Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.3 HIGH
CVE-2026-41082 — "OCaml opam Path Traversal Vulnerability"

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

| Path Traversal
Apr 16, 2026 Apr 21, 2026
Apr 16, 2026
Apr 21, 2026
8.8 HIGH
CVE-2026-33083 — DataEase has SQL Injection in Order By Clause

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the orderDirection parameter used in dataset-related endpoint…

dataease | Remote | Injection
Apr 16, 2026 Apr 20, 2026
Apr 16, 2026
Apr 20, 2026
9.8 CRITICAL
CVE-2026-33082 — DataEase: SQL Injection in v2 Dataset Export

DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerability in the dataset export functionality. The expressionTree parameter in POST…

dataease | Remote | Injection
Apr 16, 2026 Apr 20, 2026
Apr 16, 2026
Apr 20, 2026
8.7 HIGH
CVE-2026-2336 — Weak webstax_auth Cookie Authentication Allows Privilege Escalation

A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a…

Remote | Authentication
Apr 16, 2026 Apr 17, 2026
Apr 16, 2026
Apr 17, 2026
1.7 LOW
CVE-2026-27820 — zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corrupti…

zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The z…

zlib | Remote | Memory Corruption
Apr 16, 2026 Apr 17, 2026
Apr 16, 2026
Apr 17, 2026
5.3 MEDIUM
CVE-2026-24749 — Silverstripe Assets Module has a DBFile::getURL() permission bypass

The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile…

assets | Remote | Authorization
Apr 16, 2026 Apr 28, 2026
Apr 16, 2026
Apr 28, 2026
4.1 MEDIUM
CVE-2025-43883 — Dell PowerScale OneFS Denial of Service Vulnerability

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability. A high privileged attacker with local access could potentially explo…

powerscale_onefs | Denial of Service
Apr 16, 2026 Apr 21, 2026
Apr 16, 2026
Apr 21, 2026
7.5 HIGH
CVE-2026-41080 — Oracle libexpat Hash Flooding Vulnerability

libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

libexpat | Remote | Denial of Service
Apr 16, 2026 Apr 27, 2026
Apr 16, 2026
Apr 27, 2026
5.1 MEDIUM
CVE-2025-36579 — Dell Client Platform BIOS Authentication Bypass

Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leadi…

| Authentication
Apr 16, 2026 Apr 17, 2026
Apr 16, 2026
Apr 17, 2026
7.5 HIGH
CVE-2026-5426 — KnowledgeDeliver deployments before February 24, 2026 use a static ASP.NET/IIS machineKey…

Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remot…

Remote | Misconfiguration
Apr 16, 2026 Apr 18, 2026
Apr 16, 2026
Apr 18, 2026
6.5 MEDIUM
CVE-2026-37100 — Yamaha SR-B30A BLE Authentication Bypass Vulnerability

An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: Sound Bar Remote / version: 2.40) allows remote attackers within BLE radio rang…

| Authentication
Apr 16, 2026 Apr 18, 2026
Apr 16, 2026
Apr 18, 2026
Showing 20 of 6251 Results