Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 12 April 2026

RSS

167 vulnerabilities published on 12 April 2026

Severity:
Totolink A7100RU: Unauthorized Code Execution via Command Injection
CVE-2026-6116
An attacker can potentially execute unauthorized commands on your Totolink A7100RU device by exploiting a weakness in its CGI Handler. This could allow them to gain control of the device or disrupt it...
8.9
Totolink A7100RU Router Exposes Users to Remote Attack
CVE-2026-6115
A security flaw in the Totolink A7100RU router's CGI Handler allows an attacker to execute unauthorized commands on the device, potentially giving them control over the router. This can be done remote...
8.9
Totolink A7100RU Router: Remote Command Injection Risk
CVE-2026-6114
A security vulnerability in the Totolink A7100RU router's CGI Handler allows an attacker to execute unauthorized commands remotely. This could lead to unauthorized access and control of the router. Us...
8.9
Totolink A7100RU Routers: Remote Code Execution
CVE-2026-6113
A security flaw in the Totolink A7100RU router can allow hackers to execute malicious code on the device from anywhere on the internet. This could potentially be exploited by hackers who have access t...
8.9
Totolink A7100RU Router: Remote Command Execution Risk
CVE-2026-6112
The Totolink A7100RU router's CGI Handler is vulnerable to a remote attack that can allow an attacker to execute commands on the router. This could be used to take control of the router or disrupt its...
8.9
Parisneo Lollms Software Allows Malicious Code to be Injected
CVE-2026-1116
A security weakness in the Parisneo Lollms software could allow an attacker to inject malicious code into a user's browser, potentially leading to unauthorized access to accounts or sessions. This is ...
8.2
Mozilla Thunderbird Security Update: Multiple Critical Fixes
RLSA-2026:6917
Mozilla Thunderbird has released an update to fix several critical security issues that could allow attackers to take control of your computer, steal sensitive information, or disrupt your email and b...
8.2
MetaGPT up to 0.8.1 allows remote code execution
CVE-2026-6110
A security flaw in MetaGPT's thought generation feature could allow an attacker to execute arbitrary code on a server. This could happen if a malicious user sends a specially crafted request to the af...
6.9
AstrBot: Unsecured Input in MCP Endpoint Can Lead to Remote Command Execution
CVE-2026-6118
An attacker can inject malicious commands into the AstrBot system through the MCP Endpoint, potentially allowing them to execute unauthorized actions. This issue affects AstrBot versions up to 4.22.1....
5.3
AstrBot: Unsecured File Upload in Plugin Installation
CVE-2026-6117
AstrBot's plugin installation feature allows an attacker to upload malicious files without proper validation, which can lead to a security breach. This affects version 4.22.1 and earlier. To protect y...
5.3
MetaGPT up to 0.8.1 allows remote attackers to manipulate images
CVE-2026-6111
A security issue in MetaGPT's image processing code allows attackers to trick the system into fetching images from unauthorized sources. This could be used to spread malware or disrupt the system. We ...
5.3
1Panel-dev MaxKB: Remote Code Execution in MCP Node
CVE-2026-6108
An attacker can execute arbitrary system commands on a vulnerable system using the 1Panel-dev MaxKB MCP Node, which can lead to unauthorized access and data theft. This vulnerability allows an attacke...
5.3
MetaGPT Mineflayer API Cross-Site Request Forgery Risk
CVE-2026-6109
The MetaGPT Mineflayer API, used in Minecraft bots, has a security flaw that makes it vulnerable to a type of attack where an attacker can trick the system into performing unwanted actions. This could...
5.3
1Panel-dev MaxKB Chat Headers Middleware Cross-Site Scripting Risk
CVE-2026-6107
A security flaw in 1Panel-dev MaxKB's chat headers middleware can allow attackers to inject malicious code, potentially allowing them access to sensitive information or taking control of user sessions...
5.1
Apache HTTP Server Allows Remote File Disclosure
MINI-cgh2-hjjg-mpfx
Apache HTTP Server may reveal sensitive files on the server to unauthorized users. This could potentially allow an attacker to access confidential data. To protect your server, ensure that you're runn...
Adobe ColdFusion Server: Unrestricted File Upload
MINI-cf2m-cjw7-mgx9
Adobe ColdFusion Server has a vulnerability that allows attackers to upload arbitrary files, potentially allowing them to execute malicious code. This could lead to unauthorized access to sensitive da...
MINI-9x6r-jg65-6fgp
MINI-9x6r-jg65-6fgp
MINI-47vh-qqmq-32j5
MINI-47vh-qqmq-32j5
MINI-jm4g-xg59-vjwp
MINI-jm4g-xg59-vjwp
MINI-4ph6-q45g-mgxm
MINI-4ph6-q45g-mgxm
MINI-4r63-24f7-2v82
MINI-4r63-24f7-2v82
MINI-93r9-xhrh-fqpq
MINI-93r9-xhrh-fqpq
MINI-j62j-xxmm-6xc6
MINI-j62j-xxmm-6xc6
MINI-ccfh-q2fr-49p5
MINI-ccfh-q2fr-49p5
Apache HTTP Server Cross-Site Scripting (XSS) in mod_proxy_html
MINI-jv9h-3rx2-xpg2
Apache HTTP Server's mod_proxy_html module is vulnerable to a cross-site scripting (XSS) attack. This means that an attacker could inject malicious code into web pages, potentially stealing user data ...