Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-5533 — badlogic pi-mono SVG Artifact SvgArtifact.ts cross site scripting

A vulnerability was determined in badlogic pi-mono 0.58.4. The impacted element is an unknown function of the file packages/web-ui/src/tools/artifacts/SvgArtifact.ts of the component SVG Artifact Han…

Remote | Cross-Site Scripting
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
7.5 HIGH
CVE-2026-5532 — ScrapeGraphAI scrapegraph-ai GenerateCodeNode generate_code_node.py create_sandbox_and_ex…

A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sandbox_and_execute of the file scrapegraphai/nodes/generate_code_node.py of the co…

Remote | Injection
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
5.5 MEDIUM
CVE-2026-5531 — SourceCodester Student Result Management System HTTP GET Request login_credentials.txt cl…

A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. Th…

Remote | Information Disclosure
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
6.5 MEDIUM
CVE-2026-5530 — Ollama Model Pull API download.go server-side request forgery

A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side…

Remote | Server-Side Request Forgery
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
5.3 MEDIUM
CVE-2026-5529 — Dromara lamp-cloud DefUserController pageUser improper authorization

A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipul…

Remote | Authorization
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
6.5 MEDIUM
CVE-2026-5528 — MoussaabBadla code-screenshot-mcp HTTP os command injection

A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command inject…

Remote | Injection
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
5.5 MEDIUM
CVE-2026-5527 — Tenda 4G03 Pro ECDSA P-256 Private Key server.key hard-coded key

A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Pr…

Remote | Cryptography
Apr 05, 2026 Apr 05, 2026
Apr 05, 2026
Apr 05, 2026
7.5 HIGH
CVE-2026-5526 — Tenda 4G03 Pro httpd access control

A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin/httpd. The manipulation result…

Remote | Authorization
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.7 HIGH
CVE-2018-25246 — Wikipedia 12.0 Denial of Service via Search

Wikipedia 12.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can …

Remote | Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
5.3 MEDIUM
CVE-2016-20054 — Nodcms Cross Site Request Forgery via admin endpoints

Nodcms contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious forms. Attackers can trick authenticated administ…

Remote | Cross-Site Request Forgery
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.4 HIGH
CVE-2018-25255 — 10-Strike LANState 8.8 Local Buffer Overflow SEH

10-Strike LANState 8.8 contains a local buffer overflow vulnerability in structured exception handling that allows local attackers to execute arbitrary code by crafting malicious LSM map files. Attac…

| Memory Corruption
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
9.8 CRITICAL
CVE-2018-25254 — NICO-FTP 3.0.1.19 Buffer Overflow SEH

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect t…

Remote | Memory Corruption
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.2 MEDIUM
CVE-2018-25253 — Termite 3.4 Denial of Service via Settings Buffer Overflow

Termite 3.4 contains a buffer overflow vulnerability in the User interface language settings field that allows local attackers to cause a denial of service by supplying an excessively long string. At…

| Memory Corruption
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.2 MEDIUM
CVE-2018-25252 — FTP Voyager 16.2.0 Denial of Service via Malformed Site Profile

FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by injecting oversized buffer data into the site profile IP field. Attackers can cre…

ftp_voyager | Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.4 HIGH
CVE-2018-25251 — Snes9K 0.0.9z Buffer Overflow SEH via Netplay Socket

Snes9K 0.0.9z contains a buffer overflow vulnerability in the Netplay Socket Port Number field that allows local attackers to trigger a structured exception handler (SEH) overwrite. Attackers can cra…

| Memory Corruption
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
7.2 HIGH
CVE-2018-25250 — MyBB Last User's Threads in Profile Plugin 1.2 Persistent XSS

MyBB Last User's Threads in Profile Plugin 1.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by crafting thread subjects with script tags.…

mybb | Remote | Cross-Site Scripting
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.4 MEDIUM
CVE-2018-25249 — MyBB My Arcade Plugin 1.3 Persistent XSS via Comment

MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments. Attackers can add cr…

mybb | Remote | Cross-Site Scripting
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
7.2 HIGH
CVE-2018-25248 — MyBB Downloads Plugin 2.0.3 Persistent XSS via downloads.php

MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field. Attackers can submit a n…

mybb | Remote | Cross-Site Scripting
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.1 MEDIUM
CVE-2018-25247 — MyBB Like Plugin 3.0.0 Cross-Site Scripting via User Profiles

MyBB Like Plugin 3.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating posts or threads with unvalidated subject content. Attackers can cra…

mybb | Remote | Cross-Site Scripting
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.7 HIGH
CVE-2018-25245 — 7 Tik 1.0.1.0 Denial of Service via Search

7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a…

Remote | Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
Showing 20 of 5952 Results