Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-33162 — Craft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to…

Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp can move entries across sections via POST /actions/…

craft_cms | Remote | Authorization
Mar 24, 2026 Mar 26, 2026
Mar 24, 2026
Mar 26, 2026
4.3 MEDIUM
CVE-2026-33161 — Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to…

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can call asset…

craft_cms | Remote | Authorization
Mar 24, 2026 Mar 26, 2026
Mar 24, 2026
Mar 26, 2026
5.3 MEDIUM
CVE-2026-33160 — Craft CMS: Anonymous "generate transform" calls for assets can expose private assets via …

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, an unauthenticated user can call assets/generate-t…

craft_cms | Remote | Authorization
Mar 24, 2026 Mar 26, 2026
Mar 24, 2026
Mar 26, 2026
6.9 MEDIUM
CVE-2026-33159 — Craft CMS: Unauthenticated users could execute project configuration sync operations that…

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, guest users can access Config Sync updater index, …

craft_cms | Remote | Authentication
Mar 24, 2026 Mar 26, 2026
Mar 24, 2026
Mar 26, 2026
6.5 MEDIUM
CVE-2026-33158 — Craft CMS: Low-privilege users could read private asset contents when editing an asset (I…

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can read priva…

craft_cms | Remote | Authorization
Mar 24, 2026 Mar 26, 2026
Mar 24, 2026
Mar 26, 2026
8.6 HIGH
CVE-2026-33157 — Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior

Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.13, a Remote Code Execution (RCE) vulnerability exists in Craft CMS, it can be exploited by any authenticated …

craft_cms | Remote | Injection
Mar 24, 2026 Mar 26, 2026
Mar 24, 2026
Mar 26, 2026
7.5 HIGH
CVE-2026-32854 — LibVNCServer httpd proxy NULL Pointer Dereference

LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the HTTP proxy handlers within httpProcessInput() in httpd.c that allow remote att…

libvncserver | Remote | Denial of Service
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
8.1 HIGH
CVE-2026-32853 — LibVNCServer UltraZip Encoding Heap Out-of-bounds Read

LibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a heap out-of-bounds read vulnerability in the UltraZip encoding handler that allows a malicious VNC server to cause informati…

libvncserver | Remote | Memory Corruption
Mar 24, 2026 Mar 25, 2026
Mar 24, 2026
Mar 25, 2026
Showing 20 of 6348 Results