| CVE-2024-54011 |
Missing Error/Exception Handling |
28.04.2026 |
|
| CVE-2024-54012 |
Command Injection |
28.04.2026 |
|
| CVE-2024-54013 |
Authentication Bypass |
28.04.2026 |
|
| CVE-2026-40966 |
VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration |
28.04.2026 |
5.9 |
| CVE-2026-41525 |
|
28.04.2026 |
6.5 |
| CVE-2026-41526 |
|
28.04.2026 |
6.5 |
| CVE-2026-4805 |
Woostify <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lity.js Library via data-lity Attribute in Custom HTML Block |
28.04.2026 |
6.4 |
| CVE-2026-4911 |
Booking Package <= 1.7.06 - Unauthenticated Price Manipulation via 'amount' Parameter |
28.04.2026 |
5.3 |
| CVE-2026-7235 |
ErlichLiu claude-agent-sdk-master route.ts path traversal |
28.04.2026 |
|
| CVE-2026-7237 |
AgiFlow scaffold-mcp write-to-file Tool index.ts path traversal |
28.04.2026 |
|
| CVE-2026-7238 |
code-projects Online Music Site AdminUpdateAlbum.php unrestricted upload |
28.04.2026 |
|
| CVE-2026-7240 |
Totolink A8000RU CGI cstecgi.cgi setVpnAccountCfg os command injection |
28.04.2026 |
|
| CVE-2026-40356 |
|
28.04.2026 |
5.9 |
| CVE-2026-40967 |
|
28.04.2026 |
8.6 |
| CVE-2026-5306 |
Check & Log Email < 2.0.13 - Unauthenticated Stored XSS |
28.04.2026 |
|
| CVE-2026-7229 |
code-projects Coaching Management System POST reply.php sql injection |
28.04.2026 |
|
| CVE-2026-7230 |
SourceCodester Safety Anger Pad cross site scripting |
28.04.2026 |
|
| CVE-2026-7233 |
Artifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds |
28.04.2026 |
|
| CVE-2026-7234 |
BrowserOperator browser-operator-core server.js startsWith path traversal |
28.04.2026 |
|
| CVE-2026-40355 |
|
28.04.2026 |
5.9 |
| CVE-2026-42510 |
|
28.04.2026 |
6.6 |
| CVE-2026-6551 |
Timeline Blocks for Gutenberg <= 1.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag' Block Attribute |
28.04.2026 |
6.4 |
| CVE-2026-6725 |
WPC Smart Messages for WooCommerce <= 4.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute |
28.04.2026 |
6.4 |
| CVE-2026-6809 |
Social Post Embed <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Threads Embed |
28.04.2026 |
6.4 |
| CVE-2026-7224 |
SourceCodester Pizzafy Ecommerce System ajax.php delete_cart sql injection |
28.04.2026 |
|
| CVE-2026-7225 |
SourceCodester Pizzafy Ecommerce System ajax.php delete_menu sql injection |
28.04.2026 |
|
| CVE-2026-7226 |
SourceCodester Pizzafy Ecommerce System ajax.php login2 sql injection |
28.04.2026 |
|
| CVE-2026-7227 |
SourceCodester Pizzafy Ecommerce System ajax.php login sql injection |
28.04.2026 |
|
| CVE-2026-7228 |
SourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injection |
28.04.2026 |
|
| CVE-2026-7219 |
Totolink N300RT formIpQoS buffer overflow |
28.04.2026 |
|
| CVE-2026-7220 |
jackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injection |
28.04.2026 |
|
| CVE-2026-7221 |
TencentCloudBase CloudBase-MCP open-url API Endpoint interactive-server.ts openUrl server-side request forgery |
28.04.2026 |
|
| CVE-2026-7222 |
code-projects Coaching Management System Complaint Form complaint.php cross site scripting |
28.04.2026 |
|
| CVE-2026-7223 |
BigSweetPotatoStudio HyperChat AI Proxy Middleware aiProxyMiddleware.mts fetch server-side request forgery |
28.04.2026 |
|
| CVE-2026-0711 |
|
28.04.2026 |
6.8 |
