Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-29193 — ZITADEL: Bypassing Zitadel Login Behavior and Security Policy in Login V2

ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login V2 UI allowed users to bypass login behavior and security policies and self-re…

zitadel | Remote | Authentication
Mar 07, 2026 Mar 10, 2026
Mar 07, 2026
Mar 10, 2026
7.7 HIGH
CVE-2026-29192 — ZITADEL: Stored XSS via Default URI Redirect Leads to Account Takeover

ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via Defau…

zitadel | Remote | Authentication
Mar 07, 2026 Mar 10, 2026
Mar 07, 2026
Mar 10, 2026
9.3 CRITICAL
CVE-2026-29191 — ZITADEL: 1-Click Account Takeover via XSS in /saml-post Endpoint

ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via XSS i…

zitadel | Remote | Cross-Site Scripting
Mar 07, 2026 Mar 10, 2026
Mar 07, 2026
Mar 10, 2026
9.8 CRITICAL
CVE-2026-29186 — @backstage/plugin-techdocs-node: TechDocs Mkdocs Configuration Key Enables Arbitrary Code…

Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techd…

backstage backstage_plugin-techdocs-node | Remote | Misconfiguration
Mar 07, 2026 Mar 11, 2026
Mar 07, 2026
Mar 11, 2026
2.7 LOW
CVE-2026-29185 — @backstage/integration: Potential reading of SCM URLs using built in token

Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerability in the SCM URL parsing used by Backstage integrations allowed path traversal sequences in encod…

backstage backstage_plugin-techdocs-node | Remote | Path Traversal
Mar 07, 2026 Mar 09, 2026
Mar 07, 2026
Mar 09, 2026
2.0 LOW
CVE-2026-29184 — @backstage/plugin-scaffolder-backend: Potential Session Token Exfiltration via Log Redact…

Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run throug…

backstage backstage_plugin-techdocs-node | Remote | Information Disclosure
Mar 07, 2026 Mar 09, 2026
Mar 07, 2026
Mar 09, 2026
9.3 CRITICAL
CVE-2026-29067 — ZITADEL: Account Takeover Due to Improper Instance Validation in V2 Login

ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password reset mechanism in login V2. ZITADEL utilizes the Forw…

zitadel | Remote | Server-Side Request Forgery
Mar 07, 2026 Mar 10, 2026
Mar 07, 2026
Mar 10, 2026
7.2 HIGH
CVE-2026-3662 — Wavlink WL-NU516U1 adm.cgi usb_p910 command injection

A vulnerability has been found in Wavlink WL-NU516U1 240425. This vulnerability affects the function usb_p910 of the file /cgi-bin/adm.cgi. Such manipulation of the argument Pr_mode leads to command …

wl-nu516u1_firmware wl-nu516u1 | Remote | Injection
Mar 07, 2026 Mar 10, 2026
Mar 07, 2026
Mar 10, 2026
7.2 HIGH
CVE-2026-3661 — Wavlink WL-NU516U1 adm.cgi ota_new_upgrade command injection

A flaw has been found in Wavlink WL-NU516U1 240425. This affects the function ota_new_upgrade of the file /cgi-bin/adm.cgi. This manipulation of the argument model causes command injection. It is pos…

wl-nu516u1_firmware wl-nu516u1 | Remote | Injection
Mar 07, 2026 Mar 10, 2026
Mar 07, 2026
Mar 10, 2026
Showing 20 of 5869 Results