Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.0 MEDIUM
CVE-2026-19378 — code-projects Task Management System CommentSave.php cross site scripting

A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php. The manipulation of the argument comment/task_id/m…

task_management_system | Remote | Cross-Site Scripting
Aug 10, 2026 Aug 12, 2026
Aug 10, 2026
Aug 12, 2026
7.5 HIGH
CVE-2026-19376 — Uasoft Badaso File API api.php class permission

A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads…

badaso | Remote | Authorization
Aug 10, 2026 Aug 13, 2026
Aug 10, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-19375 — dmitriiweb article-scraper-mcp server.py fetch_article server-side request forgery

A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_article of the file news_scraper_mcp/server.py. The manipulation of the argument ur…

article-scraper-mcp | Remote | Server-Side Request Forgery
Aug 10, 2026 Aug 12, 2026
Aug 10, 2026
Aug 12, 2026
7.5 HIGH
CVE-2026-19374 — adafap api-mcp Proxy API Endpoint route.ts customAxios server-side request forgery

A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component …

api-mcp | Remote | Server-Side Request Forgery
Aug 09, 2026 Aug 12, 2026
Aug 09, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-19373 — PhialsBasement KoboldCPP-MCP-Server BaseConfigSchema index.ts makeRequest server-side req…

A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfigSchema. Executing a…

koboldcpp-mcp-server | Server-Side Request Forgery
Aug 09, 2026 Aug 12, 2026
Aug 09, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-19372 — Handwriting-OCR handwriting-ocr-mcp-server upload_document index.ts fs.readFileSync path …

A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSync of the file src/index.ts of the component uploa…

handwriting-ocr-mcp-server | Path Traversal
Aug 09, 2026 Aug 12, 2026
Aug 09, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-19371 — Nikolaibibo claude-comfyui-mcp comfy_upload_image utils.ts copyFileSync path traversal

A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the component comfy_upload_image. Such manipulation of …

claude-comfyui-mcp | Path Traversal
Aug 09, 2026 Aug 13, 2026
Aug 09, 2026
Aug 13, 2026
3.7 LOW
CVE-2026-12372 — Server-Side Request Forgery (SSRF) in nltk/nltk

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by r…

nltk | Remote | Server-Side Request Forgery
Aug 09, 2026 Sep 04, 2026
Aug 09, 2026
Sep 04, 2026
5.3 MEDIUM
CVE-2026-19370 — bartekke8it56w2 new-mcp geminithinking index.ts fs.readFileSync path traversal

A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component geminithinking. This ma…

new-mcp | Path Traversal
Aug 09, 2026 Aug 12, 2026
Aug 09, 2026
Aug 12, 2026
Showing 20 of 13949 Results