Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-1114 — Improper Access Control via Weak JWT Token in parisneo/lollms

In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key for signing JSON Web Tokens (JWT). This vulnerabili…

Remote | Authentication
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
0.0 NA
CVE-2025-15611 — Popup Box AYS Pro < 5.5.0 - Admin+ Stored Cross-Site Scripting (XSS) via CSRF

The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticated attackers to perform Cross-Sit…

| Cross-Site Request Forgery
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.5 MEDIUM
CVE-2026-1839 — Arbitrary Code Execution via Unsafe torch.load() in Trainer Checkpoint Loading in hugging…

A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at l…

| Injection
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
5.5 MEDIUM
CVE-2025-65116 — Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 and JP1/NETM/DM

Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Man…

| Memory Corruption
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.8 HIGH
CVE-2025-65115 — Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 and JP1/NETM/DM

Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2…

Remote | Injection
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
9.8 CRITICAL
CVE-2026-0740 — Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all …

Remote | Misconfiguration
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
4.3 MEDIUM
CVE-2026-20446 — "Microsoft Secure Boot integer overflow allows local denial of service and physical devic…

In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker has physical access to the device, with User execution priv…

| Memory Corruption
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.8 HIGH
CVE-2026-20433 — Huawei Modem Out-of-Bounds Write Privilege Escalation

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the att…

| Memory Corruption
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.0 HIGH
CVE-2026-20432 — Huawei Modem Out-of-Bounds Write Privilege Escalation Vulnerability

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the att…

| Memory Corruption
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.5 MEDIUM
CVE-2026-20431 — "Modem Remote Denial of Service Vulnerability"

In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additio…

| Denial of Service
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.5 MEDIUM
CVE-2026-5719 — itsourcecode Construction Management System borrowedtool.php sql injection

A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /borrowedtool.php. Executing a manipulation of the argument code can lead to sql…

Remote | Injection
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.2 MEDIUM
CVE-2025-13044 — Multiple Vulnerabilities in IBM Concert Software

IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.

| Misconfiguration
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
5.3 MEDIUM
CVE-2026-5705 — code-projects Online Hotel Booking Booking Endpoint booknow.php cross site scripting

A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown functionality of the file /booknow.php of the component Booking Endpoint. Such m…

Remote | Cross-Site Scripting
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
7.5 HIGH
CVE-2026-5692 — Totolink A7100RU cstecgi.cgi setGameSpeedCfg os command injection

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results in os c…

Remote | Injection
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
7.5 HIGH
CVE-2026-5691 — Totolink A7100RU cstecgi.cgi setFirewallType os command injection

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setFirewallType of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument firewallType lead…

Remote | Injection
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
7.5 HIGH
CVE-2026-5690 — Totolink A7100RU cstecgi.cgi setRemoteCfg os command injection

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument enable can…

Remote | Injection
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
7.5 HIGH
CVE-2026-5689 — Totolink A7100RU cstecgi.cgi setNtpCfg os command injection

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setNtpCfg of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument tz re…

Remote | Injection
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
7.5 HIGH
CVE-2026-5688 — Totolink A7100RU cstecgi.cgi setDdnsCfg os command injection

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument provider l…

Remote | Injection
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
8.8 HIGH
CVE-2026-5709 — AWS Research and Engineering Studio (RES) FileBrowser Command Injection

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the …

Remote | Injection
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
8.8 HIGH
CVE-2026-5708 — Improper Control of User-Modifiable Attributes in RES CreateSession API

Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to e…

Remote | Authorization
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
Showing 20 of 6034 Results