CVE Feed

    Dashboard / CVE

    5.7
    Medium

    CVE-2026-26004

    Last Modified: 24 Mar 2026

    Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organization Insecure Direct Object Reference (IDOR) vulnerability in Sentry's GroupEventJsonView endpoint. Version 26.1.0 patches the issue.

    Published: 17 Mar 2026
    7.1
    High

    CVE-2026-26001

    Last Modified: 24 Mar 2026

    The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, non sanitized user input can lend to an SQL injection from reports, with adequate rights. This vulnerability is fixed in 1.6.6.

    Published: 17 Mar 2026
    6.5
    Medium

    CVE-2026-25937

    Last Modified: 24 Mar 2026

    GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malicious actor with knowledge of a user's credentials can bypass MFA and steal their account. Version 11.0.6 fixes the issue.

    Published: 17 Mar 2026
    7.5
    High

    CVE-2026-22727

    Last Modified: 24 Mar 2026

    Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on all platforms allows any user who has bypassed the firewall to potentially replace droplets and therefore applications allowing them to access secure application information.

    Published: 17 Mar 2026
    9.8
    Critical

    CVE-2026-21994

    Last Modified: 2 Apr 2026

    Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: Desktop). The supported version that is affected is 0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit. Successful attacks of this vulnerability can result in takeover of Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

    Published: 17 Mar 2026
    7.1
    High

    CVE-2026-1264

    Last Modified: 24 Mar 2026

    IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 allows a remote unauthenticated attacker to view and delete the partners of a community and to delete the communities.

    Published: 17 Mar 2026
    7.5
    High

    CVE-2025-14031

    Last Modified: 24 Mar 2026

    IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 could allow an unauthenticated attacker to send a specially crafted request that causes the application to crash.

    Published: 17 Mar 2026
    5.4
    Medium

    CVE-2026-20643

    Last Modified: 2 Apr 2026

    A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy.

    Published: 17 Mar 2026
    5.3
    Medium

    CVE-2026-3856

    Last Modified: 24 Mar 2026

    IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for verifying the integrity of the data during transmission.

    Published: 17 Mar 2026
    Unknown

    CVE-2026-33187

    Last Modified: 18 Mar 2026

    Further research determined the issue originates from a different product.

    Published: 17 Mar 2026
    Unknown

    CVE-2026-33188

    Last Modified: 18 Mar 2026

    Further research determined the issue originates from a different product.

    Published: 17 Mar 2026
    Unknown

    CVE-2026-33189

    Last Modified: 18 Mar 2026

    Further research determined the issue originates from a different product.

    Published: 17 Mar 2026
    Unknown

    CVE-2026-33181

    Last Modified: 6 Aug 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-33942. Reason: This candidate is a duplicate of CVE-2026-33942. Notes: All CVE users should reference CVE-2026-33942 instead of this candidate.

    Published: 17 Mar 2026
    7.5
    High

    CVE-2026-1376

    Last Modified: 24 Mar 2026

    IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to improper allocation of resources.

    Published: 17 Mar 2026
    6.5
    Medium

    CVE-2026-1267

    Last Modified: 24 Mar 2026

    IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and administrative functionalities due to lack of proper access controls.

    Published: 17 Mar 2026
    5.7
    Medium

    CVE-2025-14806

    Last Modified: 24 Mar 2026

    IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing and serving sensitive, user-specific responses as publicly cacheable resources.

    Published: 17 Mar 2026
    8.7
    High

    CVE-2026-32838

    Last Modified: 14 Aug 2026

    Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. Attackers on the same network can intercept management traffic to capture administrator credentials and sensitive configuration data.

    Published: 17 Mar 2026
    5.1
    Medium

    CVE-2026-32839

    Last Modified: 14 Aug 2026

    Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remote attackers to perform unauthorized administrative actions by inducing logged-in administrators to visit malicious pages. Attackers can exploit the lack of anti-CSRF tokens and request validation to change passwords, upload firmware, reboot the device, perform factory resets, or modify network configurations.

    Published: 17 Mar 2026
    5.1
    Medium

    CVE-2026-32840

    Last Modified: 14 Aug 2026

    Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_name_set.cgi script that allows attackers to inject arbitrary script code by manipulating the sysName parameter. Attackers can send a crafted POST request with malicious script payload that executes when management pages including system_data.js are viewed by administrators.

    Published: 17 Mar 2026
    7.1
    High

    CVE-2026-32842

    Last Modified: 14 Aug 2026

    Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows attackers to obtain administrator credentials by accessing configuration backup files. Attackers can download the config.bin file through fupload.cgi to extract plaintext username and password fields for unauthorized administrative access.

    Published: 17 Mar 2026
    9.2
    Critical

    CVE-2026-32841

    Last Modified: 14 Aug 2026

    Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the management interface. Attackers can exploit the global authentication flag mechanism to gain administrative access without credentials after any user authenticates, enabling unauthorized password changes, firmware uploads, and configuration modifications.

