Common Vulnerabilities and Exposures (CVE)

CVE-2026-7061

Apr 26, 2026 22:00:17 UTC

A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/services/docker.service.ts of the component MCP/HTTP. This manipulation causes os command injec...

CVE-2026-7060

Apr 26, 2026 20:15:18 UTC

A vulnerability was determined in liyupi yu-picture up to a053632c41340152bf75b66b3c543d129123d8ec. This impacts the function PageRequest of the file yu-picture-backend/src/main/java/com/yupi/yupicturebackend/service/impl/PictureServiceImpl...

CVE-2026-7059

Apr 26, 2026 20:00:16 UTC

A vulnerability was found in 666ghj MiroFish up to 0.1.2. This affects the function get_simulation_posts of the file backend/app/api/simulation.py of the component Query Parameter Handler. Performing a manipulation of the argument Platform ...

CVE-2026-7058

Apr 26, 2026 19:45:13 UTC

A vulnerability has been found in 666ghj MiroFish up to 0.1.2. The impacted element is the function SimulationIPCClient.send_command of the file backend/app/services/simulation_ipc.py of the component Inter-Process Communication. Such manip...

CVE-2026-7057

Apr 26, 2026 18:45:15 UTC

A flaw has been found in Tenda F456 1.0.0.5. The affected element is an unknown function of the file /goform/setcfm of the component httpd. This manipulation of the argument funcname/funcpara1 causes buffer overflow. It is possible to initi...

CVE-2026-7056

Apr 26, 2026 18:30:16 UTC

A vulnerability was detected in Tenda F456 1.0.0.5. Impacted is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter of the component httpd. The manipulation of the argument page results in buffer overflow. The attack may be per...

CVE-2026-41080

Apr 26, 2026 18:14:25 UTC

libexpat before 2.7.6 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

CVE-2026-7055

Apr 26, 2026 18:00:19 UTC

A security vulnerability has been detected in Tenda F456 1.0.0.5. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component httpd. The manipulation of the argument menufacturer/Go leads to buffer overflo...

CVE-2026-7054

Apr 26, 2026 16:45:12 UTC

A weakness has been identified in Tenda F456 1.0.0.5. This vulnerability affects the function fromPptpUserAdd of the file /goform/PPTPDClient of the component httpd. Executing a manipulation of the argument opttype/usernamewith can lead to ...

CVE-2026-7053

Apr 26, 2026 16:00:20 UTC

A security flaw has been discovered in Tenda F456 1.0.0.5. This affects the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing a manipulation of the argument page results in buffer overflow. Remote exploita...

CVE-2026-7045

Apr 26, 2026 13:45:15 UTC

A vulnerability was determined in baomidou dynamic-datasource 2.5.0. Affected by this vulnerability is the function DsSpelExpressionProcessor#doDetermineDatasource of the file dynamic-datasource-spring/src/main/java/com/baomidou/dynamic/dat...

CVE-2026-7044

Apr 26, 2026 13:30:09 UTC

A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has bee...

CVE-2018-25297

Apr 26, 2026 13:19:26 UTC

Wansview 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input strings. Attackers can inject 2000-byte payloads into the Camera name and DID number fields during cam...

CVE-2018-25296

Apr 26, 2026 13:19:25 UTC

P10 Central Management Software 1.4.13 contains a buffer overflow vulnerability in the login password field that allows local attackers to crash the application by submitting an oversized input string. Attackers can paste a 2000-byte payloa...

CVE-2018-25295

Apr 26, 2026 13:19:24 UTC

ObserverIP Scan Tool 1.4.0.1 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string in the IP input field. Attackers can paste a 2000-byte buffer of repeated ...