Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-29772 — Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands

Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full request body as JSON without enforcing a size limit. Because JSON.parse() allocates …

astro \@astrojs\/node | Remote | Denial of Service
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
6.1 MEDIUM
CVE-2026-23924 — Agent 2 Docker plugin arbitrary file read via Docker API injection

Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary fi…

zabbix | Remote | Information Disclosure
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
6.9 MEDIUM
CVE-2026-23923 — Unauthenticated arbitrary PHP class instantiation

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.

zabbix | Remote | Authentication
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
8.7 HIGH
CVE-2026-23921 — Blind, read-only SQL injection in Zabbix API via sortfield parameter

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Althou…

zabbix | Remote | Injection
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.7 HIGH
CVE-2026-23920 — Host and event action script regex validation can be bypassed in certain situations, lead…

Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected n…

zabbix | Remote | Injection
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.1 HIGH
CVE-2026-23919 — Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Server

For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-…

zabbix | Information Disclosure
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.8 HIGH
CVE-2026-1995 — IDrive Cloud Backup Client for Windows contains a privilege escalation vulnerability

IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded contents of these files are used …

| Authentication
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
Showing 20 of 6347 Results