Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

31378
Total
2488
Critical
9260
High
9611
Medium
CVE ID Severity Score Description Published
CVE-2026-5387 UNKNOWN The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege … Apr 15, 2026
CVE-2026-30625 UNKNOWN Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define MCP tasks with arbitrary command … Apr 15, 2026
CVE-2026-30624 HIGH 8.6 Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The application allows users to define MCP servers using … Apr 15, 2026
CVE-2026-30617 HIGH 8.6 LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execution handling. A remote attacker can access the publicly exposed … Apr 15, 2026
CVE-2026-30616 HIGH 7.3 Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacker can send crafted network requests to the … Apr 15, 2026
CVE-2026-30615 HIGH 8.0 A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML content, malicious … Apr 15, 2026
CVE-2026-30461 UNKNOWN Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function add_git_submodule. Apr 15, 2026
CVE-2026-20205 HIGH 7.2 In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or possesses the … Apr 15, 2026
CVE-2026-20204 HIGH 7.1 In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged … Apr 15, 2026
CVE-2026-20203 MEDIUM 4.3 In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged … Apr 15, 2026
CVE-2026-20202 MEDIUM 6.6 In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.20, 10.0.2503.13, and 9.3.2411.127, a user … Apr 15, 2026
CVE-2025-67841 UNKNOWN Nordic Semiconductor IronSide SE for nRF54H20 before 23.0.2+17 has an Algorithmic complexity issue. Apr 15, 2026
CVE-2025-53444 MEDIUM 4.3 Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro allows Cross Site Request Forgery.This issue affects Userpro: from n/a before 5.1.11. Apr 15, 2026
CVE-2025-12141 UNKNOWN In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the … Apr 15, 2026
CVE-2026-4682 UNKNOWN Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer overflow when specially crafted Web Services for … Apr 15, 2026
CVE-2026-4667 UNKNOWN HP System Optimizer might potentially be vulnerable to escalation of privilege. HP is releasing an update to mitigate this potential vulnerability. Apr 15, 2026
CVE-2026-30364 HIGH 7.5 CentSDR commit e40795 was discovered to contain a stack overflow in the "Thread1" function. Apr 15, 2026
CVE-2024-53412 HIGH 8.4 Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection … Apr 15, 2026
CVE-2026-4145 HIGH 7.8 During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code … Apr 15, 2026
CVE-2026-4135 MEDIUM 6.6 During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform … Apr 15, 2026
CVE-2026-4134 HIGH 7.3 During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute … Apr 15, 2026
CVE-2026-25219 MEDIUM 6.5 The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission could see the … Apr 15, 2026
CVE-2026-1636 MEDIUM 6.7 A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with … Apr 15, 2026
CVE-2026-0827 HIGH 7.1 During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when … Apr 15, 2026
CVE-2026-3590 MEDIUM 6.5 Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, … Apr 15, 2026