CVE Feed

    Dashboard / CVE

    5.7
    Medium

    CVE-2026-30789

    Last Modified: 22 Jun 2026

    Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login, peer authentication modules) allows Password Brute Forcing. The authentication proof is SHA256(SHA256(password + salt) + challenge), where both the salt and the challenge are generated entirely by the server with no client-side nonce, and the hash uses no slow key-derivation function. A rogue or on-path API/relay server (see CVE-2026-30794 / CVE-2026-30797) can issue a chosen salt and challenge, capture the resulting proof, and recover the password offline. The capture-replay claim (CWE-294) is withdrawn: the challenge is regenerated per connection (challenge = Config::get_auto_password(6)), so a captured proof is not replayable against the legitimate server. The 1.4.7 OTP brute-force limiter and the existing LOGIN_FAILURES counter constrain only ONLINE attempts and do not address offline recovery. This vulnerability is associated with program files src/client.rs and program routines handle_hash(), handle_login_from_ui() (login proof construction). This issue affects RustDesk Client: through 1.4.8.

    Published: 5 Mar 2026
    8.2
    High

    CVE-2026-30798

    Last Modified: 22 Jun 2026

    Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop, strategy processing modules) allows Protocol Manipulation. This vulnerability is associated with program files src/hbbs_http/sync.Rs and program routines stop-service handler in heartbeat loop. This issue affects RustDesk Client: through 1.4.8.

    Published: 5 Mar 2026
    9.3
    Critical

    CVE-2026-30797

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, config import modules) allows Application API Message Manipulation via Man-in-the-Middle. This vulnerability is associated with program files flutter/lib/common.Dart and program routines importConfig() via URI handler. This issue affects RustDesk Client: through 1.4.5.

    Published: 5 Mar 2026
    8.7
    High

    CVE-2026-25048

    Last Modified: 17 Apr 2026

    xgrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.32, the multi-level nested syntax caused a segmentation fault (core dumped). This issue has been patched in version 0.1.32.

    Published: 5 Mar 2026
    5.4
    Medium

    CVE-2025-64166

    Last Modified: 13 Mar 2026

    Mercurius is a GraphQL adapter for Fastify. Prior to version 16.4.0, a cross-site request forgery (CSRF) vulnerability was identified. The issue arises from incorrect parsing of the Content-Type header in requests. Specifically, requests with Content-Type values such as application/x-www-form-urlencoded, multipart/form-data, or text/plain could be misinterpreted as application/json. This misinterpretation bypasses the preflight checks performed by the fetch() API, potentially allowing unauthorized actions to be performed on behalf of an authenticated user. This issue has been patched in version 16.4.0.

    Published: 5 Mar 2026
    6.9
    Medium

    CVE-2026-30796

    Last Modified: 19 Jul 2026

    Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat sync loop modules) allows Sniffing Attacks. The client places the preset address-book password verbatim into the heartbeat sync JSON body (src/hbbs_http/sync.rs). Over an intact HTTPS session it is not exposed in transit, but it is a reusable shared secret rather than a zero-knowledge proof, so it is recovered by any party that becomes the API endpoint - under the re-homed/rogue API server (CVE-2026-30797) - and the leaked credential then authorizes the server-side address book. This vulnerability is associated with program files src/hbbs_http/sync.rs and program routines heartbeat sync body builder (emits preset-address-book-password). This issue affects RustDesk Client: through 1.4.8.

    Published: 5 Mar 2026
    8.7
    High

    CVE-2026-30795

    Last Modified: 16 Apr 2026

    Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop modules) allows Sniffing Attacks. This vulnerability is associated with program files src/hbbs_http/sync.Rs and program routines Heartbeat JSON payload construction (preset-address-book-password). This issue affects RustDesk Client: through 1.4.5.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-30794

    Last Modified: 22 Jun 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 5 Mar 2026
    9.3
    Critical

    CVE-2026-30793

    Last Modified: 17 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, FFI bridge modules) allows Privilege Escalation. This vulnerability is associated with program files flutter/lib/common.Dart, src/flutter_ffi.Rs and program routines URI handler for rustdesk://password/, bind.MainSetPermanentPassword(). This issue affects RustDesk Client: through 1.4.5.

    Published: 5 Mar 2026
    8.3
    High

    CVE-2026-30792

    Last Modified: 22 Jun 2026

    A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Strategy sync, HTTP API client, config options engine modules) allows Application API Message Manipulation via Man-in-the-Middle. This vulnerability is associated with program files src/hbbs_http/sync.Rs, hbb_common/src/config.Rs and program routines Strategy merge loop in sync.Rs, Config::set_options(). This issue affects RustDesk Client: through 1.4.8.

