Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.3 MEDIUM
CVE-2026-7669 — sgl-project SGLang HuggingFace Transformer hf_transformers_utils.py get_tokenizer deseria…

A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transf…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-7668 — MikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-bounds

A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulatio…

Remote | Memory Corruption
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7653 — r-huijts mcp-server-rijksmuseum MCP index.ts open_image_in_browser os command injection

A security flaw has been discovered in r-huijts mcp-server-rijksmuseum up to 1.0.4. Affected is the function open_image_in_browser of the file src/index.ts of the component MCP Interface. Performing …

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7645 — ruvnet sublinear-time-solver MCP server.js export_state path traversal

A vulnerability was found in ruvnet sublinear-time-solver 1.5.0. Affected by this vulnerability is the function export_state of the file src/consciousness-explorer/mcp/server.js of the component MCP …

Remote | Path Traversal
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-7644 — ChatGPTNextWeb NextChat actions.ts addMcpServer improper authorization

A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The manipulation leads to improper authorization. Remote …

Remote | Authorization
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.0 MEDIUM
CVE-2026-7643 — ChatGPTNextWeb NextChat API Endpoint Next.js cross-domain policy

A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of the component API Endpoint. Executing a manipulation can lead to permissive cros…

Remote | Misconfiguration
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7642 — pskill9 website-downloader MCP index.ts download_website os command injection

A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the component MCP Interface. Performing a manipulation o…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7633 — Totolink N300RH cstecgi.cgi setUploadSetting file inclusion

A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to…

Remote | Path Traversal
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-7632 — code-projects Online Hospital Management System viewappointment.php sql injection

A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function of the file /viewappointment.php. This manipulation of the argument delid cause…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.5 MEDIUM
CVE-2026-7631 — code-projects Online Hospital Management System Registration improper authorization

A vulnerability was found in code-projects Online Hospital Management System 1.0. The impacted element is an unknown function of the component Registration Handler. The manipulation of the argument U…

Remote | Authorization
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-7630 — innocommerce InnoShop Installation Endpoint InstallServiceProvider.php boot improper auth…

A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallServiceProvider::boot of the file innopacks/install/src/InstallServiceProvider.php of …

Remote | Authentication
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7629 — kleneway awesome-cursor-mpc-server Ccode-Review Tool codeReview.ts runCodeReviewTool comm…

A flaw has been found in kleneway awesome-cursor-mpc-server up to 2.0.1. Impacted is the function runCodeReviewTool of the file src/tools/codeReview.ts of the component Ccode-Review Tool. Executing a…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.3 MEDIUM
CVE-2026-3504 — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenticated…

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.1 via the '/dokan/v1/…

Remote | Information Disclosure
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
8.1 HIGH
CVE-2026-2554 — WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compati…

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl…

Remote | Authorization
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.4 MEDIUM
CVE-2026-0703 — NextMove Lite - Thank You Page for WooCommerce <= 2.23.0 - Authenticated (Contributor+) S…

The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xlwcty_current_date' shortcode in all versions up to, and includ…

Remote | Cross-Site Scripting
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7628 — crazyrabbitLTC mcp-code-review-server RepoMix repomix.ts executeRepomix command injection

A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function executeRepomix of the file src/repomix.ts of the component RepoMix Command Handler. …

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.8 MEDIUM
CVE-2026-6817 — Quiz Maker by AYS <= 6.7.1.29 - Unauthenticated Stored Cross-Site Scripting via 'rate_rea…

The Quiz Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rate_reason' parameter in all versions up to, and including, 6.7.1.29 due to insufficient input saniti…

Remote | Cross-Site Scripting
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.5 MEDIUM
CVE-2026-6525 — NULL Pointer Dereference in Wireshark

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4

| Denial of Service
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-6320 — Salon Booking System – Free Version <= 10.30.25 - Unauthenticated Arbitrary File Read via…

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker…

Remote | Path Traversal
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.4 MEDIUM
CVE-2026-4790 — Premium Addons for Elementor <= 4.11.70 - Authenticated (Contributor+) Stored Cross-Site …

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_svg' parameter in versions up to, and inclu…

Remote | Cross-Site Scripting
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
Showing 20 of 5653 Results