    Published: 17 Mar 2026
    6.3
    Medium

    CVE-2026-4349

    Last Modified: 22 Apr 2026

    A vulnerability was determined in Duende IdentityServer4 up to 4.1.2. The affected element is an unknown function of the file /connect/authorize of the component Token Renewal Endpoint. This manipulation of the argument id_token_hint causes improper authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is described as difficult. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 17 Mar 2026
    7.5
    High

    CVE-2026-4645

    Last Modified: 30 Mar 2026

    Duplicate of CVE-2026-32287

    Published: 17 Mar 2026
    6.7
    Medium

    CVE-2026-2809

    Last Modified: 24 Mar 2026

    Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow a privileged user to trigger an integer overflow within the DLL Injector, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation would require the Endpoint DLP module to be enabled in the client configuration. A successful exploit can potentially result in a denial-of-service for the local machine.

    Published: 17 Mar 2026
    2
    Low

    CVE-2026-4359

    Last Modified: 2 Apr 2026

    A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.

    Published: 17 Mar 2026
    6.5
    Medium

    CVE-2026-25936

    Last Modified: 24 Mar 2026

    GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a SQL injection. Version 11.0.6 fixes the issue.

    Published: 17 Mar 2026
    8.7
    High

    CVE-2026-32981

    Last Modified: 24 Mar 2026

    A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can use traversal sequences (e.g., ../) to access files outside the intended static directory, resulting in local file disclosure.

    Published: 17 Mar 2026
    5.5
    Medium

    CVE-2026-3563

    Last Modified: 24 Mar 2026

    Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting in unintended request routing and denial of service via a conflicting URL path.

    Published: 17 Mar 2026
    8.3
    High

    CVE-2026-4064

    Last Modified: 24 Mar 2026

    Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations — including reading sensitive data, creating or deleting resources, and disrupting service operations — via crafted gRPC requests.

    Published: 17 Mar 2026
    8.5
    High

    CVE-2026-4295

    Last Modified: 24 Mar 2026

    Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote unauthenticated threat actor to execute arbitrary code via maliciously crafted project directory files that bypass workspace trust protections when a local user opens the directory. To remediate this issue, users should upgrade to version 0.8.0 or higher.

    Published: 17 Mar 2026
    6.9
    Medium

    CVE-2026-32836

    Last Modified: 27 Apr 2026

    dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks.

    Published: 17 Mar 2026
    5.1
    Medium

    CVE-2026-32837

    Last Modified: 27 Apr 2026

    miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vulnerability in the WAV BEXT metadata parser that allows attackers to trigger memory access violations by processing crafted WAV files. Attackers can exploit improper null-termination handling in the coding history field to cause out-of-bounds reads past the allocated metadata pool, resulting in application crashes or denial of service.

    Published: 17 Mar 2026
    6.1
    Medium

    CVE-2026-4358

    Last Modified: 2 Apr 2026

    A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is spilled to disk.

    Published: 17 Mar 2026
    6.8
    Medium

    CVE-2025-15584

    Last Modified: 24 Mar 2026

    Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trigger an integer overflow within the filter communication port, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation would require the Endpoint DLP module to be enabled in the client configuration. A successful exploit can potentially result in a denial-of-service for the local machine.

    Published: 17 Mar 2026
    7.8
    High

    CVE-2025-66342

    Last Modified: 24 Mar 2026

    A type confusion vulnerability exists in the EMF functionality of Canva Affinity. A specially crafted EMF file can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution.

    Published: 17 Mar 2026
    6.1
    Medium

    CVE-2025-62500

    Last Modified: 24 Mar 2026

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

    Published: 17 Mar 2026
    6.1
    Medium

    CVE-2025-61979

    Last Modified: 24 Mar 2026

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

    Published: 17 Mar 2026
    6.1
    Medium

    CVE-2025-64733

    Last Modified: 24 Mar 2026

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

    Published: 17 Mar 2026
    6.1
    Medium

    CVE-2025-66000

    Last Modified: 24 Mar 2026

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

    Published: 17 Mar 2026
    7.8
    High

    CVE-2025-64301

    Last Modified: 24 Mar 2026

    An out‑of‑bounds write vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out‑of‑bounds write, potentially leading to code execution.

    Published: 17 Mar 2026
    6.1
    Medium

    CVE-2025-64776

    Last Modified: 24 Mar 2026

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

    Published: 17 Mar 2026
    6.1
    Medium

    CVE-2025-64735

    Last Modified: 24 Mar 2026

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

    Published: 17 Mar 2026
    6.1
    Medium

    CVE-2025-66633

    Last Modified: 24 Mar 2026

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

    Published: 17 Mar 2026
    6.1
    Medium

    CVE-2025-58427

    Last Modified: 24 Mar 2026

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

    Published: 17 Mar 2026
    6.1
    Medium

    CVE-2025-66617

    Last Modified: 24 Mar 2026

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

    Published: 17 Mar 2026
    6.1
    Medium

    CVE-2025-47873

    Last Modified: 24 Mar 2026

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

    Published: 17 Mar 2026
    6.1
    Medium

    CVE-2025-61952

    Last Modified: 24 Mar 2026

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

    Published: 17 Mar 2026
    6.1
    Medium

    CVE-2025-66503

    Last Modified: 24 Mar 2026

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

    Published: 17 Mar 2026
    6.1
    Medium

    CVE-2025-66042

    Last Modified: 24 Mar 2026

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

    Published: 17 Mar 2026
    6.1
    Medium

    CVE-2025-65119

    Last Modified: 24 Mar 2026

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

    Published: 17 Mar 2026