CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-4810 Remote Code Execution in Google Agent Development Kit (ADK) 13.04.2026 9.3
CVE-2026-34865 13.04.2026 10
CVE-2026-6154 Totolink A7100RU CGI cstecgi.cgi setWizardCfg os command injection 13.04.2026 9.3
CVE-2026-6155 Totolink A7100RU CGI cstecgi.cgi setWanCfg os command injection 13.04.2026 9.3
CVE-2026-6156 Totolink A7100RU CGI cstecgi.cgi setIpQosRules os command injection 13.04.2026 9.3
CVE-2026-6139 Totolink A7100RU CGI cstecgi.cgi UploadOpenVpnCert os command injection 13.04.2026 9.3
CVE-2026-6140 Totolink A7100RU CGI cstecgi.cgi UploadFirmwareFile os command injection 13.04.2026 9.3
CVE-2026-6138 Totolink A7100RU CGI cstecgi.cgi setAccessDeviceCfg os command injection 13.04.2026 9.3
CVE-2026-6132 Totolink A7100RU CGI cstecgi.cgi setLedCfg os command injection 12.04.2026 9.3
CVE-2026-6131 Totolink A7100RU CGI cstecgi.cgi setTracerouteCfg os command injection 12.04.2026 9.3
CVE-2019-25709 CF Image Hosting Script 1.6.5 Unauthorized Database Access 12.04.2026 9.3
CVE-2026-6115 Totolink A7100RU CGI cstecgi.cgi setAppCfg os command injection 12.04.2026 9.3
CVE-2026-6116 Totolink A7100RU CGI cstecgi.cgi setDiagnosisCfg os command injection 13.04.2026 9.3
CVE-2026-6112 Totolink A7100RU CGI cstecgi.cgi setRadvdCfg os command injection 12.04.2026 9.3
CVE-2026-6113 Totolink A7100RU CGI cstecgi.cgi setTtyServiceCfg os command injection 12.04.2026 9.3
CVE-2026-6114 Totolink A7100RU CGI cstecgi.cgi setNetworkCfg os command injection 12.04.2026 9.3
CVE-2026-31845 11.04.2026 9.3
CVE-2026-4149 Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability 11.04.2026 10
CVE-2026-5058 aws-mcp-server Command Injection Remote Code Execution Vulnerability 11.04.2026 9.8
CVE-2026-5059 aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability 11.04.2026 9.8
CVE-2026-40189 goshs has a file-based ACL authorization bypass in goshs state-changing routes 10.04.2026 9.3
CVE-2026-40175 Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain 13.04.2026 10
CVE-2026-40177 Password bypass when 2FA is activated 10.04.2026 9.3
CVE-2026-33707 Weak Password Recovery Mechanism for Forgotten Password in chamilo/chamilo-lms 10.04.2026 9.4
CVE-2026-33698 Chamilo LMS affected by unauthenticated RCE in main/install folder 10.04.2026 9.3
CVE-2026-32892 OS Command Injection in Chamilo LMS 1.11.36 10.04.2026 9.1
CVE-2026-40157 PraisonAI affected by arbitrary file write via path traversal in `praisonai recipe unpack` 10.04.2026 9.4
CVE-2026-5412 Juju CloudSpec API could leak senstive information 10.04.2026 9.9
CVE-2026-1115 Stored XSS in parisneo/lollms 10.04.2026 9.6
CVE-2026-6028 Totolink A7100RU CGI cstecgi.cgi setPptpServerCfg os command injection 10.04.2026 9.3
CVE-2026-6029 Totolink A7100RU CGI cstecgi.cgi setVpnAccountCfg os command injection 10.04.2026 9.3
CVE-2026-6026 Totolink A7100RU CGI cstecgi.cgi setPortalConfWeChat os command injection 10.04.2026 9.3
CVE-2026-6027 Totolink A7100RU CGI cstecgi.cgi setUrlFilterRules os command injection 10.04.2026 9.3
CVE-2026-6025 Totolink A7100RU CGI cstecgi.cgi setSyslogCfg os command injection 10.04.2026 9.3
CVE-2026-5996 Totolink A7100RU CGI cstecgi.cgi setAdvancedInfoShow os command injection 10.04.2026 9.3
CVE-2026-5997 Totolink A7100RU CGI cstecgi.cgi setLoginPasswordCfg os command injection 10.04.2026 9.3
