Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-21866 — Dify - Stored XSS in chat

Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rendering Mermaid diagrams within chats. This occurs because Dify’s default Mermaid…

dify | Remote | Cross-Site Scripting
Mar 03, 2026 Mar 05, 2026
Mar 03, 2026
Mar 05, 2026
8.8 HIGH
CVE-2026-1775 — Missing Authentication for Critical Function in Labkotec LID-3300IP

The Labkotec LID-3300IP has an existing vulnerability in the ice detector software that enables an unauthenticated attacker to alter device parameters and run operational commands when specially craf…

Remote | Authentication
Mar 03, 2026 Mar 04, 2026
Mar 03, 2026
Mar 04, 2026
Showing 20 of 6382 Results