Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2026-32760 — File Browser Self Registration Grants Any User Admin Access When Default Permissions Incl…

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2.61.2 and below, any unauthenticated visitor can …

filebrowser | Remote | Authentication
Mar 20, 2026 Mar 23, 2026
Mar 20, 2026
Mar 23, 2026
8.1 HIGH
CVE-2026-32759 — File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurely

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2.61.2 and below, the TUS resumable upload handler…

filebrowser | Remote | Denial of Service
Mar 20, 2026 Mar 23, 2026
Mar 20, 2026
Mar 23, 2026
6.5 MEDIUM
CVE-2026-32758 — File Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination Para…

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.61.2 and below are vulnerable to Path Traversal thr…

filebrowser | Remote | Path Traversal
Mar 20, 2026 Mar 23, 2026
Mar 20, 2026
Mar 23, 2026
5.4 MEDIUM
CVE-2026-32757 — Admidio: HTMLPurifier Bypass in eCard Message Allows HTML Email Injection

Admidio is an open-source user management solution. In versions 5.0.6 and below, the eCard send handler uses a raw $_POST['ecard_message'] value instead of the HTMLPurifier-sanitized $formValues['eca…

admidio | Remote | Cross-Site Scripting
Mar 20, 2026 Mar 23, 2026
Mar 20, 2026
Mar 23, 2026
8.8 HIGH
CVE-2026-32756 — Admidio: Unrestricted File Upload via CSRF Token Validation Bypass in Documents & Files M…

Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload vulnerability in the Documents & Files module. Due to a design flaw in how CSR…

admidio | Remote | Cross-Site Request Forgery
Mar 20, 2026 Mar 23, 2026
Mar 20, 2026
Mar 23, 2026
6.5 MEDIUM
CVE-2026-32697 — SuiteCRM: RecordHandler::getRecord() missing ACLAccess('view') check allows any authentic…

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3, the `RecordHandler::getRecord()` method retrieves any record by modu…

suitecrm suitecrm | Remote | Authorization
Mar 20, 2026 Mar 23, 2026
Mar 20, 2026
Mar 23, 2026
8.1 HIGH
CVE-2026-29189 — SuiteCRM has a REST API V8 IDOR: Missing ACL Checks on User Preferences and Relationship …

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the SuiteCRM REST API V8 has missing ACL (Access Control …

suitecrm suitecrm | Remote | Authorization
Mar 20, 2026 Mar 23, 2026
Mar 20, 2026
Mar 23, 2026
8.6 HIGH
CVE-2026-29109 — SuiteCRM Authenticated Remote Code Execution via Unsafe Deserialization in SavedSearch Fi…

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to and including 8.9.2 contain an unsafe deserialization vulnerability in the Sav…

suitecrm suitecrm | Remote | Injection
Mar 20, 2026 Mar 23, 2026
Mar 20, 2026
Mar 23, 2026
6.5 MEDIUM
CVE-2026-29108 — Authenticated SuiteCRM Users Can Retrieve The Password Hash of Any User

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3, an authenticated API endpoint allows any user to retrieve detailed i…

suitecrm suitecrm | Remote | Information Disclosure
Mar 20, 2026 Mar 23, 2026
Mar 20, 2026
Mar 23, 2026
5.9 MEDIUM
CVE-2026-22737 — Spring Framework Improper Path Limitation with Script View Templates

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations …

spring_framework | Remote | Information Disclosure
Mar 20, 2026 Mar 20, 2026
Mar 20, 2026
Mar 20, 2026
2.6 LOW
CVE-2026-22735 — Server Sent Event stream corruption

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16,…

Remote | Denial of Service
Mar 20, 2026 Mar 20, 2026
Mar 20, 2026
Mar 20, 2026
8.2 HIGH
CVE-2026-22733 — Authentication Bypass under Actuator CloudFoundry endpoints

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the C…

spring_security | Remote | Authentication
Mar 20, 2026 Mar 20, 2026
Mar 20, 2026
Mar 20, 2026
Showing 20 of 6312 Results