Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2023-54359 — WordPress adivaha Travel Plugin 2.3 SQL Injection via pid

WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pid…

Remote | Injection
Apr 09, 2026 Apr 15, 2026
Apr 09, 2026
Apr 15, 2026
6.1 MEDIUM
CVE-2023-54358 — WordPress adivaha Travel Plugin 2.3 Reflected XSS via isMobile

WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter. A…

Remote | Cross-Site Scripting
Apr 09, 2026 Apr 15, 2026
Apr 09, 2026
Apr 15, 2026
10.0 HIGH
CVE-2026-5976 — Totolink A7100RU CGI cstecgi.cgi setStorageCfg os command injection

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manip…

a7100ru_firmware | Remote | Injection
Apr 09, 2026 Apr 13, 2026
Apr 09, 2026
Apr 13, 2026
10.0 HIGH
CVE-2026-5975 — Totolink A7100RU CGI cstecgi.cgi setDmzCfg os command injection

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulatio…

a7100ru_firmware | Remote | Injection
Apr 09, 2026 Apr 13, 2026
Apr 09, 2026
Apr 13, 2026
7.5 HIGH
CVE-2026-5974 — FoundationAgents MetaGPT terminal.py Bash.run os command injection

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os comman…

Remote | Injection
Apr 09, 2026 Apr 13, 2026
Apr 09, 2026
Apr 13, 2026
7.5 HIGH
CVE-2026-5973 — FoundationAgents MetaGPT common.py get_mime_type os command injection

A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The at…

Remote | Injection
Apr 09, 2026 Apr 13, 2026
Apr 09, 2026
Apr 13, 2026
7.5 HIGH
CVE-2026-5972 — FoundationAgents MetaGPT terminal.py Terminal.run_command os command injection

A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to o…

Remote | Injection
Apr 09, 2026 Apr 13, 2026
Apr 09, 2026
Apr 13, 2026
9.3 CRITICAL
CVE-2026-5194 — wolfSSL ECDSA Certificate Verification

Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller than is appropriate for the relevant key type, to be accepted by signature ver…

wolfssl | Remote | Cryptography
Apr 09, 2026 Apr 16, 2026
Apr 09, 2026
Apr 16, 2026
9.8 CRITICAL
CVE-2026-5187 — Heap Out-of-Bounds Write in DecodeObjectId() in wolfSSL

Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. First, a bounds check only validates one available slot before writing two OID arc values (out[0] …

wolfssl | Remote | Memory Corruption
Apr 09, 2026 Apr 16, 2026
Apr 09, 2026
Apr 16, 2026
8.6 HIGH
CVE-2026-4436 — GPL Odorizers GPL750 Missing Authentication for Critical Function

A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant injection logic such that too much or too little odorant is injected into a gas…

Remote | Injection
Apr 09, 2026 Apr 13, 2026
Apr 09, 2026
Apr 13, 2026
9.9 CRITICAL
CVE-2026-40089 — Sonicverse has Server-Side Request Forgery via user-controlled URLs in dashboard API clie…

Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API …

Remote | Server-Side Request Forgery
Apr 09, 2026 Apr 13, 2026
Apr 09, 2026
Apr 13, 2026
9.6 CRITICAL
CVE-2026-40088 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'…

PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are exposed to user-controlled input via agent workflows, YAML definitions, and LL…

praisonai praisonaiagents | Remote | Injection
Apr 09, 2026 Apr 16, 2026
Apr 09, 2026
Apr 16, 2026
5.3 MEDIUM
CVE-2026-40087 — LangChain has incomplete f-string validation in prompt templates

LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-string prompt-template validation was incomplete in two respects. First, some prom…

langchain langchain_core | Remote | Injection
Apr 09, 2026 Apr 16, 2026
Apr 09, 2026
Apr 16, 2026
3.5 LOW
CVE-2026-40077 — Beszel has an IDOR in hub API endpoints that read system ID from URL parameter

Beszel is a server monitoring platform. Prior to 0.18.7, some API endpoints in the Beszel hub accept a user-supplied system ID and proceed without further checks that the user should have access to t…

beszel | Remote | Authorization
Apr 09, 2026 Apr 17, 2026
Apr 09, 2026
Apr 17, 2026
7.1 HIGH
CVE-2026-39977 — flatpak-builder has a path traversal leading to arbitrary file read on host when installi…

flatpak-builder is a tool to build flatpaks from source. From 1.4.5 to before 1.4.8, the license-files manifest key takes an array of paths to user defined licence files relative to the source direct…

flatpak-builder | Remote | Path Traversal
Apr 09, 2026 Apr 16, 2026
Apr 09, 2026
Apr 16, 2026
8.1 HIGH
CVE-2026-35577 — Missing Host Header Validation in Apollo MCP Server for Localhost Deployments

Apollo MCP Server is a Model Context Protocol server that exposes GraphQL operations as MCP tools. Prior to version 1.7.0, the Apollo MCP Server did not validate the Host header on incoming HTTP requ…

apollo_mcp_server | Remote | Misconfiguration
Apr 09, 2026 Apr 17, 2026
Apr 09, 2026
Apr 17, 2026
8.8 HIGH
CVE-2026-35063 — Missing Authorization in OpenPLC_V3

OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other user, including administrators, by specifying the…

openplc_v3_firmware openplc_v3 | Remote | Authentication
Apr 09, 2026 Apr 16, 2026
Apr 09, 2026
Apr 16, 2026
7.8 HIGH
CVE-2026-34734 — HDF5: H5T__conv_struct Use After Free

HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a malicious h5 file can trigger a heap use-after-…

hdf5 | Memory Corruption
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
6.5 MEDIUM
CVE-2026-34500 — Apache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20…

tomcat | Remote | Authentication
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
7.5 HIGH
CVE-2026-34487 — Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer to…

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat…

tomcat | Remote | Information Disclosure
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
Showing 20 of 6460 Results