CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2026-34040

    Last Modified: 16 Jun 2026

    Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.

    Published: 31 Mar 2026
    8.1
    High

    CVE-2026-32727

    Last Modified: 3 Apr 2026

    SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.7, the Enforcer is vulnerable to a path traversal attack where an attacker can use dot-dot (..) in the scope claim of a token to escape the intended directory restriction. This occurs because the library normalizes both the authorized path (from the token) and the requested path (from the application) before comparing them using startswith. This issue has been patched in version 1.9.7.

    Published: 31 Mar 2026
    8.1
    High

    CVE-2026-32716

    Last Modified: 7 Apr 2026

    SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the Enforcer incorrectly validates scope paths by using a simple prefix match (startswith). This allows a token with access to a specific path (e.g., /john) to also access sibling paths that start with the same prefix (e.g., /johnathan, /johnny), which is an Authorization Bypass. This issue has been patched in version 1.9.6.

    Published: 31 Mar 2026
    9.8
    Critical

    CVE-2026-32714

    Last Modified: 7 Apr 2026

    SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scitokens was vulnerable to SQL Injection because it used Python's str.format() to construct SQL queries with user-supplied data (such as issuer and key_id). This allowed an attacker to execute arbitrary SQL commands against the local SQLite database. This issue has been patched in version 1.9.6.

    Published: 31 Mar 2026
    9.8
    Critical

    CVE-2026-3300

    Last Modified: 24 Apr 2026

    The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_filter() function concatenating user-submitted form field values into a PHP code string without proper escaping before passing it to eval(). The sanitize_text_field() function applied to input does not escape single quotes or other PHP code context characters. This makes it possible for unauthenticated attackers to inject and execute arbitrary PHP code on the server by submitting a crafted value in any string-type form field (text, email, URL, select, radio) when a form uses the "Complex Calculation" feature.

    Published: 31 Mar 2026
    7.5
    High

    CVE-2026-4020

    Last Modified: 24 Apr 2026

    The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it. When the ?page=gravitysmtp-settings query parameter is appended, the plugin's register_connector_data() method populates internal connector data, causing the endpoint to return approximately 365 KB of JSON containing the full System Report. This makes it possible for unauthenticated attackers to retrieve detailed system configuration data including PHP version, loaded extensions, web server version, document root path, database server type and version, WordPress version, all active plugins with versions, active theme, WordPress configuration details, database table names, and any API keys/tokens configured in the plugin.

    Published: 31 Mar 2026
    5.5
    Medium

    CVE-2026-5176

    Last Modified: 7 Apr 2026

    A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. Affected is the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument provided results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

    Published: 31 Mar 2026
    3.6
    Low

    CVE-2026-5115

    Last Modified: 7 Apr 2026

    The PaperCut NG/MF (specifically, the embedded application for Konica Minolta devices) is vulnerable to session hijacking. The PaperCut NG/MF Embedded application is a software interface that runs directly on the touch screen of a multi-function device. It was internally discovered that the communication channel between the embedded application and the server was insecure, which could leak data including sensitive information that may be used to mount an  attack on the device. Such an attack could potentially be used to steal data or to perform a phishing attack on the end user.

    Published: 31 Mar 2026
    7.1
    High

    CVE-2026-32734

    Last Modified: 3 Apr 2026

    baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has DOM-based cross-site scripting in tag creation. This issue has been patched in version 5.2.3.

    Published: 31 Mar 2026
    6.9
    Medium

    CVE-2026-30879

    Last Modified: 3 Apr 2026

    baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a cross-site scripting vulnerability in blog posts. This issue has been patched in version 5.2.3.

    Published: 31 Mar 2026
    7.2
    High

    CVE-2026-30940

    Last Modified: 3 Apr 2026

    baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/api/admin/bc-theme-file/theme_files/add.json) that allows arbitrary file write. An authenticated administrator can include ../ sequences in the path parameter to create a PHP file in an arbitrary directory outside the theme directory, which may result in remote code execution (RCE). This issue has been patched in version 5.2.3.

    Published: 31 Mar 2026
    5.3
    Medium

    CVE-2026-30878

    Last Modified: 3 Apr 2026

    baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. This issue has been patched in version 5.2.3.

