| CVE-2026-7164 |
pf can overflow the stack parsing crafted SCTP packets |
30.04.2026 |
|
| CVE-2024-39847 |
Arbitrary File Read and Server Side Request Forgery via XML External Entities in 4D Server SOAP |
30.04.2026 |
|
| CVE-2026-42511 |
Remote code execution via malicious DHCP options |
30.04.2026 |
|
| CVE-2026-42798 |
|
30.04.2026 |
4 |
| CVE-2026-7270 |
Local privilege escalation via execve() |
30.04.2026 |
|
| CVE-2026-41226 |
|
30.04.2026 |
|
| CVE-2026-5299 |
Uncontrolled Recursion in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-5401 |
Uncontrolled Recursion in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-5402 |
Heap-based Buffer Overflow in Wireshark |
30.04.2026 |
8.8 |
| CVE-2026-5406 |
Uncontrolled Recursion in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-5407 |
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-5408 |
Uncontrolled Recursion in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-5409 |
Uncontrolled Recursion in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-5653 |
Heap-based Buffer Overflow in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-5654 |
Stack-based Buffer Overflow in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-5655 |
Use After Free in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-5657 |
Double Free in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6519 |
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6520 |
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6521 |
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6522 |
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6523 |
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6524 |
Access of Uninitialized Pointer in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6526 |
NULL Pointer Dereference in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6527 |
Uncontrolled Recursion in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6528 |
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6529 |
Heap-based Buffer Overflow in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6530 |
Heap-based Buffer Overflow in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6531 |
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6532 |
Buffer Over-read in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6533 |
Improperly Controlled Sequential Memory Allocation in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6534 |
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6535 |
Improperly Controlled Sequential Memory Allocation in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6536 |
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6537 |
Stack-based Buffer Overflow in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6538 |
Stack-based Buffer Overflow in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6867 |
Improperly Controlled Sequential Memory Allocation in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6869 |
Improperly Controlled Sequential Memory Allocation in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-6870 |
Access of Uninitialized Pointer in Wireshark |
30.04.2026 |
5.5 |
| CVE-2025-13030 |
|
30.04.2026 |
7.1 |
| CVE-2026-6868 |
Stack-based Buffer Overflow in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-7375 |
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-7376 |
NULL Pointer Dereference in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-7378 |
