Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-7147 — JoeCastrom mcp-chat-studio LLM Models API llm.js server-side request forgery

A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/routes/llm.js of the component LLM Models API. Performi…

Remote | Server-Side Request Forgery
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
5.0 MEDIUM
CVE-2026-40970 — Spring Boot Elasticsearch SSL hostname verification bypass

When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0–4…

| Misconfiguration
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-35903 — MERCURY MIPC252W Improper Authentication in RTSP Service

MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial DESCRIBE request, …

| Authentication
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-35902 — MERCURY IP Camera MIPC252W Authentication DoS Vulnerability

The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication paramete…

| Authentication
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
4.4 MEDIUM
CVE-2026-35901 — Mercury MIPC252W RTSP Session Termination Denial-of-Service

A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger session termination by repeatedly sending SETUP requests for the…

| Denial of Service
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
5.3 MEDIUM
CVE-2026-32655 — Dell Alienware Command Center Least Privilege Violation Elevation of Privilege

Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit this vulnera…

| Authorization
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-31256 — MERCURY MIPC252W Null Pointer Dereference RTSP Service Vulnerability

A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n. During the processing of a SETUP request for the path rtsp://<IP>:554/stream…

| Memory Corruption
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-31255 — Tenda AC18 Command Injection Vulnerability

A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows…

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2025-69428 — Pro-Bit Directory Traversal

An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdirectories.

| Path Traversal
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2021-36438 — Sourcecodester Online Job Portal phppdo SQL Injection Vulnerability

SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobportal/index.php.

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7146 — AlejandroArciniegas mcp-data-vis HTTP Request server.js axios server-side request forgery

A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d. Affected by this vulnerability is the function axios of the file src/ser…

Remote | Server-Side Request Forgery
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
5.5 MEDIUM
CVE-2026-7145 — mettle sendportal Invitation WorkspaceInvitationsController.php destroy authorization

A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/Controllers/Workspaces/WorkspaceInvitationsController.php of the component Invit…

Remote | Authorization
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
5.3 MEDIUM
CVE-2026-7144 — 1000 Projects Portfolio Management System MCA update_passwd_process.php authorization

A security flaw has been discovered in 1000 Projects Portfolio Management System MCA 1.0. This impacts an unknown function of the file update_passwd_process.php. The manipulation of the argument temp…

Remote | Authorization
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
6.5 MEDIUM
CVE-2026-7143 — 1000 Projects Portfolio Management System MCA block_status.php sql injection

A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown function of the file /admin/block_status.php. The manipulation of the argument q lea…

Remote | Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-31691 — igb: remove napi_synchronize() in igb_down()

In the Linux kernel, the following vulnerability has been resolved: igb: remove napi_synchronize() in igb_down() When an AF_XDP zero-copy application terminates abruptly (e.g., kill -9), the XSK bu…

| Race Condition
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-31690 — firmware: thead: Fix buffer overflow and use standard endian macros

In the Linux kernel, the following vulnerability has been resolved: firmware: thead: Fix buffer overflow and use standard endian macros Addresses two issues in the TH1520 AON firmware protocol driv…

| Memory Corruption
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-31689 — EDAC/mc: Fix error path ordering in edac_mc_alloc()

In the Linux kernel, the following vulnerability has been resolved: EDAC/mc: Fix error path ordering in edac_mc_alloc() When the mci->pvt_info allocation in edac_mc_alloc() fails, the error path wi…

| Memory Corruption
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-31688 — driver core: enforce device_lock for driver_match_device()

In the Linux kernel, the following vulnerability has been resolved: driver core: enforce device_lock for driver_match_device() Currently, driver_match_device() is called from three sites. One site …

| Race Condition
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-31687 — gpio: omap: do not register driver in probe()

In the Linux kernel, the following vulnerability has been resolved: gpio: omap: do not register driver in probe() Commit 11a78b794496 ("ARM: OMAP: MPUIO wake updates") registers the omap_mpuio_driv…

| Misconfiguration
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-31686 — mm/kasan: fix double free for kasan pXds

In the Linux kernel, the following vulnerability has been resolved: mm/kasan: fix double free for kasan pXds kasan_free_pxd() assumes the page table is always struct page aligned. But that's not a…

| Memory Corruption
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
Showing 20 of 5733 Results