Total CVEs

124,116

Critical Severity

2,092

High Severity

7,265

Last 7 Days

1,068
Quick preset (or use dates below)
Clear Filters
๐Ÿ“† Custom Date Range: Apr 5, 2026 - Apr 5, 2026 Clear Custom Dates โ†’
Showing 1 - 20 of 112 CVEs
CVE-2026-5604 HIGH - 8.8

A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Performing a manipulation of the argument standard results in stack-based buffer overflow. Remote exploita...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5603 MEDIUM - 5.3

A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/index.ts. Such manipulation leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used....

Vendor: npm
Product: @elgentos/magento2-dev-mcp
Published: Apr 05, 2026
Source: NVD
CVE-2026-5602 MEDIUM - 5.3

A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/tools.ts of the component new_heim_application/deploy_heim_application/deploy_heim_application_to_cloud. This manipulation causes os command injection. The attack requires local acc...

Vendor: npm
Product: @nor2/heim-mcp
Published: Apr 05, 2026
Source: NVD
CVE-2026-5601 MEDIUM - 5.3

A vulnerability was found in Acrel Electrical Prepaid Cloud Platform 1.0. This issue affects some unknown processing of the file /bin.rar of the component Backup File Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been made public an...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5597 MEDIUM - 6.3

A flaw has been found in griptape-ai griptape 0.19.4. This affects an unknown part of the file griptape\tools\computer\tool.py of the component ComputerTool. Executing a manipulation of the argument filename can lead to path traversal. It is possible to launch the attack remotely. The exploit has be...

Published: Apr 05, 2026
Source: NVD
CVE-2026-4272 HIGH - 8.1

Missing Authentication for Critical Function vulnerability in Honeywell Handheld Scanners allows Authentication Abuse.This issue affects Handheld Scanners: from C1 Base(Ingenic x1000) before GK000432BAA, from D1 Base(Ingenic x1600) before HE000085BAA, from A1/B1 Base(IMX25) before BK000763BAA_BK0007...

Published: Apr 05, 2026
Source: NVD

Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.

Vendor: Zcash
Product: zcashd
Published: Apr 05, 2026
Source: NVD
CVE-2026-5596 MEDIUM - 6.3

A vulnerability was detected in griptape-ai griptape 0.19.4. Affected by this issue is some unknown functionality of the file griptape/tools/sql/tool.py of the component SqlTool. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit is now pu...

Published: Apr 05, 2026
Source: NVD
CVE-2019-25704 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the filter_user_mail parameter. Attackers can send crafted requests with malicious SQL statements to extract sensitive database information or modify data.

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25702 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_project parameter. Attackers can send crafted requests with malicious SQL statements in the id_project parameter to extract sensitive database informat...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25700 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the sort_direction parameter. Attackers can submit malicious SQL statements in the sort_direction parameter to extract sensitive database information or modif...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25698 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_to_delete parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_delete field to extract or modify sensitive databas...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25696 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the language_tag parameter. Attackers can submit malicious SQL statements in the language_tag parameter to extract sensitive database information or modify da...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25694 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user2reset parameter. Attackers can send crafted requests with malicious SQL payloads to extract sensitive database information or modify ...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25692 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id_to_modify' parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_modify field to extract sensitive datab...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25690 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the mng_profile_id parameter. Attackers can send crafted requests with malicious SQL payloads in the mng_profile_id parameter to extract sensitive database in...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25688 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the menu_lev1 parameter. Attackers can send crafted requests with malicious SQL payloads in the menu_lev1 parameter to extract sensitive datab...

Vendor: Kados
Product: Kados GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25687 CRITICAL - 9.8

Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality. Attackers can send POST requests to the submit.php endpoint with malicious PHP code in the action...

Vendor: wisdom
Product: Pegasus CMS
Published: Apr 05, 2026
Source: NVD
CVE-2019-25686 HIGH - 7.5

Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by sending a malformed command with an oversized buffer. Attackers can send a PBSZ command with a payload exceeding 211 bytes to trigger an access violatio...

Vendor: Coreftp
Product: Core FTP
Published: Apr 05, 2026
Source: NVD
CVE-2019-25685 HIGH - 8.8

phpBB contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by exploiting the plupload functionality and phar:// stream wrapper. Attackers can upload a crafted zip file containing serialized PHP objects that execute arbitrary code when deserial...

Vendor: phpBB
Product: phpBB
Published: Apr 05, 2026
Source: NVD