Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2026-0848 — Arbitrary Code Execution in NLTK StanfordSegmenter via Untrusted JAR Loading

NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verifi…

nltk | Remote | Supply Chain
Mar 05, 2026 Mar 09, 2026
Mar 05, 2026
Mar 09, 2026
8.8 HIGH
CVE-2025-70995 — Aranda Service Desk Web Edition Remote Code Execution Vulnerability

An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation of uploaded files. An authenticated user can uplo…

Remote | Misconfiguration
Mar 05, 2026 Mar 17, 2026
Mar 05, 2026
Mar 17, 2026
7.5 HIGH
CVE-2025-70949 — Couch-Auth Timing Side-Channel Information Disclosure

An observable timing discrepancy in @perfood/couch-auth v0.26.0 allows attackers to access sensitive information via a timing side-channel.

Remote | Information Disclosure
Mar 05, 2026 Mar 09, 2026
Mar 05, 2026
Mar 09, 2026
9.3 CRITICAL
CVE-2025-70948 — Couch-Auth Host Header Injection

A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover via spoofing the HTTP Host header.

Remote | Injection
Mar 05, 2026 Mar 09, 2026
Mar 05, 2026
Mar 09, 2026
8.1 HIGH
CVE-2025-70614 — OpenCode Systems OC Messaging USSD Gateway SSRF

OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web-based control panel allowing authenticated low-privileged attackers to gain to…

Remote | Authorization
Mar 05, 2026 Mar 09, 2026
Mar 05, 2026
Mar 09, 2026
9.0 CRITICAL
CVE-2025-55208 — Chamilo LMS has Stored Cross Site Scripting on Social Networks Uploaded Files

Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `Social Networks`. Through it, a low-privilege user can execute arbitrary code in…

chamilo_lms | Remote | Cross-Site Scripting
Mar 05, 2026 Mar 09, 2026
Mar 05, 2026
Mar 09, 2026
Showing 20 of 6046 Results