Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-33266 — Apache OpenMeetings: Hardcoded Remember-Me Cookie Encryption Key and Salt

Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case…

openmeetings | Remote | Cryptography
Apr 09, 2026 Apr 15, 2026
Apr 09, 2026
Apr 15, 2026
4.3 MEDIUM
CVE-2026-33005 — Apache OpenMeetings: Insufficient checks in FileWebService

Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (met…

openmeetings | Remote | Authorization
Apr 09, 2026 Apr 15, 2026
Apr 09, 2026
Apr 15, 2026
5.4 MEDIUM
CVE-2025-70365 — Kiamo Stored XSS

A stored cross-site scripting (XSS) vulnerability exists in Kiamo before 8.4 due to improper output encoding of user-supplied input in administrative interfaces. An authenticated administrative user …

Remote | Cross-Site Scripting
Apr 09, 2026 Apr 13, 2026
Apr 09, 2026
Apr 13, 2026
8.8 HIGH
CVE-2025-70364 — Kiamo PHP Code Execution Vulnerability

An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP code on the server.

Remote | Injection
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
9.1 CRITICAL
CVE-2025-15480 — Senstive information disclosure was affecting ubuntu-desktop-provision

In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desk…

ubuntu_desktop_provision | Remote | Information Disclosure
Apr 09, 2026 Apr 17, 2026
Apr 09, 2026
Apr 17, 2026
8.1 HIGH
CVE-2025-14551 — Senstive information disclosure was affecting subiquity

In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include ce…

ubuntu_subiquity | Remote | Information Disclosure
Apr 09, 2026 Apr 17, 2026
Apr 09, 2026
Apr 17, 2026
7.5 HIGH
CVE-2026-5959 — GL.iNet GL-RM1/GL-RM10/GL-RM10RC/GL-RM1PE Factory Reset improper authentication

A security flaw has been discovered in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1. Affected by this issue is some unknown functionality of the component Factory Reset Handler. Performing a…

Remote | Authentication
Apr 09, 2026 Apr 13, 2026
Apr 09, 2026
Apr 13, 2026
9.1 CRITICAL
CVE-2026-5445 — Out-of-Bounds Read in DicomImageDecoder (DecodeLookupTable)

An out-of-bounds read vulnerability exists in the `DecodeLookupTable` function within `DicomImageDecoder.cpp`. The lookup-table decoding logic used for `PALETTE COLOR` images does not validate pixel …

orthanc | Remote | Memory Corruption
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
7.1 HIGH
CVE-2026-5444 — Heap Buffer Overflow in PAM Image Buffer Allocation

A heap buffer overflow vulnerability exists in the PAM image parsing logic. When Orthanc processes a crafted PAM image embedded in a DICOM file, image dimensions are multiplied using 32-bit unsigned …

orthanc | Memory Corruption
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
9.8 CRITICAL
CVE-2026-5443 — Heap Buffer Overflow in DICOM Image Decoder (Palette Color Decode)

A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation uses 32-bit multiplication for width and height calculations. If these values …

orthanc | Remote | Memory Corruption
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
9.8 CRITICAL
CVE-2026-5442 — Heap Buffer Overflow in DICOM Image Decoder via VR UL Dimensions

A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Representation (VR) Unsigned Long (UL), instead of the expected VR Unsigned Short (US)…

orthanc | Remote | Memory Corruption
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
7.1 HIGH
CVE-2026-5441 — Out-of-Bounds Read in DicomImageDecoder (PMSCT_RLE1 Decompression)

An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1` decompression routine, which decodes the proprietary Philips Compression form…

orthanc | Memory Corruption
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
7.5 HIGH
CVE-2026-5440 — Memory Exhaustion via Unbounded Content-Length

A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The server allocates memory directly based on the attacker supplied header value with…

orthanc | Remote | Denial of Service
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
7.5 HIGH
CVE-2026-5439 — Memory Exhaustion via Forged ZIP Metadata

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed si…

orthanc | Remote | Denial of Service
Apr 09, 2026 Apr 15, 2026
Apr 09, 2026
Apr 15, 2026
7.5 HIGH
CVE-2026-5438 — Gzip Decompression Bomb via Content-Encoding Header

A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The server does not enforce limits on decompressed size and allocates memory based on…

orthanc | Remote | Denial of Service
Apr 09, 2026 Apr 15, 2026
Apr 09, 2026
Apr 15, 2026
7.5 HIGH
CVE-2026-5437 — Out-of-Bounds Read in DicomStreamReader

An out-of-bounds read vulnerability exists in `DicomStreamReader` during DICOM meta-header parsing. When processing malformed metadata structures, the parser may read beyond the bounds of the allocat…

orthanc | Remote | Memory Corruption
Apr 09, 2026 Apr 15, 2026
Apr 09, 2026
Apr 15, 2026
7.2 HIGH
CVE-2026-4116 — SonicWall SMA1000 Unicode Encoding Bypass

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.

sma1000_firmware | Remote | Authentication
Apr 09, 2026 Apr 13, 2026
Apr 09, 2026
Apr 13, 2026
0.0 NA
CVE-2026-4114 — SonicWall SMA1000 Remote Authentication Bypass

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.

sma1000_firmware | Authentication
Apr 09, 2026 Apr 13, 2026
Apr 09, 2026
Apr 13, 2026
7.2 HIGH
CVE-2026-4113 — SonicWall SSL VPN User Credentials Enumeration Vulnerability

An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.

sma1000_firmware | Remote | Information Disclosure
Apr 09, 2026 Apr 13, 2026
Apr 09, 2026
Apr 13, 2026
0.0 NA
CVE-2026-4112 — SonicWall SMA1000 SQL Injection Privilege Escalation

Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privile…

sma1000_firmware | Injection
Apr 09, 2026 Apr 13, 2026
Apr 09, 2026
Apr 13, 2026
Showing 20 of 6503 Results