CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2026-3938

    Last Modified: 16 Apr 2026

    Insufficient policy enforcement in Clipboard in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 10 Mar 2026
    8.8
    High

    CVE-2026-3931

    Last Modified: 17 Apr 2026

    Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

    Published: 10 Mar 2026
    6.5
    Medium

    CVE-2026-3935

    Last Modified: 16 Apr 2026

    Incorrect security UI in WebAppInstalls in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

    Published: 10 Mar 2026
    8.8
    High

    CVE-2026-3914

    Last Modified: 16 Apr 2026

    Integer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 10 Mar 2026
    5.3
    Medium

    CVE-2025-70129

    Last Modified: 7 Apr 2026

    If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format that can be automatically recognized for articles, such that an automated script is able to solve this anti-spam mechanism trivially and publish spam comments. The details of captcha challenge are exposed within document body of articles with comments & anti spam-captcha functionalities enabled, including "capcha-letter", "capcha-word" and "capcha-token" which can be used to construct a valid post request to publish a comment. As such, attackers can flood articles with automated spam comments, especially if there are no other web defenses available.

    Published: 10 Mar 2026
    7.5
    High

    CVE-2025-70251

    Last Modified: 11 Mar 2026

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanGuestSetup.

    Published: 10 Mar 2026
    7.5
    High

    CVE-2025-70246

    Last Modified: 11 Mar 2026

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formVirtualServ.

    Published: 10 Mar 2026
    7.5
    High

    CVE-2026-26801

    Last Modified: 7 May 2026

    Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain sensitive information via the src/URLResolver.js component. The fix was released in version 0.3.6 which introduces the setUrlAccessPolicy() method allowing server operators to define URL access rules. A warning is now logged when pdfmake is used server-side without a policy configured.

    Published: 10 Mar 2026
    7.5
    High

    CVE-2025-70244

    Last Modified: 11 Mar 2026

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanSetup.

    Published: 10 Mar 2026
    7.5
    High

    CVE-2025-70247

    Last Modified: 11 Mar 2026

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard1.

    Published: 10 Mar 2026
    8.1
    High

    CVE-2026-26742

    Last Modified: 16 Apr 2026

    PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-air emergency re-arm logic to ground scenarios. If a pilot switches to Manual mode and re-arms within 5 seconds (default configuration) of an automatic landing, the system bypasses all pre-flight safety checks, including the throttle threshold check. This allows for an immediate high-thrust takeoff if the throttle stick is raised, leading to loss of control.

    Published: 10 Mar 2026
    7.5
    High

    CVE-2025-70242

    Last Modified: 11 Mar 2026

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formSetWanPPTP.

    Published: 10 Mar 2026
    7.5
    High

    CVE-2025-70227

    Last Modified: 11 Mar 2026

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the nextPage parameter to goform/formLanguageChange.

    Published: 10 Mar 2026
    6.1
    Medium

    CVE-2025-70128

    Last Modified: 7 Apr 2026

    A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The application fails to properly sanitize or validate user-supplied input in the "link" field of a comment. An attacker can inject arbitrary JavaScript code using a <script> element. The injected payload is stored in the database and subsequently rendered in the Administration panel's "Comments" section when administrators review submitted comments. Importantly, the malicious script is not reflected in the public-facing comments interface, but only within the backend administration view. Alternatively, users of Administrator, Moderator, Manager roles can also directly input crafted payloads into existing comments. This makes the vulnerability a persistent XSS issue targeting administrative users. This affects /core/admin/comments.php, while CVE-2022-24585 affects /core/admin/comment.php, a uniquely distinct vulnerability.

    Published: 10 Mar 2026
    7.5
    High

    CVE-2025-56421

    Last Modified: 20 Mar 2026

    SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive information from the database.

    Published: 10 Mar 2026
    9.8
    Critical

    CVE-2025-56422

    Last Modified: 20 Mar 2026

    A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.

    Published: 10 Mar 2026
    6.1
    Medium

    CVE-2025-70025

    Last Modified: 7 May 2026

    An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in benkeen generatedata 4.0.14.

    Published: 10 Mar 2026
    4.3
    Medium

    CVE-2026-3941

    Last Modified: 16 Apr 2026

    Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 10 Mar 2026
    9.6
    Critical

    CVE-2026-3916

    Last Modified: 16 Apr 2026

    Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 10 Mar 2026
    5.3
    Medium

    CVE-2026-3940

    Last Modified: 16 Apr 2026

    Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 10 Mar 2026
    4.3
    Medium

    CVE-2026-3928

    Last Modified: 17 Apr 2026

    Insufficient policy enforcement in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)

    Published: 10 Mar 2026
    8.4
    High

    CVE-2025-70798

    Last Modified: 9 Apr 2026

    Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.

