Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-19356 — MingSoft MCMS ms-mdiy list information disclosure

A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosu…

mcms | Information Disclosure
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-19355 — MingSoft MCMS ms-mdiy list.do ModelDataImpl.queryDiyFormData sql injection

A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipul…

mcms | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.0 MEDIUM
CVE-2026-19353 — DedeCMS Installation Wizard index.php _4_Setup file inclusion

A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation le…

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
3.1 LOW
CVE-2026-19352 — mifi lossless-cut Built-in HTTP API Service httpServer.ts server-side request forgery

A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component Built-in HTTP API Service. E…

| Server-Side Request Forgery
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-19354 — lock-upme OPMS IN Clause message.go sql injection

A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown function of the file controllers/messages/message.go of the component IN…

| Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
7.5 HIGH
CVE-2026-19351 — dresende node-sql-query Request Parameter Select.js SelectQuery.build sql injection

A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the…

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
6.5 MEDIUM
CVE-2026-19350 — Dolibarr ERP TakePOS invoice.php fail authorization

A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing a…

Remote | Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
10.0 HIGH
CVE-2026-19348 — Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection

A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&na…

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
6.5 MEDIUM
CVE-2026-19347 — itsourcecode Hospital Management System viewdoctor.php sql injection

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php. Such manipulation of the argument delid leads to…

hospital_management_system | Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.0 HIGH
CVE-2026-19346 — Tenda CH22 CertListInfo formCertListInfo command injection

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command …

ch22 | Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
6.5 MEDIUM
CVE-2026-19345 — code-projects Task Management System UpdateTaskStatus.php authorization

A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in mis…

Remote | Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
7.5 HIGH
CVE-2026-19344 — code-projects Task Management System comment_count_user.php sql injection

A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/comment_count_user.php. The manipulation of the argu…

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
7.5 HIGH
CVE-2026-19343 — code-projects Task Management System AdminLogin.php sql injection

A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a manipulation of the argume…

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
7.3 HIGH
CVE-2026-19342 — code-projects Task Management System Login index.php improper authentication

A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Pass…

Remote | Authentication
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.0 HIGH
CVE-2026-19341 — UTT HiPER 1200GW pptpSrvGlobalConfig strcpy stack-based overflow

A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of the argument Encrypti…

hiper_1200gw | Remote | Memory Corruption
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
6.5 MEDIUM
CVE-2026-19340 — anubissbe ProjectHub-Mcp Webhooks API complete_backend.js server-side request forgery

A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js of the component Webhooks API. This manipulation o…

Remote | Server-Side Request Forgery
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
6.5 MEDIUM
CVE-2026-19339 — aliyun alibabacloud-dataworks-mcp-server initResources.ts ReadResourceRequestSchema serve…

A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts…

Remote | Server-Side Request Forgery
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19338 — automateyournetwork MCPyATS generate_mermaid_markdown index.ts processGenerateRequest pat…

A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component genera…

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19337 — adenot mcp-google-search read_webpage index.ts server-side request forgery

A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a manipulation of the argumen…

| Server-Side Request Forgery
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19336 — Pimzino spec-workflow-mcp approvals.ts ApprovalStorage.createApproval path traversal

A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the…

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
Showing 20 of 9709 Results