Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-2830 — WP All Import <= 4.0.0 - Reflected Cross-Site Scripting via 'filepath'

The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filepath’ parameter in all versions up to, and…

Remote | Cross-Site Scripting
Mar 06, 2026 Mar 09, 2026
Mar 06, 2026
Mar 09, 2026
9.8 CRITICAL
CVE-2026-2331 — CVE-2026-2331

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem direc…

Remote | Authentication
Mar 06, 2026 Mar 09, 2026
Mar 06, 2026
Mar 09, 2026
9.4 CRITICAL
CVE-2026-2330 — CVE-2026-2330

An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not cover…

Remote | Path Traversal
Mar 06, 2026 Mar 09, 2026
Mar 06, 2026
Mar 09, 2026
9.3 CRITICAL
CVE-2026-29183 — SiYuan: Unauthenticated reflected SVG XSS in `/api/icon/getDynamicIcon` (`type=8`) enable…

SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability exists in the dynamic icon API endpoint "GET /api/icon/getDynamicIcon" when ty…

siyuan | Remote | Cross-Site Scripting
Mar 06, 2026 Mar 10, 2026
Mar 06, 2026
Mar 10, 2026
7.5 HIGH
CVE-2026-29074 — SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs)

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and …

svgo | Remote | Denial of Service
Mar 06, 2026 Mar 10, 2026
Mar 06, 2026
Mar 10, 2026
8.8 HIGH
CVE-2026-29073 — SiYuan: Direct SQL Query API accessible to Reader-level users enables unauthorized databa…

SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directly, but it only checks basic auth, not admin rights, any logged-in user, even re…

siyuan | Remote | Authorization
Mar 06, 2026 Mar 10, 2026
Mar 06, 2026
Mar 10, 2026
8.7 HIGH
CVE-2026-29062 — jackson-core: Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially al…

jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 to before version 3.1.0, the UTF8DataInputJsonParse…

jackson-core | Remote | Denial of Service
Mar 06, 2026 Mar 10, 2026
Mar 06, 2026
Mar 10, 2026
6.9 MEDIUM
CVE-2026-29059 — Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability exists in Windmill…

Remote | Path Traversal
Mar 06, 2026 Mar 09, 2026
Mar 06, 2026
Mar 09, 2026
Showing 20 of 5908 Results