CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2026-3022

    Last Modified: 30 Mar 2026

    Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/hospitalization/generate-hospitalization-summary'. This vulnerability could allow an authenticated user to alter a POST request to the affected endpoint for the purpose of injecting special NoSQL commands, resulting in the attacker being able to obtain customer reports.

    Published: 16 Mar 2026
    7.1
    High

    CVE-2026-3021

    Last Modified: 30 Mar 2026

    Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/centro/equipo/empleado'. This vulnerability could allow an authenticated user to alter a GET request to the affected endpoint for the purpose of injecting special NoSQL commands. This would lead to the enumeration of sensitive employee data.

    Published: 16 Mar 2026
    8.6
    High

    CVE-2026-3020

    Last Modified: 30 Mar 2026

    Identity based authorization bypass vulnerability (IDOR) that allows an attacker to modify the data of a legitimate user account, such as changing the victim's email address, validating the new email address, and requesting a new password. This could allow them to take complete control of other users' legitimate accounts

    Published: 16 Mar 2026
    2.1
    Low

    CVE-2026-4233

    Last Modified: 22 Apr 2026

    A vulnerability was identified in ThingsGateway 12. This affects an unknown part of the file /api/file/download. The manipulation of the argument fileName leads to path traversal. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    6.9
    Medium

    CVE-2026-3111

    Last Modified: 30 Mar 2026

    Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/archivos/usuarios/[ID]/[username]/thumb_AAxAA.jpg' (translated as 80x90 and 40x45). Successful exploitation of this vulnerability could allow an unauthenticated attacker to access the profile photos of all users via a manipulated URL, enabling them to collect user photos en masse. This could lead to these photos being used maliciously to impersonate identities, perform social engineering, link identities across platforms using facial recognition, or even carry out doxxing.

    Published: 16 Mar 2026
    8.7
    High

    CVE-2026-3110

    Last Modified: 30 Mar 2026

    Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/administracion/admin_usuarios.cgi?filtro_estado=T&wAccion=listado_xlsx&wBuscar=&wFiltrar=&wOrden=alta_usuario&wid_cursoActual=[ID]' where the data of users enrolled in the course is exported. Successful exploitation of this vulnerability could allow an unauthenticated attacker to access user data (e.g., usernames, first and last names, email addresses, and phone numbers) and retrieve the data of all users enrolled in courses by performing a brute-force attack on the course ID via a manipulated URL.

    Published: 16 Mar 2026
    5.5
    Medium

    CVE-2026-4232

    Last Modified: 22 Apr 2026

    A vulnerability was determined in Tiandy Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the file /rest/user/getAuthorityByUserId. Executing a manipulation of the argument userId can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    8.7
    High

    CVE-2025-11500

    Last Modified: 30 Mar 2026

    Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms - one solely for interface management and one for protecting all other server resources. When the latter is turned off (which is a default setting), an unauthenticated attacker on the local network can obtain usernames and encoded passwords for interface management portal by inspecting the HTTP response of the server when visiting the login page, which contains a JSON file with these details. Both normal and admin users credentials are exposed.  This issue has been fixed in firmware versions: 1.36 (for tcPDU), 1.67 (for LK3.5 - hardware versions: 3.5, 3.6, 3.7 and 3.8), 1.75 (for LK3.9 - hardware version 3.9) and 1.38 (for LK4 - hardware version 4.0).

    Published: 16 Mar 2026
    8.6
    High

    CVE-2025-15587

    Last Modified: 30 Mar 2026

    Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 allow a low privileged user to read an administrator's password by directly accessing a specific resource inaccessible via a graphical interface. This issue has been fixed in firmware versions: 1.36 (for tcPDU), 1.67 (for LK3.5 - hardware versions: 3.5, 3.6, 3.7 and 3.8), 1.75 (for LK3.9 - hardware version 3.9) and 1.38 (for LK4 - hardware version 4.0).

    Published: 16 Mar 2026
    5.5
    Medium

    CVE-2026-4231

    Last Modified: 22 Apr 2026

    A vulnerability was found in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function update_sql/run_sql of the file src/vanna/legacy/flask/__init__.py of the component Endpoint. Performing a manipulation results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    2.1
    Low

    CVE-2026-4230

    Last Modified: 22 Apr 2026

    A vulnerability has been found in vanna-ai vanna up to 2.0.2. Affected is the function update_sql of the file src/vanna/legacy/flask/__init__.py of the component Endpoint. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    5.5
    Medium

    CVE-2026-4229

    Last Modified: 22 Apr 2026

    A flaw has been found in vanna-ai vanna up to 2.0.2. This impacts the function remove_training_data of the file src/vanna/legacy/google/bigquery_vector.py. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    2.1
    Low

