Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,741
Quick preset (or use dates below)
Clear Filters
Showing 6,581 - 6,600 of 13,541 CVEs
CVE-2026-30994 HIGH - 7.5

Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access sensitive information, including active session credentials.

Published: Apr 15, 2026
Source: NVD
CVE-2025-63029 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Lovers WCFM Marketplace allows SQL Injection.This issue affects WCFM Marketplace: from n/a through 3.7.1.

Vendor: WC Lovers
Product: WCFM Marketplace
Published: Apr 15, 2026
Source: NVD
CVE-2026-30624 HIGH - 8.6

Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The application allows users to define MCP servers using a JSON configuration containing arbitrary command and args values. These values are executed by the application when the configu...

Vendor: agent-zero
Product: agent-zero
Published: Apr 15, 2026
Source: NVD
CVE-2026-30617 HIGH - 8.6

LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execution handling. A remote attacker can access the publicly exposed MCP management interface and configure an MCP STDIO server with attacker-controlled commands and arguments. When the...

Published: Apr 15, 2026
Source: NVD
CVE-2026-30616 HIGH - 7.3

Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacker can send crafted network requests to the network-accessible Jaaz application, causing attacker-controlled commands to be executed on the server. Successful exploitation results i...

Published: Apr 15, 2026
Source: NVD
CVE-2026-30615 HIGH - 8.0

A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML content, malicious instructions can cause unauthorized modification of the local MCP configuration and automatic registrat...

Published: Apr 15, 2026
Source: NVD
CVE-2026-30461 HIGH - 8.3

Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function add_git_submodule.

Vendor: thedaylightstudio
Product: fuel_cms
Published: Apr 15, 2026
Source: NVD
CVE-2026-20205 HIGH - 7.2

In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or possesses the high-privilege capability `mcp_tool_admin` could view users session and authorization tokens in clear text.<br><br>The vulnerability would require either l...

Vendor: Splunk
Product: Splunk MCP Server
Published: Apr 15, 2026
Source: NVD
CVE-2026-20204 HIGH - 7.1

In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles could potentially perform...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Apr 15, 2026
Source: NVD
CVE-2025-67841 HIGH - 7.5

Nordic Semiconductor IronSide SE for nRF54H20 before 23.0.2+17 has an Algorithmic complexity issue.

Published: Apr 15, 2026
Source: NVD
CVE-2026-30364 HIGH - 7.5

CentSDR commit e40795 was discovered to contain a stack overflow in the "Thread1" function.

Published: Apr 15, 2026
Source: NVD
CVE-2024-53412 HIGH - 8.4

Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection of malicious payloads into the Port field

Published: Apr 15, 2026
Source: NVD
CVE-2026-4145 HIGH - 7.8

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

Published: Apr 15, 2026
Source: NVD
CVE-2026-4134 HIGH - 7.3

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute code with elevated privileges.

Published: Apr 15, 2026
Source: NVD
CVE-2026-0827 HIGH - 7.1

During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file write with elevated privi...

Published: Apr 15, 2026
Source: NVD
CVE-2026-40784 HIGH - 8.1

Authorization Bypass Through User-Controlled Key vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentBoards: from n/a through <= 1.91.2.

Vendor: Mahmudul Hasan Arif
Product: FluentBoards
Published: Apr 15, 2026
Source: NVD
CVE-2026-40764 HIGH - 8.1

Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Request Forgery.This issue affects Contact Form by WPForms: from n/a through <= 1.10.0.2.

Vendor: Syed Balkhi
Product: Contact Form by WPForms
Published: Apr 15, 2026
Source: NVD
CVE-2026-40745 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bdthemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Blind SQL Injection.This issue affects Element Pack Elementor Addons: from n/a through <= 8.4.2.

Vendor: bdthemes
Product: Element Pack Elementor Addons
Published: Apr 15, 2026
Source: NVD
CVE-2026-40744 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beaver Builder Beaver Builder beaver-builder-lite-version allows Blind SQL Injection.This issue affects Beaver Builder: from n/a through <= 2.10.1.2.

Vendor: Beaver Builder
Product: Beaver Builder
Published: Apr 15, 2026
Source: NVD
CVE-2026-30778 HIGH - 7.5

The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. This issue affects Apache SkyWalking: from 9.7.0 through 10.3.0. Users are recommended to upgrade to version 10.4.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache SkyWalking
Published: Apr 15, 2026
Source: NVD