Total CVEs

125,920

Critical Severity

2,280

High Severity

7,890

Last 7 Days

1,019
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 241 - 260 of 22,325 CVEs
CVE-2026-7378 MEDIUM - 5.5

Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Published: Apr 30, 2026
Source: NVD
CVE-2026-7376 MEDIUM - 5.5

Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Published: Apr 30, 2026
Source: NVD
CVE-2026-7375 MEDIUM - 5.5

UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Published: Apr 30, 2026
Source: NVD
CVE-2026-6868 MEDIUM - 5.5

HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Published: Apr 30, 2026
Source: NVD
CVE-2025-13030 HIGH - 7.1

All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker can upload malicious files and achieve arbitrary code execution since this endpoint lacks authentication protection and proper sanitisation of file nam...

Product: django-mdeditor
Published: Apr 30, 2026
Source: NVD
CVE-2026-7470 HIGH - 8.8

A flaw has been found in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. Affected is the function sub_427C3C of the file /goform/SafeMacFilter. This manipulation of the argument page causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and m...

Vendor: tenda
Product: 4g300_firmware
Published: Apr 30, 2026
Source: NVD
CVE-2026-7469 MEDIUM - 6.3

A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. This impacts the function sub_425A28 of the file /goform/DelFil. The manipulation of the argument delflag results in command injection. The attack may be launched remotely. The exploit is now public and may be used.

Vendor: tenda
Product: 4g300_firmware
Published: Apr 30, 2026
Source: NVD
CVE-2026-7468 HIGH - 7.3

A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/index.html of the component Demo Site. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been d...

Published: Apr 30, 2026
Source: NVD
CVE-2026-7447 MEDIUM - 6.3

A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/update_customer.php. This manipulation of the argument type/length/business parameter validity causes sql injection. The attack is possible to be carried out remot...

Published: Apr 30, 2026
Source: NVD
CVE-2026-7446 HIGH - 7.3

A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_results/export_results/compare_results/scan_directory/create_rule of the file src/index.ts of the component MCP Interface. The manipulation of the argument ID results in os command in...

Published: Apr 30, 2026
Source: NVD
CVE-2026-7445 MEDIUM - 6.3

A security vulnerability has been detected in ZachHandley ZMCPTools up to 0.2.2. Affected by this issue is some unknown functionality of the file src/managers/ResourceManager.ts of the component MCP Log Resource Handler. The manipulation of the argument dirname leads to path traversal. Remote exploi...

Published: Apr 30, 2026
Source: NVD
CVE-2026-7443 HIGH - 7.3

A weakness has been identified in BurtTheCoder mcp-dnstwist up to 1.0.4. Affected by this vulnerability is the function fuzz_domain of the file src/index.ts of the component MCP Interface. Executing a manipulation of the argument Request can lead to os command injection. The attack may be launched r...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7420 HIGH - 8.8

A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file route/goform/ConfigAdvideo. The manipulation of the argument Profile results in buffer overflow. The attack can be executed remotely. The exploit has been released to the pu...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7419 HIGH - 8.8

A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of the file route/goform/formTaskEdit_ap. The manipulation of the argument Profile leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly ava...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7381 CRITICAL - 9.1

Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the variation setting (sendfile type) to be set by the client via the X-Sendfile-Type header, if it is not considered in the middleware constructor or the Pl...

Published: Apr 29, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Apr 29, 2026
Source: NVD

CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

Vendor: pip
Product: ckan
Published: Apr 29, 2026
Source: GitHub

Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory Tool

Vendor: npm
Product: @anthropic-ai/sdk
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42353 HIGH - 8.2

i18next-http-middleware has path traversal / SSRF via user-controlled language and namespace parameters

Vendor: npm
Product: i18next-http-middleware
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42352 HIGH - 8.6

pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber

Vendor: pip
Product: pygeoapi
Published: Apr 29, 2026
Source: GitHub