CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2026-30812

    Last Modified: 22 Apr 2026

    Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event comments. This issue affects Pandora FMS: from 777 through 800

    Published: 13 Apr 2026
    8.4
    High

    CVE-2026-30811

    Last Modified: 22 Apr 2026

    Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affects Pandora FMS: from 777 through 800

    Published: 13 Apr 2026
    8.7
    High

    CVE-2026-30809

    Last Modified: 22 Apr 2026

    Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via WebServerModuleDebug. This issue affects Pandora FMS: from 777 through 800

    Published: 13 Apr 2026
    8.7
    High

    CVE-2026-30806

    Last Modified: 22 Apr 2026

    Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Network Report. This issue affects Pandora FMS: from 777 through 800

    Published: 13 Apr 2026
    5.5
    Medium

    CVE-2026-6188

    Last Modified: 22 Apr 2026

    A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /ajax.php?action=delete_sales. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

    Published: 13 Apr 2026
    8.6
    High

    CVE-2026-30804

    Last Modified: 22 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability allows Remote Code Execution via file upload. This issue affects Pandora FMS: from 777 through 800

    Published: 13 Apr 2026
    5.3
    Medium

    CVE-2026-6231

    Last Modified: 6 May 2026

    The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 sequences to bypass validation and be processed incorrectly. The issue may affect applications that rely on these functions to validate untrusted BSON data before further processing. This issue affects MongoDB C Driver versions prior to 1.30.5, MongoDB C Driver version 2.0.0 and MongoDB C Driver version 2.0.1

    Published: 13 Apr 2026
    5.5
    Medium

    CVE-2026-6187

    Last Modified: 22 Apr 2026

    A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.php?action=chk_prod_availability. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

    Published: 13 Apr 2026
    7.4
    High

    CVE-2026-6186

    Last Modified: 22 Apr 2026

    A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This vulnerability affects the function strcpy of the file /goform/formNatStaticMap. The manipulation of the argument NatBind leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

    Published: 13 Apr 2026
    1.9
    Low

    CVE-2026-6184

    Last Modified: 22 Apr 2026

    A weakness has been identified in code-projects Simple Content Management System 1.0. This affects an unknown part of the file /web/admin/welcome.php. Executing a manipulation of the argument News Title can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

    Published: 13 Apr 2026
    7.8
    High

    CVE-2026-1462

    Last Modified: 17 Apr 2026

    A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file paths, and the lack of validation in the `from_config()` method.

    Published: 13 Apr 2026
    5.5
    Medium

    CVE-2026-6183

    Last Modified: 22 Apr 2026

    A security flaw has been discovered in code-projects Simple Content Management System 1.0. Affected by this issue is some unknown functionality of the file /web/index.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

    Published: 13 Apr 2026
    8.8
    High

    CVE-2026-33858

    Last Modified: 17 Apr 2026

    Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which resolves this issue.

    Published: 13 Apr 2026
    5.5
    Medium

    CVE-2026-6182

    Last Modified: 22 Apr 2026

    A vulnerability was identified in code-projects Simple Content Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /web/admin/login.php. Such manipulation of the argument User leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.

    Published: 13 Apr 2026
    7.5
    High

    CVE-2025-66236

    Last Modified: 17 Apr 2026

    Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. Some assumptions the Deployment Manager could make were not clear or explicit enough, even though Airflow's intentions and security model of Airflow did not suggest different assumptions. The overall security model [1], workload isolation [2], and JWT authentication details [3] are now described in more detail. Users concerned with role isolation and following the Airflow security model of Airflow are advised to upgrade to Airflow 3.2, where several security improvements have been implemented. They should also read and follow the relevant documents to make sure that their deployment is secure enough. It also clarifies that the Deployment Manager is ultimately responsible for securing your Airflow deployment. This had also been communicated via Airflow 3.2.0 Blog announcement [4]. [1] Security Model: https://airflow.apache.org/docs/apache-airflow/stable/security/jwt_token_authentication.html [2] Workload isolation: https://airflow.apache.org/docs/apache-airflow/stable/security/workload.html [3] JWT Token authentication: https://airflow.apache.org/docs/apache-airflow/stable/security/jwt_token_authentication.html [4] Airflow 3.2.0 Blog announcement: https://airflow.apache.org/blog/airflow-3.2.0/ Users are recommended to upgrade to version 3.2.0, which fixes this issue.

    Published: 13 Apr 2026
    Unknown

    CVE-2026-6221

    Last Modified: 29 Apr 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 13 Apr 2026
    7.1
    High

    CVE-2026-34476

    Last Modified: 20 Apr 2026

    Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue.

