Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

29528
Total
2302
Critical
8845
High
9186
Medium
CVE ID Severity Score Description Published
CVE-2026-31317 UNKNOWN Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the vendor/markhuot/craftql/src/Listeners/GetAssetsFieldSchema.php file Apr 17, 2026
CVE-2025-70795 MEDIUM 5.5 STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a … Apr 17, 2026
CVE-2026-6507 HIGH 7.5 A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet … Apr 17, 2026
CVE-2026-6489 MEDIUM 6.3 A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects some unknown processing of the file admin/addteacher.php of the component … Apr 17, 2026
CVE-2026-6488 MEDIUM 6.3 A vulnerability was identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This vulnerability affects unknown code of the file admin/editcourse.php of the component GET Request Parameter … Apr 17, 2026
CVE-2026-6487 MEDIUM 4.3 A flaw has been found in Qihui jtbc5 CMS 5.0.3.6. Affected is an unknown function of the file /dev/code/common/diplomat/manage.php of the component Code Endpoint. This … Apr 17, 2026
CVE-2026-6486 LOW 3.5 A vulnerability was detected in classroombookings up to 2.17.0. This impacts the function read of the file crbs-core/application/views/layout.php of the component User Display Name Handler. … Apr 17, 2026
CVE-2026-28263 MEDIUM 5.9 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 … Apr 17, 2026
CVE-2026-23777 MEDIUM 4.3 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 … Apr 17, 2026
CVE-2025-46641 MEDIUM 6.6 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high … Apr 17, 2026
CVE-2025-46607 MEDIUM 6.6 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high … Apr 17, 2026
CVE-2025-46606 MEDIUM 6.2 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper restriction of excessive authentication … Apr 17, 2026
CVE-2025-46605 MEDIUM 6.2 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability. A high … Apr 17, 2026
CVE-2026-6483 HIGH 7.2 A vulnerability was found in Wavlink WL-WN530H4 20220721. This vulnerability affects the function strcat/snprintf of the file /cgi-bin/internet.cgi. The manipulation results in os command injection. … Apr 17, 2026
CVE-2026-5131 UNKNOWN GREENmod uses named pipes for communication between plugins, the web portal, and the system service, but the access control lists for these pipes are configured … Apr 17, 2026
CVE-2026-35153 MEDIUM 6.7 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of … Apr 17, 2026
CVE-2026-35074 MEDIUM 6.7 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of … Apr 17, 2026
CVE-2026-35073 MEDIUM 6.7 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of … Apr 17, 2026
CVE-2026-35072 MEDIUM 6.7 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of … Apr 17, 2026
CVE-2026-23779 MEDIUM 6.7 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 … Apr 17, 2026
CVE-2026-23776 HIGH 7.2 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 … Apr 17, 2026
CVE-2026-6494 MEDIUM 5.3 A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to … Apr 17, 2026
CVE-2026-6439 MEDIUM 4.4 The VideoZen plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.1. This is due to insufficient input sanitization … Apr 17, 2026
CVE-2026-23778 HIGH 7.2 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 … Apr 17, 2026
CVE-2026-23775 HIGH 7.6 Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10 … Apr 17, 2026