| CVE-2026-1460 |
|
28.04.2026 |
7.2 |
| CVE-2026-7215 |
egtai gmx-vmd-mcp VMD Launch mcp_server.py launch_vmd_gui_tool command injection |
28.04.2026 |
|
| CVE-2026-7216 |
donchelo processing-claude-mcp-bridge create_sketch Tool processing_server.py path traversal |
28.04.2026 |
|
| CVE-2026-7217 |
Deepractice PromptX Document File index.ts read_pdf absolute path traversal |
28.04.2026 |
|
| CVE-2026-7218 |
Totolink N300RT libapmib.so formWsc is_cmd_string_valid buffer overflow |
28.04.2026 |
|
| CVE-2026-7212 |
edvardlindelof notes-mcp notes_mcp.py path traversal |
28.04.2026 |
|
| CVE-2026-7213 |
ef10007 MLOps_MCP save_file Tool fastmcp_server.py path traversal |
28.04.2026 |
|
| CVE-2026-7214 |
eghuzefa engineer-your-data server.py file_inf path traversal |
28.04.2026 |
|
| CVE-2026-20766 |
Milesight Cameras Heap-based Buffer Overflow |
27.04.2026 |
|
| CVE-2026-32644 |
Milesight Cameras Use of Hard-coded Cryptographic Key |
27.04.2026 |
|
| CVE-2026-32649 |
Milesight Cameras OS Command Injection |
27.04.2026 |
|
| CVE-2026-7202 |
Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injection |
27.04.2026 |
|
| CVE-2026-7203 |
Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injection |
28.04.2026 |
|
| CVE-2026-7204 |
Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injection |
28.04.2026 |
|
| CVE-2026-7205 |
duartium papers-mcp-server main.py search_papers path traversal |
28.04.2026 |
|
| CVE-2026-7206 |
dubydu sqlite-mcp entry.py extract_to_json sql injection |
28.04.2026 |
|
| CVE-2026-7211 |
dvladimirov MCP Git Search API mcp_server.py GitSearchRequest command injection |
28.04.2026 |
|
| CVE-2026-27785 |
Milesight Cameras Use of Hard-coded Credentials |
27.04.2026 |
|
| CVE-2026-40973 |
|
27.04.2026 |
7 |
| CVE-2026-40974 |
|
27.04.2026 |
5 |
| CVE-2026-40975 |
|
27.04.2026 |
4.8 |
| CVE-2026-40976 |
|
27.04.2026 |
9.1 |
| CVE-2026-40977 |
|
27.04.2026 |
4.7 |
| CVE-2026-41362 |
OpenClaw 2026.2.19 < 2026.3.31 - Webhook Replay Dedupe Cache Event Suppression via Shared Authentication |
27.04.2026 |
|
| CVE-2026-41363 |
OpenClaw 2026.2.6 < 2026.3.28 - Arbitrary File Read via Feishu upload_image Parameter |
27.04.2026 |
|
| CVE-2026-41364 |
OpenClaw < 2026.3.31 - Arbitrary File Write via Symlink Following in SSH Sandbox Tar Upload |
27.04.2026 |
|
| CVE-2026-41365 |
OpenClaw < 2026.3.31 - Sender Allowlist Bypass via Graph API Thread History |
27.04.2026 |
|
| CVE-2026-41366 |
OpenClaw < 2026.3.31 - Arbitrary Host File Read via appendLocalMediaParentRoots Self-Whitelisting |
27.04.2026 |
|
| CVE-2026-41367 |
OpenClaw 2026.2.14 < 2026.3.28 - Policy Enforcement Bypass in Discord Component Interactions |
27.04.2026 |
|
| CVE-2026-41368 |
OpenClaw < 2026.3.28 - Environment Variable Disclosure via jq $ENV Filter Bypass |
27.04.2026 |
|
| CVE-2026-41369 |
OpenClaw < 2026.3.31 - Insufficient Environment Variable Sanitization in Host Execution |
27.04.2026 |
|
| CVE-2026-41370 |
OpenClaw < 2026.3.31 - Path Traversal via Inbound Channel Attachment Path in ACP Dispatch |
27.04.2026 |
|
| CVE-2026-41371 |
OpenClaw < 2026.3.28 - Privilege Escalation via chat.send Reset Command |
27.04.2026 |
|
| CVE-2026-41372 |
OpenClaw < 2026.4.2 - Loopback Protection Bypass via Trailing-Dot Localhost in CDP Discovery |
27.04.2026 |