    Published: 13 Apr 2026
    8.5
    High

    CVE-2026-6204

    Last Modified: 18 Jun 2026

    LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand feature. Successful exploitation requires administrative privileges. Exploitation could result in compromise of the underlying web server.

    Published: 13 Apr 2026
    4.6
    Medium

    CVE-2026-2728

    Last Modified: 22 Apr 2026

    LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Successful exploitation requires administrative privileges. Exploitation could result in XSS attacks being performed against other users with access to the page.

    Published: 13 Apr 2026
    2
    Low

    CVE-2025-15632

    Last Modified: 24 Apr 2026

    A vulnerability has been found in 1Panel-dev MaxKB up to 2.4.2. Impacted is an unknown function of the file ui/src/chat.ts of the component MdPreview. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.5.0 is recommended to address this issue. The name of the patch is 7230daa5ec3e6574b6ede83dd48a4fbc0e70b8d8. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

    Published: 13 Apr 2026
    8.8
    High

    CVE-2026-35337

    Last Modified: 15 Apr 2026

    Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob using ObjectInputStream.readObject() without any class filtering or validation. An authenticated user with topology submission rights could supply a crafted serialized object in the "TGT" credential field, leading to remote code execution in both the Nimbus and Worker JVMs. Mitigation: 2.x users should upgrade to 2.8.6. Users who cannot upgrade immediately should monkey-patch an ObjectInputFilter allow-list to ClientAuthUtils.deserializeKerberosTicket() restricting deserialized classes to javax.security.auth.kerberos.KerberosTicket and its known dependencies. A guide on how to do this is available in the release notes of 2.8.6. Credit: This issue was discovered by K.

    Published: 13 Apr 2026
    5.4
    Medium

    CVE-2026-35565

    Last Modified: 15 Apr 2026

    Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI visualization component interpolates topology metadata including component IDs, stream names, and grouping values directly into HTML via innerHTML in parseNode() and parseEdge() without sanitization at any layer. An authenticated user with topology submission rights could craft a topology containing malicious HTML/JavaScript in component identifiers (e.g., a bolt ID containing an onerror event handler). This payload flows through Nimbus → Thrift → the Visualization API → vis.js tooltip rendering, resulting in stored cross-site scripting.  In multi-tenant deployments where topology submission is available to less-trusted users but the UI is accessed by operators or administrators, this enables privilege escalation through script execution in an admin's browser session. Mitigation: 2.x users should upgrade to 2.8.6. Users who cannot upgrade immediately should monkey-patch the parseNode() and parseEdge() functions in the visualization JavaScript file to HTML-escape all API-supplied values including nodeId, :capacity, :latency, :component, :stream, and :grouping before interpolation into tooltip HTML strings, and should additionally restrict topology submission to trusted users via Nimbus ACLs as a defense-in-depth measure. A guide on how to do this is available in the release notes of 2.8.6. Credit: This issue was discovered while investigating another report by K.

    Published: 13 Apr 2026
    9.3
    Critical

    CVE-2026-4810

    Last Modified: 13 Apr 2026

    A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an unauthenticated remote attacker to execute arbitrary code on the server hosting the ADK instance. This vulnerability was patched in versions 1.28.1 and 2.0.0a2. Customers need to redeploy the upgraded ADK to their production environments. In addition, if they are running ADK Web locally, they also need to upgrade their local instance.

    Published: 13 Apr 2026
    4
    Medium

    CVE-2026-0232

    Last Modified: 13 Apr 2026

    A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.

    Published: 13 Apr 2026
    2
    Low

    CVE-2026-0233

    Last Modified: 14 Apr 2026

    A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges.

    Published: 13 Apr 2026
    7.2
    High

    CVE-2026-0234

    Last Modified: 14 Apr 2026

    An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.

    Published: 13 Apr 2026
    8.5
    High

    CVE-2026-5936

    Last Modified: 13 Apr 2026

    An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreachable endpoints (e.g., cloud metadata services), or bypass network access controls, potentially leading to sensitive information disclosure and further compromise of the internal environment.

    Published: 13 Apr 2026
    9.1
    Critical

    CVE-2026-5085

    Last Modified: 23 Apr 2026

    Solstice::Session versions through 1440 for Perl generates session ids insecurely. The _generateSessionID method returns an MD5 digest seeded by the epoch time, a random hash reference, a call to the built-in rand() function and the process id. The same method is used in the _generateID method in Solstice::Subsession, which is part of the same distribution. The epoch time may be guessed, if it is not leaked in the HTTP Date header. Stringified hash refences will contain predictable content. The built-in rand() function is seeded by 16-bits and is unsuitable for security purposes. The process id comes from a small set of numbers. Predictable session ids could allow an attacker to gain access to systems.

