Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-5532 — ScrapeGraphAI scrapegraph-ai GenerateCodeNode generate_code_node.py create_sandbox_and_ex…

A vulnerability was found in ScrapeGraphAI scrapegraph-ai up to 1.74.0. The affected element is the function create_sandbox_and_execute of the file scrapegraphai/nodes/generate_code_node.py of the co…

Remote | Injection
Apr 05, 2026 Apr 29, 2026
Apr 05, 2026
Apr 29, 2026
5.5 MEDIUM
CVE-2026-5531 — SourceCodester Student Result Management System HTTP GET Request login_credentials.txt cl…

A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. Th…

student_result_management_system | Remote | Information Disclosure
Apr 05, 2026 Apr 24, 2026
Apr 05, 2026
Apr 24, 2026
6.5 MEDIUM
CVE-2026-5530 — Ollama Model Pull API download.go server-side request forgery

A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side…

ollama | Remote | Server-Side Request Forgery
Apr 05, 2026 Apr 24, 2026
Apr 05, 2026
Apr 24, 2026
5.3 MEDIUM
CVE-2026-5529 — Dromara lamp-cloud DefUserController pageUser improper authorization

A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipul…

Remote | Authorization
Apr 05, 2026 Apr 29, 2026
Apr 05, 2026
Apr 29, 2026
6.5 MEDIUM
CVE-2026-5528 — MoussaabBadla code-screenshot-mcp HTTP os command injection

A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command inject…

Remote | Injection
Apr 05, 2026 Apr 29, 2026
Apr 05, 2026
Apr 29, 2026
5.5 MEDIUM
CVE-2026-5527 — Tenda 4G03 Pro ECDSA P-256 Private Key server.key hard-coded key

A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Pr…

4g03_pro_firmware 4g03_pro | Remote | Cryptography
Apr 05, 2026 Apr 30, 2026
Apr 05, 2026
Apr 30, 2026
9.8 CRITICAL
CVE-2026-5526 — Tenda 4G03 Pro httpd access control

A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin/httpd. The manipulation result…

4g03_pro_firmware 4g03_pro | Remote | Authorization
Apr 04, 2026 Apr 30, 2026
Apr 04, 2026
Apr 30, 2026
Showing 20 of 5607 Results