|
| CVE-2026-7200 |
SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting |
27.04.2026 |
|
| CVE-2026-40972 |
|
27.04.2026 |
7.5 |
| CVE-2026-7196 |
CodeAstro Online Classroom guestdetails sql injection |
27.04.2026 |
|
| CVE-2026-7199 |
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection |
27.04.2026 |
|
| CVE-2026-28747 |
Milesight Cameras Authorization Bypass Through User-Controlled Key |
27.04.2026 |
|
| CVE-2026-40971 |
|
27.04.2026 |
5 |
| CVE-2026-7194 |
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection |
27.04.2026 |
|
| CVE-2026-7179 |
OSPG binwalk WinCE Extraction Plugin winceextract.py read_null_terminated_string path traversal |
27.04.2026 |
|
| CVE-2026-7183 |
aligungr UERANSIM Radio Link Simulation Layer rls_pdu.cpp DecodeRlsMessage uncaught exception |
27.04.2026 |
|
| CVE-2026-7178 |
ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgery |
27.04.2026 |
|
| CVE-2026-7177 |
ChatGPTNextWeb NextChat route.ts proxyHandler server-side request forgery |
27.04.2026 |
|
| CVE-2026-7159 |
douinc mkdocs-mcp-plugin server.py list_documents path traversal |
27.04.2026 |
|
| CVE-2026-7160 |
Tenda HG3 formTracert command injection |
27.04.2026 |
|
| CVE-2024-46636 |
|
27.04.2026 |
|
| CVE-2026-3087 |
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs |
28.04.2026 |
|
| CVE-2026-7156 |
Totolink A8000RU CGI cstecgi.cgi CsteSystem os command injection |
27.04.2026 |
|
| CVE-2026-7157 |
disler aider-mcp-server aider_ai_code server.py command injection |
27.04.2026 |
|
| CVE-2026-7158 |
dmitryglhf mcp-url-downloader server.py _validate_url_safe server-side request forgery |
27.04.2026 |
|
| CVE-2026-29971 |
|
27.04.2026 |
|
| CVE-2026-5362 |
Pimcore Platform v12.3.3 - Stored XSS in Document Editable Embed rendering |
27.04.2026 |
|
| CVE-2026-7154 |
Totolink A8000RU CGI cstecgi.cgi setAdvancedInfoShow os command injection |
27.04.2026 |
|
| CVE-2026-7155 |
Totolink A8000RU CGI cstecgi.cgi setLoginPasswordCfg os command injection |
27.04.2026 |
|
| CVE-2026-7191 |
Arbitrary Code Execution via Sandbox Bypass in the open source solution QnABot on AWS |
27.04.2026 |
7.2 |
| CVE-2026-5394 |
Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling |
27.04.2026 |
|
| CVE-2026-6741 |
LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability |
27.04.2026 |
8.8 |
| CVE-2026-7151 |
Tenda HG3 formIPv6Routing formUploadConfig stack-based overflow |
27.04.2026 |
|
| CVE-2026-7152 |
Totolink A8000RU CGI cstecgi.cgi setTelnetCfg os command injection |
27.04.2026 |
|
| CVE-2026-7153 |
Totolink A8000RU CGI cstecgi.cgi setMiniuiHomeInfoShow os command injection |
27.04.2026 |
|
| CVE-2025-69428 |
|
27.04.2026 |
|
| CVE-2026-40970 |
|
27.04.2026 |
5 |
| CVE-2026-7149 |
dexhunter kaggle-mcp server.py prepare_kaggle_dataset path traversal |
27.04.2026 |
|
| CVE-2026-7150 |
dh1011 auto-favicon MCP Tool server.py generate_favicon_from_url server-side request forgery |
27.04.2026 |
|
| CVE-2021-36438 |
|
27.04.2026 |
|
| CVE-2026-31255 |
|
27.04.2026 |
|
| CVE-2026-31256 |
|
27.04.2026 |
|
| CVE-2026-32655 |
|
28.04.2026 |
5.3 |
| CVE-2026-35901 |
|
27.04.2026 |
|
| CVE-2026-35902 |
|
27.04.2026 |
|
| CVE-2026-35903 |
|
27.04.2026 |
|
| CVE-2026-7147 |
JoeCastrom mcp-chat-studio LLM Models API llm.js server-side request forgery |
