Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-6494 — Aap-mcp-server: aap mcp server: log injection allows social engineering attacks via unsan…

A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetroute` parameter. This parameter…

Remote | Injection
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
4.4 MEDIUM
CVE-2026-6439 — VideoZen <= 1.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Video…

The VideoZen plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.1. This is due to insufficient input sanitization and output escaping in the videoze…

Remote | Cross-Site Scripting
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
7.2 HIGH
CVE-2026-23778 — Dell PowerProtect Data Domain DDOS Command Injection Vulnerability

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.1…

Remote | Injection
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
7.6 HIGH
CVE-2026-23775 — "Dell PowerProtect Data Domain DD OS Sensitive Information Log Injection Vulnerability"

Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10 contain an insertion o…

Remote | Information Disclosure
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
7.8 HIGH
CVE-2025-36568 — Dell PowerProtect Data Domain BoostFS Credentials Exposure Vulnerability

Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50…

| Authentication
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
9.5 CRITICAL
CVE-2025-15625 — Unauthenticated execution of arbitrary SQL queries in Sparx Pro Cloud Server

Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.

Remote | Injection
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
9.3 CRITICAL
CVE-2025-15624 — Plaintext Storage of a Password in Sparx Pro Cloud Server.

Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.  In a setup where OpenID is used as the primary method of authentication to authenticate to Sparx EA, P…

Remote | Authentication
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
9.3 CRITICAL
CVE-2025-15623 — Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user

Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud…

Remote | Information Disclosure
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
6.2 MEDIUM
CVE-2025-15622 — Sparx Enterprise Architect Client reveals plaintext OAuth2 client secret

Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes the secret and uses the pl…

| Authentication
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
6.7 MEDIUM
CVE-2026-23779 — "Dell PowerProtect Data Domain DD OS Command Injection Vulnerability"

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.1…

| Injection
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
7.2 HIGH
CVE-2026-23776 — Dell PowerProtect Data Domain DD OS Certificate Validation Elevation of Privileges

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.1…

Remote | Authentication
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
4.3 MEDIUM
CVE-2026-6451 — CMS für Motorrad Werkstätten <= 1.0.0 - Cross-Site Request Forgery

The cms-fuer-motorrad-werkstaetten plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.0.0. This is due to missing nonce validation on all eight AJAX de…

Remote | Cross-Site Request Forgery
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
5.0 MEDIUM
CVE-2026-40002 — ZTE Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applica…

Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications access…

| Authorization
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
7.2 HIGH
CVE-2026-33392 — JetBrains YouTrack Deserialization Remote Code Execution

In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass

Remote | Misconfiguration
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
8.4 HIGH
CVE-2026-23853 — Dell PowerProtect Data Domain DD OS Weak Credentials Vulnerability

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.1…

| Authentication
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
9.8 CRITICAL
CVE-2026-6443 — Accordion and Accordion Slider 1.4.6 - Injected Backdoor

The Accordion and Accordion Slider plugin for WordPress is vulnerable to an injected backdoor in version 1.4.6. This is due to the plugin being sold to a malicious threat actor that embedded a backdo…

Remote | Supply Chain
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
4.3 MEDIUM
CVE-2026-6441 — Canto <= 3.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Setting M…

The Canto plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 3.1.1. This is due to the absence of any capability check or nonce verification in the updateOpti…

Remote | Authorization
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
7.5 HIGH
CVE-2026-4659 — Unlimited Elements For Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File R…

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up to, and including, 2.0.6. This is due to insuffic…

Remote | Path Traversal
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
8.5 HIGH
CVE-2026-6482 — Local Privilege Escalation via OpenSSL configuration file in Insight Agent

The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of a Windows host. Upon startup the agent service att…

| Misconfiguration
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
7.3 HIGH
CVE-2026-6421 — Mobatek MobaXterm Home Edition msimg32.dll uncontrolled search path

A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulation leads to uncontrolled search path. An attack has…

| Path Traversal
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
Showing 20 of 6511 Results