CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2026-26272

    Last Modified: 17 Apr 2026

    HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerability exists in the item attachment upload functionality. The application does not properly validate or restrict uploaded file types, allowing an authenticated user to upload malicious HTML or SVG files containing executable JavaScript (also, potentially other formats that render scripts). Uploaded attachments are accessible via direct links. When a user accesses such a file in their browser, the embedded JavaScript executes in the context of the application's origin. This vulnerability is fixed in 0.24.0-rc.1.

    Published: 3 Mar 2026
    9.3
    Critical

    CVE-2026-26266

    Last Modified: 16 Apr 2026

    AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnerability was identified in the email rendering feature of AliasVault Web Client versions 0.25.3 and lower. When viewing received emails on an alias, the HTML content is rendered in an iframe using srcdoc, which does not provide origin isolation. An attacker can send a crafted email containing malicious JavaScript to any AliasVault email alias. When the victim views the email in the web client, the script executes in the same origin as the application. No sanitization or sandboxing was applied to email HTML content before rendering. This vulnerability is fixed in 0.26.0.[

    Published: 3 Mar 2026
    4.5
    Medium

    CVE-2026-25590

    Last Modified: 16 Apr 2026

    The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, there is a reflected XSS vulnerability in task jobs. This vulnerability is fixed in 1.6.6.

    Published: 3 Mar 2026
    10
    Critical

    CVE-2026-24898

    Last Modified: 16 Apr 2026

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerability in the MedEx callback endpoint allows any unauthenticated visitor to obtain the practice's MedEx API tokens, leading to complete third-party service compromise, PHI exfiltration, unauthorized actions on the MedEx platform, and HIPAA violations. The vulnerability exists because the endpoint bypasses authentication ($ignoreAuth = true) and performs a MedEx login whenever $_POST['callback_key'] is provided, returning the full JSON response including sensitive API tokens. This vulnerability is fixed in 8.0.0.

    Published: 3 Mar 2026
    9.6
    Critical

    CVE-2026-25146

    Last Modified: 16 Apr 2026

    OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret value is rendered to the client in plaintext. These secret keys being leaked could result in arbitrary money movement or broad account takeover of payment gateway APIs. This vulnerability is fixed in 8.0.0.

    Published: 3 Mar 2026
    8.7
    High

    CVE-2026-24848

    Last Modified: 16 Apr 2026

    OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and earlier, the disposeDocument() method in EtherFaxActions.php allows authenticated users to write arbitrary content to arbitrary locations on the server filesystem. This vulnerability can be exploited to achieve Remote Code Execution (RCE) by uploading malicious PHP web shells.

    Published: 3 Mar 2026
    9.8
    Critical

    CVE-2026-27012

    Last Modified: 17 Apr 2026

    OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenSTAManager allows any attacker to arbitrarily change a user's group (idgruppo) by directly calling modules/utenti/actions.php. This can promote an existing account (e.g. agent) into the Amministratori group as well as demote any user including existing administrators.

    Published: 3 Mar 2026
    5.1
    Medium

    CVE-2026-24415

    Last Modified: 17 Apr 2026

    OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contains Reflected XSS vulnerabilities in invoice/order/contract modification modals. The application fails to properly sanitize user-supplied input from the righe GET parameter before reflecting it in HTML output.The $_GET['righe'] parameter is directly echoed into the HTML value attribute without any sanitization using htmlspecialchars() or equivalent functions. This allows an attacker to break out of the attribute context and inject arbitrary HTML/JavaScript.

    Published: 3 Mar 2026
    5.1
    Medium

    CVE-2026-21866

    Last Modified: 18 Apr 2026

    Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rendering Mermaid diagrams within chats. This occurs because Dify’s default Mermaid configuration uses securityLevel: loose, which allows potentially unsafe content to execute. This vulnerability is fixed in 1.11.2.

    Published: 3 Mar 2026
    2
    Low

    CVE-2026-3487

    Last Modified: 16 Apr 2026

    A vulnerability was found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/class-result.php. Performing a manipulation of the argument course_code results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

    Published: 3 Mar 2026
    9.8
    Critical

    CVE-2026-3130

    Last Modified: 17 Apr 2026

    Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one non-checked-out account and performing a bulk deletion.

