Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-7158 — dmitryglhf mcp-url-downloader server.py _validate_url_safe server-side request forgery

A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6. Affected by this issue is the function _validate_url_safe of the file src/mcp_url_downl…

| Server-Side Request Forgery
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
6.0 MEDIUM
CVE-2026-3087 — shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different tha…

Remote | Path Traversal
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-7157 — disler aider-mcp-server aider_ai_code server.py command injection

A flaw has been found in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc. Affected by this vulnerability is an unknown functionality of the file src/aider_mcp_server/server.py …

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-7156 — Totolink A8000RU CGI cstecgi.cgi CsteSystem os command injection

A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argume…

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
10.0 HIGH
CVE-2026-7153 — Totolink A8000RU CGI cstecgi.cgi setMiniuiHomeInfoShow os command injection

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setMiniuiHomeInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. …

Remote | Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
10.0 HIGH
CVE-2026-7152 — Totolink A8000RU CGI cstecgi.cgi setTelnetCfg os command injection

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulat…

Remote | Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
9.0 HIGH
CVE-2026-7151 — Tenda HG3 formIPv6Routing formUploadConfig stack-based overflow

A vulnerability was determined in Tenda HG3 2.0. Impacted is the function formUploadConfig of the file /boaform/formIPv6Routing. This manipulation of the argument destNet causes stack-based buffer ov…

Remote | Memory Corruption
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
8.8 HIGH
CVE-2026-6741 — LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'co…

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 5.4.1. This is due to a missing authoriz…

Remote | Authorization
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.0 HIGH
CVE-2026-5394 — Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling

An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. …

Remote | Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
4.8 MEDIUM
CVE-2026-5362 — Pimcore Platform v12.3.3 - Stored XSS in Document Editable Embed rendering

An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script execution when the published page is rendered. This…

Remote | Cross-Site Scripting
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-7155 — Totolink A8000RU CGI cstecgi.cgi setLoginPasswordCfg os command injection

A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setLoginPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The ma…

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
8.6 HIGH
CVE-2026-7191 — Arbitrary Code Execution via Sandbox Bypass in the open source solution QnABot on AWS

Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may allow an authenticated administrator to execute arbitrary code within the fulfillm…

Remote | Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-7154 — Totolink A8000RU CGI cstecgi.cgi setAdvancedInfoShow os command injection

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setAdvancedInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipu…

| Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
6.5 MEDIUM
CVE-2026-7150 — dh1011 auto-favicon MCP Tool server.py generate_favicon_from_url server-side request forg…

A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the function generate_favicon_from_url of the file src/auto_favicon/server.py of th…

Remote | Server-Side Request Forgery
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7149 — dexhunter kaggle-mcp server.py prepare_kaggle_dataset path traversal

A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d. This vulnerability affects the function prepare_kaggle_dataset of the file src/kaggle_mcp/server…

Remote | Path Traversal
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
6.5 MEDIUM
CVE-2026-7148 — CodeAstro Online Classroom addnewfaculty sql injection

A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the argument fname can lead to sql injection. The attack …

Remote | Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7147 — JoeCastrom mcp-chat-studio LLM Models API llm.js server-side request forgery

A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/routes/llm.js of the component LLM Models API. Performi…

Remote | Server-Side Request Forgery
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
5.0 MEDIUM
CVE-2026-40970 — Spring Boot Elasticsearch SSL hostname verification bypass

When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0–4…

| Misconfiguration
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-35903 — MERCURY MIPC252W Improper Authentication in RTSP Service

MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial DESCRIBE request, …

| Authentication
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
0.0 NA
CVE-2026-35902 — MERCURY IP Camera MIPC252W Authentication DoS Vulnerability

The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication paramete…

| Authentication
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
Showing 20 of 5731 Results