Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.6 MEDIUM
CVE-2025-31978 — HCL BigFix Service Management (SM) does not adequately sanitize or safely render

HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields whic…

bigfix_service_management | Remote | Information Disclosure
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
7.5 HIGH
CVE-2025-31976 — HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to…

bigfix_service_management | Remote | Information Disclosure
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
5.3 MEDIUM
CVE-2025-31975 — HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Bann…

HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal software versions and system details, potentially a…

bigfix_service_management | Remote | Information Disclosure
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
3.5 LOW
CVE-2025-31959 — HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded…

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentio…

bigfix_service_management | Remote | Information Disclosure
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
5.7 MEDIUM
CVE-2025-31957 — HCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vul…

HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exposure of sensitive data.

bigfix_service_management | Remote | Cross-Site Request Forgery
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
5.4 MEDIUM
CVE-2026-36358 — Juzaweb CMS Cross-Site Scripting (XSS)

Cross Site Scripting vulnerability in Juzaweb CMS v.5.0.0 allows a remote attacker via execute arbitrary code via a crafted script to the Add Banner Ads function

Remote | Cross-Site Scripting
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
Showing 20 of 7366 Results