Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2026-29000 — pac4j-jwt JwtAuthenticator Authentication Bypass

pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authenticat…

Remote | Authentication
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
5.4 MEDIUM
CVE-2026-27898 — Vaultwarden: Unauthorized Access via Partial Update API on Another User’s Cipher

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id a…

Remote | Information Disclosure
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
8.3 HIGH
CVE-2026-27803 — Vaultwarden: Collection Management Operations Allowed Without `manage` Verification for M…

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can sti…

Remote | Authorization
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
8.3 HIGH
CVE-2026-27802 — Vaultwarden: Privilege Escalation via Bulk Permission Update to Unauthorized Collections …

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vulnerability via bulk permission up…

Remote | Authorization
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
6.0 MEDIUM
CVE-2026-27801 — Vaultwarden: 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protect…

Remote | Authentication
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
8.5 HIGH
CVE-2026-25750 — LangSmith Studio has URL Parameter Injection Vulnerability that Enables Token Theft via M…

Langchain Helm Charts are Helm charts for deploying Langchain applications on Kubernetes. Prior to langchain-ai/helm version 0.12.71, a URL parameter injection vulnerability existed in LangSmith Stud…

Remote | Information Disclosure
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
5.3 MEDIUM
CVE-2026-22040 — NanoMQ 0.24.6 Use-After-Free Leading to Heap Corruption and Broker Crash

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffic pattern of high-frequency publishes and rapid reconnect/kick-out using the sa…

Remote | Memory Corruption
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
0.0 NA
CVE-2025-70222 — D-Link DIR-513 Buffer Overflow Vulnerability

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin,goform/getAuthCode.

| Memory Corruption
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
3.4 LOW
CVE-2025-68467 — Dark Reader gives users the ability to request style sheets from local web servers

Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the extension works by analyzing the colors of web pages found in CSS style sheet …

Remote | Server-Side Request Forgery
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
8.6 HIGH
CVE-2025-66024 — XWiki Blog Application home page vulnerable to Stored XSS via Post Title

The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. Th…

Remote | Cross-Site Scripting
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
0.0 NA
CVE-2025-70225 — D-Link DIR-513 Buffer Overflow

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curtime parameter to the goform/formEasySetupWWConfig component

| Memory Corruption
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
0.0 NA
CVE-2025-70221 — D-Link DIR-513 Buffer Overflow Vulnerability

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin.

| Memory Corruption
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
0.0 NA
CVE-2025-46108 — D-Link Dir-513 Buffer Overflow Vulnerability

D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup.

| Memory Corruption
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
0.0 NA
CVE-2026-3545 — Google Chrome HTML Injection Vulnerability

Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security sever…

| Information Disclosure
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
0.0 NA
CVE-2026-3544 — Google Chrome WebCodecs Heap Buffer Overflow

Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Hig…

| Memory Corruption
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
0.0 NA
CVE-2026-3543 — Google Chrome V8 Out-of-Bounds Memory Access Vulnerability

Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security se…

| Memory Corruption
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
0.0 NA
CVE-2026-3542 — Google Chrome WebAssembly Out-of-Bounds Memory Access Vulnerability

Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security sever…

| Memory Corruption
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
0.0 NA
CVE-2026-3541 — Google Chrome CSS Out-of-Bounds Memory Read Vulnerability

Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Hi…

| Memory Corruption
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
0.0 NA
CVE-2026-3540 — Google Chrome WebAudio Out-of-Bounds Memory Access Vulnerability

Inappropriate implementation in WebAudio in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity…

| Memory Corruption
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
8.8 HIGH
CVE-2026-3539 — Google Chrome DevTools Heap Corruption Vulnerability

Object lifecycle issue in DevTools in Google Chrome prior to 145.0.7632.159 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a craf…

Remote | Memory Corruption
Mar 04, 2026 Mar 04, 2026
Mar 04, 2026
Mar 04, 2026
Showing 20 of 4986 Results