Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.8 MEDIUM
CVE-2026-6623 — BichitroGan ISP Billing Software Profile users-view cross site scripting

A security flaw has been discovered in BichitroGan ISP Billing Software 2025.3.20. This impacts an unknown function of the file /?_route=settings/users-view/ of the component Profile Page Handler. Pe…

Remote | Cross-Site Scripting
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
4.8 MEDIUM
CVE-2026-6622 — BichitroGan ISP Billing Software Customer edit cross site scripting

A vulnerability was identified in BichitroGan ISP Billing Software 2025.3.20. This affects an unknown function of the file /?\_route=customers/edit/ of the component Customer Handler. Such manipulati…

Remote | Cross-Site Scripting
Apr 20, 2026 Apr 29, 2026
Apr 20, 2026
Apr 29, 2026
0.0 NA
CVE-2026-31430 — X.509: Fix out-of-bounds access when parsing extensions

In the Linux kernel, the following vulnerability has been resolved: X.509: Fix out-of-bounds access when parsing extensions Leo reports an out-of-bounds access when parsing a certificate with empty…

linux_kernel | Memory Corruption
Apr 20, 2026 Apr 23, 2026
Apr 20, 2026
Apr 23, 2026
0.0 NA
CVE-2026-31429 — net: skb: fix cross-cache free of KFENCE-allocated skb head

In the Linux kernel, the following vulnerability has been resolved: net: skb: fix cross-cache free of KFENCE-allocated skb head SKB_SMALL_HEAD_CACHE_SIZE is intentionally set to a non-power-of-2 va…

linux_kernel | Memory Corruption
Apr 20, 2026 Apr 27, 2026
Apr 20, 2026
Apr 27, 2026
6.5 MEDIUM
CVE-2025-13480 — Incorrect authorization in Fudo Enterprise

Fudo Enterprise in versions from 5.5.0 through 5.6.2 allows low privileged users to access certain administrator-only resources via improperly protected API endpoints. This includes sensitive informa…

fudo_enterprise | Remote | Authorization
Apr 20, 2026 May 11, 2026
Apr 20, 2026
May 11, 2026
7.5 HIGH
CVE-2026-6621 — 1024bit extend-deep index.js prototype pollution

A vulnerability was determined in 1024bit extend-deep up to 0.1.6. The impacted element is an unknown function of the file index.js. This manipulation of the argument __proto__ causes improperly cont…

Remote | Injection
Apr 20, 2026 Apr 29, 2026
Apr 20, 2026
Apr 29, 2026
6.5 MEDIUM
CVE-2026-6620 — SonicCloudOrg sonic-server File Upload Endpoint FileTool.java upload path traversal

A vulnerability was found in SonicCloudOrg sonic-server up to 2.0.0. The affected element is the function Upload of the file FileTool.java of the component File Upload Endpoint. The manipulation of t…

Remote | Path Traversal
Apr 20, 2026 Apr 29, 2026
Apr 20, 2026
Apr 29, 2026
5.1 MEDIUM
CVE-2026-6619 — langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting

A vulnerability has been found in langgenius dify up to 1.13.3. Impacted is the function openInNewTab of the file web/app/components/base/image-uploader/image-preview.tsx of the component ImagePrevie…

dify | Remote | Cross-Site Scripting
Apr 20, 2026 Apr 29, 2026
Apr 20, 2026
Apr 29, 2026
6.5 MEDIUM
CVE-2026-6618 — langgenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundl…

A flaw has been found in langgenius dify up to 1.13.3. This issue affects the function parse_openai_plugin_json_to_tool_bundle of the file api/core/tools/utils/parser.py of the component ApiBasedTool…

dify | Remote | Server-Side Request Forgery
Apr 20, 2026 Apr 29, 2026
Apr 20, 2026
Apr 29, 2026
8.8 HIGH
CVE-2026-5967 — TeamT5|ThreatSonar Anti-Ransomware - Privilege Escalation

ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability. Authenticated remote attackers with shell access can inject OS commands and execute them with root privilege…

threatsonar_anti-ransomware | Remote | Injection
Apr 20, 2026 May 12, 2026
Apr 20, 2026
May 12, 2026
8.5 HIGH
CVE-2026-39454 — Sky Co.,LTD. SKYSEA Client View and SKYMEC IT Manager File Permission Bypass Privilege Es…

SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrative user may manipulate and/or plac…

Apr 20, 2026 May 12, 2026
Apr 20, 2026
May 12, 2026
Showing 20 of 6411 Results