Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-16992 — Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publicat…

The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content …

| Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-16988 — GeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers RES…

The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose th…

| Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-16965 — Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status

The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-…

| Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-16957 — Slim SEO < 4.9.11 - Contributor+ Arbitrary Post Meta Disclosure

The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users with the Contributor role t…

| Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-16032 — LWS Optimize < 4.1.2 - Unauthenticated Stored XSS via Real User Monitoring

The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before storing it and rendering it in an administrative dashbo…

| Cross-Site Scripting
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-15038 — InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite

The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite insta…

| Authentication
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19334 — NightTrek Ollama-mcp index.ts command injection

A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. This manipulation of the argument name/modelfile/s…

| Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19333 — NightTrek Supabase-MCP generate_types command injection

A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by this issue is some unknown functionality of the c…

| Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19332 — NellyW8 MCP4EDA run_openlane/view_waveform command injection

A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of the ar…

| Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19331 — bazylhorsey obsidian-mcp-server CanvasService.ts writeCanvas path traversal

A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanvas of the file src/services/CanvasService.ts. Such manipulation leads to path tr…

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19330 — angrysky56 advanced-reasoning-mcp index.ts switch_memory_library path traversal

A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_system_json/create_library to get_system_json/switch_memory_library of the file …

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19329 — andreahaku codex_mcp ask MCP Tool codex-process-simple.ts command injection

A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element is an unknown function of the file src/codex-process-simple.ts of the component …

| Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
7.5 HIGH
CVE-2026-10595 — Path Traversal Vulnerability in parisneo/lollms

A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper hand…

Remote | Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19328 — aktsmm skill-ninja-mcp-server installer.ts uninstallSkill path traversal

A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file src/installer.ts. The manipul…

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19327 — abracadabra50 claude-sesh enricher.ts enrichSession path traversal

A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession of the file src/services/enricher.ts. Executing a manipulation of the argument …

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
4.4 MEDIUM
CVE-2026-19326 — Jevon-Zhong Ai-doctor filemanagement.service.ts deleteImage path traversal

A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the file ai-doctor-server/src/filemanagement/filemanagement.service.ts. Performing …

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19325 — IncomeStreamSurfer roo-code-memory-bank-mcp-server read_memory_bank_file/append_memory_ba…

A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMem…

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
3.3 LOW
CVE-2026-19324 — HelloGGX shadcn-vue-mcp callback-server.ts fs.promises.readFile path traversal

A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by this issue is the function fs.promises.readFile of the file src/server/callback-s…

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-17510 — Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in …

Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destination buffer for a B…

| Memory Corruption
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.8 CRITICAL
CVE-2026-71993 — MSI Radix AXE6600 v781521 Command Injection via openvpn function

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device.…

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
Showing 20 of 9721 Results