    Published: 13 Apr 2026
    7.1
    High

    CVE-2026-40436

    Last Modified: 12 May 2026

    The ZTE ZXEDM iEMS product has a password reset vulnerability for any user.Because the management of the cloud EMS portal does not properly control access to the user list acquisition function, attackers can read all user list information through the user list interface. Attackers can reset the passwords of obtained user information, causing risks such as unauthorized operations.

    Published: 13 Apr 2026
    7.4
    High

    CVE-2026-6168

    Last Modified: 16 Apr 2026

    A flaw has been found in TOTOLINK A7000R up to 9.1.0u.6115. The affected element is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument ssid5g causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

    Published: 13 Apr 2026
    5.5
    Medium

    CVE-2026-6167

    Last Modified: 24 Apr 2026

    A vulnerability was detected in code-projects Faculty Management System 1.0. Impacted is an unknown function of the file /subject-print.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.

    Published: 13 Apr 2026
    5.1
    Medium

    CVE-2026-34866

    Last Modified: 17 Apr 2026

    Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

    Published: 13 Apr 2026
    10
    Critical

    CVE-2026-34865

    Last Modified: 17 Apr 2026

    Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

    Published: 13 Apr 2026
    5.5
    Medium

    CVE-2026-6166

    Last Modified: 24 Apr 2026

    A security vulnerability has been detected in code-projects Vehicle Showroom Management System 1.0. This issue affects some unknown processing of the file /util/UpdateVehicleFunction.php. The manipulation of the argument VEHICLE_ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

    Published: 13 Apr 2026
    8.6
    High

    CVE-2026-3830

    Last Modified: 15 Apr 2026

    The Product Filter for WooCommerce by WBW WordPress plugin before 3.1.3 does not sanitize and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

    Published: 13 Apr 2026
    6.8
    Medium

    CVE-2025-15441

    Last Modified: 15 Apr 2026

    The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain contexts.

    Published: 13 Apr 2026
    5.5
    Medium

    CVE-2026-6165

    Last Modified: 24 Apr 2026

    A weakness has been identified in code-projects Vehicle Showroom Management System 1.0. This vulnerability affects unknown code of the file /util/Login_check.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

    Published: 13 Apr 2026
    5.5
    Medium

    CVE-2026-6164

    Last Modified: 24 Apr 2026

    A security flaw has been discovered in code-projects Lost and Found Thing Management 1.0. This affects an unknown part of the file /addcat.php. Performing a manipulation of the argument cata results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

    Published: 13 Apr 2026
    5.5
    Medium

    CVE-2026-6163

    Last Modified: 24 Apr 2026

    A vulnerability was identified in code-projects Lost and Found Thing Management 1.0. Affected by this issue is some unknown functionality of the file /catageory.php. Such manipulation of the argument cat leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

    Published: 13 Apr 2026
    6.6
    Medium

    CVE-2026-21010

    Last Modified: 15 Apr 2026

    Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged functions.

    Published: 13 Apr 2026
    5.1
    Medium

    CVE-2026-21008

    Last Modified: 15 Apr 2026

    Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information.

    Published: 13 Apr 2026
    5.1
    Medium

    CVE-2026-40447

    Last Modified: 2 Jun 2026

    Integer overflow or wraparound vulnerability in Samsung Open Source Escargot allows undefined behavior.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.

    Published: 13 Apr 2026
    5.1
    Medium

    CVE-2026-21014

    Last Modified: 18 Apr 2026

    Improper access control in Samsung Camera prior to version 16.5.00.28 allows local attacker to access location data. User interaction is required for triggering this vulnerability.

    Published: 13 Apr 2026
    6.9
    Medium

    CVE-2026-21013

    Last Modified: 17 Apr 2026

    Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive information.

    Published: 13 Apr 2026
    6.8
    Medium

    CVE-2026-21012

    Last Modified: 15 Apr 2026

    External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege.

    Published: 13 Apr 2026
    5.4
    Medium

    CVE-2026-21011

    Last Modified: 15 Apr 2026

    Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock.

    Published: 13 Apr 2026
    4.1
    Medium

    CVE-2026-21009

    Last Modified: 17 Apr 2026

    Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass App Pinning.

    Published: 13 Apr 2026
    4.4
    Medium

    CVE-2026-21007

    Last Modified: 15 Apr 2026

    Improper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Knox Guard.

    Published: 13 Apr 2026
    4.7
    Medium

    CVE-2026-21006

    Last Modified: 15 Apr 2026

    Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents.

    Published: 13 Apr 2026
    2
    Low

    CVE-2026-6162

    Last Modified: 24 Apr 2026

    A vulnerability has been found in PHPGurukul Company Visitor Management System 2.0. This impacts an unknown function of the file /bwdates-reports-details.php. The manipulation of the argument fromdate leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Apr 2026