    CVE-2026-4228

    Last Modified: 24 Mar 2026

    A vulnerability was detected in LB-LINK BL-WR9000 2.4.9. This affects the function sub_458754 of the file /goform/set_wifi. The manipulation results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    7.4
    High

    CVE-2026-4227

    Last Modified: 24 Mar 2026

    A security vulnerability has been detected in LB-LINK BL-WR9000 2.4.9. The impacted element is the function sub_44D844 of the file /goform/get_hidessid_cfg. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    7.4
    High

    CVE-2026-4226

    Last Modified: 24 Mar 2026

    A weakness has been identified in LB-LINK BL-WR9000 2.4.9. The affected element is the function sub_44E8D0 of the file /goform/get_virtual_cfg. Executing a manipulation can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    1.9
    Low

    CVE-2026-4225

    Last Modified: 22 Apr 2026

    A security flaw has been discovered in CMS Made Simple up to 2.2.21. Impacted is an unknown function of the file admin/listusers.php of the component User Management Module. Performing a manipulation of the argument Message results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

    Published: 16 Mar 2026
    8.4
    High

    CVE-2026-4255

    Last Modified: 8 Jun 2026

    A DLL search order hijacking vulnerability in Thermalright TR-VISION HOME on Windows (64-bit) allows a local attacker to escalate privileges via DLL side-loading. The application loads certain dynamic-link library (DLL) dependencies using the default Windows search order, which includes directories that may be writable by non-privileged users.\n\n\n\nBecause these directories can be modified by unprivileged users, an attacker can place a malicious DLL with the same name as a legitimate dependency in a directory that is searched before trusted system locations. When the application is executed, which is always with administrative privileges, the malicious DLL is loaded instead of the legitimate library.\n\n\n\nThe application does not enforce restrictions on DLL loading locations and does not verify the integrity or digital signature of loaded libraries. As a result, attacker-controlled code may be executed within the security context of the application, allowing arbitrary code execution with elevated privileges.\n\n\n\nSuccessful exploitation requires that an attacker place a crafted malicious DLL in a user-writable directory that is included in the application's DLL search path and then cause the affected application to be executed. Once loaded, the malicious DLL runs with the same privileges as the application.\n\n\n\nThis issue affects \nTR-VISION HOME  versions up to and including 2.0.5.

    Published: 16 Mar 2026
    5
    Medium

    CVE-2025-6969

    Last Modified: 24 Mar 2026

    in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input.

    Published: 16 Mar 2026
    3.3
    Low

    CVE-2025-26474

    Last Modified: 24 Mar 2026

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. This vulnerability can be exploited only in restricted scenarios.

    Published: 16 Mar 2026
    5.5
    Medium

    CVE-2025-52458

    Last Modified: 24 Mar 2026

    in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

    Published: 16 Mar 2026
    5.5
    Medium

    CVE-2025-41432

    Last Modified: 24 Mar 2026

    in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

    Published: 16 Mar 2026
    6.3
    Medium

    CVE-2025-25277

    Last Modified: 24 Mar 2026

    in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through using incompatible type. This vulnerability can be exploited only in restricted scenarios.

    Published: 16 Mar 2026
    6.5
    Medium

    CVE-2025-12736

    Last Modified: 24 Mar 2026

    in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uninitialized resource.

    Published: 16 Mar 2026
    3.3
    Low

    CVE-2026-0639

    Last Modified: 24 Mar 2026

    in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory.

    Published: 16 Mar 2026
    2.9
    Low

    CVE-2026-32778

    Last Modified: 24 Mar 2026

    libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.

    Published: 16 Mar 2026
    5.5
    Medium

    CVE-2026-4223

    Last Modified: 24 Mar 2026

    A vulnerability was identified in itsourcecode Payroll Management System 1.0. This issue affects some unknown processing of the file /manage_employee.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

    Published: 16 Mar 2026
    4
    Medium

    CVE-2026-32777

    Last Modified: 24 Mar 2026

    libexpat before 2.7.5 allows an infinite loop while parsing DTD content.

    Published: 16 Mar 2026
    4
    Medium

    CVE-2026-32776

    Last Modified: 24 Mar 2026

    libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.

    Published: 16 Mar 2026
    8.7
    High

    CVE-2026-25083

    Last Modified: 24 Mar 2026

    GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logged-in user who knows a shared AI assistant's identifier may view and/or tamper the other user's threads/messages.

    Published: 16 Mar 2026
    2
    Low

    CVE-2026-4222

    Last Modified: 22 Apr 2026

    A vulnerability was determined in SSCMS up to 7.4.0. This vulnerability affects the function PathUtils.RemoveParentPath of the file /api/admin/plugins/install/actions/download. This manipulation of the argument path causes path traversal. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    5.5
    Medium

    CVE-2026-4221

    Last Modified: 22 Apr 2026

    A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This affects an unknown part of the file /rest/file/uploadLedImage of the component Endpoint. The manipulation of the argument File results in unrestricted upload. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    7.4
    High

    CVE-2026-32775

    Last Modified: 21 Apr 2026

    libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.

