CVE Feed

    Dashboard / CVE

    8.6
    High

    CVE-2019-25627

    Last Modified: 15 Apr 2026

    FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overflow. Attackers can craft a malicious text file with carefully aligned shellcode and SEH chain pointers, paste the contents into the Stream Name dialog, and execute arbitrary commands like calc.exe when the exception handler is triggered.

    Published: 24 Mar 2026
    8.6
    High

    CVE-2019-25626

    Last Modified: 27 Apr 2026

    River Past Cam Do 3.7.6 contains a local buffer overflow vulnerability in the activation code input field that allows local attackers to execute arbitrary code by supplying a malicious activation code string. Attackers can craft a buffer containing 608 bytes of junk data followed by shellcode and SEH chain overwrite values to trigger code execution when the activation dialog processes the input.

    Published: 24 Mar 2026
    7.3
    High

    CVE-2025-64998

    Last Modified: 12 May 2026

    Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hijack sessions on the central site by forging session cookies.

    Published: 24 Mar 2026
    Unknown

    CVE-2010-20124

    Last Modified: 22 Apr 2026

    This CVE has the been REJECTED and will not be published by the CNA.

    Published: 24 Mar 2026
    Unknown

    CVE-2026-4759

    Last Modified: 1 Apr 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 24 Mar 2026
    5.3
    Medium

    CVE-2026-4649

    Last Modified: 25 Mar 2026

    Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages exchanged via the broker and injection of new message ( CVE-2026-27446 https://www.cve.org/CVERecord ). Since KNIME Business Hub uses Apache Artemis it is also affected by the issue. However, since Apache Artemis is not exposed to the outside it requires at least normal user privileges and the ability to execute workflows in an executor. Such a user can install and register a federated mirror without authentication to the original Apache Artemis instance and thereby read all internal messages and inject new messages. The issue affects all versions of KNIME Business Hub. A fixed version of Apache Artemis is shipped with versions 1.18.0, 1.17.4, and 1.16.3. We recommend updating to a fixed version as soon as possible since no workaround is known.

    Published: 24 Mar 2026
    2.3
    Low

    CVE-2026-32642

    Last Modified: 15 Jun 2026

    Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user which has the "createDurableQueue" permission but does not have the "createAddress" permission and address auto-creation is disabled. In this circumstance, a temporary address will be created whereas the attempt to create the non-durable subscription should instead fail since the user is not authorized to create the corresponding address. When the OpenWire connection is closed the address is removed. This issue affects Apache Artemis: from 2.50.0 through 2.52.0; Apache ActiveMQ Artemis: from 2.0.0 through 2.44.0. Users are recommended to upgrade to version 2.53.0, which fixes the issue.

    Published: 24 Mar 2026
    7.5
    High

    CVE-2026-3509

    Last Modified: 26 Mar 2026

    An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log of the CODESYS Control runtime system, potentially resulting in a denial‑of‑service (DoS) condition.

    Published: 24 Mar 2026
    8.8
    High

    CVE-2025-41660

    Last Modified: 25 Mar 2026

    A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.

    Published: 24 Mar 2026
    7.8
    High

    CVE-2026-4756

    Last Modified: 27 Mar 2026

    Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.

    Published: 24 Mar 2026
    9.8
    Critical

    CVE-2026-4755

    Last Modified: 27 Mar 2026

    CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.

    Published: 24 Mar 2026
    6.1
    Medium

    CVE-2026-4754

    Last Modified: 27 Mar 2026

    CWE-79 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.

    Published: 24 Mar 2026
    7.5
    High

    CVE-2026-33852

    Last Modified: 27 Mar 2026

    Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.

    Published: 24 Mar 2026
    7.5
    High

    CVE-2026-33856

    Last Modified: 27 Mar 2026

    Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.

    Published: 24 Mar 2026
    5.5
    Medium

    CVE-2026-33855

    Last Modified: 27 Mar 2026

    Integer Overflow or Wraparound vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.

    Published: 24 Mar 2026
    8.8
    High

    CVE-2026-33854

    Last Modified: 27 Mar 2026

    Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10.

    Published: 24 Mar 2026
    5.5
    Medium

    CVE-2026-33853

    Last Modified: 27 Mar 2026

    NULL Pointer Dereference vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10.

    Published: 24 Mar 2026
    7.8
    High

    CVE-2026-33847

    Last Modified: 20 Apr 2026

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.This issue affects rapidvms: before PR#96.

    Published: 24 Mar 2026
    8.8
    High

    CVE-2026-33849

    Last Modified: 20 Apr 2026

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.This issue affects rapidvms: before PR#96.

    Published: 24 Mar 2026
    8.8
    High

    CVE-2026-33848

    Last Modified: 20 Apr 2026

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.This issue affects rapidvms: before PR#96.

