Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.3 HIGH
CVE-2026-1917 — Login Disable - Less critical - Access bypass - SA-CONTRIB-2026-008

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Login Disable allows Functionality Bypass.This issue affects Login Disable: from 0.0.0 before 2.1.3.

login_disable login_disable | Remote | Authentication
Mar 25, 2026 Apr 02, 2026
Mar 25, 2026
Apr 02, 2026
8.8 HIGH
CVE-2024-58341 — OpenCart Core 4.0.2.3 SQL Injection via search Parameter

OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'search' parameter. Attackers can s…

opencart opencart_core | Remote | Injection
Mar 25, 2026 Mar 27, 2026
Mar 25, 2026
Mar 27, 2026
3.7 LOW
CVE-2026-4363 — Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authentica…

gitlab | Remote | Authorization
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
6.9 MEDIUM
CVE-2026-33268 — Nanoleaf Lines unauthenticated firmware file store

Nanoleaf Lines 12.3.2 does not authenticate firmware file uploads. A remote, unauthenticated attacker can upload firmware files on the device and consume storage resources. Fixed in 12.3.6.

Remote | Authentication
Mar 25, 2026 Mar 25, 2026
Mar 25, 2026
Mar 25, 2026
9.8 CRITICAL
CVE-2026-26830 — Pdf-Image OS Command Injection Vulnerability

pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConvertCommandForPage functions use util.format() to …

pdf-image | Remote | Injection
Mar 25, 2026 Apr 02, 2026
Mar 25, 2026
Apr 02, 2026
8.8 HIGH
CVE-2026-23514 — Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management

Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kite…

kiteworks | Remote | Authorization
Mar 25, 2026 Mar 27, 2026
Mar 25, 2026
Mar 27, 2026
9.8 CRITICAL
CVE-2025-59707 — N2W Spoofing Remote Code Execution

In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft because of a spoofing vulnerability.

n2w | Remote | Authentication
Mar 25, 2026 Mar 27, 2026
Mar 25, 2026
Mar 27, 2026
9.8 CRITICAL
CVE-2025-59706 — N2W Remote Code Execution Vulnerability

In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution.

n2w | Remote | Injection
Mar 25, 2026 Mar 27, 2026
Mar 25, 2026
Mar 27, 2026
9.0 CRITICAL
CVE-2025-32991 — Apache N2WS Backup & Recovery Remote Code Execution Vulnerability

In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution.

backup\&_recovery | Remote | Authentication
Mar 25, 2026 Mar 26, 2026
Mar 25, 2026
Mar 26, 2026
Showing 20 of 6209 Results