Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.0 HIGH
CVE-2026-4534 — Tenda FH451 WrlExtraSet formWrlExtraSet stack-based overflow

A flaw has been found in Tenda FH451 1.0.0.9. This affects the function formWrlExtraSet of the file /goform/WrlExtraSet. This manipulation of the argument GO causes stack-based buffer overflow. The a…

fh451_firmware | Remote | Memory Corruption
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
8.8 HIGH
CVE-2026-4314 — The Ultimate WordPress Toolkit – WP Extended <= 3.2.4 - Authenticated (Subscriber+) Privi…

The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.4. This is due to the `isDashboardOrProfileRequ…

wp_extended | Remote | Authorization
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.4 MEDIUM
CVE-2026-3427 — Yoast SEO <= 27.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'jsonT…

The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `jsonText` block attribute in all versions up to, an…

Remote | Cross-Site Scripting
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.5 MEDIUM
CVE-2026-4533 — code-projects Simple Food Ordering System all-tickets.php sql injection

A vulnerability was detected in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file all-tickets.php. The manipulation of the argument Statu…

simple_cafe_ordering_system | Remote | Injection
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
2.0 LOW
CVE-2026-33550 — SOGo OTP Weakness

SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).

sogo | Remote | Authentication
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.7 MEDIUM
CVE-2026-33549 — SPIP Unintended Privilege Assignment Vulnerability

SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.

spip | Remote | Authorization
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.4 MEDIUM
CVE-2025-71276 — SOGo Cross-Site Scripting Vulnerability

SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.

sogo | Remote | Cross-Site Scripting
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
5.5 MEDIUM
CVE-2026-4532 — code-projects Simple Food Ordering System Database Backup food.sql file access

A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /food/sql/food.sql of the com…

simple_cafe_ordering_system | Remote | Path Traversal
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.9 MEDIUM
CVE-2026-4531 — Free5GC AMF handler.go HandleRegistrationComplete denial of service

A weakness has been identified in Free5GC 4.1.0. Affected is the function HandleRegistrationComplete of the file internal/gmm/handler.go of the component AMF. Executing a manipulation can lead to den…

free5gc | Remote | Denial of Service
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.9 MEDIUM
CVE-2019-25589 — ZOC Terminal 7.23.4 Buffer Overflow Denial of Service

ZOC Terminal 7.23.4 contains a buffer overflow vulnerability in the Shell field of Program Settings that allows local attackers to crash the application by supplying an excessively long string. Attac…

| Memory Corruption
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.9 MEDIUM
CVE-2019-25588 — BulletProof FTP Server 2019.0.0.50 Denial of Service via DNS Address

BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. At…

| Denial of Service
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.9 MEDIUM
CVE-2019-25587 — BulletProof FTP Server 2019.0.0.50 Storage-Path Denial of Service

BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the Storage-Path configuration parameter that allows local attackers to crash the application by supplying an excessiv…

| Denial of Service
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.9 MEDIUM
CVE-2019-25586 — Deluge 1.3.15 Denial of Service via URL Field

Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the URL field. Attackers can paste a buffer of…

deluge | Denial of Service
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.9 MEDIUM
CVE-2019-25585 — Deluge 1.3.15 Denial of Service via Webseeds Field

Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Webseeds field. Attackers can paste a buff…

deluge | Denial of Service
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.9 MEDIUM
CVE-2019-25584 — RarmaRadio 2.72.3 Server Field Buffer Overflow Denial of Service

RarmaRadio 2.72.3 contains a buffer overflow vulnerability in the Server field of the Network settings that allows local attackers to crash the application by supplying an excessively long string. At…

| Memory Corruption
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.9 MEDIUM
CVE-2019-25583 — RarmaRadio 2.72.3 Username Field Denial of Service

RarmaRadio 2.72.3 contains a denial of service vulnerability in the Username field that allows local attackers to crash the application by submitting excessively long input. Attackers can paste a buf…

| Denial of Service
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
5.3 MEDIUM
CVE-2026-4530 — apconw Aix-DB terminology_retriever.py sql injection

A security flaw has been discovered in apconw Aix-DB up to 1.2.3. This impacts an unknown function of the file agent/text2sql/rag/terminology_retriever.py. Performing a manipulation of the argument D…

| Injection
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
9.0 HIGH
CVE-2026-4529 — D-Link DHP-1320 SOAP redirect_count_down_page stack-based overflow

A vulnerability was identified in D-Link DHP-1320 1.00WWB04. This affects the function redirect_count_down_page of the component SOAP Handler. Such manipulation leads to stack-based buffer overflow. …

Remote | Memory Corruption
Mar 21, 2026 Mar 21, 2026
Mar 21, 2026
Mar 21, 2026
8.1 HIGH
CVE-2026-3629 — Import and export users and customers <= 1.29.7 - Privilege Escalation to Administrator v…

The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' …

import_and_export_users_and_customers | Remote | Authorization
Mar 21, 2026 Mar 21, 2026
Mar 21, 2026
Mar 21, 2026
7.5 HIGH
CVE-2026-4528 — trueleaf ApiFlow URL Validation http_proxy.service.ts validateUrlSecurity server-side req…

A vulnerability was determined in trueleaf ApiFlow 0.9.7. The impacted element is the function validateUrlSecurity of the file packages/server/src/service/proxy/http_proxy.service.ts of the component…

Remote | Server-Side Request Forgery
Mar 21, 2026 Mar 21, 2026
Mar 21, 2026
Mar 21, 2026
Showing 20 of 5250 Results