Total CVEs

149,824

Critical Severity

4,834

High Severity

17,268

Last 7 Days

2,932
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 26,701 - 26,720 of 46,229 CVEs
CVE-2026-20061 MEDIUM - 4.3

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. This vu...

Vendor: Cisco
Product: Cisco Unity Connection
Published: Apr 15, 2026
Source: NVD
CVE-2026-20060 MEDIUM - 4.7

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerabili...

Vendor: Cisco
Product: Cisco Unity Connection
Published: Apr 15, 2026
Source: NVD
CVE-2026-20059 MEDIUM - 6.1

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-s...

Vendor: Cisco
Product: Cisco Unity Connection
Published: Apr 15, 2026
Source: NVD
CVE-2025-63029 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Lovers WCFM Marketplace allows SQL Injection.This issue affects WCFM Marketplace: from n/a through 3.7.1.

Vendor: WC Lovers
Product: WCFM Marketplace
Published: Apr 15, 2026
Source: NVD
CVE-2025-15636 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emarket-design YouTube Showcase allows Stored XSS.This issue affects YouTube Showcase: from n/a through 3.5.1.

Vendor: Emarket-design
Product: YouTube Showcase
Published: Apr 15, 2026
Source: NVD
CVE-2025-15635 MEDIUM - 4.3

Cross-Site Request Forgery (CSRF) vulnerability in Zaytech Smart Online Order for Clover allows Cross Site Request Forgery.This issue affects Smart Online Order for Clover: from n/a through 1.6.0.

Vendor: Zaytech
Product: Smart Online Order for Clover
Published: Apr 15, 2026
Source: NVD

Deserialization of untrusted data vulnerability in OpenText, Inc RightFax on Windows, 64 bit, 32 bit allows Object Injection.This issue affects RightFax: through 25.4.

Vendor: OpenText, Inc
Product: RightFax
Published: Apr 15, 2026
Source: NVD

The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege escalation with potential for modification of simulation parameters, training configuration, and...

Published: Apr 15, 2026
Source: NVD
CVE-2026-30625 CRITICAL - 9.8

Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define MCP tasks with arbitrary command and args values. Although an allowlist exists, certain allowed commands (npm, npx) accept argument flags that enable ex...

Published: Apr 15, 2026
Source: NVD
CVE-2026-30624 HIGH - 8.6

Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The application allows users to define MCP servers using a JSON configuration containing arbitrary command and args values. These values are executed by the application when the configu...

Vendor: agent-zero
Product: agent-zero
Published: Apr 15, 2026
Source: NVD
CVE-2026-30617 HIGH - 8.6

LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execution handling. A remote attacker can access the publicly exposed MCP management interface and configure an MCP STDIO server with attacker-controlled commands and arguments. When the...

Published: Apr 15, 2026
Source: NVD
CVE-2026-30616 HIGH - 7.3

Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacker can send crafted network requests to the network-accessible Jaaz application, causing attacker-controlled commands to be executed on the server. Successful exploitation results i...

Published: Apr 15, 2026
Source: NVD
CVE-2026-30615 HIGH - 8.0

A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML content, malicious instructions can cause unauthorized modification of the local MCP configuration and automatic registrat...

Published: Apr 15, 2026
Source: NVD
CVE-2026-30461 HIGH - 8.3

Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function add_git_submodule.

Vendor: thedaylightstudio
Product: fuel_cms
Published: Apr 15, 2026
Source: NVD
CVE-2026-20205 HIGH - 7.2

In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or possesses the high-privilege capability `mcp_tool_admin` could view users session and authorization tokens in clear text.<br><br>The vulnerability would require either l...

Vendor: Splunk
Product: Splunk MCP Server
Published: Apr 15, 2026
Source: NVD
CVE-2026-20204 HIGH - 7.1

In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles could potentially perform...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Apr 15, 2026
Source: NVD
CVE-2026-20203 MEDIUM - 4.3

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles, has write permission on...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Apr 15, 2026
Source: NVD
CVE-2026-20202 MEDIUM - 6.6

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.20, 10.0.2503.13, and 9.3.2411.127, a user who holds a role that contains the high-privilege capability `edit_user`could create a special...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Apr 15, 2026
Source: NVD
CVE-2025-67841 HIGH - 7.5

Nordic Semiconductor IronSide SE for nRF54H20 before 23.0.2+17 has an Algorithmic complexity issue.

Published: Apr 15, 2026
Source: NVD
CVE-2025-53444 MEDIUM - 4.3

Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro allows Cross Site Request Forgery.This issue affects Userpro: from n/a before 5.1.11.

Vendor: DeluxeThemes
Product: Userpro
Published: Apr 15, 2026
Source: NVD