Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2016-20030 — ZKTeco ZKBioSecurity 3.0 User Enumeration via authLoginAction

ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the username parameter. Attac…

Remote | Authentication
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
6.9 MEDIUM
CVE-2016-20029 — ZKTeco ZKBioSecurity 3.0 File Path Manipulation Vulnerability

ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files by modifying file paths used to retrieve local resources. Attackers can manipu…

| Path Traversal
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
5.3 MEDIUM
CVE-2016-20028 — ZKTeco ZKBioSecurity 3.0 Cross-Site Request Forgery Superadmin

ZKTeco ZKBioSecurity 3.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious websites. Atta…

Remote | Cross-Site Request Forgery
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
6.1 MEDIUM
CVE-2016-20027 — ZKTeco ZKBioSecurity 3.0 Multiple Reflected XSS Vulnerabilities

ZKTeco ZKBioSecurity 3.0 contains multiple reflected cross-site scripting vulnerabilities that allow attackers to execute arbitrary HTML and script code by injecting malicious payloads through unsani…

Remote | Cross-Site Scripting
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
9.8 CRITICAL
CVE-2016-20026 — ZKTeco ZKBioSecurity 3.0 Hardcoded Credentials Remote Code Execution

ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. Attackers can authenticate with har…

Remote | Authentication
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
8.8 HIGH
CVE-2016-20025 — ZKTeco ZKAccess Professional 3.5.3 Privilege Escalation via Insecure Permissions

ZKTeco ZKAccess Professional 3.5.3 contains an insecure file permissions vulnerability that allows authenticated users to escalate privileges by modifying executable files. Attackers can leverage the…

Remote | Authorization
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
9.8 CRITICAL
CVE-2016-20024 — ZKTeco ZKTime.Net 3.0.1.6 Insecure File Permissions Privilege Escalation

ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. Attackers can exploit world-writable…

Remote | Misconfiguration
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4180 — D-Link DIR-816 goahead redirect.asp access control

A vulnerability was identified in D-Link DIR-816 1.10CNB05. The impacted element is an unknown function of the file redirect.asp of the component goahead. The manipulation of the argument token_id le…

| Authorization
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4175 — Aureus ERP Chatter Message content-text-entry.blade.php cross site scripting

A vulnerability was determined in Aureus ERP up to 1.3.0-BETA2. The affected element is an unknown function of the file plugins/webkul/chatter/resources/views/filament/infolists/components/messages/c…

| Cross-Site Scripting
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4174 — Radare2 Mach-O File mach0.c walk_exports_trie resource consumption

A vulnerability has been found in Radare2 5.9.9. This issue affects the function walk_exports_trie of the file libr/bin/format/mach0/mach0.c of the component Mach-O File Parser. Such manipulation lea…

Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2025-14287 — Command Injection in mlflow/mlflow

A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/__init__.py` file at lines 161-167. The vulnerability arises from the direct in…

| Injection
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4173 — CodePhiliaX Chat2DB Database Export DMDBManage.java updateProcedure sql injection

A flaw has been found in CodePhiliaX Chat2DB up to 0.3.7. This vulnerability affects the function exportTable/exportTableColumnComment/exportView/exportProcedure/exportTriggers/exportTrigger/updatePr…

| Injection
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4172 — TRENDnet TEW-632BRP HTTP POST Request ping_response.cgi stack-based overflow

A vulnerability was detected in TRENDnet TEW-632BRP 1.010B32. This affects an unknown part of the file /ping_response.cgi of the component HTTP POST Request Handler. The manipulation of the argument …

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4171 — CodeGenieApp serverless-express API Endpoint TodoList.ts authorization

A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is some unknown functionality of the file examples/lambda-function-url/packages/api/…

| Authorization
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4170 — Topsec TopACM HTTP Request nmc_sync.php os command injection

A weakness has been identified in Topsec TopACM 3.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/management/nmc_sync.php of the component HTTP Request Ha…

| Injection
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4169 — Tecnick TCExam XML Export tce_xml_users.php F_xml_export_users cross site scripting

A security flaw has been discovered in Tecnick TCExam up to 16.6.0. Affected is the function F_xml_export_users of the file admin/code/tce_xml_users.php of the component XML Export. Performing a mani…

| Cross-Site Scripting
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4168 — Tecnick TCExam Group tce_edit_group.php cross site scripting

A vulnerability was identified in Tecnick TCExam 16.5.0. This impacts an unknown function of the file /admin/code/tce_edit_group.php of the component Group Handler. Such manipulation of the argument …

| Cross-Site Scripting
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4167 — Belkin F9K1122 formReboot stack-based overflow

A vulnerability was determined in Belkin F9K1122 1.00.33. This affects the function formReboot of the file /goform/formReboot. This manipulation of the argument webpage causes stack-based buffer over…

| Memory Corruption
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4166 — Wavlink WL-NU516U1 login.cgi sub_404F68 cross site scripting

A vulnerability was found in Wavlink WL-NU516U1 240425. The impacted element is the function sub_404F68 of the file /cgi-bin/login.cgi. The manipulation of the argument homepage/hostname results in c…

| Cross-Site Scripting
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
0.0 NA
CVE-2026-4165 — Worksuite HR, CRM and Project Management create cross site scripting

A vulnerability has been found in Worksuite HR, CRM and Project Management up to 5.5.25. The affected element is an unknown function of the file /account/orders/create. The manipulation of the argume…

| Cross-Site Scripting
Mar 15, 2026 Mar 15, 2026
Mar 15, 2026
Mar 15, 2026
Showing 20 of 5280 Results