Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-33315 — Vikunja has a 2FA Bypass via Caldav Basic Auth

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, the Caldav endpoint allows login using Basic Authentication, which in turn allows users to bypass the TOTP on 2…

vikunja | Remote | Authentication
Mar 24, 2026 Mar 24, 2026
Mar 24, 2026
Mar 24, 2026
5.3 MEDIUM
CVE-2026-33313 — Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, an authenticated user can read any task comment by ID, regardless of whether they have access to the task the c…

vikunja | Remote | Authorization
Mar 24, 2026 Mar 24, 2026
Mar 24, 2026
Mar 24, 2026
8.5 HIGH
CVE-2026-32647 — NGINX ngx_http_mp4_module vulnerability

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting…

nginx_plus nginx_open_source | Memory Corruption
Mar 24, 2026 Mar 26, 2026
Mar 24, 2026
Mar 26, 2026
6.5 MEDIUM
CVE-2026-30662 — ConcreteCMS File Manager Denial of Service (DoS)

ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method in 'concrete/controllers/backend/file.php' improperly manages memory when crea…

concrete_cms concrete5 | Remote | Denial of Service
Mar 24, 2026 Mar 24, 2026
Mar 24, 2026
Mar 24, 2026
6.1 MEDIUM
CVE-2026-30661 — iCMS Cross-Site Scripting (XSS)

iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within the index.html file. This allows remote attackers to execute arbitrary web script…

icms | Remote | Cross-Site Scripting
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
6.5 MEDIUM
CVE-2026-30655 — Solicitante SQL Injection

SQL injection in Solicitante::resetaSenha() in esiclivre/esiclivre v0.2.2 and earlier allows unauthenticated remote attackers to gain unauthorized access to sensitive information via the cpfcnpj para…

esiclivre | Remote | Injection
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
7.5 HIGH
CVE-2026-30653 — Free5GC Denial of Service (DoS)

An issue in Free5GC v.4.2.0 and before allows a remote attacker to cause a denial of service via the function HandleAuthenticationFailure of the component AMF

free5gc udm | Remote | Authentication
Mar 24, 2026 Mar 24, 2026
Mar 24, 2026
Mar 24, 2026
5.4 MEDIUM
CVE-2026-28755 — NGINX ngx_stream_ssl_module vulnerability

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_oc…

nginx_plus nginx_open_source | Remote | Misconfiguration
Mar 24, 2026 Mar 26, 2026
Mar 24, 2026
Mar 26, 2026
6.3 MEDIUM
CVE-2026-28753 — NGINX ngx_mail_proxy_module vulnerability

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server…

nginx_plus nginx_open_source | Remote | Injection
Mar 24, 2026 Mar 26, 2026
Mar 24, 2026
Mar 26, 2026
8.5 HIGH
CVE-2026-27784 — NGINX ngx_http_mp4_module vulnerability

The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its ter…

nginx_open_source | Memory Corruption
Mar 24, 2026 Mar 30, 2026
Mar 24, 2026
Mar 30, 2026
8.8 HIGH
CVE-2026-27654 — NGINX ngx_http_dav_module vulnerability

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may r…

nginx_plus nginx_open_source | Remote | Memory Corruption
Mar 24, 2026 Mar 26, 2026
Mar 24, 2026
Mar 26, 2026
8.7 HIGH
CVE-2026-27651 — NGINX ngx_mail_auth_http_module vulnerability

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP a…

nginx_plus nginx_open_source | Remote | Denial of Service
Mar 24, 2026 Mar 30, 2026
Mar 24, 2026
Mar 30, 2026
Showing 20 of 6352 Results