Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-40201 — Diplodoc Search Extension Stored Cross-Site Scripting Vulnerability

@diplodoc/search-extension 1.0.0 through 3.x before 3.0.3 allows stored XSS via the title in a .md file.

Remote | Cross-Site Scripting
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
8.4 HIGH
CVE-2026-7584 — Arbitrary Code Execution via Unsafe Deserialization in LabOne Q

The LabOne Q serialization framework uses a class-loading mechanism (import_cls) to dynamically import and instantiate Python classes during deserialization. Prior to the fix, this mechanism accepted…

| Authentication
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
10.0 CRITICAL
CVE-2026-42996 — JS8Call APRSIS Client Stack-Based Buffer Overflow

JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of @APRSIS GRID followed by a long Maidenhead locator. This occurs in grid2deg in APR…

Remote | Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2026-7555 — itsourcecode Electronic Judging System login.php sql injection

A vulnerability was identified in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /intrams/login.php. Such manipulation of the argument Username leads to sql inje…

Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
5.6 MEDIUM
CVE-2026-7554 — D-Link M60 httpd password recovery

A vulnerability was determined in D-Link M60 up to 1.20B02. Affected by this issue is some unknown functionality of the file /usr/bin/httpd. This manipulation causes weak password recovery. The attac…

Remote | Authentication
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
6.4 MEDIUM
CVE-2026-6127 — Elementor Website Builder <= 4.0.4 - Authenticated (Contributor+) Stored Cross-Site Scrip…

The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _elementor_data meta field in versions up to, and including, 4.0.4. This is due to insufficient…

website_builder | Remote | Cross-Site Scripting
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
6.1 MEDIUM
CVE-2024-13362 — Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. Thi…

May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
5.8 MEDIUM
CVE-2026-7553 — code-projects Gym Management System edit_exercises.php sql injection

A vulnerability was found in code-projects Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/edit_exercises.php. The manipulation of the argumen…

Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2026-7550 — SourceCodester Pharmacy Sales and Inventory System ajax.php save_customer sql injection

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected is an unknown function of the file /ajax.php?action=save_customer. The manipulation of the argument …

Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2026-7549 — SourceCodester Pharmacy Sales and Inventory System ajax.php delete_customer sql injection

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=delete_customer. Executing a manipulation of the argumen…

Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
8.8 HIGH
CVE-2026-42994 — Bitwarden CLI Malicious Code Injection

Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkmarx supply chain incident.

Remote | Supply Chain
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
9.0 HIGH
CVE-2026-7548 — Totolink NR1800X cstecgi.cgi sub_41A68C command injection

A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. This affects the function sub_41A68C of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument setUssd result…

nr1800x_firmware | Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
10.0 HIGH
CVE-2026-7546 — Totolink NR1800X lighttpd find_host_ip stack-based overflow

A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such manipulation of the argument Ho…

nr1800x_firmware | Remote | Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2026-7545 — SourceCodester Advanced School Management System checkEmail Endpoint commonController.php…

A weakness has been identified in SourceCodester Advanced School Management System 1.0. The affected element is an unknown function of the file commonController.php of the component checkEmail Endpoi…

advanced_school_management_system | Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
10.0 HIGH
CVE-2026-7538 — Totolink A8000RU CGI cstecgi.cgi vulnerability os command injection

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function Vulnerability of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation o…

a8000ru_firmware | Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
5.5 MEDIUM
CVE-2026-7536 — Open5GS BSF pcfBindings bsf_sess_add_by_ip_address denial of service

A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function bsf_sess_add_by_ip_address of the file /nbsf-management/v1/pcfBindings of the component BSF. Executing a…

open5gs | Remote | Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
4.3 MEDIUM
CVE-2026-7535 — Open5GS transfer-update denial of service

A vulnerability was found in Open5GS up to 2.7.7. This affects the function amf_namf_comm_handle_registration_status_update_request in the library /lib/app/ogs-init.c of the file /namf-comm/v1/ue-con…

open5gs | Remote | Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2026-7519 — Fujian Apex LiveBOS Endpoint UploadImage.do path traversal

A vulnerability has been found in Fujian Apex LiveBOS up to 2.0. Impacted is an unknown function of the file /feed/UploadImage.do of the component Endpoint. Such manipulation of the argument filename…

Remote | Path Traversal
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
4.3 MEDIUM
CVE-2026-7518 — Open5GS AMF SBI Endpoint sdmsubscription-notify amf_namf_callback_handle_sdm_data_change_…

A flaw has been found in Open5GS up to 2.7.7. This issue affects the function amf_namf_callback_handle_sdm_data_change_notify of the file /namf-callback/v1/{id}/sdmsubscription-notify of the componen…

open5gs | Remote | Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
9.0 HIGH
CVE-2026-7513 — UTT HiPER 1200GW formRemoteControl strcpy buffer overflow

A vulnerability has been found in UTT HiPER 1200GW up to 2.5.3-170306. The impacted element is the function strcpy of the file /goform/formRemoteControl. The manipulation leads to buffer overflow. Th…

Remote | Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
Showing 20 of 5903 Results