Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-94092 — dmlc dgl utils.py _read_torch_data deserialization

A vulnerability was detected in dmlc dgl up to 2.1.0. This impacts the function load_info/_read_torch_data of the file utils.py. Performing a manipulation of the argument path results in deserializat…

| Information Disclosure
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
7.5 HIGH
CVE-2026-94090 — JusticeRage Manalyze PE Parser pe.cpp _parse_debug integer underflow

A security flaw has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function PE::_parse_debug of the file manape/pe.cpp of the component PE Parser. The manipulation of the …

Remote | Memory Corruption
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
0.0 NA
CVE-2026-94091 — piskvorky gensim Model Loader utils.py load deserialization

A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file gensim/utils.py of the component Model Loader. This manipulation of the argument …

| Misconfiguration
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
10.0 CRITICAL
CVE-2026-94089 — D-Link DIR-868L Authentication webfa_authentication.cgi strcpy stack-based overflow

A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulati…

Remote | Memory Corruption
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-94051 — 0717376 cowork_bench pdf-tools-mcp server.py ControlFlowNode server-side request forgery

A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulnerability is the function ControlFlowNode of the file local_servers/pdf-tools-mc…

Remote | Server-Side Request Forgery
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
5.3 MEDIUM
CVE-2026-94050 — D-Link DIR-X1860Z ubus JSON-RPC interface routerd.get_rand_key information disclosure

A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402. Affected is the function routerd.wificfg_get/routerd.get_rand_key of the component ubus JSON-RPC interface. Such manipul…

| Information Disclosure
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.3 MEDIUM
CVE-2026-94049 — 06ketan slideshot renderer.ts render_slides path traversal

A flaw has been found in 06ketan slideshot up to 4.4.0. This impacts the function render_slides of the file packages/cli/src/renderer.ts. This manipulation of the argument htmlPath causes path traver…

Remote | Path Traversal
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.6 MEDIUM
CVE-2026-94048 — CodeAstro QR Code Attendance Management System UserController.php save privileges managem…

A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument rol…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-94047 — samanhappy MCPHub Template Import Endpoint templateService.ts importTemplate privileges m…

A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32. The impacted element is the function importTemplate of the file src/services/templateService.ts of the component Template…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.3 MEDIUM
CVE-2026-94046 — 0215AndrewFeng ACE-MCP MCP Tool getFileSnippet.ts get_file_snippet path traversal

A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8. The affected element is the function get_file_snippet of the file getFileSnippet.ts of the component MCP Tool. Executing a manip…

Remote | Path Traversal
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.0 MEDIUM
CVE-2026-94045 — newbee-ltd newbee-mall Goods Save Endpoint UploadController.java cross site scripting

A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0. Impacted is an unknown function of the file controller/common/UploadController.java of the component Goods Save Endpoint. Pe…

Remote | Cross-Site Scripting
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
7.5 HIGH
CVE-2026-94044 — 03-lovepreetSingh MCP route.ts create_file path traversal

A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affects the function create_file of the file app/api/mcp/route.ts. Such manipulation…

Remote | Path Traversal
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
5.5 MEDIUM
CVE-2026-94043 — Free5GC Gmm handler.go race condition

A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handler.go of the component Gmm Handler. This …

Remote | Race Condition
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-94042 — AdithyaYelloju Restaurant Management System add_table.php mysqli_query sql injection

A vulnerability was found in AdithyaYelloju Restaurant Management System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/add_table.php. The ma…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-94041 — AdithyaYelloju Restaurant-Management-System add_menu.php sql injection

A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is some unknown functionality of the file admin/ad…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
9.4 CRITICAL
CVE-2026-88857 — Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in Orda…

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into…

Remote | Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
9.4 CRITICAL
CVE-2026-88856 — Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in Orda…

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_o…

Remote | Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
8.6 HIGH
CVE-2026-88855 — Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joo…

Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveGallery() passes form data through a hand-rolled…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
9.3 CRITICAL
CVE-2026-88854 — Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Galler…

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsea…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
5.5 MEDIUM
CVE-2026-94040 — vas3k TaxHacker actions.ts testLLMProviderAction server-side request forgery

A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderAction of the file app/(app)/apps/settings/actions.ts. Executing a manipulation of …

taxhacker | Remote | Server-Side Request Forgery
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
Showing 20 of 13763 Results