Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2025-9497 — Hardcoded Upgrade Decryption Passwords

Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.

Remote | Authentication
Mar 28, 2026 Apr 01, 2026
Mar 28, 2026
Apr 01, 2026
5.1 MEDIUM
CVE-2026-4994 — wandb OpenUI APIStatusError server.py generic_exception_handler information exposure

A vulnerability was found in wandb OpenUI up to 1.0/3.5-turb. Affected is the function generic_exception_handler of the file backend/openui/server.py of the component APIStatusError Handler. The mani…

| Information Disclosure
Mar 28, 2026 Apr 24, 2026
Mar 28, 2026
Apr 24, 2026
3.3 LOW
CVE-2026-4993 — wandb OpenUI config.py hard-coded credentials

A vulnerability has been found in wandb OpenUI up to 0.0.0.0/1.0. This impacts an unknown function of the file backend/openui/config.py. The manipulation of the argument LITELLM_MASTER_KEY leads to h…

| Misconfiguration
Mar 28, 2026 Apr 24, 2026
Mar 28, 2026
Apr 24, 2026
5.3 MEDIUM
CVE-2026-2442 — Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email H…

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 2.…

pagelayer | Remote | Injection
Mar 28, 2026 Apr 24, 2026
Mar 28, 2026
Apr 24, 2026
5.5 MEDIUM
CVE-2026-23399 — nf_tables: nft_dynset: fix possible stateful expression memleak in error path

In the Linux kernel, the following vulnerability has been resolved: nf_tables: nft_dynset: fix possible stateful expression memleak in error path If cloning the second stateful expression in the el…

linux_kernel | Memory Corruption
Mar 28, 2026 Apr 24, 2026
Mar 28, 2026
Apr 24, 2026
6.5 MEDIUM
CVE-2026-1307 — Ninja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via…

The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.1 via a callback functio…

ninja_forms | Remote | Information Disclosure
Mar 28, 2026 Apr 24, 2026
Mar 28, 2026
Apr 24, 2026
5.4 MEDIUM
CVE-2025-15445 — Restaurant Cafeteria <= 0.4.6 - Subscriber+ Arbitrary Plugin Installation/Activation

The Restaurant Cafeteria WordPress theme through 0.4.6 exposes insecure admin-ajax actions without nonce or capability checks, allowing any logged-in user, like subscriber, to perform privileged oper…

Remote | Authorization
Mar 28, 2026 Apr 15, 2026
Mar 28, 2026
Apr 15, 2026
7.2 HIGH
CVE-2025-12886 — Oxygen <= 6.0.8 - Unauthenticated Server-Side Request Forgery via route_path

The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.8 via the laborator_calc_route AJAX action. This makes it possible for unau…

Remote | Server-Side Request Forgery
Mar 28, 2026 Apr 24, 2026
Mar 28, 2026
Apr 24, 2026
Showing 20 of 5628 Results