Heap-based Buffer Overflow in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-7379 |
Missing Release of Memory after Effective Lifetime in Wireshark |
30.04.2026 |
5.5 |
| CVE-2026-7470 |
Tenda 4G300 SafeMacFilter sub_427C3C stack-based overflow |
30.04.2026 |
|
| CVE-2026-7469 |
Tenda 4G300 DelFil sub_425A28 command injection |
30.04.2026 |
|
| CVE-2026-7447 |
SourceCodester Pet Grooming Management Software update_customer.php sql injection |
30.04.2026 |
|
| CVE-2026-7468 |
1024-lab smart-admin Demo Site index.html access control |
30.04.2026 |
|
| CVE-2026-7445 |
ZachHandley ZMCPTools MCP Log Resource ResourceManager.ts path traversal |
29.04.2026 |
|
| CVE-2026-7446 |
VetCoders mcp-server-semgrep MCP index.ts create_rule os command injection |
30.04.2026 |
|
| CVE-2026-7443 |
BurtTheCoder mcp-dnstwist MCP index.ts fuzz_domain os command injection |
29.04.2026 |
|
| CVE-2026-6221 |
|
29.04.2026 |
|
| CVE-2026-7381 |
Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting |
29.04.2026 |
|
| CVE-2026-7419 |
UTT HiPER 1250GW formTaskEdit_ap strcpy buffer overflow |
29.04.2026 |
|
| CVE-2026-7420 |
UTT HiPER 1250GW ConfigAdvideo strcpy buffer overflow |
29.04.2026 |
|
| CVE-2026-7417 |
Algovate xhs-mcp MCP mcp.server.ts xhs_publish_content server-side request forgery |
29.04.2026 |
|
| CVE-2026-7418 |
UTT HiPER 1250GW NTP strcpy buffer overflow |
29.04.2026 |
|
| CVE-2026-7416 |
PolarVista xcode-mcp-server MCP index.ts run_tests os command injection |
29.04.2026 |
|
| CVE-2026-7409 |
SourceCodester Pizzafy Ecommerce System ajax.php save_user sql injection |
29.04.2026 |
|
| CVE-2026-7410 |
SourceCodester Pizzafy Ecommerce System ajax.php add_to_cart sql injection |
29.04.2026 |
|
| CVE-2026-7407 |
SourceCodester Pizzafy Ecommerce System Setting ajax.php save_settings sql injection |
29.04.2026 |
|
| CVE-2026-7408 |
SourceCodester Pizzafy Ecommerce System ajax.php save_menu sql injection |
29.04.2026 |
|
| CVE-2025-50328 |
|
29.04.2026 |
|
| CVE-2026-1858 |
wget2 Improper Certificate Validation |
29.04.2026 |
4.8 |
| CVE-2026-7403 |
geldata gel-mcp server.py fetch_rule path traversal |
29.04.2026 |
|
| CVE-2026-7404 |
getsimpletool mcpo-simple-server base_manager.py delete_shared_prompt path traversal |
29.04.2026 |
|
| CVE-2018-25298 |
Merge PACS 7.0 Cross-Site Request Forgery via merge-viewer |
29.04.2026 |
|
| CVE-2018-25299 |
Prime95 29.4b8 Local Buffer Overflow via SEH |
29.04.2026 |
|
| CVE-2018-25300 |
XATABoost CMS 1.0.0 SQL Injection via news.php |
29.04.2026 |
|
| CVE-2018-25301 |
Easy MPEG to DVD Burner 1.7.11 SEH Local Buffer Overflow |
29.04.2026 |
|
| CVE-2018-25302 |
Allok AVI to DVD SVCD VCD Converter 4.0.1217 Buffer Overflow SEH |
29.04.2026 |
|
| CVE-2018-25303 |
Allok Video to DVD Burner 2.6.1217 Buffer Overflow SEH |
29.04.2026 |
|
| CVE-2018-25304 |
Free Download Manager 2.0 Built 417 Local Buffer Overflow SEH |
29.04.2026 |
|
| CVE-2018-25305 |
librsvg2-bin 2.40.13 Buffer Overflow via Malformed SVG |
29.04.2026 |
|
| CVE-2018-25306 |
PDFunite 0.41.0 Buffer Overflow via Malformed PDF |
29.04.2026 |
|
| CVE-2018-25307 |
SysGauge Pro 4.6.12 Local Buffer Overflow SEH |
29.04.2026 |
|
| CVE-2018-25308 |
BuddyPress Xprofile Custom Fields Type 2.6.3 Remote Code Execution |
29.04.2026 |
|
| CVE-2018-25309 |
MyBB Recent threads 17.0 Persistent Cross-Site Scripting |
29.04.2026 |
|
| CVE-2018-25310 |
VideoFlow Digital Video Protection DVP 10 Authenticated Remote Code Execution |
