Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-22675 — OCS Inventory NG Server Stored XSS via User-Agent

OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript by submitting malicious User…

Remote | Cross-Site Scripting
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
5.5 MEDIUM
CVE-2026-5683 — Tenda CX12L P2pListFilter fromP2pListFilter stack-based overflow

A vulnerability was found in Tenda CX12L 16.03.53.12. Affected by this vulnerability is the function fromP2pListFilter of the file /goform/P2pListFilter. Performing a manipulation of the argument pag…

| Memory Corruption
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
5.1 MEDIUM
CVE-2026-35472 — WeGIA - Open Redirect - EstoqueControle - listarTodos() - Unvalidated $_GET['nextPage']

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically th…

wegia | Remote | Misconfiguration
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
8.5 HIGH
CVE-2026-35399 — WeGIA has Stored XSS in backup file names

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, a stored XSS vulnerability allows an attacker to inject malicious scripts through a backup filename. This could lead to unauthorize…

wegia | Remote | Cross-Site Scripting
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
5.1 MEDIUM
CVE-2026-35398 — WeGIA - Open Redirect - OrigemControle - listarTodos() & listarId_Nome() - Unvalidated $_…

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically th…

wegia | Remote | Misconfiguration
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
5.1 MEDIUM
CVE-2026-35396 — WeGIA - Open Redirect - IsaidaControle - listarId() - Unvalidated $_GET['nextPage']

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically th…

wegia | Remote | Misconfiguration
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
8.8 HIGH
CVE-2026-35395 — WeGIA has a SQL Injection in DespachoDAO.php via id_memorando parameter

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection vulnerability in dao/memorando/DespachoDAO.php. Th…

wegia | Remote | Injection
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
8.3 HIGH
CVE-2026-35394 — Mobile Next has Arbitrary Android Intent Execution via mobile_open_url

Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in mobile-mcp passes user-supplied URLs directly to Android's intent system without any s…

mobile_mcp | Remote | Information Disclosure
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
9.8 CRITICAL
CVE-2026-35393 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs P…

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart upload directory not sanitized. This vulnerability is fixed in 2.0.0-beta.3.

Remote | Misconfiguration
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
9.8 CRITICAL
CVE-2026-35392 — goshs has an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal…

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver/updown.go has no path sanitization. This vulnerability is fixed in 2.0.0-beta.3.

Remote | Misconfiguration
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
8.7 HIGH
CVE-2026-35391 — Bulwark Webmail getClientIP() trusted client-controlled X-Forwarded-For value, enabling r…

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the getClientIP() function in lib/admin/session.ts trusted the first (leftmost) entry of the X-Forwarded-For…

Remote | Misconfiguration
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
6.1 MEDIUM
CVE-2026-35390 — Content-Security-Policy was set to Report-Only mode, failing to block XSS attacks

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the reverse proxy (proxy.ts) set the Content-Security-Policy-Report-Only header instead of the enforcing Con…

Remote | Cross-Site Scripting
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
8.7 HIGH
CVE-2026-35389 — Bulwark Webmail S/MIME signature verification accepted self-signed certificates

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification did not validate the certificate trust chain (checkChain: false). Any email si…

Remote | Cryptography
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
8.7 HIGH
CVE-2026-35213 — Regular Expression Denial of Service (ReDoS) in @hapi/content HTTP header parsing

@hapi/content provided HTTP Content-* headers parsing. All versions of @hapi/content through 6.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via crafted HTTP header values. Three…

content | Remote | Denial of Service
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
5.3 MEDIUM
CVE-2026-35208 — lichess.org has an Unsanitized Stream Title Injection on /streamer

lichess.org is the forever free, adless and open source chess server. Any approved streamer can inject arbitrary HTML into /streamer and the homepage “Live streams” widget by placing markup in their …

Remote | Injection
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
5.0 MEDIUM
CVE-2026-34972 — OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisi…

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1, under specific conditions, BatchCheck calls with…

openfga | Remote | Authorization
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
7.0 HIGH
CVE-2025-54601 — Samsung Exynos Wi-Fi Driver Double Free Vulnerability

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor amd Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Improper synchronization on …

Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
6.3 MEDIUM
CVE-2026-5682 — Meesho Online Shopping App com.meesho.supply endpoint risky encryption

A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android. Affected is an unknown function of the file /api/endpoint of the component com.meesho.supply. Such manipulation lea…

Remote | Cryptography
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
6.5 MEDIUM
CVE-2026-5681 — itsourcecode sanitize or validate this input Parameter borrowedequip.php sql injection

A flaw has been found in itsourcecode sanitize or validate this input 1.0. This impacts an unknown function of the file /borrowedequip.php of the component Parameter Handler. This manipulation of the…

college_management_system | Remote | Injection
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
5.5 MEDIUM
CVE-2026-5679 — Totolink A3300R cstecgi.cgi vsetTr069Cfg os command injection

A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the function vsetTr069Cfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argum…

a3300r_firmware | Injection
Apr 06, 2026 Apr 07, 2026
Apr 06, 2026
Apr 07, 2026
Showing 20 of 6199 Results