Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,803
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,221 - 5,240 of 13,497 CVEs
CVE-2026-5653 MEDIUM - 5.5

DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD
CVE-2026-5409 MEDIUM - 5.5

Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD
CVE-2026-5408 MEDIUM - 5.5

BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD
CVE-2026-5407 MEDIUM - 5.5

SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD
CVE-2026-5406 MEDIUM - 5.5

FC-SWILS protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD
CVE-2026-5401 MEDIUM - 5.5

AFP Spotlight protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD
CVE-2026-5299 MEDIUM - 5.5

ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD
CVE-2026-42798 MEDIUM - 4.0

Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.

Vendor: littlecms
Product: little cms color engine
Published: Apr 30, 2026
Source: NVD
CVE-2026-41226 MEDIUM - 6.1

Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may be redirected to an arbitrary website. As a result, the user may become a victim of a phishing attack.

Vendor: Ricoh Company, Ltd.
Product: Multiple laser printers and MFPs which implement Web Image Monitor
Published: Apr 30, 2026
Source: NVD
CVE-2026-7379 MEDIUM - 5.5

Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD
CVE-2026-7378 MEDIUM - 5.5

Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD
CVE-2026-7376 MEDIUM - 5.5

Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD
CVE-2026-7375 MEDIUM - 5.5

UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD
CVE-2026-6868 MEDIUM - 5.5

HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Vendor: wireshark
Product: wireshark
Published: Apr 30, 2026
Source: NVD
CVE-2026-7469 MEDIUM - 6.3

A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. This impacts the function sub_425A28 of the file /goform/DelFil. The manipulation of the argument delflag results in command injection. The attack may be launched remotely. The exploit is now public and may be used.

Vendor: tenda
Product: 4g300_firmware
Published: Apr 30, 2026
Source: NVD
CVE-2026-7447 MEDIUM - 6.3

A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/update_customer.php. This manipulation of the argument type/length/business parameter validity causes sql injection. The attack is possible to be carried out remot...

Published: Apr 30, 2026
Source: NVD
CVE-2026-7445 MEDIUM - 6.3

A security vulnerability has been detected in ZachHandley ZMCPTools up to 0.2.2. Affected by this issue is some unknown functionality of the file src/managers/ResourceManager.ts of the component MCP Log Resource Handler. The manipulation of the argument dirname leads to path traversal. Remote exploi...

Published: Apr 30, 2026
Source: NVD

Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.91.1, the BetaLocalFilesystemMemoryTool in the Anthropic TypeScript SDK created memory files and directories using the Node.js default modes (0o...

Vendor: npm
Product: @anthropic-ai/sdk
Published: Apr 29, 2026
Source: GitHub
CVE-2026-7410 MEDIUM - 6.3

A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to ...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7409 MEDIUM - 4.7

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.

Published: Apr 29, 2026
Source: NVD