CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-6528
5.5 MEDIUM

TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service

Apr 30, 2026
CVE-2026-6527
5.5 MEDIUM

ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6526
5.5 MEDIUM

RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4

Apr 30, 2026
CVE-2026-6524
5.5 MEDIUM

MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6523
5.5 MEDIUM

GNW protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6522
5.5 MEDIUM

RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6521
5.5 MEDIUM

OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6520
5.5 MEDIUM

OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6519
5.5 MEDIUM

MBIM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-5657
5.5 MEDIUM

iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-5655
5.5 MEDIUM

SDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 allows denial of service

Apr 30, 2026
CVE-2026-5654
5.5 MEDIUM

AMR-NB codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-5653
5.5 MEDIUM

DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-5409
5.5 MEDIUM

Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-5408
5.5 MEDIUM

BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-5407
5.5 MEDIUM

SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-5406
5.5 MEDIUM

FC-SWILS protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-5402
8.8 HIGH

TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution

Apr 30, 2026
CVE-2026-5401
5.5 MEDIUM

AFP Spotlight protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-5299
5.5 MEDIUM

ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-42798
4.0 MEDIUM

Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.

Apr 30, 2026
CVE-2026-42511
8.1 HIGH

The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is …

Apr 30, 2026
CVE-2026-41226
4.7 MEDIUM

Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may …

Apr 30, 2026
CVE-2024-39847
7.5 HIGH

Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access …

Apr 30, 2026
CVE-2026-7379
5.5 MEDIUM

Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-7378
5.5 MEDIUM

Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-7376
5.5 MEDIUM

Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-7375
5.5 MEDIUM

UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6868
5.5 MEDIUM

HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2025-13030
7.1 HIGH

All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker can upload malicious files …

Apr 30, 2026
CVE-2026-7470
8.8 HIGH

A flaw has been found in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. Affected is the function sub_427C3C of the file /goform/SafeMacFilter. This manipulation of the argument page causes …

Apr 30, 2026
CVE-2026-7469
6.3 MEDIUM

A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. This impacts the function sub_425A28 of the file /goform/DelFil. The manipulation of the argument delflag results in …

Apr 30, 2026
CVE-2026-7468
7.3 HIGH

A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/index.html of the component Demo …

Apr 30, 2026
CVE-2026-7447
6.3 MEDIUM

A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/update_customer.php. This manipulation of the …

Apr 30, 2026
CVE-2026-7446
7.3 HIGH

A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_results/export_results/compare_results/scan_directory/create_rule of the file src/index.ts of the component MCP Interface. The manipulation of …

Apr 30, 2026
CVE-2026-7445
6.3 MEDIUM

A security vulnerability has been detected in ZachHandley ZMCPTools up to 0.2.2. Affected by this issue is some unknown functionality of the file src/managers/ResourceManager.ts of …

Apr 30, 2026
CVE-2026-7443
7.3 HIGH

A weakness has been identified in BurtTheCoder mcp-dnstwist up to 1.0.4. Affected by this vulnerability is the function fuzz_domain of the file src/index.ts of the …

Apr 29, 2026
CVE-2026-7420
8.8 HIGH

A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file route/goform/ConfigAdvideo. The manipulation of …

Apr 29, 2026
CVE-2026-7419
8.8 HIGH

A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of the file route/goform/formTaskEdit_ap. The manipulation of the …

Apr 29, 2026
CVE-2026-7381
9.1 CRITICAL

Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the variation setting (sendfile type) to be set by the client via …

Apr 29, 2026
CVE-2026-6221

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 29, 2026
CVE-2026-7418
8.8 HIGH

A vulnerability was determined in UTT HiPER 1250GW up to 3.2.7-210907-180535. This vulnerability affects the function strcpy of the file route/goform/NTP. Executing a manipulation of …

Apr 29, 2026
CVE-2026-7417
7.3 HIGH

A vulnerability was found in Algovate xhs-mcp 0.8.11. This affects the function xhs_publish_content of the file src/server/mcp.server.ts of the component MCP Interface. Performing a manipulation …

Apr 29, 2026
CVE-2026-7416
7.3 HIGH

A vulnerability was found in PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests of the file src/index.ts of the component MCP Interface. The manipulation …

Apr 29, 2026
CVE-2026-7410
6.3 MEDIUM

A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument …

Apr 29, 2026
CVE-2026-7409
4.7 MEDIUM

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation can lead …

Apr 29, 2026
CVE-2026-7408
4.7 MEDIUM

A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Performing a manipulation …

Apr 29, 2026
CVE-2026-7407
4.7 MEDIUM

A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /pizzafy/admin/ajax.php?action=save_settings of …

Apr 29, 2026
CVE-2026-7404
7.3 HIGH

A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.py. This manipulation of the argument …

Apr 29, 2026
CVE-2026-7403
5.3 MEDIUM

A security flaw has been discovered in geldata gel-mcp 0.1.0. This impacts the function list_rules/fetch_rule of the file src/gel_mcp/server.py. The manipulation of the argument rule_name …

Apr 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.