Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-74842 — Kira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image server-side requ…

A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452. Affected is the function download_image of the file server.py of the component Image-Toolkit-MCP-Se…

| Server-Side Request Forgery
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
8.8 HIGH
CVE-2026-74845 — 2100 Technology|Official Document Management System - Arbitrary File Upload

Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby…

Remote | Authentication
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
4.0 MEDIUM
CVE-2026-58561 — Image Codec Module Null Pointer Dereference

Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
4.0 MEDIUM
CVE-2026-58560 — Image Codec Null Pointer Dereference

Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.5 MEDIUM
CVE-2026-49308 — Clipboard Module Permission Control Vulnerability

Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

harmonyos | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.2 MEDIUM
CVE-2026-49307 — Multi-mode Input Module Access Control Bypass

Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

harmonyos | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
3.3 LOW
CVE-2026-49306 — Linux Kernel Time and Time Zone Module Use-After-Free Vulnerability

UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.2 MEDIUM
CVE-2026-49305 — Wi-Fi Enhancement Module Improper Authorization Vulnerability

Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.2 MEDIUM
CVE-2026-49304 — Device Key Management Module Improper Authorization Vulnerability

Permission control vulnerability in the device key management module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.1 MEDIUM
CVE-2026-49303 — Notification Module Improper Authorization Vulnerability

Permission control vulnerability in the notification module. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.2 MEDIUM
CVE-2026-49302 — Notification Service Improper Authorization

Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

harmonyos | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.2 MEDIUM
CVE-2026-49301 — Gallery Module Improper Authorization

Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

emui harmonyos | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.5 MEDIUM
CVE-2026-20000 — itsourcecode Hospital Management System viewprescriptionrecord.php sql injection

A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewprescriptionrecord.php. The manipulation of the argument deli…

hospital_management_system | Remote | Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.5 HIGH
CVE-2026-19999 — Open Asset Import Library Assimp 3DGS MDL7 Bone Transformation Key MDLLoader.cpp ParseBon…

A security vulnerability has been detected in Open Asset Import Library Assimp Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ParseBoneTrafoKeys_3DGS_MDL7 of the file code/…

Remote | Memory Corruption
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.0 MEDIUM
CVE-2026-19998 — code-projects Online Shopping System offersmail.php cross site scripting

A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown function of the file offersmail.php. Executing a manipulation of the argument email can lead to cros…

online_shopping_system | Remote | Cross-Site Scripting
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
8.3 HIGH
CVE-2026-22072 — Arbitrary URL Loading in WebView Leading to Token Leakage Risk

Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens.

Remote | Server-Side Request Forgery
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.8 MEDIUM
CVE-2026-19997 — Webkul Bagisto Backend Sales RMA Endpoint requests authorization

A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Perfor…

bagisto | Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
4.3 MEDIUM
CVE-2026-19996 — Webkul Bagisto Backend Customer Behavior Data Endpoint customers privileges management

A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manip…

bagisto | Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
4.0 MEDIUM
CVE-2026-19995 — Webkul Bagisto RMA Message send-message cross site scripting

A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. This manipulation of th…

bagisto | Remote | Cross-Site Scripting
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.5 MEDIUM
CVE-2026-19994 — Webkul Bagisto Configuration Management execute authorization

A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-management/execute of the component Configuration …

bagisto | Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
Showing 20 of 11118 Results