    Published: 3 Mar 2026
    9.8
    Critical

    CVE-2026-3204

    Last Modified: 16 Apr 2026

    Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error message via a specially crafted URL.

    Published: 3 Mar 2026
    9.8
    Critical

    CVE-2026-2590

    Last Modified: 10 May 2026

    Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and earlier allows an authenticated user to persist credentials in vault entries, potentially exposing sensitive information to other users, by creating or editing certain connection types while password saving is disabled.

    Published: 3 Mar 2026
    9.8
    Critical

    CVE-2026-3224

    Last Modified: 17 Apr 2026

    Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT).

    Published: 3 Mar 2026
    8.8
    High

    CVE-2026-1775

    Last Modified: 16 Apr 2026

    The Labkotec LID-3300IP has an existing vulnerability in the ice detector software that enables an unauthenticated attacker to alter device parameters and run operational commands when specially crafted packets are sent to the device.

    Published: 3 Mar 2026
    2
    Low

    CVE-2026-3486

    Last Modified: 16 Apr 2026

    A vulnerability has been found in itsourcecode College Management System 1.0. This vulnerability affects unknown code of the file /admin/student-fee.php. Such manipulation of the argument roll_no leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Mar 2026
    8.9
    High

    CVE-2026-3485

    Last Modified: 16 Apr 2026

    A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 3 Mar 2026
    7.3
    High

    CVE-2026-25906

    Last Modified: 16 Apr 2026

    Dell Optimizer, versions prior to 6.3.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

    Published: 3 Mar 2026
    6.3
    Medium

    CVE-2025-13686

    Last Modified: 4 Mar 2026

    IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input through the job subroutine component.

    Published: 3 Mar 2026
    6.3
    Medium

    CVE-2025-13687

    Last Modified: 4 Mar 2026

    IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input through the user-defined function component.

    Published: 3 Mar 2026
    6.3
    Medium

    CVE-2025-13688

    Last Modified: 4 Mar 2026

    IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input through the wrapped command component.

    Published: 3 Mar 2026
    8.8
    High

    CVE-2026-24502

    Last Modified: 16 Apr 2026

    Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

    Published: 3 Mar 2026
    5.9
    Medium

    CVE-2025-14456

    Last Modified: 5 Mar 2026

    IBM MQ Appliance 9.4 CD through 9.4.4.0 to 9.4.4.1

    Published: 3 Mar 2026
    5.1
    Medium

    CVE-2025-14480

    Last Modified: 5 Mar 2026

    IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

    Published: 3 Mar 2026
    7.1
    High

    CVE-2026-1567

    Last Modified: 16 Apr 2026

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information from the server.

    Published: 3 Mar 2026
    5
    Medium

    CVE-2026-1713

    Last Modified: 16 Apr 2026

    IBM MQ 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.30.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.17 LTS, and 9.4.0.0 through 9.4.4.1 CD

    Published: 3 Mar 2026
    8.3
    High

    CVE-2026-0869

    Last Modified: 16 Apr 2026

    Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Brocade Support Link(BSL) and streaming configuration. and could even disable the ASCG application or disable use of BSL data collection on Brocade switches within the fabric.

    Published: 3 Mar 2026
    5.9
    Medium

    CVE-2025-13490

    Last Modified: 4 Mar 2026

    IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enterprise Certified Containers Operands versions CD 12.0.11.2‑r1 through 12.0.12.5‑r1 and 13.0.1.0‑r1 through 13.0.6.1‑r1, and LTS versions 12.0.12‑r1 through 12.0.12‑r20, contain a vulnerability in which the IBM App Connect Enterprise Certified Container transmits data in clear text, potentially allowing an attacker to intercept and obtain sensitive information through man‑in‑the‑middle techniques.

    Published: 3 Mar 2026
    6.5
    Medium

    CVE-2025-13616

    Last Modified: 4 Mar 2026

    IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used in further attacks against the system.

    Published: 3 Mar 2026
    5.4
    Medium

    CVE-2025-13734

    Last Modified: 4 Mar 2026

    IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data beyond their authorized access permissions.

