Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.8 MEDIUM
CVE-2026-21012 — Apache OpenOffice File Name Control Vulnerability (Execute)

External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege.

| Path Traversal
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
5.4 MEDIUM
CVE-2026-21011 — "Bluetooth Privilege Escalation in Huawei Maintenance Mode"

Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock.

| Authorization
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
6.6 MEDIUM
CVE-2026-21010 — Cisco Router Unvalidated Input Elevates Privileges

Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged functions.

| Authorization
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
4.1 MEDIUM
CVE-2026-21009 — Google Pixel App Pinning Unvalidated Input

Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass App Pinning.

| Authentication
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
5.1 MEDIUM
CVE-2026-21008 — S Share Information Disclosure

Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information.

| Information Disclosure
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
4.4 MEDIUM
CVE-2026-21007 — Samsung Knox Guard SMR Exceptional Condition Bypass

Improper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Knox Guard.

| Authentication
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
4.7 MEDIUM
CVE-2026-21006 — Samsung DeX Information Disclosure Vulnerability

Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents.

| Authorization
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
5.1 MEDIUM
CVE-2026-6162 — PHPGurukul Company Visitor Management System bwdates-reports-details.php cross site scrip…

A vulnerability has been found in PHPGurukul Company Visitor Management System 2.0. This impacts an unknown function of the file /bwdates-reports-details.php. The manipulation of the argument fromdat…

Remote | Cross-Site Scripting
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
7.5 HIGH
CVE-2026-6161 — code-projects Simple ChatBox Endpoint insert.php sql injection

A vulnerability was determined in code-projects Simple ChatBox up to 1.0. This affects an unknown part of the file /chatbox/insert.php of the component Endpoint. Executing a manipulation of the argum…

Remote | Injection
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
5.5 MEDIUM
CVE-2026-6160 — code-projects Simple ChatBox Endpoint chatbox.sql SimpleChatbox_PHP file information disc…

A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP of the file chatbox.sql of the component Endpoint. Performing a manipulation re…

Remote | Information Disclosure
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
5.3 MEDIUM
CVE-2026-6159 — code-projects Simple ChatBox Endpoint insert.php cross site scripting

A vulnerability has been found in code-projects Simple ChatBox up to 1.0. Affected by this vulnerability is an unknown functionality of the file /chatbox/insert.php of the component Endpoint. Such ma…

Remote | Cross-Site Scripting
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
7.5 HIGH
CVE-2026-6158 — Totolink N300RH upgrade.so setUpgradeUboot os command injection

A flaw has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setUpgradeUboot of the file upgrade.so. This manipulation of the argument FileName causes os command injection. …

Remote | Injection
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
6.9 MEDIUM
CVE-2026-40446 — Samsung Open Source Escargot Type Confusion Vulnerability

Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a715…

| Memory Corruption
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
8.4 HIGH
CVE-2026-35553 — Dynabook Inc. Bluetooth ACPI Driver Stack-Based Buffer Overflow Vulnerability

Bluetooth ACPI Drivers provided by Dynabook Inc. contain a stack-based buffer overflow vulnerability. An attacker may execute arbitrary code by modifying certain registry values.

| Memory Corruption
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
6.8 MEDIUM
CVE-2026-34864 — Apache Application Denial of Service

Boundary-unlimited vulnerability in the application read module. Impact: Successful exploitation of this vulnerability may affect availability.

| Denial of Service
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
6.7 MEDIUM
CVE-2026-34863 — Apache File System Out-of-Bounds Write Vulnerability

Out-of-bounds write vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.

| Memory Corruption
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
6.3 MEDIUM
CVE-2026-34862 — "Symantec Power consumption statistics module Race Condition Vulnerability"

Race condition vulnerability in the power consumption statistics module. Impact: Successful exploitation of this vulnerability may affect availability.

| Race Condition
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
6.3 MEDIUM
CVE-2026-34861 — Dell Thermal Management Module Race Condition Vulnerability

Race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vulnerability may affect availability.

| Race Condition
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
5.9 MEDIUM
CVE-2026-34859 — Apache Kernel Uninitialized Freed UAF

UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

| Memory Corruption
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
4.1 MEDIUM
CVE-2026-34858 — Apache Communication Use-After-Free (UAF)

UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

| Memory Corruption
Apr 13, 2026 Apr 13, 2026
Apr 13, 2026
Apr 13, 2026
Showing 20 of 6104 Results