Latest CVE Feed
CVE Intelligence
Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.
Score
Vulnerability
Published
10.0
CRITICAL
CVE-2026-21628
— Extension - astroidframe.work - Unauthenticated Remote Code Execution in Astroid Framewor…
A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.
Mar 05, 2026
Mar 13, 2026
Mar 05, 2026
Mar 13, 2026
7.5
HIGH
CVE-2026-1605
— Eclipse Jetty JDK Inflater Memory Leak
In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding …
Mar 05, 2026
Mar 06, 2026
Mar 05, 2026
Mar 06, 2026
6.5
MEDIUM
CVE-2025-11143
— Jetty URI Parser Differential Parsing Vulnerability
The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security…
Mar 05, 2026
Mar 06, 2026
Mar 05, 2026
Mar 06, 2026