CVE-2026-5993 Totolink A7100RU CGI cstecgi.cgi setWiFiGuestCfg os command injection 10.04.2026 9.3
CVE-2026-5994 Totolink A7100RU CGI cstecgi.cgi setTelnetCfg os command injection 10.04.2026 9.3
CVE-2026-5995 Totolink A7100RU CGI cstecgi.cgi setMiniuiHomeInfoShow os command injection 10.04.2026 9.3
CVE-2026-34424 Smart Slider 3 Pro 3.5.1.35 Supply Chain Attack Remote Access Toolkit 09.04.2026 9.3
CVE-2026-33771 CTP OS: Configuring password requirements does not work which permits the use of weak passwords 09.04.2026 9.1
CVE-2026-33784 JSI Virtual Lightweight Collector: Default password is not required to be changed which allows unauthorized high-privileged access 09.04.2026 9.3
CVE-2026-40154 PraisonAI Affected by Untrusted Remote Template Code Execution 10.04.2026 9.3
CVE-2026-40111 PraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py) 09.04.2026 9.3
CVE-2026-5977 Totolink A7100RU CGI cstecgi.cgi setWiFiBasicCfg os command injection 09.04.2026 9.3
CVE-2026-5978 Totolink A7100RU CGI cstecgi.cgi setWiFiAclRules os command injection 09.04.2026 9.3
CVE-2026-5976 Totolink A7100RU CGI cstecgi.cgi setStorageCfg os command injection 09.04.2026 9.3
CVE-2025-13926 Contemporary Controls BASC 20T Reliance on Untrusted Inputs in a Security Decision 10.04.2026 9.3
CVE-2026-40088 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai 09.04.2026 9.7
CVE-2026-40089 Sonicverse has Server-Side Request Forgery via user-controlled URLs in dashboard API client 09.04.2026 9.9
CVE-2026-5194 wolfSSL ECDSA Certificate Verification 10.04.2026 9.3
CVE-2026-5975 Totolink A7100RU CGI cstecgi.cgi setDmzCfg os command injection 09.04.2026 9.3
CVE-2026-28205 Initialization of a resource with an insecure default in OpenPLC_V3 10.04.2026 9.2
CVE-2026-34971 Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Cranelift 09.04.2026 9
CVE-2026-34987 Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access 10.04.2026 9
CVE-2026-35556 Plaintext storage of a password in OpenPLC_V3 10.04.2026 9.2
CVE-2026-39912 v2board / Xboard Authentication Token Exposure via loginWithMailLink 09.04.2026 9.1
CVE-2026-39980 OpenCTI affected by RCE via notifier template 09.04.2026 9.1
CVE-2026-39987 marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass 09.04.2026 9.3
CVE-2025-62718 Axios has a NO_PROXY Hostname Normalization Bypass Leads to SSRF 09.04.2026 9.3
CVE-2026-34177 VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf 09.04.2026 9.1
CVE-2026-34178 Importing a crafted backup leads to project restriction bypass 09.04.2026 9.1
CVE-2026-34179 Update of type field in restricted TLS certificate allows privilege escalation to cluster admin 09.04.2026 9.1
CVE-2026-5852 Totolink A7100RU CGI cstecgi.cgi setIptvCfg os command injection 09.04.2026 9.3
CVE-2026-5853 Totolink A7100RU CGI cstecgi.cgi setIpv6LanCfg os command injection 09.04.2026 9.3
CVE-2026-5854 Totolink A7100RU CGI cstecgi.cgi setWiFiEasyCfg os command injection 09.04.2026 9.3
CVE-2026-5850 Totolink A7100RU CGI cstecgi.cgi setVpnPassCfg os command injection 09.04.2026 9.3
CVE-2026-5851 Totolink A7100RU CGI cstecgi.cgi setUPnPCfg os command injection 09.04.2026 9.3
CVE-2026-1830 Quick Playground <= 1.3.1 - Missing Authorization to Unauthenticated Arbitrary File Upload 09.04.2026 9.8
CVE-2026-3199 Nexus Repository 3 - Authenticated Remote Code Execution via Task Property Injection 09.04.2026 9.4
