Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-7592 — iSourcecode Courier Management System SQL Injection Vulnerability

A weakness has been identified in itsourcecode Courier Management System 1.0. This affects an unknown function of the file /edit_staff.php. Executing a manipulation of the argument ID can lead to sql…

Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
6.5 MEDIUM
CVE-2026-7591 — TimBroddin astro-mcp-server MCP Tool Query Construction index.ts sql injection

A security flaw has been discovered in TimBroddin astro-mcp-server up to 1.1.1. The impacted element is an unknown function of the file src/index.ts of the component MCP Tool Query Construction. Perf…

Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2026-7590 — eyal-gor p_69_branch_monkey_mcp Preview Endpoint advanced.py os command injection

A vulnerability was identified in eyal-gor p_69_branch_monkey_mcp up to 69bc71874ce40050ef45fde5a435855f18af3373. The affected element is an unknown function of the file branch_monkey_mcp/bridge_and_…

Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
5.5 MEDIUM
CVE-2026-7589 — ghantakiran splunk-mcp-integration CSV Export csv_export.py create_csv_export path traver…

A vulnerability was determined in ghantakiran splunk-mcp-integration up to 0b86b09d5e5adf0433acd43c975951224613a1a6. Impacted is the function create_csv_export of the file services/csv-export-service…

Remote | Path Traversal
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
0.0 NA
CVE-2026-30363 — Flipperzero Firmware Stack Overflow Vulnerability

flipperzero-firmware commit ad2a80 was discovered to contain a stack overflow in the "Main" function.

| Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.8 HIGH
CVE-2025-52347 — PassMark DirectIo64.sys Kernel Memory Access Privilege Escalation Vulnerability

An issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and PerformanceTest v11.1 Build 1004 allows attackers to access kernel memory and escal…

| Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
5.5 MEDIUM
CVE-2026-7588 — ggerve coding-standards-mcp server.py get_best_practices path traversal

A vulnerability was found in ggerve coding-standards-mcp. This issue affects the function get_style_guide/get_best_practices of the file server.py. The manipulation of the argument Language results i…

Remote | Path Traversal
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2026-37457 — FRRouting BGP Flowspec Off-by-One Out-of-Bounds Write Denial of Service

An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) …

Remote | Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
4.4 MEDIUM
CVE-2026-35233 — Oracle dtrace ELF Parser NULL Pointer Dereference

An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-level dtrace attaches to -- or instruments -- that process (via…

| Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
6.5 MEDIUM
CVE-2026-26461 — "Aver PTC320UV2 Command Injection Vulnerability"

A Command Injection vulnerability in the web management interface in Aver PTC320UV2 0.1.0000.65 allows an unauthenticated attacker to execute arbitrary commands via a crafted web request.

Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
3.3 LOW
CVE-2026-21996 — Oracle Solaris Dtrace Integer Divide-by-Zero Vulnerability

An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an integer Divide-by-Zero in Pbuild_file_symtab()

| Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
6.1 MEDIUM
CVE-2025-69606 — GSVoIP Web Panel Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in the `/painel/gateways.php/error` endpoint does not properly sanitize user-suppli…

Remote | Cross-Site Scripting
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2025-63548 — Eprosima Micro-XREC-DDS Agent Boolean Field Denial of Service

An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a packet specially crafted to bear a non-valid value in any Boolean field.

Remote | Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2025-63547 — Eprosima Micro-XREC-DDS Agent MTU Length Field Denial of Service

An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a crafted packet to the MTU length field

Remote | Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
4.3 MEDIUM
CVE-2026-7587 — Open5GS AMF nsmf-handler.c amf_nsmf_pdusession_handle_update_sm_context denial of service

A vulnerability has been found in Open5GS up to 2.7.7. This vulnerability affects the function amf_nsmf_pdusession_handle_update_sm_context of the file /src/amf/nsmf-handler.c of the component AMF. T…

Remote | Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2026-42485 — "AGL agl-service-can-low-level Stack Buffer Overflow (RCE)"

AGL agl-service-can-low-level contains a stack buffer overflow in the uds-c library. The send_diagnostic_request function in uds.c allocates a 6-byte stack buffer (MAX_DIAGNOSTIC_PAYLOAD_SIZE=6) but …

Remote | Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
8.6 HIGH
CVE-2026-42469 — OVMS3 Buffer Overflow Vulnerability

Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_canswitch.cpp the parser does not properly validate a CANswitch DLC value, allowing remote attackers to…

Remote | Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
8.8 HIGH
CVE-2026-42468 — OVMS3 Buffer Overflow Vulnerability

Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_pcap.cpp , the parser's phdr.len field is not properly validated, allowing remote attackers to cause a …

Remote | Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2026-42467 — "Open-SAE-J1939 CAN Bus Denial of Service Vulnerability"

An issue was discovered in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Binary_Data_Transfer_DM16 causing a denial of service via crafted CAN fra…

Remote | Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
10.0 CRITICAL
CVE-2026-37541 — OVMS3 Buffer Overflow Vulnerability

Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary data is not properly validated, allowing remote attackers t…

Remote | Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
Showing 20 of 5892 Results