Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2025-69437 — PublicCMS Stored XSS in PDF Upload

PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtils.java. If a user uploads a PDF f…

publiccms | Remote | Cross-Site Scripting
Feb 27, 2026 Mar 05, 2026
Feb 27, 2026
Mar 05, 2026
8.7 HIGH
CVE-2026-3304 — Multer vulnerable to Denial of Service via incomplete cleanup

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed reques…

multer | Remote | Denial of Service
Feb 27, 2026 Mar 19, 2026
Feb 27, 2026
Mar 19, 2026
6.8 MEDIUM
CVE-2026-3277 — PowerShell Universal OpenID Connect Cleartext Client Secret Exposure

The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows a…

powershell_universal | Authentication
Feb 27, 2026 Mar 11, 2026
Feb 27, 2026
Mar 11, 2026
9.8 CRITICAL
CVE-2026-2750 — Command Injection via CLAPI generatetraps

Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affects Centreon Open Tickets on Central Server: from a…

web | Remote | Injection
Feb 27, 2026 Mar 23, 2026
Feb 27, 2026
Mar 23, 2026
9.9 CRITICAL
CVE-2026-2749 — Path traversal in Centreon Open Tickets

Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8,…

linux_kernel open_tickets | Remote | Information Disclosure
Feb 27, 2026 Mar 23, 2026
Feb 27, 2026
Mar 23, 2026
8.7 HIGH
CVE-2026-2359 — Multer vulnerable to Denial of Service via resource exhaustion

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by dropping connection duri…

multer | Remote | Denial of Service
Feb 27, 2026 Mar 19, 2026
Feb 27, 2026
Mar 19, 2026
4.8 MEDIUM
CVE-2026-3327 — Authenticated DatoCMS Web Previews Plugin Iframe Injection

Authenticated Iframe Injection in Dato CMS Web Previews plugin. This vulnerability permits a malicious authenticated user to circumvent the restriction enforced on the configured frontend URL, enabli…

Remote | Injection
Feb 27, 2026 Mar 02, 2026
Feb 27, 2026
Mar 02, 2026
Showing 20 of 5927 Results