    Published: 3 Mar 2026
    6.8
    Medium

    CVE-2026-29022

    Last Modified: 17 Apr 2026

    dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h that allows memory corruption via crafted WAV files. Attackers can exploit a mismatch between sampleLoopCount validation in pass 1 and unconditional processing in pass 2 to overflow heap allocations with 36 bytes of attacker-controlled data through any drwav_init_*_with_metadata() call on untrusted input.

    Published: 3 Mar 2026
    6.6
    Medium

    CVE-2025-14604

    Last Modified: 4 Mar 2026

    IBM Storage Scale IBM S through rage Scale 5.2.3.0 - 5.2.3.5, and IBM S through rage Scale 6.0.0.0 - 6.0.0.1 could allow a local user to unintentionally trigger additional permissions for resources in a way that allows that resource to be executed by unintended actors.

    Published: 3 Mar 2026
    4.7
    Medium

    CVE-2025-14923

    Last Modified: 4 Mar 2026

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.

    Published: 3 Mar 2026
    5.9
    Medium

    CVE-2025-36363

    Last Modified: 4 Mar 2026

    IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

    Published: 3 Mar 2026
    6.2
    Medium

    CVE-2025-36364

    Last Modified: 4 Mar 2026

    IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.

    Published: 3 Mar 2026
    4.3
    Medium

    CVE-2026-1265

    Last Modified: 16 Apr 2026

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log file.

    Published: 3 Mar 2026
    6.5
    Medium

    CVE-2026-2606

    Last Modified: 16 Apr 2026

    IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API Management (on-prem) fails to properly validate user-supplied input passed to the url parameter on the /createapi endpoint. An attacker can modify this parameter to use a file:// URI schema instead of the expected https:// schema, enabling unauthorized arbitrary file read access on the underlying server file system.

    Published: 3 Mar 2026
    5.3
    Medium

    CVE-2026-3484

    Last Modified: 16 Apr 2026

    A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function child_process.exec of the file src/index.ts of the component Nmap CLI Command Handler. The manipulation results in command injection. The attack may be performed from remote. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The patch is identified as 30a6b9e1c7fa6146f51e28d6ab83a2568d9a3488. It is best practice to apply a patch to resolve this issue.

    Published: 3 Mar 2026
    4.9
    Medium

    CVE-2026-2376

    Last Modified: 2 Jun 2026

    A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the application processes these addresses, it automatically follows redirects without verifying the final destination, allowing attackers to route requests to systems they should not have access to.

    Published: 3 Mar 2026
    5.2
    Medium

    CVE-2026-2915

    Last Modified: 17 Apr 2026

    HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability was remediated with HP System Event Utility version 3.2.16.

    Published: 3 Mar 2026
    5.3
    Medium

    CVE-2026-3494

    Last Modified: 18 Apr 2026

    In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.

    Published: 3 Mar 2026
    9.3
    Critical

    CVE-2026-3437

    Last Modified: 25 Jun 2026

    An improper restriction of operations within the bounds of a memory buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Engineering Toolkits driver. Successful exploitation of this vulnerability could result in escalation of privileges or cause a denial-of-service condition.

    Published: 3 Mar 2026
    5.3
    Medium

    CVE-2026-0540

    Last Modified: 16 Apr 2026

    DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like </noscript><img src=x onerror=alert(1)> in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.

    Published: 3 Mar 2026
    5.1
    Medium

    CVE-2025-15599

    Last Modified: 5 Mar 2026

    DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex. Attackers can include closing rawtext tags like </textarea> in attribute values to break out of rawtext contexts and execute JavaScript when sanitized output is placed inside rawtext elements. The 3.x branch was fixed in 3.2.7; the 2.x branch was never patched.

    Published: 3 Mar 2026
    Unknown

    CVE-2026-29034

    Last Modified: 24 Jun 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 3 Mar 2026
    Unknown

    CVE-2026-29033

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 3 Mar 2026
    Unknown

    CVE-2026-29032

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 3 Mar 2026
    Unknown

    CVE-2026-29031

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 3 Mar 2026
    Unknown

    CVE-2026-29030

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 3 Mar 2026
    Unknown

    CVE-2026-29029

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 3 Mar 2026