Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-24502 — Dell Command | Intel vPro Out of Band Uncontrolled Search Path Element Elevation of Privi…

Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this v…

| Path Traversal
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
5.5 MEDIUM
CVE-2026-1713 — IBM MQ is affected by an authority vulnerablility

IBM MQ 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.30.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.17 LTS, and 9.4.0.0 through 9.4.4.1 CD

Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
7.1 HIGH
CVE-2026-1567 — IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) v…

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information fro…

Remote | XML External Entity
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2025-70240 — D-Link DIR-513 Stack Buffer Overflow

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard51.

| Memory Corruption
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2025-70239 — D-Link DIR-513 Stack Buffer Overflow Vulnerability

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard55.

| Memory Corruption
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2025-70234 — D-Link DIR-513 Stack Buffer Overflow Vulnerability

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetQoS.

| Memory Corruption
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
5.1 MEDIUM
CVE-2025-14480 — IBM Aspera faspio Gateway 1.3.7 has addressed a vulnerability affected by weak cryptograp…

IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

| Cryptography
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
5.9 MEDIUM
CVE-2025-14456 — IBM MQ Appliance uses weaker than expected cryptographic algorithms

IBM MQ Appliance 9.4 CD through 9.4.4.0 to 9.4.4.1

Remote | Misconfiguration
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
8.8 HIGH
CVE-2025-13688 — DataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime …

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user su…

datastage_on_cloud_pak_for_data | Remote | Injection
Mar 03, 2026 Mar 04, 2026
Mar 03, 2026
Mar 04, 2026
8.8 HIGH
CVE-2025-13687 — DataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime …

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user su…

datastage_on_cloud_pak_for_data | Remote | Injection
Mar 03, 2026 Mar 04, 2026
Mar 03, 2026
Mar 04, 2026
8.8 HIGH
CVE-2025-13686 — DataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime …

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user su…

datastage_on_cloud_pak_for_data | Remote | Injection
Mar 03, 2026 Mar 04, 2026
Mar 03, 2026
Mar 04, 2026
5.3 MEDIUM
CVE-2026-3494 — MariaDB Server Audit Plugin Comment Handling Bypass

In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated datab…

Remote | Information Disclosure
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
6.5 MEDIUM
CVE-2026-3484 — PhialsBasement nmap-mcp-server Nmap CLI index.ts child_process.exec command injection

A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function child_process.exec of the file src/index.ts of th…

Remote | Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
5.2 MEDIUM
CVE-2026-2915 — HP System Event Utility – Denial of Service

HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability was remediated with HP System Event Utility version 3.2.16.

| Denial of Service
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
6.5 MEDIUM
CVE-2026-2606 — IBM webMethods API Management fails to validate user input and enables unauthorized arbit…

IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API Management (on-prem) fails to properly validate user-supplied input passed to th…

Remote | Path Traversal
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
6.8 MEDIUM
CVE-2026-29022 — mackron / dr_libs Heap Buffer Overflow via WAV File

dr_libs version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h that allows memory corruption …

| Memory Corruption
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2026-26892 — Sourcecodester Logistic Hub Parcel's Management System SQL Injection

Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php.

| Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
2.7 LOW
CVE-2026-26891 — Sourcecodester Logistic Hub Parcel's Management System SQL Injection Vulnerability

Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_parcel_type.php.

Mar 03, 2026 Mar 04, 2026
Mar 03, 2026
Mar 04, 2026
2.7 LOW
CVE-2026-26889 — Sourcecodester Pharmacy Point of Sale System SQL Injection Vulnerability

Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_category.php.

pharmacy_point_of_sale_system | Remote | Injection
Mar 03, 2026 Mar 04, 2026
Mar 03, 2026
Mar 04, 2026
2.7 LOW
CVE-2026-26888 — Sourcecodester Pharmacy Point of Sale System SQL Injection Vulnerability

Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_stock.php.

pharmacy_point_of_sale_system | Remote | Injection
Mar 03, 2026 Mar 04, 2026
Mar 03, 2026
Mar 04, 2026
Showing 20 of 4962 Results