Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.8 MEDIUM
CVE-2026-7673 — crmeb_java Admin Upload UploadServiceImpl.java unrestricted upload

A vulnerability was detected in crmeb_java up to 1.3.4. This vulnerability affects unknown code of the file crmeb/crmeb-service/src/main/java/com/zbkj/service/service/impl/UploadServiceImpl.java of t…

Remote | Misconfiguration
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
0.0 NA
CVE-2026-40561 — Starlet versions through 0.31 for Perl allows HTTP Request Smuggling via Improper Header …

Starlet versions through 0.31 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starlet incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both head…

| Misconfiguration
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
6.5 MEDIUM
CVE-2026-7672 — youlaitech youlai-boot Users Endpoint UserController.java getUserList sql injection

A security vulnerability has been detected in youlaitech youlai-boot up to 2.21.1. This affects the function getUserList of the file src/main/java/com/youlai/boot/system/controller/UserController.jav…

Remote | Injection
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
3.7 LOW
CVE-2026-7671 — CodeWise Tornet Scooter Mobile App TwoFactor excessive authentication

A vulnerability has been found in CodeWise Tornet Scooter Mobile App 4.75 on iOS/Android. The impacted element is an unknown function of the file /TwoFactor. Such manipulation leads to improper restr…

Remote | Authentication
May 03, 2026 May 03, 2026
May 03, 2026
May 03, 2026
7.5 HIGH
CVE-2026-7670 — Jinher OA UserSel.aspx sql injection

A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSummarize/UserSel.aspx. This manipulation of the argument DeptIDList causes sql inje…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.3 MEDIUM
CVE-2026-7669 — sgl-project SGLang HuggingFace Transformer hf_transformers_utils.py get_tokenizer deseria…

A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transf…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-7668 — MikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-bounds

A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulatio…

Remote | Memory Corruption
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7653 — r-huijts mcp-server-rijksmuseum MCP index.ts open_image_in_browser os command injection

A security flaw has been discovered in r-huijts mcp-server-rijksmuseum up to 1.0.4. Affected is the function open_image_in_browser of the file src/index.ts of the component MCP Interface. Performing …

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7645 — ruvnet sublinear-time-solver MCP server.js export_state path traversal

A vulnerability was found in ruvnet sublinear-time-solver 1.5.0. Affected by this vulnerability is the function export_state of the file src/consciousness-explorer/mcp/server.js of the component MCP …

Remote | Path Traversal
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-7644 — ChatGPTNextWeb NextChat actions.ts addMcpServer improper authorization

A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The manipulation leads to improper authorization. Remote …

Remote | Authorization
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.0 MEDIUM
CVE-2026-7643 — ChatGPTNextWeb NextChat API Endpoint Next.js cross-domain policy

A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of the component API Endpoint. Executing a manipulation can lead to permissive cros…

Remote | Misconfiguration
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7642 — pskill9 website-downloader MCP index.ts download_website os command injection

A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the component MCP Interface. Performing a manipulation o…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7633 — Totolink N300RH cstecgi.cgi setUploadSetting file inclusion

A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to…

Remote | Path Traversal
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-7632 — code-projects Online Hospital Management System viewappointment.php sql injection

A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function of the file /viewappointment.php. This manipulation of the argument delid cause…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.5 MEDIUM
CVE-2026-7631 — code-projects Online Hospital Management System Registration improper authorization

A vulnerability was found in code-projects Online Hospital Management System 1.0. The impacted element is an unknown function of the component Registration Handler. The manipulation of the argument U…

Remote | Authorization
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-7630 — innocommerce InnoShop Installation Endpoint InstallServiceProvider.php boot improper auth…

A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallServiceProvider::boot of the file innopacks/install/src/InstallServiceProvider.php of …

Remote | Authentication
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7629 — kleneway awesome-cursor-mpc-server Ccode-Review Tool codeReview.ts runCodeReviewTool comm…

A flaw has been found in kleneway awesome-cursor-mpc-server up to 2.0.1. Impacted is the function runCodeReviewTool of the file src/tools/codeReview.ts of the component Ccode-Review Tool. Executing a…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.3 MEDIUM
CVE-2026-3504 — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenticated…

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.1 via the '/dokan/v1/…

Remote | Information Disclosure
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
8.1 HIGH
CVE-2026-2554 — WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compati…

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl…

Remote | Authorization
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.4 MEDIUM
CVE-2026-0703 — NextMove Lite - Thank You Page for WooCommerce <= 2.23.0 - Authenticated (Contributor+) S…

The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xlwcty_current_date' shortcode in all versions up to, and includ…

Remote | Cross-Site Scripting
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
Showing 20 of 5658 Results