Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.9 MEDIUM
CVE-2026-20148 — Cisco Identity Services Engine Path Traversal Vulnerability

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit …

identity_services_engine | Remote | Path Traversal
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
9.9 CRITICAL
CVE-2026-20147 — Cisco Identity Services Engine Remote Code Execution Vulnerability

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vu…

identity_services_engine | Remote | Injection
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
6.0 MEDIUM
CVE-2026-20136 — Cisco Identity Services Engine Authenticated Privilege Escalation Vulnerability

A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges …

Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
4.8 MEDIUM
CVE-2026-20132 — Cisco Identity Services Engine Multiple Cross-Site Scripting Vulnerabilities

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative write privileges to condu…

identity_services_engine | Remote | Cross-Site Scripting
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
6.5 MEDIUM
CVE-2026-20081 — Cisco Unity Connection Arbitrary File Download Vulnerability

Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attack…

unity_connection | Remote | Path Traversal
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
6.5 MEDIUM
CVE-2026-20078 — Cisco Unity Connection Arbitrary File Download Vulnerability

Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attack…

unity_connection | Remote | Path Traversal
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
4.3 MEDIUM
CVE-2026-20061 — Cisco Unity Connection SQL Injection Vulnerability

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit…

unity_connection | Remote | Injection
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
4.7 MEDIUM
CVE-2026-20060 — Cisco Unity Connection Open Redirect Vulnerability

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is du…

unity_connection | Remote | Server-Side Request Forgery
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
6.1 MEDIUM
CVE-2026-20059 — Cisco Unity Connection Reflected Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. T…

unity_connection | Remote | Cross-Site Scripting
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
7.6 HIGH
CVE-2025-63029 — WordPress WCFM Marketplace plugin <= 3.7.1 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Lovers WCFM Marketplace allows SQL Injection.This issue affects WCFM Marketplace: from n/a thr…

wcfm_marketplace | Remote | Injection
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
6.5 MEDIUM
CVE-2025-15636 — WordPress YouTube Showcase plugin <= 3.5.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emarket-design YouTube Showcase allows Stored XSS.This issue affects YouTube Showcase: from n/a t…

youtube_video_gallery | Remote | Cross-Site Scripting
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
4.3 MEDIUM
CVE-2025-15635 — WordPress Smart Online Order for Clover plugin <= 1.6.0 - Cross Site Request Forgery (CSR…

Cross-Site Request Forgery (CSRF) vulnerability in Zaytech Smart Online Order for Clover allows Cross Site Request Forgery.This issue affects Smart Online Order for Clover: from n/a through 1.6.0.

smart_online_order_for_clover | Remote | Cross-Site Request Forgery
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
9.3 CRITICAL
CVE-2025-15610 — OpenText RightFax Object Injection Vulnerability

Deserialization of untrusted data vulnerability in OpenText, Inc RightFax on Windows, 64 bit, 32 bit allows Object Injection.This issue affects RightFax: through 25.4.

Remote | Injection
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
9.3 CRITICAL
CVE-2026-5387 — AVEVA Pipeline Simulation Missing Authorization

The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privi…

Remote | Authorization
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
9.8 CRITICAL
CVE-2026-30625 — Upsonic MCP Server Remote Code Execution Vulnerability

Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define MCP tasks with arbitrary command and args values. A…

upsonic | Remote | Injection
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
8.6 HIGH
CVE-2026-30624 — "Agent Zero External MCP Servers Code Execution"

Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The application allows users to define MCP servers using a JSON configuration contai…

Remote | Injection
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
8.6 HIGH
CVE-2026-30617 — LangChain-ChatChat MCP STDIO Remote Code Execution Vulnerability

LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execution handling. A remote attacker can access the publicly exposed MCP management …

Remote | Misconfiguration
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
7.3 HIGH
CVE-2026-30616 — Jaaz MCP STDIO Command Execution Remote Code Execution Vulnerability

Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacker can send crafted network requests to the network-accessible Jaaz application,…

Remote | Injection
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
8.0 HIGH
CVE-2026-30615 — Windsurf Web Application Command Injection Vulnerability

A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML content, malicious in…

| Injection
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
8.3 HIGH
CVE-2026-30461 — Daylight Studio FuelCMS Remote Code Execution Vulnerability

Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function add_git_submodule.

Remote | Authentication
Apr 15, 2026 Apr 17, 2026
Apr 15, 2026
Apr 17, 2026
Showing 20 of 6505 Results