    Published: 10 Mar 2026
    8.4
    High

    CVE-2025-70802

    Last Modified: 9 Apr 2026

    Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.

    Published: 10 Mar 2026
    7.5
    High

    CVE-2025-70249

    Last Modified: 11 Mar 2026

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard2.

    Published: 10 Mar 2026
    9.4
    Critical

    CVE-2025-69614

    Last Modified: 7 May 2026

    Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 2025-10-27, fixed 2025-10-31.

    Published: 10 Mar 2026
    9.1
    Critical

    CVE-2025-69615

    Last Modified: 7 May 2026

    Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 2025-10-24, fixed 2025-11-03.

    Published: 10 Mar 2026
    4.3
    Medium

    CVE-2026-3942

    Last Modified: 16 Apr 2026

    Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 10 Mar 2026
    5.3
    Medium

    CVE-2026-3939

    Last Modified: 16 Apr 2026

    Insufficient policy enforcement in PDF in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted PDF file. (Chromium security severity: Low)

    Published: 10 Mar 2026
    6.5
    Medium

    CVE-2026-3934

    Last Modified: 16 Apr 2026

    Insufficient policy enforcement in ChromeDriver in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 10 Mar 2026
    8.1
    High

    CVE-2026-26741

    Last Modified: 16 Apr 2026

    PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from Auto mode to Manual mode while the drone is in the "ARMED" state (after landing and before the automatic disarm triggered by the COM_DISARM_LAND parameter), the system lacks a throttle threshold safety check for the physical throttle stick. This flaw can directly cause the drone to lose control, experience rapid uncontrolled ascent (flyaway), and result in property damage

    Published: 10 Mar 2026
    3.1
    Low

    CVE-2026-3929

    Last Modified: 16 Apr 2026

    Side-channel information leakage in ResourceTiming in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 10 Mar 2026
    8.8
    High

    CVE-2026-3926

    Last Modified: 16 Apr 2026

    Out of bounds read in V8 in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

    Published: 10 Mar 2026
    8.8
    High

    CVE-2026-3923

    Last Modified: 16 Apr 2026

    Use after free in WebMIDI in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 10 Mar 2026
    8.8
    High

    CVE-2026-3920

    Last Modified: 16 Apr 2026

    Out of bounds memory access in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 10 Mar 2026
    8.8
    High

    CVE-2026-3919

    Last Modified: 16 Apr 2026

    Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 10 Mar 2026
    5.3
    Medium

    CVE-2026-30927

    Last Modified: 17 Apr 2026

    Admidio is an open-source user management solution. Prior to 5.0.6, in modules/events/events_function.php, the event participation logic allows any user who can participate in an event to register OTHER users by manipulating the user_uuid GET parameter. The condition uses || (OR), meaning if possibleToParticipate() returns true (event is open for participation), ANY user - not just leaders - can specify a different user_uuid and register/cancel participation for that user. The code then operates on $user->getValue('usr_id') (the target user from user_uuid) rather than the current user. This vulnerability is fixed in 5.0.6.

    Published: 9 Mar 2026
    8.2
    High

    CVE-2026-30925

    Last Modified: 17 Apr 2026

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-alpha.14 and 8.6.11, a malicious client can subscribe to a LiveQuery with a crafted $regex pattern that causes catastrophic backtracking, blocking the Node.js event loop. This makes the entire Parse Server unresponsive, affecting all clients. Any Parse Server deployment with LiveQuery enabled is affected. The attacker only needs the application ID and JavaScript key, both of which are public in client-side apps. This only affects LiveQuery subscription matching, which evaluates regex in JavaScript on the Node.js event loop. Normal REST and GraphQL queries are not affected because their regex is evaluated by the database engine. This vulnerability is fixed in 9.5.0-alpha.14 and 8.6.11.

    Published: 9 Mar 2026
    9.9
    Critical

    CVE-2026-30921

    Last Modified: 16 Apr 2026

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project users to submit custom Playwright code that is executed on the oneuptime-probe service. In the current implementation, this untrusted code is run inside Node's vm and is given live host Playwright objects such as browser and page. This creates a distinct server-side RCE primitive: the attacker does not need the classic this.constructor.constructor(...) sandbox escape. Instead, the attacker can directly use the injected Playwright browser object to reach browser.browserType().launch(...) and spawn an arbitrary executable on the probe host/container. This vulnerability is fixed in 10.0.20.

