026-34121 — Authentication Bypass in DS Configuration Service via HTTP Request Parsing Differential o…

An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v2.6 was identified, due to inconsistent parsing and authorization logic in JSON…

Apr 02, 2026 Apr 06, 2026
Apr 02, 2026
Apr 06, 2026
Showing 20 of 6029 Results