CVE-2026-40035 Unfurl - Werkzeug Debugger Exposure via String Config Parsing 09.04.2026 9.3
CVE-2026-39860 Nix sandbox escape: file write via symlink at FOD `.tmp` copy destination 09.04.2026 9
CVE-2026-39888 PraisonAIAgents has a sandbox escape via exception frame traversal in `execute_code` (subprocess mode) 09.04.2026 10
CVE-2026-39890 PraisonAI Affected by Remote Code Execution via YAML Deserialization in Agent Definition Loading 09.04.2026 9.8
CVE-2026-2942 ProSolution WP Client <= 1.9.9 - Unauthenticated Arbitrary File Upload via proSol_fileUploadProcess 08.04.2026 9.8
CVE-2025-14815 Information Disclosure, Tampering, and Denial-of-Service Vulnerabilities in GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, GENESIS, and MC Works64 08.04.2026 9.3
CVE-2025-14816 Information Disclosure, Tampering, and Denial-of-Service Vulnerabilities in GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, GENESIS, and MC Works64 08.04.2026 9.3
CVE-2026-25776 08.04.2026 9.3
CVE-2026-3535 DSGVO Google Web Fonts GDPR <= 1.1 - Unauthenticated Arbitrary File Upload via 'fonturl' Parameter 08.04.2026 9.8
CVE-2026-4003 Users manager – PN <= 1.1.15 - Unauthenticated Privilege Escalation via Account Takeover via 'userspn_form_save' AJAX Action 08.04.2026 9.8
CVE-2026-3296 Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata 08.04.2026 9.8
CVE-2026-1346 Security Vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 09.04.2026 9.3
CVE-2026-34078 Flatpak has a complete sandbox escape leading to host file access and code execution in the host context 11.04.2026 9.3
CVE-2026-39846 SiYuan affected by Remote Code Execution in the Electron desktop client via stored XSS in synced table captions 08.04.2026 9.1
CVE-2026-39847 Emmett has a path traversal in internal assets handler 08.04.2026 9.1
CVE-2026-34580 Botan has a certificate authentication bypass due to trust anchor confusion 09.04.2026 9.3
CVE-2026-33439 Pre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAM 08.04.2026 9.3
CVE-2026-39397 @delmaredigital/payload-puc is missing authorization on /api/puck/* CRUD endpoints allows unauthenticated access to Puck-registered collections 07.04.2026 9.4
CVE-2026-39382 dbt has a Command Injection in Reusable Workflow via Unsanitized comment-body Output 08.04.2026 9.3
CVE-2026-39322 PolarLearn: Any password authenticates banned accounts and grants API access 09.04.2026 9.2
CVE-2026-39355 Genealogy is Missing Authorization in `TeamController::transferOwnership()` Allows Any Authenticated User to Hijack Any Team (Broken Access Control) 08.04.2026 10
CVE-2026-39324 Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization 08.04.2026 9.3
CVE-2026-39337 ChurchCRM Affected by Unauthenticated RCE in Install Wizard 07.04.2026 10
CVE-2026-39339 ChurchCRM has an API Authentication Bypass 07.04.2026 9.1
CVE-2026-39342 ChurchCRM has a SQL injection searchwhat parameter via QueryView.php 09.04.2026 9.4
CVE-2026-35573 ChurchCRM has a Path traversal leads to RCE 08.04.2026 9.1
CVE-2026-23696 Windmill < 1.603.3 File Ownership Handling SQLi RCE 08.04.2026 9.4
CVE-2026-35614 Frappe has a SQL injection in bulk_update 09.04.2026 9.3
CVE-2026-35615 PraisonAI has a Path Traversal in FileTools 09.04.2026 9.2
CVE-2026-39305 Arbitrary File Write / Path Traversal in Action Orchestrator 07.04.2026 9
CVE-2026-4631 Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection 10.04.2026 9.8
