Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-19381 — Kingston FURY CTRL RGB Control Software Driver NTIOLib_KSFX.sys privileges management

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performin…

| Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
5.0 MEDIUM
CVE-2026-19378 — code-projects Task Management System CommentSave.php cross site scripting

A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php. The manipulation of the argument comment/task_id/m…

task_management_system | Remote | Cross-Site Scripting
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
7.5 HIGH
CVE-2026-19376 — Uasoft Badaso File API api.php class permission

A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads…

Remote | Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
6.5 MEDIUM
CVE-2026-19375 — dmitriiweb article-scraper-mcp server.py fetch_article server-side request forgery

A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_article of the file news_scraper_mcp/server.py. The manipulation of the argument ur…

Remote | Server-Side Request Forgery
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-19380 — Mullvad wireguard.sys IOCTL AdapterState reference count

A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of referen…

| Memory Corruption
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-19379 — EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection

A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os co…

| Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
7.5 HIGH
CVE-2026-19374 — adafap api-mcp Proxy API Endpoint route.ts customAxios server-side request forgery

A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component …

Remote | Server-Side Request Forgery
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19373 — PhialsBasement KoboldCPP-MCP-Server BaseConfigSchema index.ts makeRequest server-side req…

A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfigSchema. Executing a…

| Server-Side Request Forgery
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19372 — Handwriting-OCR handwriting-ocr-mcp-server upload_document index.ts fs.readFileSync path …

A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSync of the file src/index.ts of the component uploa…

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19371 — Nikolaibibo claude-comfyui-mcp comfy_upload_image utils.ts copyFileSync path traversal

A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the component comfy_upload_image. Such manipulation of …

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
3.7 LOW
CVE-2026-12372 — Server-Side Request Forgery (SSRF) in nltk/nltk

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by r…

Remote | Server-Side Request Forgery
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19370 — bartekke8it56w2 new-mcp geminithinking index.ts fs.readFileSync path traversal

A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component geminithinking. This ma…

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19369 — KS-GEN-AI jira-mcp-server add_attachment_from_public_url index.ts axios.get server-side r…

A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the arg…

| Server-Side Request Forgery
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
4.8 MEDIUM
CVE-2026-19368 — PV-Bhat gemsuite-mcp gemini_search unified-gemini.ts path traversal

A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component gemini_search/gemini_reason/g…

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
6.5 MEDIUM
CVE-2026-19367 — NocteDefensor LudusMCP read_range_config rangeConfig.ts server-side request forgery

A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality of the file src/tools/rangeConfig.ts of the component read_range_config. Th…

ludusmcp | Remote | Server-Side Request Forgery
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
2.1 LOW
CVE-2026-70395 — Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys…

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name, and to recover the secret val…

ash | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19366 — NocteDefensor LudusMCP insert_creds_range_config insertCredsRangeConfig.ts path traversal

A flaw has been found in NocteDefensor LudusMCP up to 1.0.24. Affected is an unknown function of the file src/tools/insertCredsRangeConfig.ts of the component insert_creds_range_config. Executing a m…

ludusmcp | Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19365 — Ichigo3766 image-gen-mcp upscale_images index.ts path traversal

A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the file src/index.ts of the component upscale_images. Such manipulation of the argume…

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.9 MEDIUM
CVE-2026-69659 — Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.…

Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination de…

ash | Denial of Service
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
6.5 MEDIUM
CVE-2026-19364 — itsourcecode Hospital Management System viewdoctorconsultancycharge.php sql injection

A vulnerability was determined in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /viewdoctorconsultancycharge.php. This manipulation of the argum…

hospital_management_system | Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
Showing 20 of 9494 Results