Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-35520 — Pi-hole FTL affected by Remote Code Execution (RCE) via dhcp.leaseTime Newline Injection

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulner…

Remote | Injection
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.8 HIGH
CVE-2026-35519 — Pi-hole FTL affected by Remote Code Execution (RCE) via dns.hostRecord Newline Injection

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulner…

Remote | Injection
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.8 HIGH
CVE-2026-35518 — Pi-hole FTL affected by Remote Code Execution (RCE) via dns.cnameRecords Newline Injection

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulner…

Remote | Injection
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.8 HIGH
CVE-2026-35517 — Pi-hole FTL affected by Remote Code Execution (RCE) via dns.upstreams Newline Injection

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulner…

Remote | Injection
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
5.0 MEDIUM
CVE-2026-35516 — LinkAce has SSRF via CheckLinksCommand - Link URL Update Bypasses laravel-html-meta Prote…

LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, LinkRepository::update and CheckLinksCommand::checkLink do not check for private IPs. An authenticated user can read respons…

Remote | Server-Side Request Forgery
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.3 MEDIUM
CVE-2026-35515 — @nestjs/core Improperly Neutralizes Special Elements in Output Used by a Downstream Compo…

Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.18, SseStream._transform() interpolates message.type and message.id directly into Server-Sent Events text pro…

Remote | Injection
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.5 MEDIUM
CVE-2026-35492 — Kedro-Datasets has a path traversal vulnerability in PartitionedDataset allows arbitrary …

Kedro-Datasets is a Kendo plugin providing data connectors. Prior to 9.3.0, PartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the da…

Remote | Path Traversal
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.1 MEDIUM
CVE-2026-35491 — Pi-hole FTL: CLI API sessions can import Teleporter archives and modify configuration

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, Pi-hole FTL supports a CLI password feature (webserver.api.cli_pw) t…

| Authorization
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
9.8 CRITICAL
CVE-2026-35490 — changedetection.io has an Authentication Bypass via Decorator Ordering

changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (outer to) @blueprint.route() instead of after it. …

Remote | Authentication
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
7.3 HIGH
CVE-2026-35489 — Tandoor Recipes — `amount`/`unit` bypass serializer in `food/{id}/shopping/`

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the POST /api/food/{id}/shopping/ endpoint reads amount and unit directly from req…

Remote | Injection
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.1 HIGH
CVE-2026-35488 — Tandoor Recipes — CustomIsShared permits DELETE/PUT on RecipeBook by shared (read-only) u…

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, RecipeBookViewSet and RecipeBookEntryViewSet use CustomIsShared as an alternative …

Remote | Authorization
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
5.3 MEDIUM
CVE-2026-35487 — text-generation-webui has a Path Traversal in load_prompt() — .txt file read without auth…

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_prompt() allows reading any .txt file on…

Remote | Path Traversal
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
7.5 HIGH
CVE-2026-35486 — text-generation-webui has a SSRF in superbooga/superboogav2 extensions — no URL validation

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, he superbooga and superboogav2 RAG extensions fetch user-supplied URLs via requests.get() with z…

Remote | Server-Side Request Forgery
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
0.0 NA
CVE-2026-33816 — CVE-2026-33816 in github.com/jackc/pgx

Memory-safety vulnerability in github.com/jackc/pgx/v5.

| Memory Corruption
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
0.0 NA
CVE-2026-33815 — CVE-2026-33815 in github.com/jackc/pgx

Memory-safety vulnerability in github.com/jackc/pgx/v5.

| Memory Corruption
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
0.0 NA
CVE-2026-30460 — Daylight Studio FuelCMS RCE Vulnerability

Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.

| Authentication
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.0 MEDIUM
CVE-2026-1079 — A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of al…

A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Automation who have installed Pega Browser Extension. A bad actor could create a we…

Remote | Cross-Site Scripting
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
7.2 HIGH
CVE-2026-1078 — An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Roboti…

An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R25 users who are running automations that work with Google Chrome or Microsoft E…

Remote | Misconfiguration
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
0.0 NA
CVE-2025-52908 — Samsung Exynos Wi-Fi Driver NL80211 Vendor Command Buffer Overflow

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Incorrect Handling of the NL80211 …

| Memory Corruption
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
5.7 MEDIUM
CVE-2025-24819 — A Relative Path Traversal vulnerability in Nokia MantaRay NM

Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter on the file system in Software Manager application.

| Path Traversal
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
Showing 20 of 6199 Results