5.1

CVSS4.0

CVE-2026-7021 - SmythOS sre Connector Service utils.ts information disclosure

A weakness has been identified in SmythOS sre up to 0.0.15. This impacts an unknown function of the file packages/sdk/src/LLM/utils.ts of the component Connector Service. This manipulation of the argument baseURL causes information disclosure. It is possible to initiate the attack remotely. The exp…

πŸ“… Published: April 26, 2026, 5:30 a.m. πŸ”„ Last Modified: April 26, 2026, 6:16 a.m.

6.3

CVSS4.0

CVE-2026-7020 - Ollama Tensor Model Transfer transfer.go digestToPath path traversal

A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The manipulation of the argument digest results in path traversal. The attack may be performed from remote. …

πŸ“… Published: April 26, 2026, 4:45 a.m. πŸ”„ Last Modified: April 26, 2026, 10:03 a.m.

8.7

CVSS4.0

CVE-2026-7019 - Tenda F456 P2pListFilter fromP2pListFilter buffer overflow

A vulnerability was identified in Tenda F456 1.0.0.5. The impacted element is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument menufacturer/Go leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly avail…

πŸ“… Published: April 26, 2026, 4:30 a.m. πŸ”„ Last Modified: April 29, 2026, 6:44 p.m.

6.3

CVSS4.0

CVE-2026-7018 - Datavane Datavines JWT Token TokenManager.java hard-coded key

A vulnerability was determined in Datavane Datavines up to 13607645e14a4982468cfdbcf75c85cde63bae71. The affected element is an unknown function of the file datavines-core/src/main/java/io/datavines/core/utils/TokenManager.java of the component JWT Token Handler. Executing a manipulation of the arg…

πŸ“… Published: April 26, 2026, 3:30 a.m. πŸ”„ Last Modified: April 27, 2026, 5:02 p.m.

4.8

CVSS4.0

CVE-2026-7016 - MaxSite CMS ushki Plugin cross site scripting

A vulnerability was found in MaxSite CMS up to 109.3. Impacted is an unknown function of the component ushki Plugin. Performing a manipulation of the argument f_ushka_new/f_ushk results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and coul…

πŸ“… Published: April 26, 2026, 3:15 a.m. πŸ”„ Last Modified: April 27, 2026, 1:51 p.m.

7.2

CVSS3.1

CVE-2026-42255 - DNS Amplification via Cyclic Name Server Delegation

Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.

πŸ“… Published: April 26, 2026, 2:48 a.m. πŸ”„ Last Modified: April 28, 2026, 1:30 p.m.

4.8

CVSS4.0

CVE-2026-7015 - MaxSite CMS Guestbook Plugin cross site scripting

A vulnerability has been found in MaxSite CMS up to 109.3. This issue affects some unknown processing of the component Guestbook Plugin. Such manipulation of the argument f_text/f_slug/f_limit/f_email leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed…

πŸ“… Published: April 26, 2026, 2:45 a.m. πŸ”„ Last Modified: April 27, 2026, 1:33 p.m.

4

CVSS3.1

CVE-2026-42254 -

Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that triggered a response.

πŸ“… Published: April 26, 2026, 2:38 a.m. πŸ”„ Last Modified: April 27, 2026, 1:33 p.m.

4.8

CVSS4.0

CVE-2026-7014 - MaxSite CMS down_count Plugin cross site scripting

A flaw has been found in MaxSite CMS up to 109.3. This vulnerability affects unknown code of the component down_count Plugin. This manipulation of the argument f_file/f_prefix causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. Upgradin…

πŸ“… Published: April 26, 2026, 2:30 a.m. πŸ”„ Last Modified: April 27, 2026, 1:24 p.m.

4.8

CVSS4.0

CVE-2026-7013 - MaxSite CMS mail_send Plugin cross site scripting

A security vulnerability has been detected in MaxSite CMS up to 109.3. Affected by this issue is some unknown functionality of the component mail_send Plugin. The manipulation of the argument f_subject/f_files/f_from leads to cross site scripting. The attack can be initiated remotely. The exploit h…

πŸ“… Published: April 26, 2026, 2 a.m. πŸ”„ Last Modified: April 26, 2026, 3:16 a.m.
Total resulsts: 347288
Page 72 of 34,729
Β« previous page Β» next page
Filters