Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.3 MEDIUM
CVE-2026-4115 — PuTTY Ed25519 Signature ecc-ssh.c eddsa_verify signature verification

A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the component Ed25519 Signature Handler. The manipulation results in improper verific…

putty | Remote | Authentication
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
7.3 HIGH
CVE-2026-4545 — Flos Freeware Notepad2 PROPSYS.dll uncontrolled search path

A security flaw has been discovered in Flos Freeware Notepad2 4.2.25. This affects an unknown function in the library PROPSYS.dll. Performing a manipulation results in uncontrolled search path. The a…

| Misconfiguration
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
4.8 MEDIUM
CVE-2026-4544 — Wavlink WL-WN578W2 POST Request login.cgi cross site scripting

A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects an unknown function of the file /cgi-bin/login.cgi of the component POST Request Handler. Executing a manipulation of the arg…

wl-wn578w2_firmware | Remote | Cross-Site Scripting
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.5 MEDIUM
CVE-2026-4543 — Wavlink WL-WN578W2 POST Request firewall.cgi command injection

A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is an unknown function of the file /cgi-bin/firewall.cgi of the component POST Request Handler. Performing a manipulation …

wl-wn578w2_firmware | Remote | Injection
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
5.5 MEDIUM
CVE-2026-4542 — SSCMS layerImage Endpoint LayerImageController.Submit.cs path traversal

A vulnerability has been found in SSCMS 4.7.0. The affected element is an unknown function of the file LayerImageController.Submit.cs of the component layerImage Endpoint. Such manipulation of the ar…

sscms | Remote | Path Traversal
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
2.5 LOW
CVE-2026-4541 — janmojzis tinyssh Ed25519 Signature crypto_sign_ed25519_tinyssh.c signature verification

A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the component Ed25519 Signature Handler. This manipulat…

| Cryptography
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
7.5 HIGH
CVE-2026-4540 — projectworlds Online Notes Sharing System Parameters login.php sql injection

A vulnerability was detected in projectworlds Online Notes Sharing System 1.0. This issue affects some unknown processing of the file /login.php of the component Parameters Handler. The manipulation …

Remote | Injection
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
4.8 MEDIUM
CVE-2026-4539 — pygments archetype.py AdlLexer redos

A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular e…

| Denial of Service
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
5.3 MEDIUM
CVE-2026-4538 — PyTorch pt2 Loading deserialization

A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be p…

pytorch | Misconfiguration
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
5.8 MEDIUM
CVE-2026-4537 — Cudy TR1200 ipsec.lua action_ipsec_conn command injection

A vulnerability was determined in Cudy TR1200 R46-2.4.15-20250721-164017. Impacted is the function action_ipsec_conn of the file /usr/bin/lib/lua/luci/controller/ipsec.lua. Executing a manipulation c…

Remote | Injection
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
7.5 HIGH
CVE-2026-4536 — Acrel Environmental Monitoring Cloud Platform unrestricted upload

A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1.1.0. This issue affects some unknown processing. Performing a manipulation results in unrestricted upload. The attack may …

Remote | Misconfiguration
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
9.0 HIGH
CVE-2026-4535 — Tenda FH451 WrlclientSet stack-based overflow

A vulnerability has been found in Tenda FH451 1.0.0.9. This vulnerability affects the function WrlclientSet of the file /goform/WrlclientSet. Such manipulation of the argument GO leads to stack-based…

fh451_firmware | Remote | Memory Corruption
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
9.0 HIGH
CVE-2026-4534 — Tenda FH451 WrlExtraSet formWrlExtraSet stack-based overflow

A flaw has been found in Tenda FH451 1.0.0.9. This affects the function formWrlExtraSet of the file /goform/WrlExtraSet. This manipulation of the argument GO causes stack-based buffer overflow. The a…

fh451_firmware | Remote | Memory Corruption
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
8.8 HIGH
CVE-2026-4314 — The Ultimate WordPress Toolkit – WP Extended <= 3.2.4 - Authenticated (Subscriber+) Privi…

The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.4. This is due to the `isDashboardOrProfileRequ…

wp_extended | Remote | Authorization
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.4 MEDIUM
CVE-2026-3427 — Yoast SEO <= 27.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'jsonT…

The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `jsonText` block attribute in all versions up to, an…

Remote | Cross-Site Scripting
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.5 MEDIUM
CVE-2026-4533 — code-projects Simple Food Ordering System all-tickets.php sql injection

A vulnerability was detected in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file all-tickets.php. The manipulation of the argument Statu…

simple_cafe_ordering_system | Remote | Injection
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
2.0 LOW
CVE-2026-33550 — SOGo OTP Weakness

SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).

sogo | Remote | Authentication
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.7 MEDIUM
CVE-2026-33549 — SPIP Unintended Privilege Assignment Vulnerability

SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure because of STATUT mishandling.

spip | Remote | Authorization
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.4 MEDIUM
CVE-2025-71276 — SOGo Cross-Site Scripting Vulnerability

SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.

sogo | Remote | Cross-Site Scripting
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
5.5 MEDIUM
CVE-2026-4532 — code-projects Simple Food Ordering System Database Backup food.sql file access

A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /food/sql/food.sql of the com…

simple_cafe_ordering_system | Remote | Path Traversal
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
Showing 20 of 5183 Results