Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-6603 — modelscope agentscope _python.py execute_shell_command code injection

A vulnerability was determined in modelscope agentscope up to 1.0.18. Affected by this vulnerability is the function execute_python_code/execute_shell_command of the file src/AgentScope/tool/_coding/…

agentscope | Remote | Injection
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
7.5 HIGH
CVE-2026-6602 — rickxy Hospital Management System his_admin_account.php unrestricted upload

A vulnerability was found in rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4. Affected is an unknown function of the file /backend/admin/his_admin_account.php. The ma…

hospital_management_system | Remote | Misconfiguration
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
5.3 MEDIUM
CVE-2026-6601 — Lagom WHMCS Template Datatables resource consumption

A vulnerability has been found in Lagom WHMCS Template up to 2.4.2. This impacts an unknown function of the component Datatables. The manipulation leads to resource consumption. Remote exploitation o…

Remote | Denial of Service
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
5.1 MEDIUM
CVE-2026-6600 — langflow-ai langflow Frontend React Component Rendering edit-message.tsx cross site scrip…

A flaw has been found in langflow-ai langflow up to 1.8.3. This affects an unknown function of the file src/frontend/src/modals/IOModal/components/chatView/chatMessage/components/edit-message.tsx of …

langflow | Remote | Cross-Site Scripting
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
6.5 MEDIUM
CVE-2026-6599 — langflow-ai langflow Model Context Protocol Configuration API mcp_projects.py install_mcp…

A vulnerability was detected in langflow-ai langflow up to 1.8.3. The impacted element is the function get_client_ip/install_mcp_config of the file src/backend/base/langflow/api/v1/mcp_projects.py of…

langflow | Remote | Injection
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
5.3 MEDIUM
CVE-2026-6598 — langflow-ai langflow Project Creation Endpoint projects.py encrypt_auth_settings cleartex…

A security vulnerability has been detected in langflow-ai langflow up to 1.8.3. The affected element is the function create_project/encrypt_auth_settings of the file src/backend/base/Langflow/api/v1/…

langflow | Remote | Misconfiguration
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
8.7 HIGH
CVE-2026-32965 — Silex SD-330AC and AMC Manager Default Password Vulnerability

Initialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC Manager provided by silex technology, Inc. When the affected device is connected to the network with the…

Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
6.9 MEDIUM
CVE-2026-32964 — Silex Technology, Inc. SD-330AC and AMC Manager CRLF Injection

SD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF Injection') vulnerability. Processing some crafted configuration data may lead …

Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
6.1 MEDIUM
CVE-2026-32963 — Silex Technology, Inc. SD-330AC and AMC Manager Reflected Cross-Site Scripting

SD-330AC and AMC Manager provided by silex technology, Inc. contain a reflected cross-site scripting vulnerability. When a user logs in to the affected device and access some crafted web page, arbitr…

sd-330ac_firmware sd-330ac amc_manager | Cross-Site Scripting
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
6.9 MEDIUM
CVE-2026-32962 — Silex SD-330AC and AMC Manager Unauthenticated Configuration Alteration Vulnerability

SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue. The device configuration may be altered without authentication.

Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
6.9 MEDIUM
CVE-2026-32961 — Silex SD-330AC and AMC Manager Heap-Based Buffer Overflow Vulnerability

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet data processing of sx_smpd. Processing a crafted packet may cause a temporary …

sd-330ac_firmware sd-330ac amc_manager | Memory Corruption
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
7.1 HIGH
CVE-2026-32960 — Silex Technology, Inc. SD-330AC and AMC Manager Password Bypass

SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in resource not removed before reuse. An attacker may login to the device without knowing th…

Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
8.2 HIGH
CVE-2026-32959 — Silex Technology, Inc. SD-330AC and AMC Manager Weak Cryptography Vulnerability

SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a use of a broken or risky cryptographic algorithm. Information in the traffic may be retrieved via man-in-the-middle…

Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
6.9 MEDIUM
CVE-2026-32958 — Silex SD-330AC and AMC Manager Cryptographic Key Hard-Coded Vulnerability

SD-330AC and AMC Manager provided by silex technology, Inc. use a hard-coded cryptographic key. An administrative user may be directed to apply a fake firmware update.

Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
6.9 MEDIUM
CVE-2026-32957 — Silex Technology, Inc. SD-330AC and AMC Manager Unauthenticated File Upload Vulnerability

SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue on firmware maintenance. Arbitrary file may be uploaded on the device without …

Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
9.8 CRITICAL
CVE-2026-32956 — Silex Technology, Inc. SD-330AC and AMC Manager Heap-Based Buffer Overflow Vulnerability

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device.

sd-330ac_firmware sd-330ac amc_manager | Memory Corruption
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
8.8 HIGH
CVE-2026-32955 — Silex Technology, Inc. SD-330AC and AMC Manager Stack-Based Buffer Overflow Vulnerability

SD-330AC and AMC Manager provided by silex technology, Inc. contain a stack-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device.

sd-330ac_firmware sd-330ac amc_manager | Memory Corruption
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
5.1 MEDIUM
CVE-2026-6597 — langflow-ai langflow Flow Using API core.py has_api_terms credentials storage

A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py of the component Flo…

langflow | Remote | Misconfiguration
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
7.5 HIGH
CVE-2026-6596 — langflow-ai langflow API Endpoint endpoints.py create_upload_file unrestricted upload

A security flaw has been discovered in langflow-ai langflow up to 1.1.0. This issue affects the function create_upload_file of the file src/backend/base/Langflow/api/v1/endpoints.py of the component …

langflow | Remote | Misconfiguration
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
7.5 HIGH
CVE-2026-6595 — ProjectsAndPrograms School Management System HTTP GET Parameter buslocation.php sql injec…

A vulnerability was identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This vulnerability affects unknown code of the file buslocation.php of t…

school_management_system | Remote | Injection
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
Showing 20 of 6444 Results