    Published: 24 Mar 2026
    7.8
    High

    CVE-2026-33851

    Last Modified: 25 Mar 2026

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in joncampbell123 doslib.This issue affects doslib: before doslib-20250729.

    Published: 24 Mar 2026
    7.8
    High

    CVE-2026-33850

    Last Modified: 25 Mar 2026

    Out-of-bounds Write vulnerability in WujekFoliarz DualSenseY-v2.This issue affects DualSenseY-v2: before 54.

    Published: 24 Mar 2026
    9.1
    Critical

    CVE-2026-4753

    Last Modified: 25 Mar 2026

    Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72.

    Published: 24 Mar 2026
    6.4
    Medium

    CVE-2026-4752

    Last Modified: 25 Mar 2026

    Use After Free vulnerability in No-Chicken Echo-Mate.This issue affects Echo-Mate: before V250329.

    Published: 24 Mar 2026
    5.3
    Medium

    CVE-2026-4751

    Last Modified: 25 Mar 2026

    NULL Pointer Dereference vulnerability in tmate-io tmate.This issue affects tmate: before 2.4.0.

    Published: 24 Mar 2026
    9.1
    Critical

    CVE-2026-4750

    Last Modified: 25 Mar 2026

    Out-of-bounds Read vulnerability in fabiangreffrath woof.This issue affects woof: before woof_15.3.0.

    Published: 24 Mar 2026
    6.5
    Medium

    CVE-2026-4749

    Last Modified: 29 Mar 2026

    NVD-CWE-noinfo vulnerability in albfan miraclecast.This issue affects miraclecast: before v1.0.

    Published: 24 Mar 2026
    7.5
    High

    CVE-2026-4662

    Last Modified: 24 Apr 2026

    The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3.8.6.1. This is due to the `filtered_query` parameter being excluded from the HMAC signature validation (allowing attacker-controlled input to bypass security checks) combined with the `prepare_where_clause()` method in the SQL Query Builder not sanitizing the `compare` operator before concatenating it into SQL statements. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database, provided the site has a JetEngine Listing Grid with Load More enabled that uses a SQL Query Builder query.

    Published: 24 Mar 2026
    9.1
    Critical

    CVE-2026-4283

    Last Modified: 24 Apr 2026

    The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accepting a `process_now` parameter from unauthenticated users, which bypasses the intended email-confirmation flow and immediately triggers irreversible account anonymization. This makes it possible for unauthenticated attackers to permanently destroy any non-administrator user account (password randomized, username/email overwritten, roles stripped, comments anonymized, sensitive usermeta wiped) by submitting the victim's email address with `process_now=1`. The nonce required for the request is publicly available on any page containing the `[unsubscribe_form]` shortcode.

    Published: 24 Mar 2026
    6.5
    Medium

    CVE-2026-3138

    Last Modified: 24 Apr 2026

    The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check in all versions up to, and including, 3.1.2. This is due to the plugin's MVC framework dynamically registering unauthenticated AJAX handlers via `wp_ajax_nopriv_` hooks without verifying user capabilities, combined with the base controller's `__call()` magic method forwarding undefined method calls to the model layer, and the `havePermissions()` method defaulting to `true` when no permissions are explicitly defined. This makes it possible for unauthenticated attackers to truncate the plugin's `wp_wpf_filters` database table via a crafted AJAX request with `action=delete`, permanently destroying all filter configurations.

    Published: 24 Mar 2026
    8.7
    High

    CVE-2026-4640

    Last Modified: 15 Apr 2026

    Vitals ESP developed by Galaxy Software Services has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to execute certain functions to obtain sensitive information.

    Published: 24 Mar 2026
    8.7
    High

    CVE-2026-4639

    Last Modified: 15 Apr 2026

    Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticated remote attackers to perform certain administrative functions, thereby escalating privileges.

    Published: 24 Mar 2026
    5.5
    Medium

    CVE-2026-4632

    Last Modified: 24 Apr 2026

    A weakness has been identified in itsourcecode Online Enrollment System 1.0. This vulnerability affects unknown code of the file /sms/user/index.php?view=add of the component Parameter Handler. Executing a manipulation of the argument Name can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

    Published: 24 Mar 2026
    5.9
    Medium

    CVE-2026-3260

    Last Modified: 7 Jul 2026

    The Undertow web server enforces a default maximum HTTP request entity size limit. Any request (including GET or HEAD) containing a body that exceeds this configurable limit is safely dropped by the server, preventing single-request Resource Exhaustion (Out of Memory) Denial of Service attacks.

