Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2018-25303 — Allok Video to DVD Burner 2.6.1217 Buffer Overflow SEH

Allok Video to DVD Burner 2.6.1217 contains a stack-based buffer overflow vulnerability in the License Name field that allows local attackers to execute arbitrary code by triggering a structured exce…

| Memory Corruption
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.5 HIGH
CVE-2018-25302 — Allok AVI to DVD SVCD VCD Converter 4.0.1217 Buffer Overflow SEH

Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a ma…

wmv_to_avi_mpeg_dvd_wmv_convertor | Memory Corruption
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.6 HIGH
CVE-2018-25301 — Easy MPEG to DVD Burner 1.7.11 SEH Local Buffer Overflow

Easy MPEG to DVD Burner 1.7.11 contains a structured exception handling (SEH) local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious userna…

easy_mpeg_to_dvd_burner | Memory Corruption
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
8.8 HIGH
CVE-2018-25300 — XATABoost CMS 1.0.0 SQL Injection via news.php

XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers c…

Remote | Injection
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
8.6 HIGH
CVE-2018-25299 — Prime95 29.4b8 Local Buffer Overflow via SEH

Prime95 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling (SEH) mechanisms. Attackers can inject malici…

prime95 | Memory Corruption
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
6.9 MEDIUM
CVE-2018-25298 — Merge PACS 7.0 Cross-Site Request Forgery via merge-viewer

Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attacker…

Remote | Cross-Site Request Forgery
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.8 HIGH
CVE-2026-7466 — AgentFlow Arbitrary Python Pipeline Execution via pipeline_path

AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST /api/runs …

Remote | Injection
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
4.8 MEDIUM
CVE-2026-7439 — AgentFlow Local Web API Content-Type Validation Bypass

AgentFlow's local web API accepts non-JSON content types on POST /api/runs and POST /api/runs/validate endpoints without enforcing application/json validation, allowing attackers to bypass trust-boun…

| Misconfiguration
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
8.1 HIGH
CVE-2026-7424 — Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP

Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DNS configuration, an…

freertos-plus-tcp | Denial of Service
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
6.0 MEDIUM
CVE-2026-7423 — Integer Underflow in ICMP Echo Reply Processing in FreeRTOS-Plus-TCP

Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a denial of service (device crash) when outgoing pi…

freertos-plus-tcp | Denial of Service
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
7.1 HIGH
CVE-2026-7422 — MAC Address Validation Bypass in FreeRTOS-Plus-TCP IPv4 and IPv6 Packet Processing

Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC ad…

freertos-plus-tcp | Misconfiguration
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
7.5 HIGH
CVE-2026-7398 — florensiawidjaja BioinfoMCP Upload Endpoint app.py upload path traversal

A weakness has been identified in florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54. This vulnerability affects the function Upload of the file bioinfo_mcp_platform/app.py of…

Remote | Path Traversal
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
4.4 MEDIUM
CVE-2026-7397 — NousResearch hermes-agent file_tools.py _check_sensitive_path symlink

A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path of the file tools/file_tools.py. The manipulation results in symlink following.…

| Path Traversal
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
6.5 MEDIUM
CVE-2026-41499 — Wazuh: Multiple Heap-based NULL WRITE Buffer Underflows in parse_uname_string()

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, multiple heap-based out-of-bounds WRITE vulnerabilities exis…

wazuh | Remote | Memory Corruption
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
9.0 CRITICAL
CVE-2026-30893 — Wazuh cluster sync path traversal in decompress_files() enables arbitrary file write and …

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchroniz…

wazuh | Remote | Path Traversal
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
6.5 MEDIUM
CVE-2026-28221 — Wazuh: Pre-auth stack-based buffer overflow in wazuh-remoted print_hex_string() due to si…

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to before version 4.14.4, a stack-based buffer overflow exists in print_hex_string() i…

wazuh | Remote | Memory Corruption
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
6.3 MEDIUM
CVE-2026-27105 — Dell/Alienware Purchased Apps Link Following Arbitrary File Write

Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could p…

| Path Traversal
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
6.5 MEDIUM
CVE-2026-26206 — Wazuh: API brute-force protection bypass via race condition in login attempt tracking

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, Wazuh's server API brute-force protection for POST /security…

wazuh | Remote | Authentication
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
5.5 MEDIUM
CVE-2026-7396 — NousResearch hermes-agent WeChat Work Platform Adapter wecom.py path traversal

A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component WeChat Work Platform Ad…

Remote | Path Traversal
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
5.8 MEDIUM
CVE-2026-7394 — SourceCodester Pizzafy Ecommerce System GET Parameter view_order.php sql injection

A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/view_order.php of the component GET Parame…

Remote | Injection
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
Showing 20 of 5889 Results