29.04.2026 |
|
| CVE-2018-25311 |
VideoFlow Digital Video Protection DVP 10 Authenticated Directory Traversal 2.10 (X-Prototype-Version: 1.6.0.2) |
29.04.2026 |
|
| CVE-2018-25312 |
LifeSize ClearSea 3.1.4 Directory Traversal Remote Code Execution |
29.04.2026 |
|
| CVE-2018-25313 |
SysGauge 4.5.18 Local Denial of Service via Proxy Configuration |
29.04.2026 |
|
| CVE-2018-25314 |
Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 Buffer Overflow |
29.04.2026 |
|
| CVE-2018-25315 |
Alloksoft Video joiner 4.6.1217 Buffer Overflow via License Name |
29.04.2026 |
|
| CVE-2018-25316 |
Tenda W308R v2 V5.07.48 Cookie Session Weakness DNS Change |
29.04.2026 |
|
| CVE-2018-25317 |
Tenda W3002R/A302/W309R V5.07.64_en Cookie Session Weakness DNS Change |
29.04.2026 |
|
| CVE-2018-25318 |
Tenda FH303/A300 V5.07.68_EN Cookie Session Weakness DNS Change |
29.04.2026 |
|
| CVE-2026-34965 |
Cockpit CMS Authenticated Remote Code Execution via Collections |
29.04.2026 |
8.8 |
| CVE-2026-7400 |
geekgod382 filesystem-mcp-server read_file_tool/write_file_tool server.py is_path_allowed path traversal |
29.04.2026 |
|
| CVE-2026-7401 |
SourceCodester CET Automated Grading System with AI Predictive Analytics Registration index.php register cross site scripting |
29.04.2026 |
|
| CVE-2026-7425 |
Out-of-Bounds Read in Router Advertisement Option Parser in FreeRTOS-Plus-TCP |
29.04.2026 |
6.5 |
| CVE-2026-7426 |
Out-of-Bounds Write via Unsanitized Prefix Length in Router Advertisement Processing in FreeRTOS-Plus-TCP |
29.04.2026 |
8.1 |
| CVE-2026-27105 |
|
29.04.2026 |
6.3 |
| CVE-2026-7398 |
florensiawidjaja BioinfoMCP Upload Endpoint app.py upload path traversal |
29.04.2026 |
|
| CVE-2026-7422 |
MAC Address Validation Bypass in FreeRTOS-Plus-TCP IPv4 and IPv6 Packet Processing |
29.04.2026 |
6.5 |
| CVE-2026-7423 |
Integer Underflow in ICMP Echo Reply Processing in FreeRTOS-Plus-TCP |
29.04.2026 |
5.3 |
| CVE-2026-7424 |
Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP |
29.04.2026 |
8.1 |
| CVE-2026-7466 |
AgentFlow Arbitrary Python Pipeline Execution via pipeline_path |
29.04.2026 |
|
| CVE-2026-26206 |
Wazuh: API brute-force protection bypass via race condition in login attempt tracking |
29.04.2026 |
6.5 |
| CVE-2026-28221 |
Wazuh: Pre-auth stack-based buffer overflow in wazuh-remoted print_hex_string() due to signed char promotion on x86_64 |
29.04.2026 |
6.5 |
| CVE-2026-30893 |
Wazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peer |
29.04.2026 |
9 |
| CVE-2026-41499 |
Wazuh: Multiple Heap-based NULL WRITE Buffer Underflows in parse_uname_string() |
29.04.2026 |
6.5 |
| CVE-2026-7397 |
NousResearch hermes-agent file_tools.py _check_sensitive_path symlink |
29.04.2026 |
|
| CVE-2026-7439 |
AgentFlow Local Web API Content-Type Validation Bypass |
29.04.2026 |
|
| CVE-2026-26015 |
Unauthenticated RCE in DocsGPT MCP STDIO Configuration |
29.04.2026 |
|
| CVE-2026-26204 |
Wazuh: Heap-based NULL WRITE Buffer Underflow in GetAlertData |
29.04.2026 |
4.4 |
| CVE-2026-5712 |
IdentityIQ Role Editor Incorrect Authorization Vulnerability |
30.04.2026 |
8 |
| CVE-2026-7394 |
SourceCodester Pizzafy Ecommerce System GET Parameter view_order.php sql injection |
29.04.2026 |
|
| CVE-2026-7396 |
NousResearch hermes-agent WeChat Work Platform Adapter wecom.py path traversal |
29.04.2026 |
|
| CVE-2026-6914 |
MD5 checksum creation may cause availability loss |
29.04.2026 |
|
| CVE-2026-6915 |
