Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-32960 — Silex Technology, Inc. SD-330AC and AMC Manager Password Bypass

SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in resource not removed before reuse. An attacker may login to the device without knowing th…

Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
8.2 HIGH
CVE-2026-32959 — Silex Technology, Inc. SD-330AC and AMC Manager Weak Cryptography Vulnerability

SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a use of a broken or risky cryptographic algorithm. Information in the traffic may be retrieved via man-in-the-middle…

Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
6.9 MEDIUM
CVE-2026-32958 — Silex SD-330AC and AMC Manager Cryptographic Key Hard-Coded Vulnerability

SD-330AC and AMC Manager provided by silex technology, Inc. use a hard-coded cryptographic key. An administrative user may be directed to apply a fake firmware update.

Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
6.9 MEDIUM
CVE-2026-32957 — Silex Technology, Inc. SD-330AC and AMC Manager Unauthenticated File Upload Vulnerability

SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue on firmware maintenance. Arbitrary file may be uploaded on the device without …

Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
9.8 CRITICAL
CVE-2026-32956 — Silex Technology, Inc. SD-330AC and AMC Manager Heap-Based Buffer Overflow Vulnerability

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device.

sd-330ac_firmware sd-330ac amc_manager | Memory Corruption
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
8.8 HIGH
CVE-2026-32955 — Silex Technology, Inc. SD-330AC and AMC Manager Stack-Based Buffer Overflow Vulnerability

SD-330AC and AMC Manager provided by silex technology, Inc. contain a stack-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device.

sd-330ac_firmware sd-330ac amc_manager | Memory Corruption
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
5.1 MEDIUM
CVE-2026-6597 — langflow-ai langflow Flow Using API core.py has_api_terms credentials storage

A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py of the component Flo…

langflow | Remote | Misconfiguration
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
7.5 HIGH
CVE-2026-6596 — langflow-ai langflow API Endpoint endpoints.py create_upload_file unrestricted upload

A security flaw has been discovered in langflow-ai langflow up to 1.1.0. This issue affects the function create_upload_file of the file src/backend/base/Langflow/api/v1/endpoints.py of the component …

langflow | Remote | Misconfiguration
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
7.5 HIGH
CVE-2026-6595 — ProjectsAndPrograms School Management System HTTP GET Parameter buslocation.php sql injec…

A vulnerability was identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This vulnerability affects unknown code of the file buslocation.php of t…

school_management_system | Remote | Injection
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
7.5 HIGH
CVE-2026-6594 — brikcss merge prototype pollution

A vulnerability was determined in brikcss merge up to 1.3.0. This affects an unknown part. Executing a manipulation of the argument __proto__/constructor.prototype/prototype can lead to improperly co…

Remote | Injection
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
5.1 MEDIUM
CVE-2026-6593 — ComfyUI View Endpoint server.py cross site scripting

A vulnerability was found in ComfyUI up to 0.13.0. Affected by this issue is some unknown functionality of the file server.py of the component View Endpoint. Performing a manipulation results in cros…

Remote | Cross-Site Scripting
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
5.1 MEDIUM
CVE-2026-6592 — ComfyUI userdata Endpoint user_manager.py getuserdata cross site scripting

A vulnerability has been found in ComfyUI up to 0.13.0. Affected by this vulnerability is the function getuserdata of the file app/user_manager.py of the component userdata Endpoint. Such manipulatio…

Remote | Cross-Site Scripting
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
5.3 MEDIUM
CVE-2026-6591 — ComfyUI LoadImage Node folder_paths.py folder_paths.get_annotated_filepath path traversal

A flaw has been found in ComfyUI up to 0.13.0. Affected is the function folder_paths.get_annotated_filepath of the file folder_paths.py of the component LoadImage Node. This manipulation of the argum…

Remote | Path Traversal
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
5.3 MEDIUM
CVE-2026-6590 — ComfyUI Model Preview Endpoint model_manager.py get_model_preview path traversal

A vulnerability was detected in ComfyUI up to 0.13.0. This impacts the function get_model_preview of the file app/model_manager.py of the component Model Preview Endpoint. The manipulation results in…

Remote | Path Traversal
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
5.3 MEDIUM
CVE-2026-6589 — ComfyUI server.py create_origin_only_middleware cross-site request forgery

A security vulnerability has been detected in ComfyUI up to 0.13.0. This affects the function create_origin_only_middleware of the file server.py. The manipulation leads to cross-site request forgery…

Remote | Cross-Site Request Forgery
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
6.9 MEDIUM
CVE-2026-6588 — serge-chat serge Model API Endpoint model.py delete_model missing authentication

A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/delete_model of the file api/src/serge/routers/model.py of the component Model API …

Remote | Authentication
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
6.5 MEDIUM
CVE-2026-6587 — vibrantlabsai RAGAS Collections util.py _try_process_url server-side request forgery

A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_m…

Remote | Server-Side Request Forgery
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
6.5 MEDIUM
CVE-2026-6586 — TransformerOptimus SuperAGI Budget Endpoint budget.py update_budget authorization

A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get_budget/update_budget of the file superagi/controllers/budget.py of the component Budget Endpoi…

superagi | Remote | Authorization
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
5.5 MEDIUM
CVE-2026-6585 — TransformerOptimus SuperAGI Organisation Update Endpoint organisation.py update_organisat…

A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This issue affects the function update_organisation of the file superagi/controllers/organisation.py of the component Organ…

superagi | Remote | Authorization
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
5.5 MEDIUM
CVE-2026-6584 — TransformerOptimus SuperAGI User Update Endpoint user.py update_user authorization

A vulnerability was found in TransformerOptimus SuperAGI up to 0.0.14. This vulnerability affects the function update_user of the file superagi/controllers/user.py of the component User Update Endpoi…

superagi | Remote | Authorization
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
Showing 20 of 6460 Results