    Published: 5 Mar 2026
    8.7
    High

    CVE-2026-30791

    Last Modified: 16 Apr 2026

    Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Config import, URI scheme handler, CLI --config modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated with program files flutter/lib/common.Dart, hbb_common/src/config.Rs and program routines parseRustdeskUri(), importConfig(). This issue affects RustDesk Client: through 1.4.5.

    Published: 5 Mar 2026
    7.8
    High

    CVE-2026-27748

    Last Modified: 15 Apr 2026

    Avira Internet Security contains an improper link resolution vulnerability in the Software Updater component. During the update process, a privileged service running as SYSTEM deletes a file under C:\\ProgramData without validating whether the path resolves through a symbolic link or reparse point. A local attacker can create a malicious link to redirect the delete operation to an arbitrary file, resulting in deletion of attacker-chosen files with SYSTEM privileges. This may lead to local privilege escalation, denial of service, or system integrity compromise depending on the targeted file and operating system configuration.

    Published: 5 Mar 2026
    7.8
    High

    CVE-2026-27749

    Last Modified: 16 Apr 2026

    Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The Avira.SystemSpeedup.RealTimeOptimizer.exe process, which runs with SYSTEM privileges, deserializes data from a file located in C:\\ProgramData using .NET BinaryFormatter without implementing input validation or deserialization safeguards. Because the file can be created or modified by a local user in default configurations, an attacker can supply a crafted serialized payload that is deserialized by the privileged process, resulting in arbitrary code execution as SYSTEM.

    Published: 5 Mar 2026
    7.8
    High

    CVE-2026-27750

    Last Modified: 16 Apr 2026

    Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerability in the Optimizer component. A privileged service running as SYSTEM identifies directories for cleanup during a scan phase and subsequently deletes them during a separate cleanup phase without revalidating the target path. A local attacker can replace a previously scanned directory with a junction or reparse point before deletion occurs, causing the privileged process to delete an unintended system location. This may result in deletion of protected files or directories and can lead to local privilege escalation, denial of service, or system integrity compromise depending on the affected target.

    Published: 5 Mar 2026
    8.7
    High

    CVE-2026-3598

    Last Modified: 17 Apr 2026

    Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Config string generation, web console export modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated with program routines Config export/generation routines. This issue affects RustDesk Server Pro: through 1.7.5.

    Published: 5 Mar 2026
    8.8
    High

    CVE-2026-1720

    Last Modified: 22 Apr 2026

    The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the 'install_and_active_plugin' function in all versions up to, and including, 1.4.24. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins.

    Published: 5 Mar 2026
    7.7
    High

    CVE-2026-2092

    Last Modified: 18 Aug 2026

    A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploit this by crafting a malicious SAML response. This allows the attacker to inject an encrypted assertion for an arbitrary principal, leading to unauthorized access and potential information disclosure.

    Published: 5 Mar 2026
    9.8
    Critical

    CVE-2026-2599

    Last Modified: 22 Apr 2026

    The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input in the 'download_csv' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

    Published: 5 Mar 2026
    8.8
    High

    CVE-2026-3047

    Last Modified: 15 Jul 2026

    A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This allows a remote attacker to gain unauthorized access to other enabled clients without re-authentication, effectively bypassing security restrictions.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-2603

    Last Modified: 18 Aug 2026

    A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the SAML Identity Provider is disabled, leading to unauthorized authentication.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-3009

    Last Modified: 16 Apr 2026

    A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass the administrative restriction. This undermines access control enforcement and may allow unauthorized authentication through a disabled external provider.

    Published: 5 Mar 2026
    2.3
    Low

    CVE-2026-3236

    Last Modified: 16 Apr 2026

    In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key having a lifetime exceeding the original API key used to mint the access token.

    Published: 5 Mar 2026
    7.5
    High

    CVE-2026-1605

    Last Modified: 27 Aug 2026

    In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed. This happens because the JDK Inflater is allocated for decompressing the request, but it is not released because the release mechanism is tied to the compressed response. In this case, since the response is not compressed, the release mechanism does not trigger, causing the leak.

    Published: 5 Mar 2026
    3.7
    Low

    CVE-2025-11143

    Last Modified: 6 Mar 2026

    The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details.

    Published: 5 Mar 2026
    10
    Critical

    CVE-2026-21628

    Last Modified: 17 Apr 2026

    A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.

