| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-7024 | rawchen sims deleteFileServlet Endpoint DeleteFileServlet.java path traversal | rawchen | sims | Medium | 5.4 | 2026-04-26 06:45:11 | Deep Dive |
| CVE-2026-7023 | ByteDance coze-studio databaseTool database_impl.go ExecuteSQL sql injection | ByteDance | coze-studio | Medium | 6.3 | 2026-04-26 06:30:15 | Deep Dive |
| CVE-2026-7022 | SmythOS sre HTTP Header AgentRuntime.class.ts AgentRuntime improper authentication | SmythOS | sre | High | 7.3 | 2026-04-26 05:45:12 | Deep Dive |
| CVE-2026-7021 | SmythOS sre Connector Service utils.ts information disclosure | SmythOS | sre | Low | 3.5 | 2026-04-26 05:30:15 | Deep Dive |
| CVE-2026-7020 | Ollama Tensor Model Transfer transfer.go digestToPath path traversal | - | Ollama | Medium | 5.6 | 2026-04-26 04:45:11 | Deep Dive |
| CVE-2026-7019 | Tenda F456 P2pListFilter fromP2pListFilter buffer overflow | Tenda | F456 | High | 8.8 | 2026-04-26 04:30:18 | Deep Dive |
| CVE-2026-7018 | Datavane Datavines JWT Token TokenManager.java hard-coded key | Datavane | Datavines | Medium | 5.6 | 2026-04-26 03:30:21 | Deep Dive |
| CVE-2026-7016 | MaxSite CMS ushki Plugin cross site scripting | MaxSite | CMS | Low | 2.4 | 2026-04-26 03:15:16 | Deep Dive |
| CVE-2026-42255 | Technitium DNS Server 安全漏洞 | Technitium | DnsServer | High | 7.2 | 2026-04-26 02:48:45 | Deep Dive |
| CVE-2026-7015 | MaxSite CMS Guestbook Plugin cross site scripting | MaxSite | CMS | Low | 2.4 | 2026-04-26 02:45:13 | Deep Dive |
| CVE-2026-42254 | Hickory DNS 安全漏洞 | Hickory Project | Hickory DNS | Medium | 4.0 | 2026-04-26 02:38:41 | Deep Dive |
| CVE-2026-7014 | MaxSite CMS down_count Plugin cross site scripting | MaxSite | CMS | Low | 2.4 | 2026-04-26 02:30:21 | Deep Dive |
| CVE-2026-7013 | MaxSite CMS mail_send Plugin cross site scripting | MaxSite | CMS | Low | 2.4 | 2026-04-26 02:00:20 | Deep Dive |
| CVE-2026-7012 | MaxSite CMS Redirect Plugin cross site scripting | MaxSite | CMS | Low | 2.4 | 2026-04-26 01:15:17 | Deep Dive |
| CVE-2026-7011 | MaxSite CMS Antispam Plugin plugin_antispam cross site scripting | MaxSite | CMS | Low | 2.4 | 2026-04-26 00:30:21 | Deep Dive |
| CVE-2026-7002 | KLiK SocialMediaWebsite Private Message get_message_ajax.php sql injection | KLiK | SocialMediaWebsite | High | 7.3 | 2026-04-25 21:30:16 | Deep Dive |
| CVE-2026-7001 | Datacom DM4100 Ethernet Configuration cross site scripting | Datacom | DM4100 | Low | 2.4 | 2026-04-25 21:15:14 | Deep Dive |
| CVE-2026-7000 | Datacom DM4100 VLAN Page cross site scripting | Datacom | DM4100 | Low | 2.4 | 2026-04-25 21:00:24 | Deep Dive |
| CVE-2026-6999 | BIVOCOM TR321 Wireless Setting cross site scripting | BIVOCOM | TR321 | Low | 2.4 | 2026-04-25 20:45:15 | Deep Dive |
| CVE-2026-6998 | BDCOM P3310D New RMON Statistics cross site scripting | BDCOM | P3310D | Low | 2.4 | 2026-04-25 20:15:15 | Deep Dive |