CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2026-30930

    Last Modified: 16 Apr 2026

    Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string concatenation with unsanitized system monitoring data. The normalize() method wraps string values in single quotes but does not escape embedded single quotes, making SQL injection trivial via attacker-controlled data such as process names, filesystem mount points, network interface names, or container names. This vulnerability is fixed in 4.5.1.

    Published: 10 Mar 2026
    8.7
    High

    CVE-2026-30928

    Last Modified: 21 Apr 2026

    Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glances configuration file (glances.conf) via self.config.as_dict() with no filtering of sensitive values. The configuration file contains credentials for all configured backend services including database passwords, API tokens, JWT signing keys, and SSL key passwords. This vulnerability is fixed in 4.5.1.

    Published: 10 Mar 2026
    8.9
    High

    CVE-2026-30934

    Last Modified: 16 Apr 2026

    FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., title, description) that are rendered into HTML for /public/share/<hash> without context-aware escaping. The server uses text/template instead of html/template, allowing injected scripts to execute when victims visit the share URL. This vulnerability is fixed in 1.3.1-beta and 1.2.2-stable.

    Published: 10 Mar 2026
    7.5
    High

    CVE-2026-30933

    Last Modified: 16 Apr 2026

    FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/share/info. This vulnerability is fixed in 1.3.1-beta and 1.2.2-stable.

    Published: 10 Mar 2026
    5.3
    Medium

    CVE-2026-27661

    Last Modified: 16 Apr 2026

    A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application leaks confidential information in metadata, and files such as information on contributors and email address, on `SSM Server`.

    Published: 10 Mar 2026
    5.9
    Medium

    CVE-2026-25605

    Last Modified: 17 Apr 2026

    A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application performs file deletion without properly validating the file path or target. An attacker could delete files or sockets that the affected process has permission to remove, potentially resulting in denial of service or service disruption.

    Published: 10 Mar 2026
    8.6
    High

    CVE-2026-25573

    Last Modified: 16 Apr 2026

    A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application builds shell commands with caller-provided strings and executes them. An attacker could influence the executed command, potentially resulting in command injection and full system compromise.

    Published: 10 Mar 2026
    5.9
    Medium

    CVE-2026-25572

    Last Modified: 17 Apr 2026

    A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK server component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially causing denial of service.

    Published: 10 Mar 2026
    5.9
    Medium

    CVE-2026-25571

    Last Modified: 17 Apr 2026

    A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK client component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially causing denial of service.

    Published: 10 Mar 2026
    7.5
    High

    CVE-2026-25570

    Last Modified: 16 Apr 2026

    A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK does not perform checks on input values potentially resulting in stack overflow. This could allow an attacker to perform code execution and denial of service.

    Published: 10 Mar 2026
    7.5
    High

    CVE-2026-25569

    Last Modified: 16 Apr 2026

    A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). An out-of-bounds write vulnerability exists in SICAM SIAPP SDK. This could allow an attacker to write data beyond the intended buffer, potentially leading to denial of service, or arbitrary code execution.

    Published: 10 Mar 2026
    9.4
    Critical

    CVE-2025-40943

    Last Modified: 19 Mar 2026

    Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code through social engineering an authorized user, who has the function right "Read diagnostics", to import a specially crafted trace file. The malicious trace file is insufficiently sanitized and malicious code could be executed in the clients browser session and trigger PLC operations via the webserver that the legitimate user is authorized to perform.

    Published: 10 Mar 2026
    2.4
    Low

    CVE-2025-27769

    Last Modified: 11 Mar 2026

    A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC 40 kW EV Charging Station (All versions < L4.10.1). Affected devices contain improper access control that could allow an attacker to reach unauthorized services via the charging cable.

    Published: 10 Mar 2026
    8.8
    High

    CVE-2026-3847

    Last Modified: 15 Apr 2026

    Memory safety bugs present in Firefox 148.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148.0.2.

    Published: 10 Mar 2026
    6.5
    Medium

    CVE-2026-3846

    Last Modified: 15 Apr 2026

    Same-origin policy bypass in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 148.0.2.

    Published: 10 Mar 2026
    8.8
    High

    CVE-2026-3845

    Last Modified: 15 Apr 2026

    Heap buffer overflow in the Audio/Video: Playback component in Firefox for Android. This vulnerability was fixed in Firefox 148.0.2.

    Published: 10 Mar 2026
    4.6
    Medium

    CVE-2026-3862

    Last Modified: 7 May 2026

    Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unaltered in the resulting web page.

    Published: 10 Mar 2026
    Unknown

    CVE-2026-3883

    Last Modified: 13 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 10 Mar 2026
    7.8
    High

    CVE-2026-3483

    Last Modified: 17 Apr 2026

    An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges.

