Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-7068 — D-Link DIR-825 nmbd sserver.c NMBD_process buffer overflow

A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file sserver.c of the component nmbd. Such manipulation leads to buffer overflow. The attack ca…

dir-825_firmware | Memory Corruption
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7067 — D-Link DIR-822 udhcpd DHCP Service dhcpd.c system command injection

A vulnerability was determined in D-Link DIR-822 A_101. The impacted element is the function system of the file /udhcpcd/dhcpd.c of the component udhcpd DHCP Service. This manipulation of the argumen…

dir-822_firmware | Remote | Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7066 — choieastsea simple-openstack-mcp server.py exec_openstack os command injection

A vulnerability was found in choieastsea simple-openstack-mcp up to 767b2f4a8154cca344344b9725537a58399e6036. The affected element is the function exec_openstack of the file server.py. The manipulati…

Remote | Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7065 — BidingCC BuildingAI Remote Upload API file-storage.service.ts uploadRemoteFile server-sid…

A vulnerability has been found in BidingCC BuildingAI up to 26.0.1. Impacted is the function uploadRemoteFile of the file packages/core/src/modules/upload/services/file-storage.service.ts of the comp…

Remote | Server-Side Request Forgery
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
9.3 CRITICAL
CVE-2026-42363 — GeoVision GV-IP Device Utility Device Authentication insufficient encryption vulnerability

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An att…

gv-ip_device_utility | Remote | Cryptography
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
5.1 MEDIUM
CVE-2026-33566 — LogonTracer Cipher Injection Vulnerability

There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows event log data is loaded, the contents of the database may be altered.

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
8.8 HIGH
CVE-2026-33277 — LogonTracer OS Command Injection Vulnerability

An OS command Injection issue exists in LogonTracer prior to v2.0.0. An arbitrary OS command may be executed by a logged-in user.

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2025-69428 — Pro-Bit Directory Traversal

An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdirectories.

| Path Traversal
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-35903 — MERCURY MIPC252W Improper Authentication in RTSP Service

MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial DESCRIBE request, …

| Authentication
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-35902 — MERCURY IP Camera MIPC252W Authentication DoS Vulnerability

The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication paramete…

| Authentication
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-35901 — Mercury MIPC252W RTSP Session Termination Denial-of-Service

A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger session termination by repeatedly sending SETUP requests for the…

| Denial of Service
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-31256 — MERCURY MIPC252W Null Pointer Dereference RTSP Service Vulnerability

A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n. During the processing of a SETUP request for the path rtsp://<IP>:554/stream…

| Memory Corruption
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-31255 — Tenda AC18 Command Injection Vulnerability

A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows…

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2021-36438 — Sourcecodester Online Job Portal phppdo SQL Injection Vulnerability

SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobportal/index.php.

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7064 — AgentDeskAI browser-tools-mcp browser-connector.ts os command injection

A flaw has been found in AgentDeskAI browser-tools-mcp up to 1.2.0. This issue affects some unknown processing of the file browser-tools-server/browser-connector.ts. Executing a manipulation can lead…

Remote | Injection
Apr 26, 2026 Apr 27, 2026
Apr 26, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7063 — code-projects Employee Management System Endpoint eprocess.php sql injection

A vulnerability was detected in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file /370project/process/eprocess.php of the component Endpoint. Performin…

Remote | Injection
Apr 26, 2026 Apr 27, 2026
Apr 26, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7062 — Intina47 context-sync Git Integration git-integration.ts os command injection

A security vulnerability has been detected in Intina47 context-sync up to 2.0.0. This affects an unknown part of the file src/git-integration.ts of the component Git Integration. Such manipulation le…

Remote | Injection
Apr 26, 2026 Apr 27, 2026
Apr 26, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7061 — Toowiredd chatgpt-mcp-server MCP/HTTP docker.service.ts os command injection

A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/services/docker.service.ts of the component MCP/HTTP. …

Remote | Injection
Apr 26, 2026 Apr 27, 2026
Apr 26, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7060 — liyupi yu-picture MyBatis-Plus PictureServiceImpl.java PageRequest sql injection

A vulnerability was determined in liyupi yu-picture up to a053632c41340152bf75b66b3c543d129123d8ec. This impacts the function PageRequest of the file yu-picture-backend/src/main/java/com/yupi/yupictu…

Remote | Injection
Apr 26, 2026 Apr 27, 2026
Apr 26, 2026
Apr 27, 2026
5.5 MEDIUM
CVE-2026-7059 — 666ghj MiroFish Query Parameter simulation.py get_simulation_posts path traversal

A vulnerability was found in 666ghj MiroFish up to 0.1.2. This affects the function get_simulation_posts of the file backend/app/api/simulation.py of the component Query Parameter Handler. Performing…

Remote | Path Traversal
Apr 26, 2026 Apr 27, 2026
Apr 26, 2026
Apr 27, 2026
Showing 20 of 5720 Results