Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2025-69649 — Apache GNU Binutils Null Pointer Dereference Vulnerability

GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null se…

binutils | Remote | Memory Corruption
Mar 06, 2026 Mar 11, 2026
Mar 06, 2026
Mar 11, 2026
5.3 MEDIUM
CVE-2026-3419 — Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass V…

Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in violation of RFC 9110 §8.3.1(https://httpwg.org/specs/rfc9110.html#field.conten…

fastify | Misconfiguration
Mar 06, 2026 Mar 18, 2026
Mar 06, 2026
Mar 18, 2026
6.9 MEDIUM
CVE-2026-30833 — Rocket.Chat: NoSQL injection in the EE ddp-streamer-service

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, a NoSQL injection vulnerability exists in…

rocket.chat | Remote | Injection
Mar 06, 2026 Mar 13, 2026
Mar 06, 2026
Mar 13, 2026
9.8 CRITICAL
CVE-2026-30831 — Rocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamer

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, authentication vulnerabilities exist in R…

rocket.chat | Remote | Authentication
Mar 06, 2026 Mar 13, 2026
Mar 06, 2026
Mar 13, 2026
7.7 HIGH
CVE-2026-29178 — Lemmy: Unauthenticated SSRF via file_type query parameter injection in image endpoint

Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. Prior to…

lemmy | Remote | Server-Side Request Forgery
Mar 06, 2026 Mar 09, 2026
Mar 06, 2026
Mar 09, 2026
5.3 MEDIUM
CVE-2026-29110 — Cryptomator: Leaking of cleartext paths into log file in non-debug mode

Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.0, in non-debug mode Cryptomator might leak cleartext paths into the log file. This can reveal meta information a…

cryptomator | Remote | Information Disclosure
Mar 06, 2026 Mar 13, 2026
Mar 06, 2026
Mar 13, 2026
8.1 HIGH
CVE-2026-29091 — Locutus: Remote Code Execution (RCE) in locutus call_user_func_array due to Code Injection

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a remote code execution (RCE) flaw was discovered in the locutus project, specifi…

locutus | Remote | Injection
Mar 06, 2026 Mar 13, 2026
Mar 06, 2026
Mar 13, 2026
8.8 HIGH
CVE-2026-29089 — TimescaleDB uses untrusted search path during extension upgrade

TimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgres extension. From version 2.23.0 to 2.25.1, PostgreSQL uses the search_path setting to locate unqua…

timescaledb | Misconfiguration
Mar 06, 2026 Mar 18, 2026
Mar 06, 2026
Mar 18, 2026
7.5 HIGH
CVE-2026-29087 — @hono/node-server: Authorization bypass for protected static paths via encoded slashes in…

@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. p…

node-server | Remote | Authorization
Mar 06, 2026 Mar 09, 2026
Mar 06, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-28514 — Rocket.Chat: Users can login with any password via the EE ddp-streamer-service

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, and 8.0.0, a critical authentication bypass vulnerab…

rocket.chat | Remote | Authentication
Mar 06, 2026 Mar 18, 2026
Mar 06, 2026
Mar 18, 2026
5.5 MEDIUM
CVE-2025-69651 — Apache GNU Binutils Denial of Service (DoS) Vulnerability

GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations return…

binutils | Memory Corruption
Mar 06, 2026 Mar 19, 2026
Mar 06, 2026
Mar 19, 2026
5.5 MEDIUM
CVE-2025-69646 — Apache Binutils Denial-of-Service Vulnerability

Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can c…

binutils | Denial of Service
Mar 06, 2026 Mar 20, 2026
Mar 06, 2026
Mar 20, 2026
5.5 MEDIUM
CVE-2025-69645 — Apache Binutils Denial-of-Service Vulnerability

Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can resul…

binutils | Denial of Service
Mar 06, 2026 Mar 20, 2026
Mar 06, 2026
Mar 20, 2026
5.0 MEDIUM
CVE-2025-69644 — "Binutils objdump Denial-of-Service Vulnerability"

An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling…

binutils | Denial of Service
Mar 06, 2026 Mar 10, 2026
Mar 06, 2026
Mar 10, 2026
Showing 20 of 5874 Results