Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-4673 — Google Chrome Heap Buffer Overflow Vulnerability in WebAudio

Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Mar 24, 2026 Mar 24, 2026
Mar 24, 2026
Mar 24, 2026
7.5 HIGH
CVE-2026-4617 — SourceCodester Patients Waiting Area Queue Management System Patient Check-In api_patient…

A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element is the function ValidateToken of the file /php/api_patient_checkin.php of the …

Mar 24, 2026 Mar 24, 2026
Mar 24, 2026
Mar 24, 2026
4.8 MEDIUM
CVE-2026-4616 — bolo-blog Article Title article cross site scripting

A security flaw has been discovered in bolo-blog up to 2.6.4. The affected element is an unknown function of the file /console/article/ of the component Article Title Handler. Performing a manipulati…

Remote | Cross-Site Scripting
Mar 24, 2026 Mar 27, 2026
Mar 24, 2026
Mar 27, 2026
6.2 MEDIUM
CVE-2026-33320 — Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. Starting in version 3.0.0 and prior to version 3.3.1, Dasel's YAML reader allows an attacker who ca…

dasel | Denial of Service
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.5 HIGH
CVE-2026-33306 — bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost…

bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorithm. Prior to version 3.1.22, an integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations i…

bcrypt-ruby | Remote | Cryptography
Mar 24, 2026 Mar 30, 2026
Mar 24, 2026
Mar 30, 2026
7.8 HIGH
CVE-2026-33298 — llama.cpp has a Heap Buffer Overflow via Integer Overflow in GGUF Tensor Parsing

llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml_nbytes` function allows an attacker to bypass memory validation by crafting a …

llama.cpp | Memory Corruption
Mar 24, 2026 Mar 24, 2026
Mar 24, 2026
Mar 24, 2026
4.3 MEDIUM
CVE-2026-33290 — WPGraphQL Repo's updateComment allows low-privileged authenticated users to change commen…

WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.10.0, an authorization flaw in updateComment allows an authenticated low-privileged user (including a custom role with zero ca…

wpgraphql | Remote | Authorization
Mar 24, 2026 Apr 16, 2026
Mar 24, 2026
Apr 16, 2026
8.6 HIGH
CVE-2026-22739 — Spring Cloud Config Profile Substitution Can Allow Unintended Access To Files And Enable …

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible …

Remote | Path Traversal
Mar 24, 2026 Mar 24, 2026
Mar 24, 2026
Mar 24, 2026
Showing 20 of 6448 Results