Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2025-15636 — WordPress YouTube Showcase plugin <= 3.5.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emarket-design YouTube Showcase allows Stored XSS.This issue affects YouTube Showcase: from n/a t…

youtube_video_gallery | Remote | Cross-Site Scripting
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
4.3 MEDIUM
CVE-2025-15635 — WordPress Smart Online Order for Clover plugin <= 1.6.0 - Cross Site Request Forgery (CSR…

Cross-Site Request Forgery (CSRF) vulnerability in Zaytech Smart Online Order for Clover allows Cross Site Request Forgery.This issue affects Smart Online Order for Clover: from n/a through 1.6.0.

smart_online_order_for_clover | Remote | Cross-Site Request Forgery
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
9.3 CRITICAL
CVE-2025-15610 — OpenText RightFax Object Injection Vulnerability

Deserialization of untrusted data vulnerability in OpenText, Inc RightFax on Windows, 64 bit, 32 bit allows Object Injection.This issue affects RightFax: through 25.4.

Remote | Injection
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
9.3 CRITICAL
CVE-2026-5387 — AVEVA Pipeline Simulation Missing Authorization

The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privi…

Remote | Authorization
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
9.8 CRITICAL
CVE-2026-30625 — Upsonic MCP Server Remote Code Execution Vulnerability

Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define MCP tasks with arbitrary command and args values. A…

upsonic | Remote | Injection
Apr 15, 2026 Apr 16, 2026
Apr 15, 2026
Apr 16, 2026
8.6 HIGH
CVE-2026-30624 — "Agent Zero External MCP Servers Code Execution"

Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The application allows users to define MCP servers using a JSON configuration contai…

Remote | Injection
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
8.6 HIGH
CVE-2026-30617 — LangChain-ChatChat MCP STDIO Remote Code Execution Vulnerability

LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execution handling. A remote attacker can access the publicly exposed MCP management …

Remote | Misconfiguration
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
7.3 HIGH
CVE-2026-30616 — Jaaz MCP STDIO Command Execution Remote Code Execution Vulnerability

Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacker can send crafted network requests to the network-accessible Jaaz application,…

Remote | Injection
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
8.0 HIGH
CVE-2026-30615 — Windsurf Web Application Command Injection Vulnerability

A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML content, malicious in…

| Injection
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
8.3 HIGH
CVE-2026-30461 — Daylight Studio FuelCMS Remote Code Execution Vulnerability

Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function add_git_submodule.

Remote | Authentication
Apr 15, 2026 Apr 16, 2026
Apr 15, 2026
Apr 16, 2026
7.2 HIGH
CVE-2026-20205 — Sensitive Information Disclosure in ''_internal'' index in Splunk MCP Server app

In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or possesses the high-privilege capability `mcp_tool_admin` could view users sessio…

Remote | Information Disclosure
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
7.1 HIGH
CVE-2026-20204 — Improper Handling and Insufficient Isolation of Specific Temporary Files in Splunk Enterp…

In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a…

splunk splunk_cloud_platform | Remote | Authentication
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
4.3 MEDIUM
CVE-2026-20203 — Improper Access Control in Data Model Acceleration in Splunk Enterprise

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, …

splunk splunk_cloud_platform | Remote | Authorization
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
6.6 MEDIUM
CVE-2026-20202 — Improper Input Validation during User Account Creation in Splunk Enterprise

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.20, 10.0.2503.13, and 9.3.2411.127, …

splunk splunk_cloud_platform | Remote | Authentication
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
7.5 HIGH
CVE-2025-67841 — Nordic Semiconductor IronSide SE for nRF54H20 Crypto Complexity Weakness

Nordic Semiconductor IronSide SE for nRF54H20 before 23.0.2+17 has an Algorithmic complexity issue.

Remote | Denial of Service
Apr 15, 2026 Apr 16, 2026
Apr 15, 2026
Apr 16, 2026
4.3 MEDIUM
CVE-2025-53444 — WordPress Userpro plugin < 5.1.11 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro allows Cross Site Request Forgery.This issue affects Userpro: from n/a before 5.1.11.

userpro | Remote | Cross-Site Request Forgery
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
1.3 LOW
CVE-2025-12141 — Grafana Alerting Editors can edit destination of webhooks they did not create

In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as par…

Remote | Authorization
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
8.7 HIGH
CVE-2026-4682 — Certain HP DeskJet All In One (AIO) Devices – Potential Remote Code Execution & Potential…

Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer overflow when specially crafted Web Services for Devices (WSD) scan requests are improperly validat…

| Memory Corruption
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
7.3 HIGH
CVE-2026-4667 — HP System Optimizer - Escalation of Privilege

HP System Optimizer might potentially be vulnerable to escalation of privilege. HP is releasing an update to mitigate this potential vulnerability.

| Authorization
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
7.5 HIGH
CVE-2026-30364 — CentSDR Stack Overflow Vulnerability

CentSDR commit e40795 was discovered to contain a stack overflow in the "Thread1" function.

Remote | Memory Corruption
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
Showing 20 of 6514 Results