Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2025-55040 — MuraCMS CSRF Form Definition Upload Vulnerability

The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vulnerable cForm.importform function lacks C…

mura_cms | Remote | Cross-Site Request Forgery
Mar 18, 2026 Mar 20, 2026
Mar 18, 2026
Mar 20, 2026
7.5 HIGH
CVE-2026-32609 — Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and S…

Glances is an open-source system cross-platform monitoring tool. The GHSA-gh4x fix (commit 5d3de60) addressed unauthenticated configuration secrets exposure on the `/api/v4/config` endpoints by intro…

glances | Remote | Information Disclosure
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
7.4 HIGH
CVE-2026-3278 — XSS Vulnerability discovered in OpenText™ ZENworks Service Desk.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks Service Desk allows Cross-Site Scripting (XSS). The vulnerability could allow …

zenworks_service_desk | Remote | Cross-Site Scripting
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
6.6 MEDIUM
CVE-2026-32694 — Insecure Direct Object Reference attack via predictable secret ID in Juju

In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a predictable XID of the secret to verify ownership.…

juju | Remote | Authorization
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
9.8 CRITICAL
CVE-2026-25449 — WordPress Traveler theme < 3.2.8.1 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affects Traveler: from n/a through < 3.2.8.1.

Remote | Injection
Mar 18, 2026 Apr 01, 2026
Mar 18, 2026
Apr 01, 2026
8.8 HIGH
CVE-2026-32693 — Unauthorized access to Kubernetes secrets in Juju

In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updat…

juju | Remote | Authorization
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
7.6 HIGH
CVE-2026-32692 — Unauthorized update of out-of-scope Vault secrets

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret r…

juju | Remote | Authorization
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
5.3 MEDIUM
CVE-2026-32691 — Timing ownership claim attack on new external back-end secrets

A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secret. Between generating a Ju…

juju | Remote | Race Condition
Mar 18, 2026 Mar 19, 2026
Mar 18, 2026
Mar 19, 2026
Showing 20 of 6508 Results