Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
10692
Total
727
Critical
3080
High
3407
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-5406 | MEDIUM | 5.5 | FC-SWILS protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | Apr 30, 2026 |
| CVE-2026-5402 | HIGH | 8.8 | TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution | Apr 30, 2026 |
| CVE-2026-5401 | MEDIUM | 5.5 | AFP Spotlight protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | Apr 30, 2026 |
| CVE-2026-5299 | MEDIUM | 5.5 | ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | Apr 30, 2026 |
| CVE-2026-42798 | MEDIUM | 4.0 | Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c. | Apr 30, 2026 |
| CVE-2026-42511 | HIGH | 7.3 | The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is … | Apr 30, 2026 |
| CVE-2026-41226 | MEDIUM | 6.1 | Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may … | Apr 30, 2026 |
| CVE-2024-39847 | UNKNOWN | — | Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access … | Apr 30, 2026 |
| CVE-2026-7379 | MEDIUM | 5.5 | Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | Apr 30, 2026 |
| CVE-2026-7378 | MEDIUM | 5.5 | Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | Apr 30, 2026 |
| CVE-2026-7376 | MEDIUM | 5.5 | Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | Apr 30, 2026 |
| CVE-2026-7375 | MEDIUM | 5.5 | UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | Apr 30, 2026 |
| CVE-2026-6868 | MEDIUM | 5.5 | HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | Apr 30, 2026 |
| CVE-2025-13030 | HIGH | 7.1 | All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker can upload malicious files … | Apr 30, 2026 |
| CVE-2026-7470 | HIGH | 8.8 | A flaw has been found in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. Affected is the function sub_427C3C of the file /goform/SafeMacFilter. This manipulation of the argument page causes … | Apr 30, 2026 |
| CVE-2026-7469 | MEDIUM | 6.3 | A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. This impacts the function sub_425A28 of the file /goform/DelFil. The manipulation of the argument delflag results in … | Apr 30, 2026 |
| CVE-2026-7468 | HIGH | 7.3 | A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/index.html of the component Demo … | Apr 30, 2026 |
| CVE-2026-7447 | MEDIUM | 6.3 | A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/update_customer.php. This manipulation of the … | Apr 30, 2026 |
| CVE-2026-7446 | HIGH | 7.3 | A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_results/export_results/compare_results/scan_directory/create_rule of the file src/index.ts of the component MCP Interface. The manipulation of … | Apr 30, 2026 |
| CVE-2026-7445 | MEDIUM | 6.3 | A security vulnerability has been detected in ZachHandley ZMCPTools up to 0.2.2. Affected by this issue is some unknown functionality of the file src/managers/ResourceManager.ts of … | Apr 30, 2026 |
| CVE-2026-7443 | HIGH | 7.3 | A weakness has been identified in BurtTheCoder mcp-dnstwist up to 1.0.4. Affected by this vulnerability is the function fuzz_domain of the file src/index.ts of the … | Apr 29, 2026 |
| CVE-2026-7420 | HIGH | 8.8 | A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file route/goform/ConfigAdvideo. The manipulation of … | Apr 29, 2026 |
| CVE-2026-7419 | HIGH | 8.8 | A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of the file route/goform/formTaskEdit_ap. The manipulation of the … | Apr 29, 2026 |
| CVE-2026-7381 | CRITICAL | 9.1 | Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the variation setting (sendfile type) to be set by the client via … | Apr 29, 2026 |
| CVE-2026-6221 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Apr 29, 2026 |