Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2026-25041 — Budibase has a Command Injection in PostgreSQL Dump Command

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the PostgreSQL integration constructs shell commands using user-controlled configurat…

Remote | Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
8.6 HIGH
CVE-2026-0846 — Arbitrary File Read via Absolute Path Input in nltk.util.filestring()

A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files …

Remote | Path Traversal
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2025-70031 — SunbirdEd Cross-Site Request Forgery

An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

| Cross-Site Request Forgery
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2025-70030 — SunbirdEd Regular Expression Denial of Service

An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

| Denial of Service
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
8.2 HIGH
CVE-2025-68402 — FreshRSS has an authentication bypass due to truncated bcrypt hash [edge branch]

FreshRSS is a free, self-hostable RSS aggregator. From 57e1a37 - 00f2f04, the lengths of the nonce was changed from 40 chars to 64. password_verify() is currently being called with a constructed stri…

Remote | Authentication
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
7.5 HIGH
CVE-2025-62166 — FreshRSS has an IDOR which allows for viewing feeds of any user and leaking tokens

FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed. Usually only the default user's feed sho…

Remote | Authentication
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-25045 — Budibase Critical Privilege Escalation & IDOR via Missing RBAC on User Role Management (C…

Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of Vertical Privilege Escalation and IDOR (Insecure Direct Object Reference) due …

| Authorization
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-25737 — Budibase Arbitrary File Upload Leading to Multiple Critical Vulnerabilities (SSRF, Stored…

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload vulnerability exists even though file extension restrictions …

| Misconfiguration
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
5.9 MEDIUM
CVE-2026-3638 — Devolutions Server Access Control Vulnerability

Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a low-privileged authenticated user to restore deleted users and roles via crafted …

Remote | Authorization
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2026-30140 — Tenda W15E Information Disclosure and Privilege Escalation

An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access the /cgi-bin/DownloadCfg/RouterCfm.jpg endpoint to download the configuration fi…

| Information Disclosure
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2025-70032 — SunbirdEd URL Redirection Vulnerability

An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

| Misconfiguration
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
7.3 HIGH
CVE-2026-29023 — Keygraph Shannon Hard-coded Router API Key

Keygraph Shannon contains a hard-coded API key in its router configuration that, when the router component is enabled and exposed, allows network attackers to authenticate using the publicly known st…

Remote | Authentication
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2025-70039 — Linagora Twake OS Command Injection

An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223.

| Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2025-70038 — Linagora Twake Cross-Site Scripting (XSS)

An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Twake v2023.Q1.1223. This allows attackers to execute arbitrary code.

| Cross-Site Scripting
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2025-70034 — MSCDEX SSH2 Regular Expression Complexity Vulnerability

An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in mscdex ssh2 v1.17.0.

| Denial of Service
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
5.4 MEDIUM
CVE-2025-70033 — SunbirdEd Stored Cross-Site Scripting (XSS)

An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

Remote | Cross-Site Scripting
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
0.0 NA
CVE-2025-70037 — Linagora Twake URL Redirection to Untrusted Site Vulnerability

An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v2023.Q1.1223. This allows attackers to obtain sensitive information and execute arbitrary code.

| Misconfiguration
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
8.5 HIGH
CVE-2025-15568 — Command Injection Vulnerability on TP-Link Archer AXE75

A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated attacker with adjacent-network access may be able to perform remote code executi…

| Injection
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
7.5 HIGH
CVE-2026-3588 — Server-Side Request Forgery (SSRF) in ikea dirigera

A server-side request forgery (SSRF) vulnerability in IKEA Dirigera v2.866.4 allows an attacker to exfiltrate private keys by sending a crafted request.

| Server-Side Request Forgery
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
7.8 HIGH
CVE-2026-25866 — MobaXterm < 26.1 Notepad++ Unquoted Service Path

MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExec to execute Notepad++ without a fully qualified executable path when opening r…

| Misconfiguration
Mar 09, 2026 Mar 09, 2026
Mar 09, 2026
Mar 09, 2026
Showing 20 of 5037 Results