Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2025-13616 — DataStage on Cloud Pak for Data is vulnerable to sensitive information leak due to HTTP r…

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used in further attacks against the system.

Remote | Information Disclosure
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
5.9 MEDIUM
CVE-2025-13490 — IBM App Connect Enterprise Certified Container IntegrationServer and IntegrationRuntime o…

IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enterprise Certified Containers Operands versions CD 12…

Remote | Cryptography
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2024-55027 — Weintek cMT-3072XH2 EasyWeb Plaintext Credentials Storage Vulnerability

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.

| Information Disclosure
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2024-55026 — Weintek cMT-3072XH2 easyweb Command Injection

An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request.

| Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
6.5 MEDIUM
CVE-2024-55025 — Weintek cMT-3072XH2 easyweb VNC Access Control Vulnerability

Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access the HMI system.

Remote | Authorization
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
8.8 HIGH
CVE-2024-55024 — Weintek cMT-3072XH2 easyweb Authentication Bypass Vulnerability

An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to perform Administrative actions using servic…

Remote | Authentication
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
5.3 MEDIUM
CVE-2024-55023 — Weintek cMT-3072XH2 EasyWeb Hardcoded Encryption Key Vulnerability

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access sensitive information.

Remote | Cryptography
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2024-55022 — Weintek cMT-3072XH2 Easyweb OS Command Injection

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name parameter.

| Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2024-55021 — Weintek cMT-3072XH2 EasyWeb FTP Hardcoded Password Vulnerability

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.

| Misconfiguration
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2024-55020 — Weintek cMT-3072XH2 easyweb Command Injection Vulnerability

A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands with root privileges.

Remote | Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
6.5 MEDIUM
CVE-2024-55019 — Weintek cMT-3072XH2 easyweb Web File Download Arbitrary File Access Control Bypass

Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated attack to download arbitrary files.

Remote | Authorization
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
9.3 CRITICAL
CVE-2026-3437 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Portwell Engin…

An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to…

| Memory Corruption
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
2.7 LOW
CVE-2026-26890 — Sourcecodester Pharmacy Point of Sale System SQL Injection Vulnerability

Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_product.php.

Remote | Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
6.1 MEDIUM
CVE-2026-0540 — DOMPurify XSS via Missing Rawtext Elements in SAFE_FOR_XML

DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 729097f, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five …

Remote | Cross-Site Scripting
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
7.5 HIGH
CVE-2025-69765 — Tenda AX3 Stack Overflow Vulnerability

Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can cause memory corruption and enable remote code execution.

Remote | Memory Corruption
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
7.2 HIGH
CVE-2025-67840 — Cohesity TranZman OS Command Injection Vulnerability

Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Build 14614 through TZM_1757588060_SEP2025_FULL.depot web application API endpoints…

Remote | Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
0.0 NA
CVE-2025-63912 — Cohesity TranZman Migration Appliance Weak Cryptography Vulnerability

Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to use a weak cryptography algorithm for data encryption, allowing attackers to trivially reverse the encyption and expose…

| Cryptography
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
7.2 HIGH
CVE-2025-63911 — Cohesity TranZman Migration Appliance Command Injection Vulnerability

Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injection vulnerability.

Remote | Injection
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
7.2 HIGH
CVE-2025-63910 — Cohesity TranZman Migration Appliance File Upload Code Execution Vulnerability

An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers with Administrator privileges to execute arbitrary code via uplo…

Remote | Authentication
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
7.2 HIGH
CVE-2025-63909 — Cohesity TranZman Migration Appliance Privilege Escalation (Arbitrary File Access)

Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers to escalate privileges to root and read and writ…

Remote | Authorization
Mar 03, 2026 Mar 03, 2026
Mar 03, 2026
Mar 03, 2026
Showing 20 of 4958 Results