5.1
CVE-2026-7021 - SmythOS sre Connector Service utils.ts information disclosure
A weakness has been identified in SmythOS sre up to 0.0.15. This impacts an unknown function of the file packages/sdk/src/LLM/utils.ts of the component Connector Service. This manipulation of the argument baseURL causes information disclosure. It is possible to initiate the attack remotely. The expβ¦
6.3
CVE-2026-7020 - Ollama Tensor Model Transfer transfer.go digestToPath path traversal
A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The manipulation of the argument digest results in path traversal. The attack may be performed from remote. β¦
8.7
CVE-2026-7019 - Tenda F456 P2pListFilter fromP2pListFilter buffer overflow
A vulnerability was identified in Tenda F456 1.0.0.5. The impacted element is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument menufacturer/Go leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly availβ¦
6.3
CVE-2026-7018 - Datavane Datavines JWT Token TokenManager.java hard-coded key
A vulnerability was determined in Datavane Datavines up to 13607645e14a4982468cfdbcf75c85cde63bae71. The affected element is an unknown function of the file datavines-core/src/main/java/io/datavines/core/utils/TokenManager.java of the component JWT Token Handler. Executing a manipulation of the argβ¦
4.8
CVE-2026-7016 - MaxSite CMS ushki Plugin cross site scripting
A vulnerability was found in MaxSite CMS up to 109.3. Impacted is an unknown function of the component ushki Plugin. Performing a manipulation of the argument f_ushka_new/f_ushk results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and coulβ¦
7.2
CVE-2026-42255 - DNS Amplification via Cyclic Name Server Delegation
Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.
4.8
CVE-2026-7015 - MaxSite CMS Guestbook Plugin cross site scripting
A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_email leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosedβ¦
4
CVE-2026-42254 -
Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that triggered a response.
4.8
CVE-2026-7014 - MaxSite CMS down_count Plugin cross site scripting
A flaw has been found in MaxSite CMS up to 109.3. This vulnerability affects unknown code of the component down_count Plugin. This manipulation of the argument f_file/f_prefix causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. Upgradinβ¦
4.8
CVE-2026-7013 - MaxSite CMS mail_send Plugin cross site scripting
A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subject/f_files/f_from leads to cross site scripting. The attack can be initiated remotely. The exploit hβ¦