Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.3 LOW
CVE-2026-21716 — Microsoft Node.js FileHandle Permission Bypass Vulnerability

An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmo…

| Authorization
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
3.3 LOW
CVE-2026-21715 — Node.js Permission Model fs.realpathSync.native() Permission Bypass

A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce th…

| Authorization
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
5.3 MEDIUM
CVE-2026-21714 — Node.js HTTP2 Memory Leak Vulnerability

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The ser…

Remote | Memory Corruption
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
5.9 MEDIUM
CVE-2026-21713 — Node.js HMAC Timing Oracle Vulnerability

A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. …

Remote | Cryptography
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
5.3 MEDIUM
CVE-2026-21711 — Node.js Permission Model UDS Server Local IPC Exfiltration

A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce t…

| Misconfiguration
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
7.5 HIGH
CVE-2026-21710 — Node.js HTTP Server Prototype Pollution Vulnerability

A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occu…

Remote | Misconfiguration
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
0.0 NA
CVE-2026-27018 — Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme

Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can be bypassed using mixed-case or uppercase URL schemes. This issue has been patc…

| Misconfiguration
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
0.0 NA
CVE-2026-32696 — NanoMQ HTTP Auth: Missing username/password can trigger a NULL-pointer strlen() in auth_h…

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In NanoMQ version 0.24.6, after enabling auth.http_auth (HTTP authentication), when a client connects to the broker using MQTT CO…

| Misconfiguration
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
0.0 NA
CVE-2026-25627 — nanomq: OOB Read / Crash (DoS) via Malformed MQTT Remaining Length over WebSocket

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSocket transport can be crashed by sending an MQTT packet with a deliberately larg…

| Memory Corruption
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
7.5 HIGH
CVE-2026-5147 — YunaiV yudao-cloud get-by-website sql injection

A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This affects an unknown part of the file /admin-api/system/tenant/get-by-website. The manipulation of the argument Website res…

Remote | Injection
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
7.8 HIGH
CVE-2026-3991 — Elevation of Privileges in Symantec Data Loss Prevention Windows Endpoint

Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 MP2 HF15, may be susceptible to a Elevation of Privilege vulnerability, which is…

| Authorization
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
7.8 HIGH
CVE-2026-3502 — TrueConf Client Update Integrity Verification Bypass

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payloa…

| Supply Chain
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
9.2 CRITICAL
CVE-2026-34714 — Vim Tabpanel Expression Injection

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

| Injection
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
7.7 HIGH
CVE-2026-29925 — Invoice Ninja SSRF

Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php.

Remote | Server-Side Request Forgery
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
7.6 HIGH
CVE-2026-29924 — Grav CMS XXE Injection

Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.

Remote | XML External Entity
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
6.5 MEDIUM
CVE-2026-5126 — SourceCodester RSS Feed Parser file_get_contents server-side request forgery

A flaw has been found in SourceCodester RSS Feed Parser 1.0. Affected by this issue is the function file_get_contents. This manipulation causes server-side request forgery. The attack is possible to …

Remote | Server-Side Request Forgery
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
5.3 MEDIUM
CVE-2026-5125 — raine consult-llm-mcp server.ts child_process.execSync os command injection

A vulnerability was detected in raine consult-llm-mcp up to 2.5.3. Affected by this vulnerability is the function child_process.execSync of the file src/server.ts. The manipulation of the argument gi…

| Injection
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
7.5 HIGH
CVE-2026-4046 — iconv crash due to assertion failure with untrusted input

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remot…

Remote | Denial of Service
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
9.8 CRITICAL
CVE-2026-33032 — Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While …

Remote | Authentication
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
8.8 HIGH
CVE-2026-33030 — Nginx UI: Unencrypted Storage of DNS API Tokens and ACME Private Keys

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user t…

| Authorization
Mar 30, 2026 Mar 30, 2026
Mar 30, 2026
Mar 30, 2026
Showing 20 of 5969 Results