    Published: 31 Mar 2026
    9.1
    Critical

    CVE-2026-30877

    Last Modified: 3 Apr 2026

    baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of the user account running baserCMS. This issue has been patched in version 5.2.3.

    Published: 31 Mar 2026
    9.2
    Critical

    CVE-2026-30880

    Last Modified: 3 Apr 2026

    baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue has been patched in version 5.2.3.

    Published: 31 Mar 2026
    6.9
    Medium

    CVE-2026-27697

    Last Modified: 3 Apr 2026

    baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog posts. This issue has been patched in version 5.2.3.

    Published: 31 Mar 2026
    9.1
    Critical

    CVE-2026-21861

    Last Modified: 3 Apr 2026

    baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated administrator can execute arbitrary OS commands on the server due to improper handling of user-controlled input that is directly passed to exec() without sufficient validation or escaping. This issue has been patched in version 5.2.3.

    Published: 31 Mar 2026
    8.7
    High

    CVE-2025-32957

    Last Modified: 3 Apr 2026

    baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to upload a .zip file, which is then automatically extracted. A PHP file inside the archive is included using require_once without validating or restricting the filename. An attacker can craft a malicious PHP file within the zip and achieve arbitrary code execution when it is included. This issue has been patched in version 5.2.3.

    Published: 31 Mar 2026
    2.1
    Low

    CVE-2026-4794

    Last Modified: 7 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PaperCut NG/MF before 25.0.10 allow authenticated administrator users to inject arbitrary web script or HTML code via different UI fields. This could be used to compromise other admininistrator's sessions or perform unauthorized actions via the administrator's authenticated context (e.g. requires an active login session).

    Published: 31 Mar 2026
    7.5
    High

    CVE-2026-5201

    Last Modified: 10 Jun 2026

    A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.

    Published: 31 Mar 2026
    5.4
    Medium

    CVE-2026-30520

    Last Modified: 7 Apr 2026

    A Blind SQL Injection vulnerability exists in SourceCodester Loan Management System v1.0. The vulnerability is located in the ajax.php file (specifically the save_loan action). The application fails to properly sanitize user input supplied to the "borrower_id" parameter in a POST request, allowing an authenticated attacker to inject malicious SQL commands.

    Published: 31 Mar 2026
    9.8
    Critical

    CVE-2026-30286

    Last Modified: 7 Apr 2026

    An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

    Published: 31 Mar 2026
    9.8
    Critical

    CVE-2026-30281

    Last Modified: 7 Apr 2026

    An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

    Published: 31 Mar 2026
    9.8
    Critical

    CVE-2026-30278

    Last Modified: 7 Apr 2026

    An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

    Published: 31 Mar 2026
    8.4
    High

    CVE-2026-30277

    Last Modified: 7 Apr 2026

    An arbitrary file overwrite vulnerability in PDF Reader App : TA/UTAX Mobile Print v3.7.2.251001 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

    Published: 31 Mar 2026
    Unknown

    CVE-2026-34882

    Last Modified: 4 May 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-6074. Reason: This record is a reservation duplicate of CVE-2026-6074. Notes: All CVE users should reference CVE-2026-6074 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

    Published: 31 Mar 2026
    9.8
    Critical

    CVE-2026-30283

    Last Modified: 7 Apr 2026

    An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

    Published: 31 Mar 2026
    9.8
    Critical

    CVE-2026-30314

    Last Modified: 3 Apr 2026

    Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, it fails to account for standard Shell command substitution Ridvay Code (specifically$(...)and backticks ...). An attacker can construct a command such as git log --grep="$(malicious_command)", forcing Syntx to misidentify it as a safe git operation and automatically approve it. The underlying Shell prioritizes the execution of the malicious code injected within the arguments, resulting in Remote Code Execution without any user interaction.

    Published: 31 Mar 2026
    9.8
    Critical

    CVE-2026-30311

    Last Modified: 3 Apr 2026

    Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, it fails to account for standard Shell command substitution Ridvay Code (specifically$(...)and backticks ...). An attacker can construct a command such as git log --grep="$(malicious_command)", forcing Syntx to misidentify it as a safe git operation and automatically approve it. The underlying Shell prioritizes the execution of the malicious code injected within the arguments, resulting in Remote Code Execution without any user interaction.

