CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2026-6532

    Last Modified: 1 May 2026

    Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6531

    Last Modified: 2 May 2026

    SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6530

    Last Modified: 1 May 2026

    DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6529

    Last Modified: 1 May 2026

    iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6528

    Last Modified: 1 May 2026

    TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6527

    Last Modified: 1 May 2026

    ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6526

    Last Modified: 2 May 2026

    RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6524

    Last Modified: 1 May 2026

    MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6523

    Last Modified: 1 May 2026

    GNW protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6521

    Last Modified: 1 May 2026

    OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6520

    Last Modified: 1 May 2026

    OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6519

    Last Modified: 1 May 2026

    MBIM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6522

    Last Modified: 1 May 2026

    RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6870

    Last Modified: 2 May 2026

    GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6869

    Last Modified: 1 May 2026

    WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6867

    Last Modified: 1 May 2026

    SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-6868

    Last Modified: 1 May 2026

    HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-7378

    Last Modified: 1 May 2026

    Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-7379

    Last Modified: 1 May 2026

    Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-7375

    Last Modified: 1 May 2026

    UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-7376

    Last Modified: 6 May 2026

    Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

    Published: 30 Apr 2026
    2
    Low

    CVE-2025-13030

    Last Modified: 5 May 2026

    All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker can upload malicious files and achieve arbitrary code execution since this endpoint lacks authentication protection and proper sanitisation of file names.

    Published: 30 Apr 2026
    7.4
    High

    CVE-2026-7470

    Last Modified: 4 May 2026

    A flaw has been found in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. Affected is the function sub_427C3C of the file /goform/SafeMacFilter. This manipulation of the argument page causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

    Published: 30 Apr 2026
    2.1
    Low

    CVE-2026-7469

    Last Modified: 30 Apr 2026

    A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. This impacts the function sub_425A28 of the file /goform/DelFil. The manipulation of the argument delflag results in command injection. The attack may be launched remotely. The exploit is now public and may be used.

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-7468

    Last Modified: 30 Apr 2026

    A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/index.html of the component Demo Site. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 30 Apr 2026
    2.1
    Low

    CVE-2026-7447

    Last Modified: 30 Apr 2026

    A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/update_customer.php. This manipulation of the argument type/length/business parameter validity causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-7446

    Last Modified: 30 Apr 2026

    A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_results/export_results/compare_results/scan_directory/create_rule of the file src/index.ts of the component MCP Interface. The manipulation of the argument ID results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 1.0.1 is able to mitigate this issue. The patch is identified as 141335da044e53c3f5b315e0386e01238405b771. It is advisable to upgrade the affected component.

    Published: 30 Apr 2026
    5.4
    Medium

    CVE-2026-7500

    Last Modified: 26 Jun 2026

    When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write operations — because they lack the `checkAccountApiEnabled()` gate that correctly blocks four other endpoints in the same REST service class. The user needs to have permissions to use the API.

    Published: 30 Apr 2026
    7.8
    High

    CVE-2026-31693

    Last Modified: 7 May 2026

    In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In several places in the code, we have a label to signify the start of the code where a request can be replayed if necessary. However, some of these places were missing the necessary reinitializations of certain local variables before replay. This change makes sure that these variables get initialized after the label.

    Published: 30 Apr 2026
    7.8
    High

    CVE-2026-31787

    Last Modified: 6 May 2026

    In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: fix double free via VMA splitting privcmd_vm_ops defines .close (privcmd_close), but neither .may_split nor .open. When userspace does a partial munmap() on a privcmd mapping, the kernel splits the VMA via __split_vma(). Since may_split is NULL, the split is allowed. vm_area_dup() copies vm_private_data (a pages array allocated in alloc_empty_pages()) into the new VMA without any fixup, because there is no .open callback. Both VMAs now point to the same pages array. When the unmapped portion is closed, privcmd_close() calls: - xen_unmap_domain_gfn_range() - xen_free_unpopulated_pages() - kvfree(pages) The surviving VMA still holds the dangling pointer. When it is later destroyed, the same sequence runs again, which leads to a double free. Fix this issue by adding a .may_split callback denying the VMA split. This is XSA-487 / CVE-2026-31787

    Published: 30 Apr 2026
    7.8
    High

    CVE-2026-31786

    Last Modified: 6 May 2026

    In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c The build id returned by HYPERVISOR_xen_version(XENVER_build_id) is neither NUL terminated nor a string. The first causes a buffer overflow as sprintf in buildid_show will read and copy till it finds a NUL. 00000000 f4 91 51 f4 dd 38 9e 9d 65 47 52 eb 10 71 db 50 |..Q..8..eGR..q.P| 00000010 b9 a8 01 42 6f 2e 32 |...Bo.2| 00000017 So use a memcpy instead of sprintf to have the correct value: 00000000 f4 91 51 f4 dd 00 9e 9d 65 47 52 eb 10 71 db 50 |..Q.....eGR..q.P| 00000010 b9 a8 01 42 |...B| 00000014 (the above have a hack to embed a zero inside and check it's returned correctly). This is XSA-485 / CVE-2026-31786

