Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-0953 — Tutor LMS Pro <= 3.9.5 - Authentication Bypass via Social Login

The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.5 via the Social Login addon. This is due to the plugin failing to verify that …

tutor_lms | Remote | Authentication
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
6.1 MEDIUM
CVE-2026-0489 — DOM-based Cross-Site Scripting (XSS) Vulnerability in SAP Business One (Job Service)

Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could allow an unauthenticated attacker to inject specially crafted input which upon …

Remote | Cross-Site Scripting
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
6.1 MEDIUM
CVE-2025-36173 — InfoSphere Data Architect (IDA) 9.2.1 Vulnerability Fixes.

Affected Product(s)Version(s)InfoSphere Data Architect9.2.1

Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
4.4 MEDIUM
CVE-2025-36105 — IBM Planning Analytics Advanced Certified Containers is vulnerable to a sensitive informa…

IBM Planning Analytics Advanced Certified Containers 3.1.0 through 3.1.4 could allow a local privileged user to obtain sensitive information from environment variables.

Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
5.9 MEDIUM
CVE-2025-2399 — Denial of Service (DoS) Vulnerability in Mitsubishi Electric CNC Series

Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Series M800VW and M800VS, M80V Series M80V and M80VW, M800 Series M800W and M800S, …

Remote | Denial of Service
Mar 10, 2026 Mar 24, 2026
Mar 10, 2026
Mar 24, 2026
9.1 CRITICAL
CVE-2025-11158 — Hitachi Vantara Pentaho Data Integration & Analytics - Missing Authorization

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of …

Remote | Injection
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
Showing 20 of 6606 Results