Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-9732 — EmergencyWP <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Update

The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorr…

Remote | Cross-Site Request Forgery
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
4.4 MEDIUM
CVE-2026-7421 — Passeum Ticketing <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via…

The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0. This is due to the `get_shop_url()` method returning the `shop_name`…

Remote | Cross-Site Scripting
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
4.3 MEDIUM
CVE-2026-10692 — johnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redos

A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_pattern of the component search_code_advanced. Executing a manipulation of the argum…

code-index-mcp | Remote | Denial of Service
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
4.3 MEDIUM
CVE-2026-10691 — wonderwhy-er DesktopCommanderMCP start_search search-manager.ts redos

A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function of the file src/search-manager.ts of the component start_search. Performing a ma…

desktopcommandermcp | Remote | Denial of Service
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
6.5 MEDIUM
CVE-2026-10690 — wonderwhy-er DesktopCommanderMCP read_file filesystem.ts readFileFromUrl server-side requ…

A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation …

desktopcommandermcp | Remote | Server-Side Request Forgery
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
8.1 HIGH
CVE-2026-44654 — LibreChat: Shared-agent editor can globally delete owner's file records — breaks owner's …

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a shared-agent editor can delete file records through `DELETE /api/files` that the o…

librechat | Remote | Authorization
Jun 02, 2026 Jun 04, 2026
Jun 02, 2026
Jun 04, 2026
6.5 MEDIUM
CVE-2026-44653 — LibreChat Shared MCP Server View Leaks Decrypted Admin Secrets

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users with only `VIEW` access to an MCP server can retrieve the server's decrypted a…

librechat | Remote | Information Disclosure
Jun 02, 2026 Jun 04, 2026
Jun 02, 2026
Jun 04, 2026
5.3 MEDIUM
CVE-2026-42507 — Arbitrary inputs are included in errors without any escaping in net/textproto

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or log…

go | Remote | Information Disclosure
Jun 02, 2026 Jun 04, 2026
Jun 02, 2026
Jun 04, 2026
7.5 HIGH
CVE-2026-42504 — Quadratic complexity in WordDecoder.DecodeHeader in mime

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

go | Remote | Denial of Service
Jun 02, 2026 Jun 04, 2026
Jun 02, 2026
Jun 04, 2026
4.9 MEDIUM
CVE-2026-41412 — alf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Extension Script

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, the alf.io extension sandbox injects a fully-functional HTTP cli…

alf | Remote | Path Traversal
Jun 02, 2026 Jun 04, 2026
Jun 02, 2026
Jun 04, 2026
7.1 HIGH
CVE-2026-40108 — GLPI Vulnerable to Stored XSS in ITIL Costs

GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL costs. This issue has been fixed in version 11.0.7.

glpi | Remote | Cross-Site Scripting
Jun 02, 2026 Jun 04, 2026
Jun 02, 2026
Jun 04, 2026
8.0 HIGH
CVE-2026-35482 — alf.io has an Authenticated RCE via Extension Script Sandbox Escape

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox escape vulnerability in the alf.io extension script en…

alf | Remote | Injection
Jun 02, 2026 Jun 04, 2026
Jun 02, 2026
Jun 04, 2026
9.6 CRITICAL
CVE-2026-32625 — LibreChat Exfiltrates Server Secrets via MCP Server URL Injection

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration resolves ${VAR} placeholders aga…

librechat | Remote | Misconfiguration
Jun 02, 2026 Jun 04, 2026
Jun 02, 2026
Jun 04, 2026
7.1 HIGH
CVE-2026-31942 — LibreChat has IDOR in API Keys Management that allows any authenticated user to overwrite…

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the API keys mana…

librechat | Remote | Authorization
Jun 02, 2026 Jun 04, 2026
Jun 02, 2026
Jun 04, 2026
6.5 MEDIUM
CVE-2026-27145 — Inefficient candidate hostname parsing in crypto/x509

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the sa…

go | Remote | Misconfiguration
Jun 02, 2026 Jun 04, 2026
Jun 02, 2026
Jun 04, 2026
8.2 HIGH
CVE-2026-25861 — QloApps 1.7.0 Weak Password Hashing via MD5 in Tools.php

QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attackers to compromise user credentials by exploiting the use of MD5 for password ha…

Remote | Cryptography
Jun 02, 2026 Jun 04, 2026
Jun 02, 2026
Jun 04, 2026
1.8 LOW
CVE-2026-10719 — Open Seachest/Seachest NVMe show Format Descriptors Vulnerability

Out of bounds write in openSeaChest’s --showSupportedFormats in Seagate’s openSeaChest v25.05.3 on all supported platforms allows for writing 1 extra byte outside of allocated memory which sets a val…

| Memory Corruption
Jun 02, 2026 Jun 04, 2026
Jun 02, 2026
Jun 04, 2026
4.6 MEDIUM
CVE-2026-10718 — Open Seachest/Seachest NVMe Trim (Deallocate) Vulnerability

Out of bounds write in openSeaChest’s Trim/Unmap operation in Seagate’s openSeaChest v26.03.0 on all supported platforms allows for writing extra memory describing a range of LBAs to deallocate 16 by…

| Memory Corruption
Jun 02, 2026 Jun 04, 2026
Jun 02, 2026
Jun 04, 2026
1.8 LOW
CVE-2026-10717 — Open-Seachest/Seachest show SCSI Defect List Vulnerability

Out of bounds write and reads in openSeaChest’s --showSCSIDefects in Seagate’s openSeaChest v25.05.3 on all supported platforms allows for writing defect information out of bounds for very large defe…

| Memory Corruption
Jun 02, 2026 Jun 04, 2026
Jun 02, 2026
Jun 04, 2026
6.5 MEDIUM
CVE-2026-10688 — ahujasid blender-mcp server.py execute_blender_code code injection

A vulnerability was determined in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The impacted element is the function execute_blender_code of the file /src/blender_mcp/server.py…

blender-mcp | Remote | Injection
Jun 02, 2026 Jun 04, 2026
Jun 02, 2026
Jun 04, 2026
Showing 20 of 7127 Results