Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-94044 — 03-lovepreetSingh MCP route.ts create_file path traversal

A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affects the function create_file of the file app/api/mcp/route.ts. Such manipulation…

Remote | Path Traversal
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
5.5 MEDIUM
CVE-2026-94043 — Free5GC Gmm handler.go race condition

A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handler.go of the component Gmm Handler. This …

Remote | Race Condition
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-94042 — AdithyaYelloju Restaurant Management System add_table.php mysqli_query sql injection

A vulnerability was found in AdithyaYelloju Restaurant Management System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/add_table.php. The ma…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-94041 — AdithyaYelloju Restaurant-Management-System add_menu.php sql injection

A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is some unknown functionality of the file admin/ad…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
9.4 CRITICAL
CVE-2026-88857 — Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in Orda…

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into…

Remote | Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
9.4 CRITICAL
CVE-2026-88856 — Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in Orda…

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_o…

Remote | Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
8.6 HIGH
CVE-2026-88855 — Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joo…

Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveGallery() passes form data through a hand-rolled…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
9.3 CRITICAL
CVE-2026-88854 — Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Galler…

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsea…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
5.5 MEDIUM
CVE-2026-94040 — vas3k TaxHacker actions.ts testLLMProviderAction server-side request forgery

A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderAction of the file app/(app)/apps/settings/actions.ts. Executing a manipulation of …

taxhacker | Remote | Server-Side Request Forgery
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
7.5 HIGH
CVE-2026-94039 — vas3k TaxHacker Invoice PDF Renderer actions.ts generateInvoicePDF server-side request fo…

A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer. Performing a mani…

taxhacker | Remote | Server-Side Request Forgery
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
7.5 HIGH
CVE-2026-94038 — NonceGeek dim-sum-app Deno Backend main.tsx textSearchV2Handler server-side request forge…

A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of the file deno/main.tsx of the component Deno Backend. Such manipulation of the ar…

Remote | Server-Side Request Forgery
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.3 MEDIUM
CVE-2026-94037 — 00Kisumi00 mcp-file-analyzer analyze_csv_data MCP tool main.py ControlFlowNode path trave…

A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405. This affects the function ControlFlowNode of the file main.py of the component analyze_c…

Remote | Path Traversal
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
8.8 HIGH
CVE-2026-94036 — D-Link DIR-X1860/DIR-X1860Z routerd ubus access control

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulat…

| Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
5.0 MEDIUM
CVE-2026-94035 — SourceCodester Drug Recommendation System index.php cross site scripting

A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the file /drug_recommender/index.php. Executing a manipulation of the argument full…

drug_recommendation_system | Remote | Cross-Site Scripting
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.0 MEDIUM
CVE-2026-94034 — SourceCodester Drug Recommendation System Password Change change_password cross site scri…

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /drug_recommender/Admin/change_password of the component Password Ch…

drug_recommendation_system | Remote | Cross-Site Scripting
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.0 MEDIUM
CVE-2026-94033 — SourceCodester Drug Recommendation System User Management add_user cross site scripting

A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This vulnerability affects unknown code of the file /drug_recommender/Admin/add_user of the component User Management.…

drug_recommendation_system | Remote | Cross-Site Scripting
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-94032 — itsourcecode Leave Management System index.php sql injection

A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown part of the file /module/department/index.php. This manipulation of the argument ID causes sql injection. It…

leave_management_system | Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-94031 — 0-Gaurav-0 nexus-mcp nexus_reauth MCP tool browser.ts child_process.exec command injection

A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914. Affected by this issue is the function child_process.exec of the file src/auth/browser.ts of the compone…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
3.1 LOW
CVE-2026-94030 — SerenityOS LibGfx BMPLoader.cpp decode_bmp_pixel_data integer overflow

A security vulnerability has been detected in SerenityOS up to 3d83e4509fd20d7438e1ae8470ffe668c136229c. Affected by this vulnerability is the function decode_bmp_pixel_data of the file Userland/Libr…

Remote | Memory Corruption
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.3 MEDIUM
CVE-2026-94028 — mealie-recipes Mealie Recipe Action Trigger controller_group_recipe_actions.py payload.mo…

A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the file mealie/routes/households/controller_group_recipe_actions.py of the compon…

Remote | Server-Side Request Forgery
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
Showing 20 of 13763 Results