    Published: 30 Apr 2026
    5.5
    Medium

    CVE-2026-31692

    Last Modified: 6 May 2026

    In the Linux kernel, the following vulnerability has been resolved: rtnetlink: add missing netlink_ns_capable() check for peer netns rtnl_newlink() lacks a CAP_NET_ADMIN capability check on the peer network namespace when creating paired devices (veth, vxcan, netkit). This allows an unprivileged user with a user namespace to create interfaces in arbitrary network namespaces, including init_net. Add a netlink_ns_capable() check for CAP_NET_ADMIN in the peer namespace before allowing device creation to proceed.

    Published: 30 Apr 2026
    7.5
    High

    CVE-2026-36958

    Last Modified: 5 May 2026

    A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random or non-existent endpoints on the web management interface, an attacker can exhaust system resources in the embedded Boa HTTP server. This causes the router web interface to become unresponsive and may require manual reboot to restore normal operation.

    Published: 30 Apr 2026
    8.8
    High

    CVE-2026-36956

    Last Modified: 5 May 2026

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to implement proper CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a malicious webpage that sends forged HTTP requests to configuration endpoints such as /api/setWlan. If an authenticated administrator visits the malicious webpage, the victim's browser automatically includes the valid session cookie in the request, allowing the router to process the request as a legitimate administrative action.

    Published: 30 Apr 2026
    7.5
    High

    CVE-2025-56568

    Last Modified: 4 May 2026

    Assertion failure vulnerability in the PCO (Protocol Configuration Options) parser in the SMF (Session Management Function) component of Open5GS before v2.7.5 allows remote attackers to cause denial of service via specially crafted NGAP messages containing malformed length fields in protocol configuration data.

    Published: 30 Apr 2026
    7.5
    High

    CVE-2025-46115

    Last Modified: 4 May 2026

    An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification Request

    Published: 30 Apr 2026
    8.8
    High

    CVE-2026-36765

    Last Modified: 4 May 2026

    An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload.

    Published: 30 Apr 2026
    8.8
    High

    CVE-2026-36762

    Last Modified: 4 May 2026

    An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files with whitelisted suffixes to arbitrary filesystem locations.

    Published: 30 Apr 2026
    8.1
    High

    CVE-2026-36340

    Last Modified: 2 May 2026

    An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function

    Published: 30 Apr 2026
    6.1
    Medium

    CVE-2026-38940

    Last Modified: 2 May 2026

    Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code via the detail_produk.php component

    Published: 30 Apr 2026
    6.1
    Medium

    CVE-2026-36763

    Last Modified: 2 May 2026

    A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into the content parameter.

    Published: 30 Apr 2026
    4.3
    Medium

    CVE-2026-36758

    Last Modified: 2 May 2026

    A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

    Published: 30 Apr 2026
    8.8
    High

    CVE-2026-36960

    Last Modified: 2 May 2026

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a malicious webpage that sends forged HTTP requests to configuration endpoints. If an authenticated administrator visits the malicious webpage, the victim's browser automatically includes the valid session cookie in the request, allowing the router to process the request as a legitimate administrative action.

    Published: 30 Apr 2026
    7.5
    High

    CVE-2026-36959

    Last Modified: 5 May 2026

    U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attacker on the local network to perform unlimited authentication attempts, enabling brute-force attacks against the administrator account and potential unauthorized access to the router management interface.

    Published: 30 Apr 2026
    4.3
    Medium

    CVE-2026-36757

    Last Modified: 2 May 2026

    A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

    Published: 30 Apr 2026
    5.9
    Medium

    CVE-2026-40684

    Last Modified: 1 May 2026

    In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

    Published: 30 Apr 2026
    4.8
    Medium

    CVE-2026-40687

    Last Modified: 1 May 2026

    In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.

    Published: 30 Apr 2026
    3.7
    Low

    CVE-2026-40686

    Last Modified: 1 May 2026

    In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.

    Published: 30 Apr 2026
    7.5
    High

    CVE-2026-36957

    Last Modified: 5 May 2026

    Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating a high-volume flood of HTTP GET requests to non-existent URIs, an attacker can exhaust critical system resources, including file descriptors and memory buffers. This results in a kernel deadlock or system hang that disables the web management portal and all routing capabilities.

    Published: 30 Apr 2026
    5.4
    Medium

    CVE-2026-36756

    Last Modified: 1 May 2026

    A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

    Published: 30 Apr 2026