Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-7153 — Totolink A8000RU CGI cstecgi.cgi setMiniuiHomeInfoShow os command injection

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setMiniuiHomeInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. …

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-6741 — LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'co…

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 5.4.1. This is due to a missing authoriz…

| Authorization
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-7152 — Totolink A8000RU CGI cstecgi.cgi setTelnetCfg os command injection

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulat…

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
6.5 MEDIUM
CVE-2026-7150 — dh1011 auto-favicon MCP Tool server.py generate_favicon_from_url server-side request forg…

A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the function generate_favicon_from_url of the file src/auto_favicon/server.py of th…

Remote | Server-Side Request Forgery
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7149 — dexhunter kaggle-mcp server.py prepare_kaggle_dataset path traversal

A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d. This vulnerability affects the function prepare_kaggle_dataset of the file src/kaggle_mcp/server…

Remote | Path Traversal
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
6.5 MEDIUM
CVE-2026-7148 — CodeAstro Online Classroom addnewfaculty sql injection

A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the argument fname can lead to sql injection. The attack …

Remote | Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7147 — JoeCastrom mcp-chat-studio LLM Models API llm.js server-side request forgery

A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/routes/llm.js of the component LLM Models API. Performi…

Remote | Server-Side Request Forgery
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
5.0 MEDIUM
CVE-2026-40970 — Spring Boot Elasticsearch SSL hostname verification bypass

When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0–4…

| Misconfiguration
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-35903 — MERCURY MIPC252W Improper Authentication in RTSP Service

MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial DESCRIBE request, …

| Authentication
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-35902 — MERCURY IP Camera MIPC252W Authentication DoS Vulnerability

The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication paramete…

| Authentication
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-35901 — Mercury MIPC252W RTSP Session Termination Denial-of-Service

A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger session termination by repeatedly sending SETUP requests for the…

| Denial of Service
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
5.3 MEDIUM
CVE-2026-32655 — Dell Alienware Command Center Least Privilege Violation Elevation of Privilege

Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit this vulnera…

| Authorization
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-31256 — MERCURY MIPC252W Null Pointer Dereference RTSP Service Vulnerability

A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n. During the processing of a SETUP request for the path rtsp://<IP>:554/stream…

| Memory Corruption
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-31255 — Tenda AC18 Command Injection Vulnerability

A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows…

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2025-69428 — Pro-Bit Directory Traversal

An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdirectories.

| Path Traversal
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2021-36438 — Sourcecodester Online Job Portal phppdo SQL Injection Vulnerability

SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobportal/index.php.

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-7151 — Tenda HG3 formIPv6Routing formUploadConfig stack-based overflow

A vulnerability was determined in Tenda HG3 2.0. Impacted is the function formUploadConfig of the file /boaform/formIPv6Routing. This manipulation of the argument destNet causes stack-based buffer ov…

| Memory Corruption
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.0 HIGH
CVE-2026-5394 — Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling

An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. …

Remote | Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7146 — AlejandroArciniegas mcp-data-vis HTTP Request server.js axios server-side request forgery

A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d. Affected by this vulnerability is the function axios of the file src/ser…

Remote | Server-Side Request Forgery
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
5.5 MEDIUM
CVE-2026-7145 — mettle sendportal Invitation WorkspaceInvitationsController.php destroy authorization

A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/Controllers/Workspaces/WorkspaceInvitationsController.php of the component Invit…

Remote | Authorization
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
Showing 20 of 5725 Results