Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-4424 — Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive…

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions betw…

enterprise_linux grub2 gix-date | Remote | Memory Corruption
Mar 19, 2026 Apr 16, 2026
Mar 19, 2026
Apr 16, 2026
5.1 MEDIUM
CVE-2026-32843 — Linkit ONE Location Aware Sensor System (LASS) Reflected XSS via PM25.php

Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arb…

Remote | Cross-Site Scripting
Mar 19, 2026 Mar 20, 2026
Mar 19, 2026
Mar 20, 2026
8.8 HIGH
CVE-2026-30711 — Devome GRR SQL Injection Vulnerability

Devome GRR v4.5.0 was discovered to contain multiple authenticated SQL injection vulnerabilities in the include/session.inc.php file via the referer and user-agent.

Remote | Injection
Mar 19, 2026 Mar 24, 2026
Mar 19, 2026
Mar 24, 2026
9.8 CRITICAL
CVE-2026-30402 — Apache WireGuard Code Execution Vulnerability

An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection function

wgcloud | Remote | Authentication
Mar 19, 2026 Apr 02, 2026
Mar 19, 2026
Apr 02, 2026
6.5 MEDIUM
CVE-2026-2369 — Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length reso…

A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially acc…

Remote | Memory Corruption
Mar 19, 2026 Mar 20, 2026
Mar 19, 2026
Mar 20, 2026
7.2 HIGH
CVE-2026-27043 — WordPress Photography theme < 7.7.6 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This issue affects Photography: from n/a before 7.7.6.

photography | Remote | Path Traversal
Mar 19, 2026 Apr 07, 2026
Mar 19, 2026
Apr 07, 2026
7.7 HIGH
CVE-2026-22558 — "UniFi Network Authenticated NoSQL Injection Vulnerability"

An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges.

unifi_network_application | Remote | Injection
Mar 19, 2026 Mar 20, 2026
Mar 19, 2026
Mar 20, 2026
10.0 CRITICAL
CVE-2026-22557 — "UniFi Network Application Path Traversal Account Access Vulnerability"

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to …

unifi_network_application | Remote | Path Traversal
Mar 19, 2026 Mar 20, 2026
Mar 19, 2026
Mar 20, 2026
9.8 CRITICAL
CVE-2025-69720 — "ncurses Buffer Overflow Vulnerability"

The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.

ncurses ncurses | Remote | Memory Corruption
Mar 19, 2026 Mar 26, 2026
Mar 19, 2026
Mar 26, 2026
8.8 HIGH
CVE-2025-71260 — BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to…

Remote | Injection
Mar 19, 2026 Mar 20, 2026
Mar 19, 2026
Mar 20, 2026
5.3 MEDIUM
CVE-2025-71259 — BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in externalfeed/RSS

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigg…

Remote | Server-Side Request Forgery
Mar 19, 2026 Mar 20, 2026
Mar 19, 2026
Mar 20, 2026
5.3 MEDIUM
CVE-2025-71258 — BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in searchWeb

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the se…

Remote | Server-Side Request Forgery
Mar 19, 2026 Mar 20, 2026
Mar 19, 2026
Mar 20, 2026
7.3 HIGH
CVE-2025-71257 — BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets…

Remote | Authentication
Mar 19, 2026 Mar 20, 2026
Mar 19, 2026
Mar 20, 2026
Showing 20 of 6473 Results