    Published: 5 Mar 2026
    7.3
    High

    CVE-2026-28542

    Last Modified: 17 Apr 2026

    Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Mar 2026
    7.1
    High

    CVE-2026-28548

    Last Modified: 16 Apr 2026

    Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 5 Mar 2026
    4.7
    Medium

    CVE-2026-28551

    Last Modified: 16 Apr 2026

    Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Mar 2026
    6.6
    Medium

    CVE-2026-28549

    Last Modified: 15 Apr 2026

    Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Mar 2026
    6.8
    Medium

    CVE-2026-28547

    Last Modified: 16 Apr 2026

    Vulnerability of uninitialized pointer access in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Mar 2026
    5.9
    Medium

    CVE-2026-28546

    Last Modified: 16 Apr 2026

    Buffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Mar 2026
    4.4
    Medium

    CVE-2026-28543

    Last Modified: 16 Apr 2026

    Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Mar 2026
    4
    Medium

    CVE-2026-28541

    Last Modified: 16 Apr 2026

    Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Mar 2026
    4
    Medium

    CVE-2026-28540

    Last Modified: 16 Apr 2026

    Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 5 Mar 2026
    6.2
    Medium

    CVE-2026-28539

    Last Modified: 18 Apr 2026

    Data processing vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 5 Mar 2026
    5.9
    Medium

    CVE-2026-28538

    Last Modified: 16 Apr 2026

    Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Mar 2026
    3.3
    Low

    CVE-2025-66319

    Last Modified: 6 Mar 2026

    Permission control vulnerability in the resource scheduling module. Impact: Successful exploitation of this vulnerability may affect service integrity.

    Published: 5 Mar 2026
    6.5
    Medium

    CVE-2026-28552

    Last Modified: 16 Apr 2026

    Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Mar 2026
    4
    Medium

    CVE-2026-28550

    Last Modified: 16 Apr 2026

    Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Mar 2026
    5.9
    Medium

    CVE-2026-28545

    Last Modified: 18 Apr 2026

    Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Mar 2026
    6.2
    Medium

    CVE-2026-28544

    Last Modified: 17 Apr 2026

    Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-1321

    Last Modified: 22 Apr 2026

    The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. This is due to the `rcp_setup_registration_init()` function accepting any membership level ID via the `rcp_level` POST parameter without validating that the level is active or that payment is required. Combined with the `add_user_role()` method which assigns the WordPress role configured on the membership level without status checks, this makes it possible for unauthenticated attackers to register with any membership level, including inactive levels that grant privileged WordPress roles such as Administrator, or paid levels that charge a sign-up fee. The vulnerability was partially patched in version 3.2.18.

    Published: 5 Mar 2026
    6.5
    Medium

    CVE-2026-2893

    Last Modified: 22 Apr 2026

    The Page and Post Clone plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' parameter in the content_clone() function in all versions up to, and including, 6.3. This is due to insufficient escaping on the user-supplied meta_key value and insufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The injection is second-order: the malicious payload is stored as a post meta key and executed when the post is cloned.

    Published: 5 Mar 2026
    3.3
    Low

    CVE-2026-21786

    Last Modified: 16 Apr 2026

    HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs.

    Published: 5 Mar 2026
    5.1
    Medium

    CVE-2026-28537

    Last Modified: 16 Apr 2026

    Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Mar 2026
    9.6
    Critical

    CVE-2026-28536

    Last Modified: 18 Apr 2026

    Authentication bypass vulnerability in the device authentication module. Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

    Published: 5 Mar 2026
    7.3
    High

    CVE-2026-25702

    Last Modified: 16 Apr 2026

    A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via nftables to not be effective.This issue affects SUSE Linux Enterprise Server: from 9e6d9d4601768c75fdb0bad3fbbe636e748939c2 before 9c294edb7085fb91650bc12233495a8974c5ff2d.

    Published: 5 Mar 2026
    10
    Critical

    CVE-2026-2743

    Last Modified: 19 May 2026

    Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT). This issue affects SeppMail: 15.0.2.1 and before

    Published: 5 Mar 2026
    9.4
    Critical

    CVE-2026-1678

    Last Modified: 16 Apr 2026

    dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cached size becomes incorrect, and the final null terminator can be written past the buffer. With assertions disabled (default), a malicious DNS response can trigger an out-of-bounds write when CONFIG_DNS_RESOLVER is enabled.

    Published: 5 Mar 2026
    9.1
    Critical

    CVE-2026-2418

    Last Modified: 16 Apr 2026

    The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email

    Published: 5 Mar 2026