Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-7446 — VetCoders mcp-server-semgrep MCP index.ts create_rule os command injection

A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_results/export_results/compare_results/scan_directory/create_rule of the file src/…

Remote | Injection
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
6.5 MEDIUM
CVE-2026-7445 — ZachHandley ZMCPTools MCP Log Resource ResourceManager.ts path traversal

A security vulnerability has been detected in ZachHandley ZMCPTools up to 0.2.2. Affected by this issue is some unknown functionality of the file src/managers/ResourceManager.ts of the component MCP …

Remote | Path Traversal
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
0.0 NA
CVE-2026-38940 — RafyMrX TOKO-ONLINE-ROTI Cross-Site Scripting

Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code via the detail_produk.php component

| Cross-Site Scripting
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
0.0 NA
CVE-2026-38939 — Andrewtch88 MVC-Ecommerce Cross-Site Scripting Vulnerability

Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the product_catalogue.php component

| Cross-Site Scripting
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
0.0 NA
CVE-2026-36960 — U-SPEED N300 Router CSRF Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanisms such as anti-CSRF…

| Cross-Site Request Forgery
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
7.5 HIGH
CVE-2026-7443 — BurtTheCoder mcp-dnstwist MCP index.ts fuzz_domain os command injection

A weakness has been identified in BurtTheCoder mcp-dnstwist up to 1.0.4. Affected by this vulnerability is the function fuzz_domain of the file src/index.ts of the component MCP Interface. Executing …

Remote | Injection
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
9.0 HIGH
CVE-2026-7420 — UTT HiPER 1250GW ConfigAdvideo strcpy buffer overflow

A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file route/goform/ConfigAdvideo. The manipulation of the argument Profile res…

Remote | Memory Corruption
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
9.0 HIGH
CVE-2026-7419 — UTT HiPER 1250GW formTaskEdit_ap strcpy buffer overflow

A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of the file route/goform/formTaskEdit_ap. The manipulation of the argument Profile…

Remote | Memory Corruption
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
9.1 CRITICAL
CVE-2026-7381 — Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled…

Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the variation setting (sendfile type) to be set by the c…

Remote | Path Traversal
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
9.0 HIGH
CVE-2026-7418 — UTT HiPER 1250GW NTP strcpy buffer overflow

A vulnerability was determined in UTT HiPER 1250GW up to 3.2.7-210907-180535. This vulnerability affects the function strcpy of the file route/goform/NTP. Executing a manipulation of the argument Pro…

Remote | Memory Corruption
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
7.5 HIGH
CVE-2026-7417 — Algovate xhs-mcp MCP mcp.server.ts xhs_publish_content server-side request forgery

A vulnerability was found in Algovate xhs-mcp 0.8.11. This affects the function xhs_publish_content of the file src/server/mcp.server.ts of the component MCP Interface. Performing a manipulation of t…

Remote | Server-Side Request Forgery
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
7.5 HIGH
CVE-2026-7416 — PolarVista xcode-mcp-server MCP index.ts run_tests os command injection

A vulnerability was found in PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests of the file src/index.ts of the component MCP Interface. The manipulation of th…

Remote | Injection
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
6.5 MEDIUM
CVE-2026-7410 — SourceCodester Pizzafy Ecommerce System ajax.php add_to_cart sql injection

A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument…

Remote | Injection
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
5.8 MEDIUM
CVE-2026-7409 — SourceCodester Pizzafy Ecommerce System ajax.php save_user sql injection

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation can lead to sql inject…

Remote | Injection
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
5.8 MEDIUM
CVE-2026-7408 — SourceCodester Pizzafy Ecommerce System ajax.php save_menu sql injection

A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Performing a manipulation r…

Remote | Injection
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
5.8 MEDIUM
CVE-2026-7407 — SourceCodester Pizzafy Ecommerce System Setting ajax.php save_settings sql injection

A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /pizzafy/admin/ajax.php?action=save…

Remote | Injection
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
7.5 HIGH
CVE-2026-7404 — getsimpletool mcpo-simple-server base_manager.py delete_shared_prompt path traversal

A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.p…

Remote | Path Traversal
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
5.5 MEDIUM
CVE-2026-7403 — geldata gel-mcp server.py fetch_rule path traversal

A security flaw has been discovered in geldata gel-mcp 0.1.0. This impacts the function list_rules/fetch_rule of the file src/gel_mcp/server.py. The manipulation of the argument rule_name results in …

Remote | Path Traversal
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
4.8 MEDIUM
CVE-2026-1858 — wget2 Improper Certificate Validation

wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpos…

wget2 | Remote | Cryptography
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
7.3 HIGH
CVE-2025-50328 — B1 Free Archiver Untrusted Code Execution

A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of the Web (MotW) protections. When an archive is downloaded from the internet and e…

Remote | Misconfiguration
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
Showing 20 of 5889 Results