| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-42254 | Hickory DNS 0.1-0.25.2 域外缓存投毒漏洞 | Hickory Project | Hickory DNS | Medium | 4.0 | 2026-04-26 02:38:41 | Deep Dive |
| CVE-2026-34306 | Oracle PeopleSoft Enterprise FIN Project Costing 安全漏洞 | Oracle Corporation | PeopleSoft Enterprise FIN Project Costing | Medium | 6.5 | 2026-04-21 20:35:34 | Deep Dive |
| CVE-2026-5720 | miniupnpd Integer Underflow SOAPAction Header Parsing | miniupnp project | miniupnpd | - | - | 2026-04-17 21:39:55 | Deep Dive |
| CVE-2026-40474 | wger has Broken Access Control in the Global Gym Configuration Update Endpoint | wger-project | wger | High | 7.6 | 2026-04-17 21:39:04 | Deep Dive |
| CVE-2026-40353 | wger: Stored XSS via Unescaped License Attribution Fields | wger-project | wger | - | - | 2026-04-17 21:16:12 | Deep Dive |
| CVE-2026-40258 | Gramps Web API has Zip Slip Path Traversal in Media Archive Import | gramps-project | gramps-web-api | Critical | 9.1 | 2026-04-17 21:12:54 | Deep Dive |
| CVE-2026-41080 | libexpat 安全漏洞 | libexpat project | libexpat | Low | 2.9 | 2026-04-16 16:52:01 | Deep Dive |
| CVE-2026-6328 | XQUIC Improper STREAM Frame Validation in Initial/Handshake Packets | XQUIC Project | XQUIC | 中危 | - | 2026-04-15 03:18:10 | Deep Dive |
| CVE-2026-40386 | Libexif 数字错误漏洞 | libexif project | libexif | Medium | 4.0 | 2026-04-12 18:19:09 | Deep Dive |
| CVE-2026-40385 | Libexif 输入验证错误漏洞 | libexif project | libexif | Medium | 4.0 | 2026-04-12 18:16:30 | Deep Dive |
| CVE-2019-25713 | MyT-PM 1.5.1 SQL Injection via Charge[group_total] Parameter | MyT | Project Management | High | 7.1 | 2026-04-12 12:28:57 | Deep Dive |
| CVE-2019-25695 | R 3.4.4 Local Buffer Overflow Windows XP SP3 | r-project | R | High | 8.4 | 2026-04-12 12:28:48 | Deep Dive |
| CVE-2018-25258 | RGui 3.5.0 Local Buffer Overflow SEH DEP Bypass | R-Project | RGui | High | 8.4 | 2026-04-12 12:28:44 | Deep Dive |
| CVE-2026-5525 | Stack-Based Buffer Overflow in Notepad++ File Drop Handler leads to DoS | Notepad++ Project | Notepad++ | Medium | 6.0 | 2026-04-10 07:41:00 | Deep Dive |
| CVE-2026-5840 | PHPGurukul News Portal Project check_availability.php sql injection | PHPGurukul | News Portal Project | Medium | 4.7 | 2026-04-09 04:00:16 | Deep Dive |
| CVE-2026-5839 | PHPGurukul News Portal Project add-subcategory.php sql injection | PHPGurukul | News Portal Project | Medium | 4.7 | 2026-04-09 03:45:14 | Deep Dive |
| CVE-2026-5838 | PHPGurukul News Portal Project add-subadmins.php sql injection | PHPGurukul | News Portal Project | Medium | 4.7 | 2026-04-09 03:30:15 | Deep Dive |
| CVE-2026-5837 | PHPGurukul News Portal Project news-details.php sql injection | PHPGurukul | News Portal Project | High | 7.3 | 2026-04-09 03:15:12 | Deep Dive |
| CVE-2026-39416 | Stored XSS in modal item preview for long item content in AIL Framework | ail-project | ail-framework | - | - | 2026-04-08 20:11:04 | Deep Dive |
| CVE-2026-31842 | Tinyproxy HTTP request parsing desynchronization via case-sensitive Transfer-Encoding handling | Tinyproxy Project | Tinyproxy | High | 7.5 | 2026-04-07 11:17:34 | Deep Dive |