Total CVEs

125,743

Critical Severity

2,263

High Severity

7,843

Last 7 Days

1,200
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 741 - 760 of 22,148 CVEs
CVE-2026-7031 HIGH - 8.8

A vulnerability was detected in Tenda F456 1.0.0.5. This impacts the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page results in buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used.

Vendor: tenda
Product: f456_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7030 HIGH - 8.8

A security vulnerability has been detected in Tenda F456 1.0.0.5. This affects the function fromRouteStatic of the file /goform/RouteStatic. The manipulation of the argument page leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may...

Vendor: tenda
Product: f456_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7029 HIGH - 8.8

A weakness has been identified in Tenda F456 1.0.0.5. The impacted element is the function fromaddressNat of the file /goform/addressNat. Executing a manipulation of the argument menufacturer/Go can lead to buffer overflow. The attack may be performed from remote. The exploit has been made available...

Vendor: tenda
Product: f456_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7028 MEDIUM - 4.7

A security flaw has been discovered in CodeAstro Online Job Portal 1.0. The affected element is an unknown function of the file /admin/jobs-admins/delete-jobs.php of the component All Jobs Page. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carri...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7027 LOW - 2.4

A vulnerability was identified in D-Link DSL-2740R EU_01.15. Impacted is an unknown function of the component Wireless Setup Section. Such manipulation of the argument Wireless Network Name leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and migh...

Vendor: dlink
Product: dsl-2740r_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7026 MEDIUM - 4.5

A vulnerability was determined in D-Link DGS-3420 1.50.018. This issue affects some unknown processing of the component System Information Settings Page. This manipulation of the argument System Name causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been pub...

Vendor: dlink
Product: dgs-3420-28tc_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7025 HIGH - 7.3

A vulnerability was found in Typecho up to 1.3.0. This vulnerability affects the function Service::sendPingHandle of the file var/Widget/Service.php of the component Ping Back Service Endpoint. The manipulation of the argument X-Pingback/link results in server-side request forgery. The attack may be...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7024 MEDIUM - 5.4

A flaw has been found in rawchen sims up to 004f783b1db5ecdfad81c8fdc3b34171211112de. Affected by this issue is some unknown functionality of the file sims-master/src/web/servlet/file/DeleteFileServlet.java of the component deleteFileServlet Endpoint. Executing a manipulation of the argument filenam...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7023 MEDIUM - 6.3

A vulnerability was detected in ByteDance coze-studio up to 0.5.1. Affected by this vulnerability is the function ExecuteSQL of the file backend/domain/memory/database/service/database_impl.go of the component databaseTool. Performing a manipulation results in sql injection. The attack can be initia...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7022 HIGH - 7.3

A security vulnerability has been detected in SmythOS sre up to 0.0.15. Affected is the function AgentRuntime of the file packages/core/src/subsystems/AgentManager/AgentRuntime.class.ts of the component HTTP Header Handler. Such manipulation of the argument X-DEBUG-RUN/X-DEBUG-INJ leads to improper ...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7021 LOW - 3.5

A weakness has been identified in SmythOS sre up to 0.0.15. This impacts an unknown function of the file packages/sdk/src/LLM/utils.ts of the component Connector Service. This manipulation of the argument baseURL causes information disclosure. It is possible to initiate the attack remotely. The expl...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7020 MEDIUM - 5.6

A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The manipulation of the argument digest results in path traversal. The attack may be performed from remote. T...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7019 HIGH - 8.8

A vulnerability was identified in Tenda F456 1.0.0.5. The impacted element is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument menufacturer/Go leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly availa...

Vendor: tenda
Product: f456_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7018 MEDIUM - 5.6

A vulnerability was determined in Datavane Datavines up to 13607645e14a4982468cfdbcf75c85cde63bae71. The affected element is an unknown function of the file datavines-core/src/main/java/io/datavines/core/utils/TokenManager.java of the component JWT Token Handler. Executing a manipulation of the argu...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7016 LOW - 2.4

A vulnerability was found in MaxSite CMS up to 109.3. Impacted is an unknown function of the component ushki Plugin. Performing a manipulation of the argument f_ushka_new/f_ushk results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could...

Published: Apr 26, 2026
Source: NVD
CVE-2026-42255 HIGH - 7.2

Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.

Vendor: Technitium
Product: DnsServer
Published: Apr 26, 2026
Source: NVD
CVE-2026-7015 LOW - 2.4

A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_email leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed ...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7014 LOW - 2.4

A flaw has been found in MaxSite CMS up to 109.3. This vulnerability affects unknown code of the component down_count Plugin. This manipulation of the argument f_file/f_prefix causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7013 LOW - 2.4

A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subject/f_files/f_from leads to cross site scripting. The attack can be initiated remotely. The exploit ha...

Published: Apr 26, 2026
Source: NVD
CVE-2026-42254 MEDIUM - 4.0

Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that triggered a response.

Vendor: Hickory Project
Product: Hickory DNS
Published: Apr 26, 2026
Source: NVD