Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-30694 — DedeCMS Code Execution Vulnerability

An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component

dedecms | Remote | Injection
Mar 19, 2026 Mar 25, 2026
Mar 19, 2026
Mar 25, 2026
5.0 MEDIUM
CVE-2026-2646 — Heap buffer overflow in session parsing with wolfSSL_d2i_SSL_SESSION() function

A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. When deserializing session data with SESSION_CERTS enabled, certificate and session id lengths are read fr…

wolfssl | Memory Corruption
Mar 19, 2026 Mar 20, 2026
Mar 19, 2026
Mar 20, 2026
5.5 MEDIUM
CVE-2026-2645 — Acceptance of CertificateVerify Message before ClientKeyExchange in TLS 1.2

In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. The server could incorrectly accept the CertificateVerify message before the ClientKeyExchange m…

wolfssl | Remote | Authentication
Mar 19, 2026 Mar 20, 2026
Mar 19, 2026
Mar 20, 2026
6.5 MEDIUM
CVE-2026-26940 — Improper Validation of Specified Quantity in Input in Kibana Leading to Denial of Service

Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead Denial of Service via Excessive Allocation (CAPEC-130). The vulnerability allows …

kibana | Remote | Denial of Service
Mar 19, 2026 Mar 23, 2026
Mar 19, 2026
Mar 23, 2026
6.5 MEDIUM
CVE-2026-26939 — Missing Authorization in Kibana Leading to Unauthorized Endpoint Response Action Configur…

Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Response Action Configuration (host isolation, process termination, and process sus…

kibana | Remote | Authorization
Mar 19, 2026 Mar 23, 2026
Mar 19, 2026
Mar 23, 2026
5.7 MEDIUM
CVE-2026-26933 — Improper Validation of Array Index in Packetbeat Leading to Denial of Service

Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker with the ability to s…

packetbeat | Memory Corruption
Mar 19, 2026 Mar 23, 2026
Mar 19, 2026
Mar 23, 2026
6.5 MEDIUM
CVE-2025-67115 — Sercomm Small Cell Path Traversal Vulnerability

A path traversal vulnerability in /ftl/web/setup.cgi in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote authenticated users to read arbitrary files…

Remote | Path Traversal
Mar 19, 2026 Mar 24, 2026
Mar 19, 2026
Mar 24, 2026
9.8 CRITICAL
CVE-2025-67114 — Sercomm Small Cell FreedomFi Englewood Deterministic Credential Generation Algorithm Vuln…

Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers to derive v…

Remote | Authentication
Mar 19, 2026 Mar 24, 2026
Mar 19, 2026
Mar 24, 2026
9.8 CRITICAL
CVE-2025-67113 — Sercomm Small Cell CWMP Command Injection Vulnerability

OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers controlling the ACS endpoint t…

Remote | Injection
Mar 19, 2026 Mar 24, 2026
Mar 19, 2026
Mar 24, 2026
9.8 CRITICAL
CVE-2025-67112 — Small Cell Sercomm SCE4255W FreedomFi Englewood Hard-Coded AES-256-CBC Key Vulnerability

Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote authentic…

Remote | Cryptography
Mar 19, 2026 Mar 24, 2026
Mar 19, 2026
Mar 24, 2026
Showing 20 of 6450 Results