Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-33147 — GMT: Stack-based Buffer Overflow in gmt_remote_dataset_id

GMT is an open source collection of command-line tools for manipulating geographic and Cartesian data sets. In versions from 6.6.0 and prior, a stack-based buffer overflow vulnerability was identifie…

gmt | Memory Corruption
Mar 20, 2026 Mar 27, 2026
Mar 20, 2026
Mar 27, 2026
7.8 HIGH
CVE-2026-33144 — GPAC MP4Box Heap Buffer Overflow Write in gf_xml_parse_bit_sequence_bs (NHML BS Parsing)

GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in the gf_xml_parse_bi…

gpac | Memory Corruption
Mar 20, 2026 Apr 14, 2026
Mar 20, 2026
Apr 14, 2026
8.7 HIGH
CVE-2026-33143 — OneUptime: WhatsApp Webhook Missing Signature Verification

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook handler (/notification/whatsapp/webhook) processes incoming status update even…

oneuptime | Remote | Authentication
Mar 20, 2026 Mar 23, 2026
Mar 20, 2026
Mar 23, 2026
8.1 HIGH
CVE-2026-33142 — OneUptime: ClickHouse SQL Injection via unvalidated column identifiers in sort, select, a…

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-32306 (ClickHouse SQL injection via aggregate query parameters) added column name v…

oneuptime | Remote | Injection
Mar 20, 2026 Mar 23, 2026
Mar 20, 2026
Mar 23, 2026
7.8 HIGH
CVE-2025-63261 — AWStats Command Injection Vulnerability

AWStats 8.0 is vulnerable to Command Injection via the open function

debian_linux awstats | Injection
Mar 20, 2026 Apr 07, 2026
Mar 20, 2026
Apr 07, 2026
7.2 HIGH
CVE-2025-55988 — DreamFactory Core Directory Traversal Vulnerability

An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path.

dreamfactory_core | Remote | Path Traversal
Mar 20, 2026 Apr 14, 2026
Mar 20, 2026
Apr 14, 2026
Showing 20 of 6086 Results