Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-7065 — BidingCC BuildingAI Remote Upload API file-storage.service.ts uploadRemoteFile server-sid…

A vulnerability has been found in BidingCC BuildingAI up to 26.0.1. Impacted is the function uploadRemoteFile of the file packages/core/src/modules/upload/services/file-storage.service.ts of the comp…

Remote | Server-Side Request Forgery
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
9.3 CRITICAL
CVE-2026-42363 — GeoVision GV-IP Device Utility Device Authentication insufficient encryption vulnerability

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An att…

gv-ip_device_utility | Remote | Cryptography
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
5.1 MEDIUM
CVE-2026-33566 — LogonTracer Cipher Injection Vulnerability

There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows event log data is loaded, the contents of the database may be altered.

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
8.8 HIGH
CVE-2026-33277 — LogonTracer OS Command Injection Vulnerability

An OS command Injection issue exists in LogonTracer prior to v2.0.0. An arbitrary OS command may be executed by a logged-in user.

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-35903 — MERCURY MIPC252W Improper Authentication in RTSP Service

MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial DESCRIBE request, …

| Authentication
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-35902 — MERCURY IP Camera MIPC252W Authentication DoS Vulnerability

The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication paramete…

| Authentication
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-35901 — Mercury MIPC252W RTSP Session Termination Denial-of-Service

A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger session termination by repeatedly sending SETUP requests for the…

| Denial of Service
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-31256 — MERCURY MIPC252W Null Pointer Dereference RTSP Service Vulnerability

A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n. During the processing of a SETUP request for the path rtsp://<IP>:554/stream…

| Memory Corruption
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-31255 — Tenda AC18 Command Injection Vulnerability

A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows…

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2021-36438 — Sourcecodester Online Job Portal phppdo SQL Injection Vulnerability

SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobportal/index.php.

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7064 — AgentDeskAI browser-tools-mcp browser-connector.ts os command injection

A flaw has been found in AgentDeskAI browser-tools-mcp up to 1.2.0. This issue affects some unknown processing of the file browser-tools-server/browser-connector.ts. Executing a manipulation can lead…

Remote | Injection
Apr 26, 2026 Apr 27, 2026
Apr 26, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7063 — code-projects Employee Management System Endpoint eprocess.php sql injection

A vulnerability was detected in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file /370project/process/eprocess.php of the component Endpoint. Performin…

Remote | Injection
Apr 26, 2026 Apr 27, 2026
Apr 26, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7062 — Intina47 context-sync Git Integration git-integration.ts os command injection

A security vulnerability has been detected in Intina47 context-sync up to 2.0.0. This affects an unknown part of the file src/git-integration.ts of the component Git Integration. Such manipulation le…

Remote | Injection
Apr 26, 2026 Apr 27, 2026
Apr 26, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7061 — Toowiredd chatgpt-mcp-server MCP/HTTP docker.service.ts os command injection

A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/services/docker.service.ts of the component MCP/HTTP. …

Remote | Injection
Apr 26, 2026 Apr 27, 2026
Apr 26, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7060 — liyupi yu-picture MyBatis-Plus PictureServiceImpl.java PageRequest sql injection

A vulnerability was determined in liyupi yu-picture up to a053632c41340152bf75b66b3c543d129123d8ec. This impacts the function PageRequest of the file yu-picture-backend/src/main/java/com/yupi/yupictu…

Remote | Injection
Apr 26, 2026 Apr 27, 2026
Apr 26, 2026
Apr 27, 2026
5.5 MEDIUM
CVE-2026-7059 — 666ghj MiroFish Query Parameter simulation.py get_simulation_posts path traversal

A vulnerability was found in 666ghj MiroFish up to 0.1.2. This affects the function get_simulation_posts of the file backend/app/api/simulation.py of the component Query Parameter Handler. Performing…

Remote | Path Traversal
Apr 26, 2026 Apr 27, 2026
Apr 26, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7058 — 666ghj MiroFish Inter-Process Communication simulation_ipc.py SimulationIPCClient.send_co…

A vulnerability has been found in 666ghj MiroFish up to 0.1.2. The impacted element is the function SimulationIPCClient.send_command of the file backend/app/services/simulation_ipc.py of the componen…

Remote | Injection
Apr 26, 2026 Apr 27, 2026
Apr 26, 2026
Apr 27, 2026
9.0 HIGH
CVE-2026-7057 — Tenda F456 httpd setcfm buffer overflow

A flaw has been found in Tenda F456 1.0.0.5. The affected element is an unknown function of the file /goform/setcfm of the component httpd. This manipulation of the argument funcname/funcpara1 causes…

Remote | Memory Corruption
Apr 26, 2026 Apr 27, 2026
Apr 26, 2026
Apr 27, 2026
9.0 HIGH
CVE-2026-7056 — Tenda F456 httpd SafeUrlFilter fromSafeUrlFilter buffer overflow

A vulnerability was detected in Tenda F456 1.0.0.5. Impacted is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter of the component httpd. The manipulation of the argument page results …

Remote | Memory Corruption
Apr 26, 2026 Apr 27, 2026
Apr 26, 2026
Apr 27, 2026
9.0 HIGH
CVE-2026-7055 — Tenda F456 httpd VirtualSer fromVirtualSer buffer overflow

A security vulnerability has been detected in Tenda F456 1.0.0.5. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component httpd. The manipulation of the argumen…

Remote | Memory Corruption
Apr 26, 2026 Apr 27, 2026
Apr 26, 2026
Apr 27, 2026
Showing 20 of 5720 Results