    Published: 16 Mar 2026
    3.7
    Low

    CVE-2025-71264

    Last Modified: 2 Apr 2026

    Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client crash).

    Published: 16 Mar 2026
    5.5
    Medium

    CVE-2026-4220

    Last Modified: 22 Apr 2026

    A vulnerability has been found in Technologies Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the file /SetWebpagePic.jsp. The manipulation of the argument targetPath/Suffix leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    1.9
    Low

    CVE-2026-4219

    Last Modified: 22 Apr 2026

    A flaw has been found in INDEX Conferences & Exhibitions Organization YWF BPOF APGCS App up to 1.0.2 on Android. Affected by this vulnerability is an unknown functionality of the file com/index/event/BuildConfig.java of the component ae.index.apgcs. Executing a manipulation of the argument ACCESS_KEY/HASH_KEY can lead to hard-coded credentials. The attack is restricted to local execution. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    1.1
    Low

    CVE-2026-4218

    Last Modified: 22 Apr 2026

    A vulnerability was detected in myAEDES App up to 1.18.4 on Android. Affected is an unknown function of the file aedes/me/beta/utils/EngageBayUtils.java of the component aedes.me.beta. Performing a manipulation of the argument AUTH_KEY results in information disclosure. The attack is only possible with local access. The attack's complexity is rated as high. The exploitability is told to be difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    8.6
    High

    CVE-2026-31386

    Last Modified: 18 Jun 2026

    OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by an attacker with the administrative privilege.

    Published: 16 Mar 2026
    1.1
    Low

    CVE-2026-4217

    Last Modified: 22 Apr 2026

    A security vulnerability has been detected in XREAL Nebula App up to 3.2.1 on Android. This impacts an unknown function of the file in ai/nreal/nebula/flutterPlugin/CloudStoragePlugin.java of the component ai.nreal.nebula.universal. Such manipulation of the argument accessKey/secretAccessKey/securityToken leads to unprotected storage of credentials. The attack can only be performed from a local environment. The attack requires a high level of complexity. The exploitability is said to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    1.9
    Low

    CVE-2026-4216

    Last Modified: 22 Apr 2026

    A weakness has been identified in i-SENS SmartLog App up to 2.6.8 on Android. This affects an unknown function of the component air.SmartLog.android. This manipulation causes hard-coded credentials. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor explains: "The function referenced in the report currently exists in our deployed system. It is related to a developer mode used during the configuration process for Bluetooth pairing between the blood glucose meter and the SmartLog application. This function is intended for configuration purposes related to device integration and testing. (...) [I]n a future application update, we plan to review measures to either remove the developer mode function or restrict access to it."

    Published: 16 Mar 2026
    7.1
    High

    CVE-2026-21005

    Last Modified: 2 Apr 2026

    Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.

    Published: 16 Mar 2026
    6.9
    Medium

    CVE-2026-21004

    Last Modified: 2 Apr 2026

    Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.

    Published: 16 Mar 2026
    2.1
    Low

    CVE-2026-4215

    Last Modified: 22 Apr 2026

    A security flaw has been discovered in FlowCI flow-core-x up to 1.23.01. The impacted element is the function Save of the file core/src/main/java/com/flowci/core/config/service/ConfigServiceImpl.java of the component SMTP Host Handler. The manipulation results in server-side request forgery. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    5.9
    Medium

    CVE-2026-21002

    Last Modified: 9 Apr 2026

    Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.

    Published: 16 Mar 2026
    7.4
    High

    CVE-2026-4214

    Last Modified: 24 Mar 2026

    A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This issue affects the function UPnP_AV_Server_Path_Setting of the file /cgi-bin/app_mgr.cgi. Executing a manipulation can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used.

    Published: 16 Mar 2026
    5.9
    Medium

    CVE-2026-21001

    Last Modified: 9 Apr 2026

    Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.

    Published: 16 Mar 2026
    7
    High

    CVE-2026-21000

    Last Modified: 9 Apr 2026

    Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.

    Published: 16 Mar 2026
    7.1
    High

    CVE-2026-20999

    Last Modified: 2 Apr 2026

    Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.

    Published: 16 Mar 2026
    7.1
    High

    CVE-2026-20998

    Last Modified: 2 Apr 2026

    Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.

    Published: 16 Mar 2026
    5.3
    Medium

    CVE-2026-20997

    Last Modified: 2 Apr 2026

    Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication.

    Published: 16 Mar 2026
    7.1
    High

    CVE-2026-20996

    Last Modified: 31 Mar 2026

    Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication.

    Published: 16 Mar 2026