    Published: 9 Mar 2026
    8.6
    High

    CVE-2026-30920

    Last Modified: 16 Apr 2026

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.gitHubAppInstallationId with isRoot: true without validating that the caller is authorized for the target project. This allows an attacker to overwrite another project's GitHub App installation binding. Related GitHub endpoints also lack effective authorization, so a valid installation ID can be used to enumerate repositories and create CodeRepository records in an arbitrary project. This vulnerability is fixed in 10.0.19.

    Published: 9 Mar 2026
    7.6
    High

    CVE-2026-30919

    Last Modified: 16 Apr 2026

    facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as persistent or second-order XSS) occurs when an application receives data from an untrusted source and includes that data in its subsequent HTTP responses in an unsafe manner. This vulnerability was found in the fmDNS module. This vulnerability is fixed in 6.0.4.

    Published: 9 Mar 2026
    7.6
    High

    CVE-2026-30918

    Last Modified: 16 Apr 2026

    facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs when an application receives data from an untrusted source and uses it in its HTTP responses in a way that could lead to vulnerabilities. It is possible to inject malicious JavaScript code into a URL by adding a script in a parameter. This vulnerability was found in the fmDNS module. The parameter that is vulnerable to an XSS attack is log_search_query. This vulnerability is fixed in 6.0.4.

    Published: 9 Mar 2026
    8.8
    High

    CVE-2026-30917

    Last Modified: 18 Apr 2026

    Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to 2.1.1, a stored XSS can be inserted into any Bucket table field that has a PAGE type, which will execute whenever a user views that table's corresponding Bucket namespace page. This vulnerability is fixed in 2.1.1.

    Published: 9 Mar 2026
    Unknown

    CVE-2026-30916

    Last Modified: 20 Mar 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: Further investigation determined that the software behavior described did not falls within the project's threat model. See https://github.com/github/advisory-database/pull/7206 for more information.

    Published: 9 Mar 2026
    4.6
    Medium

    CVE-2026-30913

    Last Modified: 16 Apr 2026

    Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their nickname to a string that email clients interpret as a hyperlink. The nickname is inserted verbatim into plain-text notification emails, and recipients may be misled into visiting attacker-controlled domains.

    Published: 9 Mar 2026
    9.9
    Critical

    CVE-2026-30887

    Last Modified: 17 Apr 2026

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/JavaScript code via Synthetic Monitors to test websites. However, the system executes this untrusted user code inside the insecure Node.js vm module. By leveraging a standard prototype-chain escape (this.constructor.constructor), an attacker can bypass the sandbox, gain access to the underlying Node.js process object, and execute arbitrary system commands (RCE) on the oneuptime-probe container. Furthermore, because the probe holds database/cluster credentials in its environment variables, this directly leads to a complete cluster compromise. This vulnerability is fixed in 10.0.18.

    Published: 9 Mar 2026
    5.5
    Medium

    CVE-2026-30885

    Last Modified: 16 Apr 2026

    WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user without requiring authentication or authorization. An unauthenticated attacker can enumerate user IDs and retrieve playlist information including playlist names, video IDs, and playlist status for any user on the platform. This vulnerability is fixed in 25.0.

    Published: 9 Mar 2026
    6.5
    Medium

    CVE-2026-30870

    Last Modified: 16 Apr 2026

    PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync streams with config.edition: 3, certain subquery filters were ignored when determining which data to sync to users. Depending on the sync stream configuration, this could result in authenticated users syncing data that should have been restricted. Only queries that gate synchronization using subqueries without partitioning the result set are affected. This vulnerability is fixed in 1.20.1.

    Published: 9 Mar 2026
    6.8
    Medium

    CVE-2026-28267

    Last Modified: 16 Apr 2026

    Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwritten in the system directory or backup directory by a non-administrative user.

    Published: 9 Mar 2026
    9.3
    Critical

    CVE-2026-30869

    Last Modified: 17 Apr 2026

    SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read arbitrary files from the server filesystem. By exploiting double‑encoded traversal sequences, an attacker can access sensitive files such as conf/conf.json, which contains secrets including the API token, cookie signing key, and workspace access authentication code. Leaking these secrets may enable administrative access to the SiYuan kernel API, and in certain deployment scenarios could potentially be chained into remote code execution (RCE). This vulnerability is fixed in 3.5.10.

    Published: 9 Mar 2026
    9
    Critical

    CVE-2026-30862

    Last Modified: 16 Apr 2026

    Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table Widget (TableWidgetV2). The root cause is a lack of HTML sanitization in the React component rendering pipeline, allowing malicious attributes to be interpolated into the DOM. By leveraging the "Invite Users" feature, an attacker with a regular user account ([email protected]) can force a System Administrator to execute a high-privileged API call (/api/v1/admin/env), resulting in a Full Administrative Account Takeover. This vulnerability is fixed in 1.96.

    Published: 9 Mar 2026