Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-7018 — Datavane Datavines JWT Token TokenManager.java hard-coded key

A vulnerability was determined in Datavane Datavines up to 13607645e14a4982468cfdbcf75c85cde63bae71. The affected element is an unknown function of the file datavines-core/src/main/java/io/datavines/…

| Cryptography
Apr 26, 2026 Apr 26, 2026
Apr 26, 2026
Apr 26, 2026
4.8 MEDIUM
CVE-2026-7015 — MaxSite CMS Guestbook Plugin cross site scripting

A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_emai…

Remote | Cross-Site Scripting
Apr 26, 2026 Apr 26, 2026
Apr 26, 2026
Apr 26, 2026
4.8 MEDIUM
CVE-2026-7014 — MaxSite CMS down_count Plugin cross site scripting

A flaw has been found in MaxSite CMS up to 109.3. This vulnerability affects unknown code of the component down_count Plugin. This manipulation of the argument f_file/f_prefix causes cross site scrip…

Remote | Cross-Site Scripting
Apr 26, 2026 Apr 26, 2026
Apr 26, 2026
Apr 26, 2026
4.8 MEDIUM
CVE-2026-7013 — MaxSite CMS mail_send Plugin cross site scripting

A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subje…

Remote | Cross-Site Scripting
Apr 26, 2026 Apr 26, 2026
Apr 26, 2026
Apr 26, 2026
4.0 MEDIUM
CVE-2026-42254 — Hickory DNS Zone Poisoning Vulnerability

Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that triggered a response.

Remote | Information Disclosure
Apr 26, 2026 Apr 26, 2026
Apr 26, 2026
Apr 26, 2026
0.0 NA
CVE-2026-7016 — MaxSite CMS ushki Plugin cross site scripting

A vulnerability was found in MaxSite CMS up to 109.3. Impacted is an unknown function of the component ushki Plugin. Performing a manipulation of the argument f_ushka_new/f_ushk results in cross site…

| Cross-Site Scripting
Apr 26, 2026 Apr 26, 2026
Apr 26, 2026
Apr 26, 2026
7.2 HIGH
CVE-2026-42255 — Technitium DNS Server DNS Amplification Vulnerability

Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.

Remote | Denial of Service
Apr 26, 2026 Apr 26, 2026
Apr 26, 2026
Apr 26, 2026
4.8 MEDIUM
CVE-2026-7012 — MaxSite CMS Redirect Plugin cross site scripting

A vulnerability was detected in MaxSite CMS up to 109.3. This affects an unknown part of the component Redirect Plugin. The manipulation of the argument f_all/f_all404 results in cross site scripting…

Remote | Cross-Site Scripting
Apr 26, 2026 Apr 26, 2026
Apr 26, 2026
Apr 26, 2026
4.8 MEDIUM
CVE-2026-7011 — MaxSite CMS Antispam Plugin plugin_antispam cross site scripting

A weakness has been identified in MaxSite CMS up to 109.3. Affected by this vulnerability is an unknown functionality of the file /admin/plugin_antispam of the component Antispam Plugin. Executing a …

Remote | Cross-Site Scripting
Apr 26, 2026 Apr 26, 2026
Apr 26, 2026
Apr 26, 2026
7.5 HIGH
CVE-2026-7002 — KLiK SocialMediaWebsite Private Message get_message_ajax.php sql injection

A vulnerability was determined in KLiK SocialMediaWebsite up to 1.0.1. This vulnerability affects unknown code of the file /includes/get_message_ajax.php of the component Private Message Handler. Exe…

Remote | Injection
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
4.8 MEDIUM
CVE-2026-7001 — Datacom DM4100 Ethernet Configuration cross site scripting

A vulnerability was found in Datacom DM4100 1.3.6.1.4.1.3709. This affects an unknown part of the component Ethernet Configuration Page. Performing a manipulation of the argument Name results in cros…

Remote | Cross-Site Scripting
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
4.8 MEDIUM
CVE-2026-7000 — Datacom DM4100 VLAN Page cross site scripting

A vulnerability has been found in Datacom DM4100 1.3.6.1.4.1.3709. Affected by this issue is some unknown functionality of the component VLAN Page. Such manipulation of the argument VLAN Name leads t…

Remote | Cross-Site Scripting
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
4.8 MEDIUM
CVE-2026-6999 — BIVOCOM TR321 Wireless Setting cross site scripting

A flaw has been found in BIVOCOM TR321 21.1.1.50. Affected by this vulnerability is an unknown functionality of the component Wireless Setting. This manipulation of the argument Network Name SSID cau…

Remote | Cross-Site Scripting
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
4.8 MEDIUM
CVE-2026-6998 — BDCOM P3310D New RMON Statistics cross site scripting

A vulnerability was detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. Affected is an unknown function of the component New RMON Statistics Page. The manipulation of the argument Owner results in cr…

Remote | Cross-Site Scripting
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
4.8 MEDIUM
CVE-2026-6997 — BDCOM P3310D New RMON History cross site scripting

A security vulnerability has been detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This impacts an unknown function of the component New RMON History Page. The manipulation of the argument Owner l…

Remote | Cross-Site Scripting
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
4.8 MEDIUM
CVE-2026-6996 — BDCOM P3310D rmon event Tab cross site scripting

A weakness has been identified in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This affects an unknown function of the component rmon event Tab. Executing a manipulation of the argument Description can le…

Remote | Cross-Site Scripting
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
4.8 MEDIUM
CVE-2026-6995 — BDCOM P3310D New User index.asp cross site scripting

A security flaw has been discovered in BDCOM P3310D 0.4.2 10.1.0F Build 86345. The impacted element is an unknown function of the file /index.asp of the component New User Page. Performing a manipula…

Remote | Cross-Site Scripting
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
6.5 MEDIUM
CVE-2026-6994 — Envoy Query Parameter header_mutation.cc params.add injection

A weakness has been identified in Envoy up to 1.33.0. Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc of the component Query Paramete…

Remote | Injection
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
5.5 MEDIUM
CVE-2026-6993 — go-kratos http.DefaultServeMux Fallback server.go NewServer confused deputy

A security flaw has been discovered in go-kratos kratos up to 2.9.2. This impacts the function NewServer of the file transport/http/server.go of the component http.DefaultServeMux Fallback Handler. T…

Remote | Misconfiguration
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
8.3 HIGH
CVE-2026-6992 — Linksys MR9600 JNAP Action run_central2.sh BTRequestGetSmartConnectStatus os command inje…

A vulnerability was identified in Linksys MR9600 2.0.6.206937. This affects the function BTRequestGetSmartConnectStatus of the file /etc/init.d/run_central2.sh of the component JNAP Action Handler. T…

Remote | Injection
Apr 25, 2026 Apr 25, 2026
Apr 25, 2026
Apr 25, 2026
Showing 20 of 5765 Results