Total CVEs

125,674

Critical Severity

2,261

High Severity

7,825

Last 7 Days

1,174
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 461 - 480 of 22,079 CVEs
CVE-2026-7152 CRITICAL - 9.8

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument telnet_enabled leads to os command injection. It is possible to launch the attack...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7151 HIGH - 8.8

A vulnerability was determined in Tenda HG3 2.0. Impacted is the function formUploadConfig of the file /boaform/formIPv6Routing. This manipulation of the argument destNet causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and m...

Published: Apr 27, 2026
Source: NVD
CVE-2026-6741 HIGH - 8.8

The LatePoint โ€“ Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 5.4.1. This is due to a missing authorization check in the execute() method of the connect-customer-to-wp-user ability, which only requires t...

Published: Apr 27, 2026
Source: NVD

An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. This issue affects pimcore: 12.3.3.

Published: Apr 27, 2026
Source: NVD
CVE-2026-7150 MEDIUM - 6.3

A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the function generate_favicon_from_url of the file src/auto_favicon/server.py of the component MCP Tool. The manipulation of the argument image_url results in server-side request forge...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7149 HIGH - 7.3

A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d. This vulnerability affects the function prepare_kaggle_dataset of the file src/kaggle_mcp/server.py. The manipulation of the argument competition_id leads to path traversal. The attack is possible ...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7148 MEDIUM - 6.3

A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.

Published: Apr 27, 2026
Source: NVD
CVE-2026-7147 HIGH - 7.3

A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/routes/llm.js of the component LLM Models API. Performing a manipulation of the argument req.query.base_url results in server-side request forgery. Remote e...

Published: Apr 27, 2026
Source: NVD
CVE-2026-40970 MEDIUM - 5.0

When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0โ€“4.0.5; upgrade to 4.0.6 or later per vendor advisory.

Vendor: Spring
Product: Spring Boot
Published: Apr 27, 2026
Source: NVD
CVE-2026-35903 CRITICAL - 9.8

MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial DESCRIBE request, the device does not verify the Digest response parameter in subsequent RTSP requests within the same ...

Published: Apr 27, 2026
Source: NVD
CVE-2026-35902 MEDIUM - 6.2

The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication parameters, an unauthenticated attacker can cause the RTSP service to enter a persistent authentication failu...

Published: Apr 27, 2026
Source: NVD
CVE-2026-35901 MEDIUM - 4.4

A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger session termination by repeatedly sending SETUP requests for the same media track within a single RTSP session. This causes the server to reset the RTSP connection, ...

Published: Apr 27, 2026
Source: NVD
CVE-2026-32655 MEDIUM - 5.3

Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

Vendor: Dell
Product: Alienware Command Center (AWCC)
Published: Apr 27, 2026
Source: NVD
CVE-2026-31256 HIGH - 7.5

A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n. During the processing of a SETUP request for the path rtsp://<IP>:554/stream1/track2, the device fails to properly validate the Transport header field. When this header is...

Published: Apr 27, 2026
Source: NVD
CVE-2026-31255 CRITICAL - 9.8

A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows attackers to execute arbitrary system commands.

Vendor: tenda
Product: ac18_firmware
Published: Apr 27, 2026
Source: NVD
CVE-2025-69428 HIGH - 7.5

An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdirectories.

Published: Apr 27, 2026
Source: NVD
CVE-2021-36438 MEDIUM - 6.5

SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobportal/index.php.

Published: Apr 27, 2026
Source: NVD
CVE-2026-7146 HIGH - 7.3

A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d. Affected by this vulnerability is the function axios of the file src/servers/web-scraper/server.js of the component HTTP Request Handler. Such manipulation leads to server-s...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7145 MEDIUM - 5.4

A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/Controllers/Workspaces/WorkspaceInvitationsController.php of the component Invitation Handler. This manipulation of the argument invitation causes authorization bypass. The attack m...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7144 MEDIUM - 4.3

A security flaw has been discovered in 1000 Projects Portfolio Management System MCA 1.0. This impacts an unknown function of the file update_passwd_process.php. The manipulation of the argument temp_user results in authorization bypass. The attack can be launched remotely. The exploit has been rele...

Published: Apr 27, 2026
Source: NVD