    Published: 10 Mar 2026
    Unknown

    CVE-2026-3882

    Last Modified: 1 Apr 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 10 Mar 2026
    7.5
    High

    CVE-2026-2339

    Last Modified: 6 Jun 2026

    Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Remote Code Inclusion, Privilege Abuse, Command Injection. This issue affects Liderahenk: before 3.5.1.

    Published: 10 Mar 2026
    8.5
    High

    CVE-2025-11739

    Last Modified: 11 Mar 2026

    CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.

    Published: 10 Mar 2026
    7.5
    High

    CVE-2025-13957

    Last Modified: 11 Mar 2026

    CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code execution when SOCKS Proxy is enabled, and administrator credentials and PostgreSQL database credentials are known. SOCKS Proxy is disabled by default.

    Published: 10 Mar 2026
    5.3
    Medium

    CVE-2026-2742

    Last Modified: 7 May 2026

    An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24.9.7 and 25.0.0 through 25.0.1, applications using Spring Security due to inconsistent path pattern matching of reserved framework paths. Accessing the /VAADIN endpoint without a trailing slash bypasses security filters, and allowing unauthenticated users to trigger framework initialization and create sessions without proper authorization. Users of affected versions using Spring Security should upgrade as follows: 14.0.0-14.14.0 upgrade to 14.14.1, 23.0.0-23.6.6 to 23.6.7, 24.0.0 - 24.9.7 to 24.9.8, and 25.0.0-25.0.1 upgrade to 25.0.2 or newer. Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 14, 23, 24, 25 version.

    Published: 10 Mar 2026
    2.3
    Low

    CVE-2026-2741

    Last Modified: 7 May 2026

    Specially crafted ZIP archives can escape the intended extraction directory during Node.js download and extraction in Vaadin 14.2.0 through 14.14.0, 15.0.0 through 23.6.6, 24.0.0 through 24.9.8, and 25.0.0 through 25.0.2. Vaadin’s build process can automatically download and extract Node.js if it is not installed locally. If an attacker can intercept or control this download via DNS hijacking, a MITM attack, a compromised mirror, or a supply chain attack, they can serve a malicious archive containing path traversal sequences that write files outside the intended extraction directory. Users of affected versions should use a globally preinstalled Node.js version compatible with their Vaadin version, or upgrade as follows: 14.2.0-14.14.0 to 14.14.1, 15.0.0-23.6.6 to 23.6.7, 24.0.0-24.9.8 to 24.9.9, and 25.0.0-25.0.2 to 25.0.3 or newer. Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 14, 23, 24, 25 version.

    Published: 10 Mar 2026
    9.3
    Critical

    CVE-2026-3843

    Last Modified: 10 Aug 2026

    Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data (e.g., action=do&sql=<query_here>&reload_driver=0) to execute arbitrary SQL commands and potentially achieve remote code execution.

    Published: 10 Mar 2026
    6.1
    Medium

    CVE-2026-22614

    Last Modified: 21 May 2026

    The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an attacker with access to this file and the local host machine could potentially read the sensitive information stored and tamper with the project file. This security issue has been fixed in the latest version of Eaton EasySoft which is available on the Eaton download centre.

    Published: 10 Mar 2026
    3.3
    Low

    CVE-2026-21791

    Last Modified: 7 May 2026

    HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URL

    Published: 10 Mar 2026
    6.4
    Medium

    CVE-2026-3228

    Last Modified: 22 Apr 2026

    The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[nxs_fbembed]` shortcode in all versions up to, and including, 4.4.6. This is due to insufficient input sanitization and output escaping on the `snapFB` post meta value. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 10 Mar 2026
    7.2
    High

    CVE-2026-2724

    Last Modified: 22 Apr 2026

    The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entry fields in all versions up to, and including, 2.0.5. This is due to insufficient input sanitization and output escaping on form submission data displayed in the admin Form Entries Trash view. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator views the trashed form entries.

    Published: 10 Mar 2026
    5.3
    Medium

    CVE-2026-23907

    Last Modified: 16 Apr 2026

    This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that is obtained from PDComplexFileSpecification.getFilename() is appended to the extraction path. Users who have copied this example into their production code should review it to ensure that the extraction path is acceptable. The example has been changed accordingly, now the initial path and the extraction paths are converted into canonical paths and it is verified that extraction path contains the initial path. The documentation has also been adjusted.

    Published: 10 Mar 2026
    5.8
    Medium

    CVE-2026-3315

    Last Modified: 7 May 2026

    Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical Resource vulnerability in ASSA ABLOY Visionline on Windows allows Configuration/Environment Manipulation.This issue affects Visionline: from 1.0 before 1.33.