CVE-2026-35580 Emissary has GitHub Actions Shell Injection via Workflow Inputs 07.04.2026 9.1
CVE-2026-35490 changedetection.io has an Authentication Bypass via Decorator Ordering 09.04.2026 9.8
CVE-2026-20889 08.04.2026 9.8
CVE-2026-20911 08.04.2026 9.8
CVE-2026-21413 08.04.2026 9.8
CVE-2026-5627 Path Traversal in mintplex-labs/anything-llm 07.04.2026 9.1
CVE-2021-4473 Tianxin Internet Behavior Management System Command Injection via toQuery.php 08.04.2026 9.3
CVE-2026-22679 Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint 07.04.2026 9.3
CVE-2025-39666 omd: Local privilege escalation when executing omd commands as root 07.04.2026 9.3
CVE-2026-1114 Improper Access Control via Weak JWT Token in parisneo/lollms 07.04.2026 9.8
CVE-2026-0740 Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload 08.04.2026 9.8
CVE-2026-35471 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs 07.04.2026 9.8
CVE-2026-35392 goshs has an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload 07.04.2026 9.8
CVE-2026-35393 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload 08.04.2026 9.8
CVE-2026-35459 pyLoad has SSRF fix bypass via HTTP redirect 07.04.2026 9.3
CVE-2026-35022 Anthropic Claude Code & Agent SDK OS Command Injection via Authentication Helper 07.04.2026 9.3
CVE-2026-35178 Workbench Affected by Remote Code Execution (RCE) via Malicious Cookie in Timezone Conversion 07.04.2026 9.3

Latest Updates

CVE Title Updated Score
CVE-2025-66769 13.04.2026
CVE-2025-69624 13.04.2026
CVE-2025-69627 13.04.2026
CVE-2026-6184 code-projects Simple Content Management System welcome.php cross site scripting 13.04.2026
CVE-2026-6186 UTT HiPER 1200GW formNatStaticMap strcpy buffer overflow 13.04.2026
CVE-2025-66236 Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI 13.04.2026
CVE-2026-1462 Safe Mode Bypass in keras-team/keras 13.04.2026
CVE-2026-30997 13.04.2026
CVE-2026-30998 13.04.2026
CVE-2026-30999 13.04.2026
CVE-2026-33858 Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API 13.04.2026
CVE-2026-36941 13.04.2026
CVE-2026-6182 code-projects Simple Content Management System login.php sql injection 13.04.2026
CVE-2026-6183 code-projects Simple Content Management System index.php sql injection 13.04.2026
CVE-2026-29628 13.04.2026
CVE-2026-31281 13.04.2026
CVE-2026-31282 13.04.2026
CVE-2026-31283 13.04.2026
CVE-2026-36942 13.04.2026
CVE-2026-36943 13.04.2026
CVE-2026-36944 13.04.2026
CVE-2026-36945 13.04.2026
CVE-2026-31414 netfilter: nf_conntrack_expect: use expect->helper 13.04.2026
CVE-2026-31415 ipv6: avoid overflows in ip6_datagram_send_ctl() 13.04.2026
CVE-2026-31416 netfilter: nfnetlink_log: account for netlink header size 13.04.2026
CVE-2026-31417 net/x25: Fix overflow when accumulating packets 13.04.2026
CVE-2026-31418 netfilter: ipset: drop logically empty buckets in mtype_del 13.04.2026
CVE-2026-31419 net: bonding: fix use-after-free in bond_xmit_broadcast() 13.04.2026
CVE-2026-31420 bridge: mrp: reject zero test interval to avoid OOM panic 13.04.2026
CVE-2026-31421 net/sched: cls_fw: fix NULL pointer dereference on shared blocks 13.04.2026
CVE-2026-31422 net/sched: cls_flow: fix NULL pointer dereference on shared blocks 13.04.2026
CVE-2026-31423 net/sched: sch_hfsc: fix divide-by-zero in rtsc_min() 13.04.2026
CVE-2026-31424 netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP 13.04.2026