27.04.2026 |
|
| CVE-2026-7148 |
CodeAstro Online Classroom addnewfaculty sql injection |
27.04.2026 |
|
| CVE-2026-25908 |
|
28.04.2026 |
6.7 |
| CVE-2026-7146 |
AlejandroArciniegas mcp-data-vis HTTP Request server.js axios server-side request forgery |
27.04.2026 |
|
| CVE-2025-69689 |
|
27.04.2026 |
|
| CVE-2026-31686 |
mm/kasan: fix double free for kasan pXds |
27.04.2026 |
|
| CVE-2026-31687 |
gpio: omap: do not register driver in probe() |
27.04.2026 |
|
| CVE-2026-31688 |
driver core: enforce device_lock for driver_match_device() |
27.04.2026 |
|
| CVE-2026-31689 |
EDAC/mc: Fix error path ordering in edac_mc_alloc() |
27.04.2026 |
|
| CVE-2026-31690 |
firmware: thead: Fix buffer overflow and use standard endian macros |
27.04.2026 |
|
| CVE-2026-31691 |
igb: remove napi_synchronize() in igb_down() |
27.04.2026 |
|
| CVE-2026-7143 |
1000 Projects Portfolio Management System MCA block_status.php sql injection |
27.04.2026 |
|
| CVE-2026-7144 |
1000 Projects Portfolio Management System MCA update_passwd_process.php authorization |
27.04.2026 |
|
| CVE-2026-7145 |
mettle sendportal Invitation WorkspaceInvitationsController.php destroy authorization |
27.04.2026 |
|
| CVE-2026-30462 |
|
27.04.2026 |
|
| CVE-2026-38934 |
|
27.04.2026 |
|
| CVE-2026-38935 |
|
27.04.2026 |
|
| CVE-2026-38936 |
|
27.04.2026 |
|
| CVE-2026-7141 |
vllm KV Block kv_cache_interface.py has_mamba_layers uninitialized resource |
27.04.2026 |
|
| CVE-2026-7142 |
Wooey API Endpoint scripts.py add_or_update_script improper authorization |
27.04.2026 |
|
| CVE-2026-30346 |
|
27.04.2026 |
|
| CVE-2026-7139 |
Totolink A8000RU CGI cstecgi.cgi setWiFiAclRules os command injection |
27.04.2026 |
|
| CVE-2026-7140 |
Totolink A8000RU CGI cstecgi.cgi CsteSystem os command injection |
27.04.2026 |
|
| CVE-2026-6970 |
authd Denial of Service and Local Privilege Escalation |
27.04.2026 |
|
| CVE-2026-7136 |
Totolink A8000RU CGI cstecgi.cgi setDmzCfg os command injection |
27.04.2026 |
|
| CVE-2026-7137 |
Totolink A8000RU CGI cstecgi.cgi setStorageCfg os command injection |
27.04.2026 |
|
| CVE-2026-7138 |
Totolink A8000RU CGI cstecgi.cgi setNtpCfg os command injection |
27.04.2026 |
|
| CVE-2025-54505 |
|
27.04.2026 |
|
| CVE-2026-30351 |
|
27.04.2026 |
|
| CVE-2026-30352 |
|
27.04.2026 |
|
| CVE-2026-41462 |
ProjeQtor < 12.4.4 Unauthenticated SQL Injection via Login |
27.04.2026 |
|
| CVE-2026-41463 |
ProjeQtor < 12.4.4 ZipSlip Path Traversal via uploadPlugin.php |
27.04.2026 |
|
| CVE-2026-41464 |
ProjeQtor < 12.4.4 Missing Authorization via objectDetail.php |
27.04.2026 |
|
| CVE-2026-41465 |
ProjeQtor < 12.4.4 Path Traversal via dynamicDialog.php |
27.04.2026 |
|
| CVE-2026-41466 |
ProjeQtor < 12.4.4 Stored XSS via checkValidHtmlText() |
27.04.2026 |
|
| CVE-2026-41467 |
ProjeQtor < 12.4.4 Stored XSS via checkValidFileName() |
27.04.2026 |
|
| CVE-2026-7134 |
code-projects Online Lot Reservation System edithousepic.php unrestricted upload |
27.04.2026 |
|
| CVE-2026-7135 |
GPAC MP4Box box_code_base.c elng_box_read out-of-bounds |
27.04.2026 |
|
| CVE-2026-30350 |
|
27.04.2026 |
|
| CVE-2026-40514 |
SmarterTools SmarterMail < Build 9610 Cryptographic Weakness via Weak RNG |
27.04.2026 |
|
| CVE-2026-6337 |
|
27.04.2026 |
|