    Published: 10 Mar 2026
    7.2
    High

    CVE-2026-1261

    Last Modified: 22 Apr 2026

    The MetForm Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Quiz feature in all versions up to, and including, 3.9.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 10 Mar 2026
    6.5
    Medium

    CVE-2025-41712

    Last Modified: 11 Mar 2026

    An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive information on the device. This is a result of incorrect permission assignment for the web server.

    Published: 10 Mar 2026
    5.3
    Medium

    CVE-2025-41711

    Last Modified: 11 Mar 2026

    An unauthenticated remote attacker can use firmware images to extract password hashes and brute force plaintext passwords of accounts with limited access.

    Published: 10 Mar 2026
    6.5
    Medium

    CVE-2025-41710

    Last Modified: 11 Mar 2026

    An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server with limited read and write privileges.

    Published: 10 Mar 2026
    9.8
    Critical

    CVE-2025-41709

    Last Modified: 18 Mar 2026

    An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device.

    Published: 10 Mar 2026
    7.3
    High

    CVE-2026-2364

    Last Modified: 17 Apr 2026

    If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Development System, a low privileged local attacker can gain elevated rights due to a TOCTOU vulnerability in the CODESYS installer.

    Published: 10 Mar 2026
    4.3
    Medium

    CVE-2026-1508

    Last Modified: 16 Apr 2026

    The Court Reservation WordPress plugin before 1.10.9 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete them via a CSRF attack

    Published: 10 Mar 2026
    9.8
    Critical

    CVE-2026-0953

    Last Modified: 22 Apr 2026

    The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.5 via the Social Login addon. This is due to the plugin failing to verify that the email provided in the authentication request matches the email from the validated OAuth token. This makes it possible for unauthenticated attackers to log in as any existing user, including administrators, by supplying a valid OAuth token from their own account along with the victim's email address.

    Published: 10 Mar 2026
    5.9
    Medium

    CVE-2025-2399

    Last Modified: 27 Aug 2026

    Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Series M800VW and M800VS, M80V Series M80V and M80VW, M800 Series M800W and M800S, M80 Series M80 and M80W, E80 Series E80, C80 Series C80, and M700V Series M750VW, M720VW, 730VW, M720VS, M730VS, and M750VS, M70V Series M70V, E70 Series E70 allows a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition by sending specially crafted packets to TCP port 683.

    Published: 10 Mar 2026
    7.5
    High

    CVE-2026-3585

    Last Modified: 22 Apr 2026

    The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_import' function. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

    Published: 10 Mar 2026
    5.3
    Medium

    CVE-2026-1919

    Last Modified: 22 Apr 2026

    The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple REST API endpoints in all versions up to, and including, 1.0.16. This makes it possible for unauthenticated attackers to query sensitive data.

    Published: 10 Mar 2026
    5.3
    Medium

    CVE-2026-1920

    Last Modified: 22 Apr 2026

    The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'Extension_Controller::update_item_permissions_check' function in all versions up to, and including, 1.0.16. This makes it possible for unauthenticated attackers to install addon plugins.

    Published: 10 Mar 2026
    6.1
    Medium

    CVE-2025-36173

    Last Modified: 11 Mar 2026

    Affected Product(s)Version(s)InfoSphere Data Architect9.2.1

    Published: 10 Mar 2026
    4.4
    Medium

    CVE-2025-36105

    Last Modified: 6 May 2026

    IBM Planning Analytics Advanced Certified Containers 3.1.0 through 3.1.4 could allow a local privileged user to obtain sensitive information from environment variables.

    Published: 10 Mar 2026
    7.7
    High

    CVE-2026-27689

    Last Modified: 16 Apr 2026

    Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.

    Published: 10 Mar 2026
    5
    Medium

    CVE-2026-27688

    Last Modified: 3 Jun 2026

    Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user privileges could read Database Analyzer Log Files via a specific RFC function module. The attacker with the necessary privileges to execute this function module could potentially escalate their privileges and read the sensitive data, resulting in a limited impact on the confidentiality of the information stored. However, the integrity and availability of the system are not affected.

    Published: 10 Mar 2026
    5.8
    Medium

    CVE-2026-27687

    Last Modified: 16 Apr 2026

    Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges could access sensitive data belonging to another company. This vulnerability has a high impact on confidentiality and does not affect integrity and availability.

    Published: 10 Mar 2026
    5.9
    Medium

    CVE-2026-27686

    Last Modified: 16 Apr 2026

    Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation could enable unauthorized configuration and control changes, potentially disrupting request processing and causing denial of service. This results in low impact on integrity and high impact on availability, while confidentiality remains unaffected.

    Published: 10 Mar 2026