CVE-2026-31425 rds: ib: reject FRMR registration before IB connection is established 13.04.2026
CVE-2026-31426 ACPI: EC: clean up handlers on probe failure in acpi_ec_setup() 13.04.2026
CVE-2026-31427 netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp 13.04.2026
CVE-2026-31428 netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD 13.04.2026
CVE-2026-36946 13.04.2026
CVE-2026-36947 13.04.2026
CVE-2026-34476 Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server 13.04.2026
CVE-2026-36920 13.04.2026
CVE-2026-36922 13.04.2026
CVE-2026-36923 13.04.2026
CVE-2026-36872 13.04.2026
CVE-2026-36873 13.04.2026
CVE-2026-36874 13.04.2026
CVE-2026-36919 13.04.2026
CVE-2026-2728 13.04.2026
CVE-2026-6204 13.04.2026
CVE-2025-15632 1Panel-dev MaxKB MdPreview chat.ts cross site scripting 13.04.2026
CVE-2026-35337 Apache Storm Client: RCE through Unsafe Deserialization via Kerberos TGT Credential Handling 13.04.2026
CVE-2026-35565 Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Storm UI 13.04.2026
CVE-2026-4810 Remote Code Execution in Google Agent Development Kit (ADK) 13.04.2026
CVE-2026-0232 Cortex XDR Agent: Local Administrator can disable the agent on Windows 13.04.2026
CVE-2026-0233 Autonomous Digital Experience Manager: Improper validation of ADEM certificate 13.04.2026
CVE-2026-0234 Cortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integration 13.04.2026
CVE-2025-15441 Form Maker < 1.15.38 - SQL Injection 13.04.2026
CVE-2026-34865 13.04.2026
CVE-2026-34866 13.04.2026 5.1
CVE-2026-3830 Product Filter for WooCommerce by WBW < 3.1.3 - Unauthenticated SQLi 13.04.2026
CVE-2026-40436 ZTE ZXEDM iEMS product has a password reset vulnerability 13.04.2026 7.1
CVE-2026-5085 Solstice::Session versions through 1440 for Perl generates session ids insecurely 13.04.2026
CVE-2026-5936 Server-Side Request Forgery (SSRF) via URL Parameter in Foxit PDF Services API 13.04.2026 8.5
CVE-2026-6166 code-projects Vehicle Showroom Management System UpdateVehicleFunction.php sql injection 13.04.2026
CVE-2026-6167 code-projects Faculty Management System subject-print.php sql injection 13.04.2026
CVE-2026-6168 TOTOLINK A7000R cstecgi.cgi setWiFiEasyGuestCfg stack-based overflow 13.04.2026
CVE-2026-21006 13.04.2026
CVE-2026-21007 13.04.2026
CVE-2026-21008 13.04.2026
CVE-2026-21009 13.04.2026
CVE-2026-21010 13.04.2026 6.6
CVE-2026-21011 13.04.2026
CVE-2026-21012 13.04.2026
CVE-2026-21013 13.04.2026
CVE-2026-21014 13.04.2026
CVE-2026-40447 13.04.2026 5.1
CVE-2026-6163 code-projects Lost and Found Thing Management catageory.php sql injection 13.04.2026
CVE-2026-6164 code-projects Lost and Found Thing Management addcat.php sql injection 13.04.2026
CVE-2026-6165 code-projects Vehicle Showroom Management System Login_check.php sql injection 13.04.2026
CVE-2026-21003 13.04.2026
CVE-2026-25205 13.04.2026 7.4
CVE-2026-25206 13.04.2026 6.7
CVE-2026-25207 13.04.2026 7.4
CVE-2026-25208 13.04.2026 8.1
CVE-2026-25209 13.04.2026 6.5
CVE-2026-34849 13.04.2026 2.5
CVE-2026-34854 13.04.2026 5.7
CVE-2026-34855 13.04.2026 5.7
CVE-2026-34857 13.04.2026 4.7
CVE-2026-34858 13.04.2026 4.1
CVE-2026-34859 13.04.2026 5.9
CVE-2026-34861 13.04.2026 6.3
CVE-2026-34862 13.04.2026 6.3
CVE-2026-34863 13.04.2026 6.7
CVE-2026-34864 13.04.2026 6.8
CVE-2026-35553 13.04.2026 6.7
CVE-2026-40446 13.04.2026 6.9
CVE-2026-6158 Totolink N300RH upgrade.so setUpgradeUboot os command injection 13.04.2026
