Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-6625 — moxi624 Mogu Blog v2 Picture Storage Service LocalFileServiceImpl.java LocalFileServiceIm…

A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of the file mogu_picture/src/main/…

mogublog | Remote | Server-Side Request Forgery
Apr 20, 2026 Apr 29, 2026
Apr 20, 2026
Apr 29, 2026
4.8 MEDIUM
CVE-2026-6624 — BichitroGan ISP Billing Software Pool List add cross site scripting

A weakness has been identified in BichitroGan ISP Billing Software 2025.3.20. Affected is an unknown function of the file /?\_route=pool/add of the component Pool List Interface. Executing a manipula…

Remote | Cross-Site Scripting
Apr 20, 2026 Apr 29, 2026
Apr 20, 2026
Apr 29, 2026
4.8 MEDIUM
CVE-2026-6623 — BichitroGan ISP Billing Software Profile users-view cross site scripting

A security flaw has been discovered in BichitroGan ISP Billing Software 2025.3.20. This impacts an unknown function of the file /?_route=settings/users-view/ of the component Profile Page Handler. Pe…

Remote | Cross-Site Scripting
Apr 20, 2026 Apr 22, 2026
Apr 20, 2026
Apr 22, 2026
4.8 MEDIUM
CVE-2026-6622 — BichitroGan ISP Billing Software Customer edit cross site scripting

A vulnerability was identified in BichitroGan ISP Billing Software 2025.3.20. This affects an unknown function of the file /?\_route=customers/edit/ of the component Customer Handler. Such manipulati…

Remote | Cross-Site Scripting
Apr 20, 2026 Apr 29, 2026
Apr 20, 2026
Apr 29, 2026
0.0 NA
CVE-2026-31430 — X.509: Fix out-of-bounds access when parsing extensions

In the Linux kernel, the following vulnerability has been resolved: X.509: Fix out-of-bounds access when parsing extensions Leo reports an out-of-bounds access when parsing a certificate with empty…

linux_kernel | Memory Corruption
Apr 20, 2026 Apr 23, 2026
Apr 20, 2026
Apr 23, 2026
0.0 NA
CVE-2026-31429 — net: skb: fix cross-cache free of KFENCE-allocated skb head

In the Linux kernel, the following vulnerability has been resolved: net: skb: fix cross-cache free of KFENCE-allocated skb head SKB_SMALL_HEAD_CACHE_SIZE is intentionally set to a non-power-of-2 va…

linux_kernel | Memory Corruption
Apr 20, 2026 Apr 27, 2026
Apr 20, 2026
Apr 27, 2026
6.5 MEDIUM
CVE-2025-13480 — Incorrect authorization in Fudo Enterprise

Fudo Enterprise in versions from 5.5.0 through 5.6.2 allows low privileged users to access certain administrator-only resources via improperly protected API endpoints. This includes sensitive informa…

fudo_enterprise | Remote | Authorization
Apr 20, 2026 May 11, 2026
Apr 20, 2026
May 11, 2026
Showing 20 of 6407 Results