| CVE-2026-6357 |
pip self-update functionality can import newly installed modules after wheel installation |
27.04.2026 |
|
| CVE-2026-7131 |
code-projects Online Lot Reservation System loginuser.php sql injection |
27.04.2026 |
|
| CVE-2026-7132 |
code-projects Online Lot Reservation System download.php readfile path traversal |
27.04.2026 |
|
| CVE-2026-7133 |
code-projects Online Lot Reservation System activity.php unrestricted upload |
27.04.2026 |
|
| CVE-2026-32688 |
Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy |
28.04.2026 |
|
| CVE-2026-7128 |
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection |
27.04.2026 |
|
| CVE-2026-7129 |
SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting |
27.04.2026 |
|
| CVE-2026-7130 |
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection |
27.04.2026 |
|
| CVE-2025-15626 |
Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application |
27.04.2026 |
|
| CVE-2026-40557 |
Apache Storm Prometheus Reporter: Disabling TLS verification for Prometheus Reporter also disables it for all other connections |
27.04.2026 |
|
| CVE-2026-41081 |
Apache Storm Client: Anonymous principal assigned on TLS client certificate verification failure |
27.04.2026 |
|
| CVE-2026-6265 |
Local Privilege Escalation in Cerberus FTP Server =< 2025.4.2 |
27.04.2026 |
|
| CVE-2026-7126 |
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection |
27.04.2026 |
|
| CVE-2026-7127 |
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection |
27.04.2026 |
|
| CVE-2026-7040 |
Text::Minify::XS versions from v0.3.0 before v0.7.8 for Perl have heap overflow when processing some malformed UTF-8 characters |
27.04.2026 |
|
| CVE-2026-7123 |
Totolink A8000RU CGI cstecgi.cgi setIptvCfg os command injection |
27.04.2026 |
|
| CVE-2026-7124 |
Totolink A8000RU CGI cstecgi.cgi setIpv6LanCfg os command injection |
27.04.2026 |
|
| CVE-2026-7125 |
Totolink A8000RU CGI cstecgi.cgi setWiFiEasyCfg os command injection |
27.04.2026 |
|
| CVE-2026-7119 |
Tenda HG3 formCountrystr os command injection |
27.04.2026 |
|
| CVE-2026-7121 |
Totolink A8000RU CGI cstecgi.cgi setWizardCfg os command injection |
27.04.2026 |
|
| CVE-2026-7122 |
Totolink A8000RU CGI cstecgi.cgi setUPnPCfg os command injection |
27.04.2026 |
|
| CVE-2026-5937 |
Foxit PDF Editor/Reader's insufficient parameter validation leads to denial-of-service vulnerability |
27.04.2026 |
5.5 |
| CVE-2026-5938 |
Foxit PDF Editor/Reader Infinite Loop Denial-of-Service Vulnerability |
27.04.2026 |
5.5 |
| CVE-2026-5939 |
UAF in Foxit PDF Editor/Reader via XFA calculate event |
28.04.2026 |
5.5 |
| CVE-2026-5940 |
Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability |
28.04.2026 |
7.8 |
| CVE-2026-5941 |
Foxit PDF Editor/Reader AcroForm Signature Remote Code Execution Vulnerability |
28.04.2026 |
7.8 |
| CVE-2026-5942 |
Foxit PDF Editor/Reader AcroForm Signature Use-After-Free Vulnerability |
27.04.2026 |
5.5 |
| CVE-2026-5943 |
Foxit PDF Editor/Reader AcroForm Annotation Use-After-Free Remote Code Execution Vulnerability |
28.04.2026 |
7.8 |
| CVE-2026-7117 |
code-projects Employee Management System approve.php sql injection |
27.04.2026 |
|
| CVE-2026-7118 |
code-projects Employee Management System cancel.php sql injection |
27.04.2026 |
|