CVE-2026-6159 code-projects Simple ChatBox Endpoint insert.php cross site scripting 13.04.2026
CVE-2026-6160 code-projects Simple ChatBox Endpoint chatbox.sql SimpleChatbox_PHP file information disclosure 13.04.2026
CVE-2026-6161 code-projects Simple ChatBox Endpoint insert.php sql injection 13.04.2026
CVE-2026-6162 PHPGurukul Company Visitor Management System bwdates-reports-details.php cross site scripting 13.04.2026
CVE-2026-28553 13.04.2026 6.9
CVE-2026-34850 13.04.2026 1.9
CVE-2026-34851 13.04.2026 2.2
CVE-2026-34852 13.04.2026 6.1
CVE-2026-34853 13.04.2026 7.7
CVE-2026-34856 13.04.2026 7.3
CVE-2026-34860 13.04.2026 4.1
CVE-2026-34867 13.04.2026 5.6
CVE-2026-6153 code-projects Vehicle Showroom Management System StaffDetailsFunction.php sql injection 13.04.2026
CVE-2026-6154 Totolink A7100RU CGI cstecgi.cgi setWizardCfg os command injection 13.04.2026
CVE-2026-6155 Totolink A7100RU CGI cstecgi.cgi setWanCfg os command injection 13.04.2026
CVE-2026-6156 Totolink A7100RU CGI cstecgi.cgi setIpQosRules os command injection 13.04.2026
CVE-2026-6157 Totolink A800R app.so setAppEasyWizardConfig buffer overflow 13.04.2026
CVE-2026-6150 code-projects Simple Laundry System checkupdatestatus.php cross site scripting 13.04.2026
CVE-2026-6151 code-projects Vehicle Showroom Management System PaymentStatusFunction.php sql injection 13.04.2026
CVE-2026-6152 code-projects Vehicle Showroom Management System StaffAddingFunction.php sql injection 13.04.2026
CVE-2026-6179 Stored Cross Site Scripting in NightWolf Penetration Testing Platform 13.04.2026
CVE-2026-6143 farion1231 cc-switch ProxyServer server.rs cross-domain policy 13.04.2026
CVE-2026-6148 code-projects Vehicle Showroom Management System MonthTotalReportUpdateFunction.php sql injection 13.04.2026
CVE-2026-6149 code-projects Vehicle Showroom Management System BookVehicleFunction.php sql injection 13.04.2026
CVE-2026-25204 13.04.2026 6.2
CVE-2026-6139 Totolink A7100RU CGI cstecgi.cgi UploadOpenVpnCert os command injection 13.04.2026
CVE-2026-6140 Totolink A7100RU CGI cstecgi.cgi UploadFirmwareFile os command injection 13.04.2026
CVE-2026-6141 danielmiessler Personal_AI_Infrastructure parse_url.ts os command injection 13.04.2026
CVE-2026-6142 tushar-2223 Hotel Management System roomdelete.php sql injection 13.04.2026
CVE-2026-6138 Totolink A7100RU CGI cstecgi.cgi setAccessDeviceCfg os command injection 13.04.2026
CVE-2026-6137 Tenda F451 AdvSetWan fromAdvSetWan stack-based overflow 12.04.2026
CVE-2026-6136 Tenda F451 L7Im frmL7ImForm stack-based overflow 12.04.2026
CVE-2026-6135 Tenda F451 SetIpBind fromSetIpBind stack-based overflow 13.04.2026
CVE-2026-6134 Tenda F451 qossetting fromqossetting stack-based overflow 12.04.2026
CVE-2026-6133 Tenda F451 SafeUrlFilter fromSafeUrlFilter stack-based overflow 13.04.2026
CVE-2026-6132 Totolink A7100RU CGI cstecgi.cgi setLedCfg os command injection 12.04.2026
CVE-2026-6131 Totolink A7100RU CGI cstecgi.cgi setTracerouteCfg os command injection 12.04.2026
CVE-2026-6130 chatboxai chatbox Model Context Protocol Server Management System ipc-stdio-transport.ts StdioClientTransport os command injection 12.04.2026
CVE-2026-6129 zhayujie chatgpt-on-wechat CowAgent Agent Mode Service missing authentication 12.04.2026
CVE-2026-40394 12.04.2026 4
CVE-2026-40395 12.04.2026 4
CVE-2026-40396 12.04.2026 4
CVE-2026-40393 12.04.2026 8.1