| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-3530 | OpenID Connect / OAuth client - Moderately critical - Server-side request forgery, Information disclosure - SA-CONTRIB-2026-025 | Drupal | OpenID Connect / OAuth client | - | - | 2026-03-26 20:03:40 | Deep Dive |
| CVE-2026-1995 | IDrive Cloud Backup Client for Windows contains a privilege escalation vulnerability | IDrive | IDrive Cloud Backup Client for Windows | - | - | 2026-03-24 18:00:16 | Deep Dive |
| CVE-2026-0609 | Logo Slider <= 4.9.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'logo-slider' Shortcode | logichunt | Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin | Medium | 6.4 | 2026-03-21 03:27:01 | Deep Dive |
| CVE-2026-2809 | Endpoint DLP Driver DLL | Netskope | Endpoint DLP Module for Netskope Client | - | - | 2026-03-17 20:20:19 | Deep Dive |
| CVE-2025-15584 | Endpoint DLP Driver Filter Communication Port Integer Overflow | Netskope | Endpoint DLP Module for Netskope Client | - | - | 2026-03-17 18:55:59 | Deep Dive |
| CVE-2026-32401 | WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.9 - Local File Inclusion vulnerability | BoldGrid | Client Invoicing by Sprout Invoices | 中危 | - | 2026-03-13 11:42:13 | Deep Dive |
| CVE-2026-23656 | Windows App Installer Spoofing Vulnerability | Microsoft | Windows App Client for Windows Desktop | Medium | 5.9 | 2026-03-10 17:05:05 | Deep Dive |
| CVE-2026-30896 | Qsee Client 代码问题漏洞 | Qsee | Qsee Client | - | - | 2026-03-09 05:01:16 | Deep Dive |
| CVE-2026-3764 | SourceCodester Client Database Management System superadmin_user_update.php improper authorization | SourceCodester | Client Database Management System | High | 7.3 | 2026-03-08 19:32:07 | Deep Dive |
| CVE-2026-3762 | SourceCodester Client Database Management System Endpoint superadmin_delete_manager.php improper authorization | SourceCodester | Client Database Management System | High | 7.3 | 2026-03-08 18:32:14 | Deep Dive |
| CVE-2026-3761 | SourceCodester Client Database Management System Endpoint superadmin_user_delete.php improper authorization | SourceCodester | Client Database Management System | Medium | 5.4 | 2026-03-08 18:32:11 | Deep Dive |
| CVE-2026-3734 | SourceCodester Client Database Management System Endpoint fetch_manager_details.php improper authorization | SourceCodester | Client Database Management System | High | 7.3 | 2026-03-08 13:02:09 | Deep Dive |
| CVE-2026-30785 | RustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Poly1305) | rustdesk-client | RustDesk Client | 中危 | - | 2026-03-05 16:04:36 | Deep Dive |
| CVE-2026-30783 | RustDesk Client Can Orphan API Channel to Ignore All Admin Commands and ACL Policies | rustdesk-client | RustDesk Client | 高危 | - | 2026-03-05 15:52:22 | Deep Dive |
| CVE-2026-30789 | RustDesk Client Generates Auth Proof Without Client-Side Nonce, Enabling Replay Attacks | rustdesk-client | RustDesk Client | 中危 | - | 2026-03-05 15:41:51 | Deep Dive |
| CVE-2026-30798 | RustDesk Client Accepts Unauthenticated stop-service Command via Strategy Payload | rustdesk-client | RustDesk Client | 高危 | - | 2026-03-05 15:38:49 | Deep Dive |
| CVE-2026-30797 | RustDesk rustdesk://config/ URI Silently Re-homes Client to Attacker-Controlled Server | rustdesk-client | RustDesk Client | 高危 | - | 2026-03-05 15:35:09 | Deep Dive |
| CVE-2026-30795 | RustDesk HTTP Client Silently Accepts Invalid TLS Certificates After Handshake Failure | rustdesk-client | RustDesk Client | 高危 | - | 2026-03-05 15:27:17 | Deep Dive |
| CVE-2026-30794 | RustDesk HTTP Client Silently Accepts Invalid TLS Certificates After Handshake Failure | rustdesk-client | RustDesk Client | 超危 | - | 2026-03-05 15:24:35 | Deep Dive |
| CVE-2026-30793 | RustDesk Flutter URI Handler Sets Permanent Password Without Privilege Check or User Confirmation | rustdesk-client | RustDesk Client | 高危 | - | 2026-03-05 15:21:03 | Deep Dive |