Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-7416 — PolarVista xcode-mcp-server MCP index.ts run_tests os command injection

A vulnerability was found in PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests of the file src/index.ts of the component MCP Interface. The manipulation of th…

Remote | Injection
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
6.5 MEDIUM
CVE-2026-7410 — SourceCodester Pizzafy Ecommerce System ajax.php add_to_cart sql injection

A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument…

Remote | Injection
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
5.8 MEDIUM
CVE-2026-7409 — SourceCodester Pizzafy Ecommerce System ajax.php save_user sql injection

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation can lead to sql inject…

Remote | Injection
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
5.8 MEDIUM
CVE-2026-7408 — SourceCodester Pizzafy Ecommerce System ajax.php save_menu sql injection

A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Performing a manipulation r…

Remote | Injection
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
5.8 MEDIUM
CVE-2026-7407 — SourceCodester Pizzafy Ecommerce System Setting ajax.php save_settings sql injection

A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /pizzafy/admin/ajax.php?action=save…

Remote | Injection
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
7.5 HIGH
CVE-2026-7404 — getsimpletool mcpo-simple-server base_manager.py delete_shared_prompt path traversal

A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.p…

Remote | Path Traversal
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
5.5 MEDIUM
CVE-2026-7403 — geldata gel-mcp server.py fetch_rule path traversal

A security flaw has been discovered in geldata gel-mcp 0.1.0. This impacts the function list_rules/fetch_rule of the file src/gel_mcp/server.py. The manipulation of the argument rule_name results in …

Remote | Path Traversal
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
4.8 MEDIUM
CVE-2026-1858 — wget2 Improper Certificate Validation

wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpos…

wget2 | Remote | Cryptography
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
7.3 HIGH
CVE-2025-50328 — B1 Free Archiver Untrusted Code Execution

A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of the Web (MotW) protections. When an archive is downloaded from the internet and e…

Remote | Misconfiguration
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
8.1 HIGH
CVE-2026-7426 — Out-of-Bounds Write via Unsanitized Prefix Length in Router Advertisement Processing in F…

Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by…

freertos-plus-tcp | Memory Corruption
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
6.5 MEDIUM
CVE-2026-7425 — Out-of-Bounds Read in Router Advertisement Option Parser in FreeRTOS-Plus-TCP

Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of service (device crash…

freertos-plus-tcp | Denial of Service
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
5.0 MEDIUM
CVE-2026-7401 — SourceCodester CET Automated Grading System with AI Predictive Analytics Registration ind…

A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=register of the com…

Remote | Cross-Site Scripting
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
7.5 HIGH
CVE-2026-7400 — geekgod382 filesystem-mcp-server read_file_tool/write_file_tool server.py is_path_allowed…

A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is_path_allowed of the file server.py of the component read_file_tool/write_file_…

Remote | Path Traversal
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.8 HIGH
CVE-2026-34965 — Cockpit CMS Authenticated Remote Code Execution via Collections

Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privilege…

Remote | Injection
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
9.8 CRITICAL
CVE-2018-25318 — Tenda FH303/A300 V5.07.68_EN Cookie Session Weakness DNS Change

Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers ca…

Remote | Authentication
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
9.8 CRITICAL
CVE-2018-25317 — Tenda W3002R/A302/W309R V5.07.64_en Cookie Session Weakness DNS Change

Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient se…

Remote | Authentication
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
9.8 CRITICAL
CVE-2018-25316 — Tenda W308R v2 V5.07.48 Cookie Session Weakness DNS Change

Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send…

Remote | Authentication
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
8.6 HIGH
CVE-2018-25315 — Alloksoft Video joiner 4.6.1217 Buffer Overflow via License Name

Alloksoft Video joiner 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can…

| Memory Corruption
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.6 HIGH
CVE-2018-25314 — Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 Buffer Overflow

Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized string in the License Na…

| Memory Corruption
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
6.9 MEDIUM
CVE-2018-25313 — SysGauge 4.5.18 Local Denial of Service via Proxy Configuration

SysGauge 4.5.18 contains a buffer overflow vulnerability in the proxy configuration handler that allows local attackers to cause a denial of service by supplying an oversized string. Attackers can in…

sysgauge | Denial of Service
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
Showing 20 of 5875 Results