Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-6979 — devlikeapro WAHA API Request media.controller.ts server-side request forgery

A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.controller.ts of the component API Request Handler. This manipulation causes serve…

Remote | Server-Side Request Forgery
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
5.8 MEDIUM
CVE-2026-6978 — JiZhiCMS addcache.html htmlspecialchars_decode sql injection

A vulnerability was detected in JiZhiCMS up to 2.5.6. The impacted element is the function htmlspecialchars_decode of the file /index.php/admins/Sys/addcache.html. The manipulation of the argument sq…

Remote | Injection
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
7.5 HIGH
CVE-2026-6977 — vanna-ai vanna Legacy Flask API improper authorization

A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. The affected element is an unknown function of the component Legacy Flask API. The manipulation leads to improper authorizati…

Remote | Authorization
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
0.0 NA
CVE-2026-31685 — netfilter: ip6t_eui64: reject invalid MAC header for all packets

In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid MAC header for all packets `eui64_mt6()` derives a modified EUI-64 from the Ethernet source…

| Misconfiguration
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
0.0 NA
CVE-2026-31684 — net: sched: act_csum: validate nested VLAN headers

In the Linux kernel, the following vulnerability has been resolved: net: sched: act_csum: validate nested VLAN headers tcf_csum_act() walks nested VLAN headers directly from skb->data when an skb s…

| Memory Corruption
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
0.0 NA
CVE-2026-31683 — batman-adv: avoid OGM aggregation when skb tailroom is insufficient

In the Linux kernel, the following vulnerability has been resolved: batman-adv: avoid OGM aggregation when skb tailroom is insufficient When OGM aggregation state is toggled at runtime, an existing…

| Memory Corruption
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
0.0 NA
CVE-2026-31682 — bridge: br_nd_send: linearize skb before parsing ND options

In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: linearize skb before parsing ND options br_nd_send() parses neighbour discovery options from ns->opt[] and as…

| Memory Corruption
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
0.0 NA
CVE-2026-31681 — netfilter: xt_multiport: validate range encoding in checkentry

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_multiport: validate range encoding in checkentry ports_match_v1() treats any non-zero pflags entry as the start of …

| Misconfiguration
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
0.0 NA
CVE-2026-31680 — net: ipv6: flowlabel: defer exclusive option free until RCU teardown

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: flowlabel: defer exclusive option free until RCU teardown `ip6fl_seq_show()` walks the global flowlabel hash under the…

| Race Condition
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
0.0 NA
CVE-2026-31679 — openvswitch: validate MPLS set/set_masked payload length

In the Linux kernel, the following vulnerability has been resolved: openvswitch: validate MPLS set/set_masked payload length validate_set() accepted OVS_KEY_ATTR_MPLS as variable-sized payload for …

| Misconfiguration
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
0.0 NA
CVE-2026-31678 — openvswitch: defer tunnel netdev_put to RCU release

In the Linux kernel, the following vulnerability has been resolved: openvswitch: defer tunnel netdev_put to RCU release ovs_netdev_tunnel_destroy() may run after NETDEV_UNREGISTER already detached …

| Race Condition
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
0.0 NA
CVE-2026-31677 — crypto: af_alg - limit RX SG extraction by receive buffer budget

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - limit RX SG extraction by receive buffer budget Make af_alg_get_rsgl() limit each RX scatterlist extraction to t…

| Denial of Service
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
0.0 NA
CVE-2026-31676 — rxrpc: only handle RESPONSE during service challenge

In the Linux kernel, the following vulnerability has been resolved: rxrpc: only handle RESPONSE during service challenge Only process RESPONSE packets while the service connection is still in RXRPC…

| Authentication
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
0.0 NA
CVE-2026-31675 — net/sched: sch_netem: fix out-of-bounds access in packet corruption

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_netem: fix out-of-bounds access in packet corruption In netem_enqueue(), the packet corruption logic uses get_rand…

| Memory Corruption
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
0.0 NA
CVE-2026-31674 — netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check()

In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() Reject rt match rules whose addrnr exceeds IP6T_RT_HOPS. rt_mt6() …

| Misconfiguration
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
0.0 NA
CVE-2026-31673 — af_unix: read UNIX_DIAG_VFS data under unix_state_lock

In the Linux kernel, the following vulnerability has been resolved: af_unix: read UNIX_DIAG_VFS data under unix_state_lock Exact UNIX diag lookups hold a reference to the socket, but not to u->path…

| Race Condition
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
9.8 CRITICAL
CVE-2026-6951 — SimpleGit Remote Code Execution (RCE)

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) t…

Remote | Injection
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
7.8 HIGH
CVE-2026-42171 — NSIS Privilege Escalation Vulnerability

NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTe…

Apr 24, 2026 Apr 24, 2026
Apr 24, 2026
Apr 24, 2026
3.1 LOW
CVE-2026-41488 — angchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_num_tokens_from_messages for image token counting) va…

Remote | Server-Side Request Forgery
Apr 24, 2026 Apr 24, 2026
Apr 24, 2026
Apr 24, 2026
6.5 MEDIUM
CVE-2026-41481 — LangChain: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass

LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters 1.1.2, HTMLHeaderTextSplitter.split_text_from_url() validated the initial URL using valid…

Remote | Server-Side Request Forgery
Apr 24, 2026 Apr 24, 2026
Apr 24, 2026
Apr 24, 2026
Showing 20 of 5971 Results