    Published: 31 Mar 2026
    6.5
    Medium

    CVE-2026-5291

    Last Modified: 3 Apr 2026

    Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 31 Mar 2026
    6.5
    Medium

    CVE-2026-30521

    Last Modified: 3 Apr 2026

    A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validation. The application allows administrators to create "Loan Plans" with specific interest rates. While the frontend interface prevents users from entering negative numbers, this constraint is not enforced on the backend. An authenticated attacker can bypass the client-side restriction by manipulating the HTTP POST request to submit a negative value for the interest_percentage. This results in the creation of loan plans with negative interest rates.

    Published: 31 Mar 2026
    9.8
    Critical

    CVE-2026-30310

    Last Modified: 3 Apr 2026

    In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all commands. The description for the former states that commands determined by the model to be safe will be automatically executed, whereas if the model judges a command to be potentially destructive, it still requires user approval. However, this design is highly susceptible to prompt injection attacks. An attacker can employ a generic template to wrap any malicious command and mislead the model into misclassifying it as a 'safe' command, thereby bypassing the user approval requirement and resulting in arbitrary command execution.

    Published: 31 Mar 2026
    8.6
    High

    CVE-2026-30284

    Last Modified: 7 Apr 2026

    An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

    Published: 31 Mar 2026
    9
    Critical

    CVE-2026-30282

    Last Modified: 8 Apr 2026

    An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure.

    Published: 31 Mar 2026
    5.3
    Medium

    CVE-2026-30280

    Last Modified: 3 Apr 2026

    An arbitrary file overwrite vulnerability in RAREPROB SOLUTIONS PRIVATE LIMITED Video player Play All Videos v1.0.135 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure.

    Published: 31 Mar 2026
    7.6
    High

    CVE-2026-29870

    Last Modified: 3 Apr 2026

    A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file writes via the checkpoint_dir parameter in OfflineACE.run. The save_to_file method in ace/skillbook.py fails to normalize or validate filesystem paths, allowing traversal sequences to escape the intended checkpoint directory. This vulnerability allows attackers to overwrite arbitrary files accessible to the application process, potentially leading to application corruption, privilege escalation, or code execution depending on the deployment context.

    Published: 31 Mar 2026
    8.8
    High

    CVE-2026-5287

    Last Modified: 2 Apr 2026

    Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)

    Published: 31 Mar 2026
    8.8
    High

    CVE-2026-5286

    Last Modified: 2 Apr 2026

    Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

    Published: 31 Mar 2026
    8.8
    High

    CVE-2026-5285

    Last Modified: 2 Apr 2026

    Use after free in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 31 Mar 2026
    7.5
    High

    CVE-2026-5284

    Last Modified: 2 Apr 2026

    Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

    Published: 31 Mar 2026
    6.5
    Medium

    CVE-2026-5283

    Last Modified: 2 Apr 2026

    Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 31 Mar 2026
    8.1
    High

    CVE-2026-5282

    Last Modified: 2 Apr 2026

    Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

    Published: 31 Mar 2026
    8.8
    High

    CVE-2026-5280

    Last Modified: 18 Apr 2026

    Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 31 Mar 2026
    8.8
    High

    CVE-2026-5279

    Last Modified: 2 Apr 2026

    Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 31 Mar 2026
    8.8
    High

    CVE-2026-5278

    Last Modified: 2 Apr 2026

    Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

    Published: 31 Mar 2026
    7.5
    High

    CVE-2026-5277

    Last Modified: 2 Apr 2026

    Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

    Published: 31 Mar 2026
    6.5
    Medium

    CVE-2026-5276

    Last Modified: 2 Apr 2026

    Insufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

    Published: 31 Mar 2026
    8.8
    High

    CVE-2026-5275

    Last Modified: 2 Apr 2026

    Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

    Published: 31 Mar 2026
    8.8
    High

    CVE-2026-5274

    Last Modified: 2 Apr 2026

    Integer overflow in Codecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

    Published: 31 Mar 2026
    6.3
    Medium

    CVE-2026-5273

    Last Modified: 2 Apr 2026

    Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 31 Mar 2026
    8.8
    High

    CVE-2026-5272

    Last Modified: 2 Apr 2026

    Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

    Published: 31 Mar 2026