Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-7142 — Wooey API Endpoint scripts.py add_or_update_script improper authorization

A vulnerability was determined in Wooey up to 0.13.2. The impacted element is the function add_or_update_script of the file wooey/api/scripts.py of the component API Endpoint. Executing a manipulatio…

Remote | Authorization
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
6.3 MEDIUM
CVE-2026-7141 — vllm KV Block kv_cache_interface.py has_mamba_layers uninitialized resource

A vulnerability was found in vllm up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v1/kv_cache_interface.py of the component KV Block Handler. Performing a manipul…

Remote | Memory Corruption
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
10.0 HIGH
CVE-2026-7140 — Totolink A8000RU CGI cstecgi.cgi CsteSystem os command injection

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the arg…

Remote | Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
10.0 HIGH
CVE-2026-7139 — Totolink A8000RU CGI cstecgi.cgi setWiFiAclRules os command injection

A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the …

Remote | Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
6.1 MEDIUM
CVE-2026-38936 — Apache Diskover Cross-Site Scripting Vulnerability

A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/selectindices.php via the namecontains parameter

Remote | Cross-Site Scripting
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
6.1 MEDIUM
CVE-2026-38935 — Diskover Community Reflected XSS Vulnerability

A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/view.php via the doctype parameter

Remote | Cross-Site Scripting
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
8.8 HIGH
CVE-2026-38934 — Diskoverdata Diskover-Community Cross Site Request Forgery Privilege Escalation

Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker to escalate privileges and obtain sensitive information via the public/setting…

Remote | Cross-Site Request Forgery
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
4.3 MEDIUM
CVE-2026-30462 — Daylight Studio FuelCMS Path Traversal Vulnerability

A path traversal vulnerability in the Blocks module of Daylight Studio FuelCMS v1.5.2 allows attackers to execute a directory traversal.

Remote | Path Traversal
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
4.3 MEDIUM
CVE-2026-30346 — Hunvreus DevPush Open Redirect Vulnerability

An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows attackers to redirect users to malicious sites via supplying a crafted URL.

Remote | Misconfiguration
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
10.0 HIGH
CVE-2026-7138 — Totolink A8000RU CGI cstecgi.cgi setNtpCfg os command injection

A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setNtpCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation…

Remote | Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
10.0 HIGH
CVE-2026-7137 — Totolink A8000RU CGI cstecgi.cgi setStorageCfg os command injection

A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipula…

Remote | Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
10.0 HIGH
CVE-2026-7136 — Totolink A8000RU CGI cstecgi.cgi setDmzCfg os command injection

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a man…

Remote | Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
5.3 MEDIUM
CVE-2026-7135 — GPAC MP4Box box_code_base.c elng_box_read out-of-bounds

A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is the function elng_box_read of the file src/isomedia/box_code_base.c of the comp…

| Memory Corruption
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
5.8 MEDIUM
CVE-2026-7134 — code-projects Online Lot Reservation System edithousepic.php unrestricted upload

A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of the file /edithousepic.php. Such manipulation of the argument image leads to unre…

Remote | Misconfiguration
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.3 HIGH
CVE-2026-6970 — authd Denial of Service and Local Privilege Escalation

authd prior to version 0.6.4 contains a logic error in primary group ID assignment that can lead to local privilege escalation. When a user's primary group ID (GID) differs from their UID, either bec…

| Authorization
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
5.4 MEDIUM
CVE-2026-41467 — ProjeQtor < 12.4.4 Stored XSS via checkValidFileName()

ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionality where the checkValidFileName() function fails to restrict HTML and HTM file …

Remote | Cross-Site Scripting
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
5.4 MEDIUM
CVE-2026-41466 — ProjeQtor < 12.4.4 Stored XSS via checkValidHtmlText()

ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the checkValidHtmlText() function within Security.php that fails to properly sanitize user input by only d…

Remote | Cross-Site Scripting
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.1 HIGH
CVE-2026-41465 — ProjeQtor < 12.4.4 Path Traversal via dynamicDialog.php

ProjeQtor versions 7.0 through 12.4.3 contains a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal sequ…

Remote | Path Traversal
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.1 HIGH
CVE-2026-41464 — ProjeQtor < 12.4.4 Missing Authorization via objectDetail.php

ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint that allows authenticated users with guest-level privileges to retrieve sensitive …

Remote | Authorization
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
8.8 HIGH
CVE-2026-41463 — ProjeQtor < 12.4.4 ZipSlip Path Traversal via uploadPlugin.php

ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path traversal vulnerability in the plugin upload functionality that allows authenticated attackers with upload permissions to write files outs…

Remote | Path Traversal
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
Showing 20 of 5731 Results