Flaw in the updateUser Command May Allow Unauthorized Configuration Change |
29.04.2026 |
|
| CVE-2026-7392 |
SourceCodester Pharmacy Sales and Inventory System ajax.php delete_supplier sql injection |
29.04.2026 |
|
| CVE-2026-7393 |
SourceCodester Pizzafy Ecommerce System File Extension admin_class_novo.php save_menu unrestricted upload |
29.04.2026 |
|
| CVE-2026-0204 |
|
30.04.2026 |
|
| CVE-2026-0205 |
|
29.04.2026 |
|
| CVE-2026-0206 |
|
29.04.2026 |
|
| CVE-2026-7391 |
SourceCodester Pharmacy Sales and Inventory System ajax.php save_supplier sql injection |
29.04.2026 |
|
| CVE-2025-56534 |
|
29.04.2026 |
|
| CVE-2025-56535 |
|
29.04.2026 |
|
| CVE-2025-56536 |
|
29.04.2026 |
|
| CVE-2025-56537 |
|
29.04.2026 |
|
| CVE-2026-2810 |
Endpoint DLP Driver Out-of-Bounds Read |
29.04.2026 |
|
| CVE-2026-30769 |
|
29.04.2026 |
|
| CVE-2026-37555 |
|
29.04.2026 |
|
| CVE-2026-40229 |
Helpy 2.8.0 - Stored XSS in post author display via PostsHelper |
29.04.2026 |
|
| CVE-2026-40230 |
Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering |
29.04.2026 |
|
| CVE-2026-42198 |
pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS |
29.04.2026 |
7.5 |
| CVE-2026-7389 |
EyouCMS common.php GetSortData sql injection |
29.04.2026 |
|
| CVE-2026-7390 |
SourceCodester Pharmacy Sales and Inventory System index.php customer cross site scripting |
29.04.2026 |
|
| CVE-2026-38991 |
|
29.04.2026 |
|
| CVE-2026-38993 |
|
29.04.2026 |
|
| CVE-2026-41940 |
cPanel and WHM Authentication Bypass via Login Flow |
30.04.2026 |
|
| CVE-2026-5166 |
Path Traversal in TUBITAK BILGEM's Pardus Software Center |
29.04.2026 |
9.6 |
| CVE-2026-6849 |
OS Command Injection in TUBITAK BILGEM's Pardus OS My Computer |
29.04.2026 |
8.8 |
| CVE-2026-7386 |
fatbobman mail-mcp-bridge mail_mcp_server.py path traversal |
29.04.2026 |
|
| CVE-2026-7388 |
EyouCMS Template File FilemanagerLogic.php editFile code injection |
29.04.2026 |
|
| CVE-2026-25852 |
|
29.04.2026 |
|
| CVE-2026-36837 |
|
29.04.2026 |
|
| CVE-2026-36841 |
|
29.04.2026 |
|
| CVE-2026-38992 |
|
29.04.2026 |
|
| CVE-2026-41220 |
|
29.04.2026 |
|
| CVE-2026-41952 |
|
29.04.2026 |
|
| CVE-2026-5141 |
Improper Access Control in TUBITAK BILGEM's Pardus Software Center |
29.04.2026 |
8.8 |
| CVE-2026-5161 |
Improper Authentication in TUBITAK BILGEM's Pardus About |
29.04.2026 |
8.8 |
| CVE-2026-7111 |
Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption |
29.04.2026 |
|
| CVE-2026-7384 |
ezequiroga mcp-bases research_server.py search_papers path traversal |
29.04.2026 |
|
| CVE-2026-42519 |
|
29.04.2026 |
|
| CVE-2026-42520 |
|
29.04.2026 |
|
| CVE-2026-42521 |
|
29.04.2026 |
|
| CVE-2026-42522 |
|
29.04.2026 |
|
| CVE-2026-42523 |
|
29.04.2026 |
|
| CVE-2026-42524 |
|
29.04.2026 |
|
| CVE-2026-42525 |
|
29.04.2026 |
|
| CVE-2026-5140 |
Authorization Bypass in TUBITAK BILGEM's Pardus Update |
29.04.2026 |
8.8 |
| CVE-2026-22741 |
Static resource cache poisoning in Spring MVC and WebFlux |
29.04.2026 |
3.1 |
| CVE-2026-22745 |
CVE-2026-22745 : Denial of service in static resource handling on Windows platforms |
29.04.2026 |
5.3 |
| CVE-2026-2902 |
WP Meteor Website Speed Optimization Addon <= 3.4.16 - Unauthenticated Stored Cross-Site Scripting via Comment |
29.04.2026 |
6.1 |
| CVE-2026-42248 |
Missing Signature Verification for Updates in Ollama |
29.04.2026 |
|
| CVE-2026-42249 |
Remote Code Execution in Ollama via Update Mechanism |
29.04.2026 |
|