    Published: 24 Mar 2026
    8.6
    High

    CVE-2026-4627

    Last Modified: 24 Apr 2026

    A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. Affected is the function handler_update_system_time of the file libdeuteron_modules.so of the component NTP Service. The manipulation results in os command injection. The attack may be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 24 Mar 2026
    10
    Critical

    CVE-2026-4746

    Last Modified: 25 Mar 2026

    Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src‎ modules). This vulnerability is associated with program files inflate.C. This issue affects proton: before 1.6.16.

    Published: 24 Mar 2026
    10
    Critical

    CVE-2026-4745

    Last Modified: 25 Mar 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in dendibakh perf-ninja (labs/misc/pgo/lua modules). This vulnerability is associated with program files ldo.C. This issue affects perf-ninja.

    Published: 24 Mar 2026
    9.3
    Critical

    CVE-2026-4744

    Last Modified: 25 Mar 2026

    Out-of-bounds Read vulnerability in rizonesoft Notepad3 (‎scintilla/oniguruma/src modules). This vulnerability is associated with program files regcomp.C‎. This issue affects Notepad3: before 6.25.714.1.

    Published: 24 Mar 2026
    5.2
    Medium

    CVE-2026-4743

    Last Modified: 25 Mar 2026

    NULL Pointer Dereference vulnerability in taurusxin ncmdump (‎src/utils‎ modules). This vulnerability is associated with program files cJSON.Cpp‎. This issue affects ncmdump: before 1.4.0.

    Published: 24 Mar 2026
    2.9
    Low

    CVE-2026-4742

    Last Modified: 25 Mar 2026

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in visualfc liteide (liteidex/src/3rdparty/qjsonrpc/src/http-parser modules). This vulnerability is associated with program files http_parser.C. This issue affects liteide: before x38.4.

    Published: 24 Mar 2026
    8.6
    High

    CVE-2026-4741

    Last Modified: 25 Mar 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TeamJCD JoyConDroid (app/src/main/java/com/rdapps/gamepad/util modules). This vulnerability is associated with program files UnzipUtil.Java‎. This issue affects JoyConDroid: through 1.0.93.

    Published: 24 Mar 2026
    9.4
    Critical

    CVE-2026-4739

    Last Modified: 25 Mar 2026

    Integer Overflow or Wraparound vulnerability in InsightSoftwareConsortium ITK (‎Modules/ThirdParty/Expat/src/expat modules).This issue affects ITK: before 2.7.1.

    Published: 24 Mar 2026
    9.4
    Critical

    CVE-2026-4738

    Last Modified: 25 Mar 2026

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/contrib/infback9 modules). This vulnerability is associated with program files inftree9.C‎. This issue affects gdal: before 3.11.0.

    Published: 24 Mar 2026
    7.3
    High

    CVE-2026-4737

    Last Modified: 25 Mar 2026

    Use After Free vulnerability in No-Chicken Echo-Mate (‎SDK/rv1106-sdk/sysdrv/source/kernel/mm modules). This vulnerability is associated with program files rmap.C‎. This issue affects Echo-Mate: before V250329.

    Published: 24 Mar 2026
    7.3
    High

    CVE-2026-4736

    Last Modified: 25 Mar 2026

    Improper Handling of Values vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/include/net/netfilter modules). This vulnerability is associated with program files nf_tables.H‎, nft_byteorder.C‎, nft_meta.C‎. This issue affects Echo-Mate: before V250329.

    Published: 24 Mar 2026
    8.7
    High

    CVE-2026-4735

    Last Modified: 25 Mar 2026

    Deserialization of Untrusted Data vulnerability in DTStack chunjun (‎chunjun-core/src/main/java/com/dtstack/chunjun/util modules). This vulnerability is associated with program files GsonUtil.Java. This issue affects chunjun: before 1.16.1.

    Published: 24 Mar 2026
    9.4
    Critical

    CVE-2026-4734

    Last Modified: 25 Mar 2026

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in yoyofr modizer (libs/libopenmpt/openmpt-trunk/include/premake/contrib/curl/lib modules). This vulnerability is associated with program files imap.C‎. This issue affects modizer: before v4.3.

    Published: 24 Mar 2026
    5.3
    Medium

    CVE-2026-4733

    Last Modified: 25 Mar 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

    Published: 24 Mar 2026
    8.4
    High

    CVE-2026-4732

    Last Modified: 25 Mar 2026

    Out-of-bounds Read vulnerability in tildearrow furnace (‎extern/libsndfile-modified/src modules). This vulnerability is associated with program files flac.C‎. This issue affects furnace: before 0.7.

    Published: 24 Mar 2026
    2
    Low

    CVE-2026-4626

    Last Modified: 9 Apr 2026

    A vulnerability has been found in projectworlds Lawyer Management System 1.0. This impacts an unknown function of the file /lawyer_booking.php. The manipulation of the argument Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Mar 2026