Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-41603 — Apache Thrift: Java TSSLTransportFactory hostname verification

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixe…

| Misconfiguration
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
0.0 NA
CVE-2026-41602 — Apache Thrift: Go TFramedTransport uint32 overflow

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to versio…

| Memory Corruption
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
0.0 NA
CVE-2025-48431 — Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid poin…

Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, w…

| Memory Corruption
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
10.0 HIGH
CVE-2026-7248 — D-Link DI-8100 CGI Endpoint tgfile.htm tgfile_htm buffer overflow

A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. The manipulation of the argument fn results in buffe…

Remote | Memory Corruption
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
8.3 HIGH
CVE-2026-7247 — D-Link DI-8100 File Extension file_exten.asp file_exten_asp buffer overflow

A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component File Extension Handler. The manipulation…

Remote | Memory Corruption
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
10.0 HIGH
CVE-2026-7244 — Totolink A8000RU CGI cstecgi.cgi setWiFiEasyGuestCfg os command injection

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Th…

Remote | Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
10.0 HIGH
CVE-2026-7243 — Totolink A8000RU CGI cstecgi.cgi setRadvdCfg os command injection

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulatio…

Remote | Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
10.0 HIGH
CVE-2026-7242 — Totolink A8000RU CGI cstecgi.cgi setOpenVpnClientCfg os command injection

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnClientCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipul…

Remote | Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
10.0 HIGH
CVE-2026-7241 — Totolink A8000RU CGI cstecgi.cgi setWiFiBasicCfg os command injection

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipula…

Remote | Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
6.5 MEDIUM
CVE-2026-40980 — Spring AI Memory Allocation Denial of Service (DoS)

In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayoutTextStripper`. Affected versions: Spring AI: 1.0.0 - 1.…

Remote | Denial of Service
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
6.1 MEDIUM
CVE-2026-40979 — Spring AI ONNX Model Exposure Vulnerability

In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)

| Misconfiguration
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
8.8 HIGH
CVE-2026-40978 — Spring AI CosmosDBVectorStore SQL Injection

SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0…

Remote | Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
0.0 NA
CVE-2025-10539 — Improper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking App

Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime upda…

| Misconfiguration
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
10.0 HIGH
CVE-2026-7240 — Totolink A8000RU CGI cstecgi.cgi setVpnAccountCfg os command injection

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setVpnAccountCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such ma…

Remote | Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
5.8 MEDIUM
CVE-2026-7238 — code-projects Online Music Site AdminUpdateAlbum.php unrestricted upload

A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. This manipulation of the argument txtimage causes unres…

Remote | Misconfiguration
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
7.5 HIGH
CVE-2026-7237 — AgiFlow scaffold-mcp write-to-file Tool index.ts path traversal

A vulnerability was detected in AgiFlow scaffold-mcp up to 1.0.27. Affected by this issue is some unknown functionality of the file packages/scaffold-mcp/src/server/index.ts of the component write-to…

Remote | Path Traversal
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
5.5 MEDIUM
CVE-2026-7235 — ErlichLiu claude-agent-sdk-master route.ts path traversal

A security vulnerability has been detected in ErlichLiu claude-agent-sdk-master up to b185aa7ff0d864581257008077b4010fca1747bf. Affected by this vulnerability is an unknown functionality of the file …

Remote | Path Traversal
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
5.3 MEDIUM
CVE-2026-4911 — Booking Package <= 1.7.06 - Unauthenticated Price Manipulation via 'amount' Parameter

The Booking Package plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.7.06 This is due to the intentForStripe() function passing user-controlled $_POST['amo…

Remote | Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
6.4 MEDIUM
CVE-2026-4805 — Woostify <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lity.js …

The Woostify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.0 This is due to insufficient input sanitization and output escaping in the bundle…

Remote | Cross-Site Scripting
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
6.5 MEDIUM
CVE-2026-41526 — KDE KCoreAddons Shell Injection Vulnerability

In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading …

| Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
Showing 20 of 5808 Results