Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-7645 — ruvnet sublinear-time-solver MCP server.js export_state path traversal

A vulnerability was found in ruvnet sublinear-time-solver 1.5.0. Affected by this vulnerability is the function export_state of the file src/consciousness-explorer/mcp/server.js of the component MCP …

Remote | Path Traversal
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-7644 — ChatGPTNextWeb NextChat actions.ts addMcpServer improper authorization

A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The manipulation leads to improper authorization. Remote …

Remote | Authorization
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.0 MEDIUM
CVE-2026-7643 — ChatGPTNextWeb NextChat API Endpoint Next.js cross-domain policy

A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of the component API Endpoint. Executing a manipulation can lead to permissive cros…

Remote | Misconfiguration
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7642 — pskill9 website-downloader MCP index.ts download_website os command injection

A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the component MCP Interface. Performing a manipulation o…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7633 — Totolink N300RH cstecgi.cgi setUploadSetting file inclusion

A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to…

Remote | Path Traversal
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-7632 — code-projects Online Hospital Management System viewappointment.php sql injection

A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function of the file /viewappointment.php. This manipulation of the argument delid cause…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.5 MEDIUM
CVE-2026-7631 — code-projects Online Hospital Management System Registration improper authorization

A vulnerability was found in code-projects Online Hospital Management System 1.0. The impacted element is an unknown function of the component Registration Handler. The manipulation of the argument U…

Remote | Authorization
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-7630 — innocommerce InnoShop Installation Endpoint InstallServiceProvider.php boot improper auth…

A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallServiceProvider::boot of the file innopacks/install/src/InstallServiceProvider.php of …

Remote | Authentication
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7629 — kleneway awesome-cursor-mpc-server Ccode-Review Tool codeReview.ts runCodeReviewTool comm…

A flaw has been found in kleneway awesome-cursor-mpc-server up to 2.0.1. Impacted is the function runCodeReviewTool of the file src/tools/codeReview.ts of the component Ccode-Review Tool. Executing a…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.3 MEDIUM
CVE-2026-3504 — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenticated…

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.1 via the '/dokan/v1/…

Remote | Information Disclosure
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
8.1 HIGH
CVE-2026-2554 — WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compati…

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl…

Remote | Authorization
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.4 MEDIUM
CVE-2026-0703 — NextMove Lite - Thank You Page for WooCommerce <= 2.23.0 - Authenticated (Contributor+) S…

The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xlwcty_current_date' shortcode in all versions up to, and includ…

Remote | Cross-Site Scripting
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
6.5 MEDIUM
CVE-2026-7628 — crazyrabbitLTC mcp-code-review-server RepoMix repomix.ts executeRepomix command injection

A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function executeRepomix of the file src/repomix.ts of the component RepoMix Command Handler. …

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.8 MEDIUM
CVE-2026-6817 — Quiz Maker by AYS <= 6.7.1.29 - Unauthenticated Stored Cross-Site Scripting via 'rate_rea…

The Quiz Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rate_reason' parameter in all versions up to, and including, 6.7.1.29 due to insufficient input saniti…

Remote | Cross-Site Scripting
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.5 MEDIUM
CVE-2026-6525 — NULL Pointer Dereference in Wireshark

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4

| Denial of Service
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-6320 — Salon Booking System – Free Version <= 10.30.25 - Unauthenticated Arbitrary File Read via…

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker…

Remote | Path Traversal
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
5.4 MEDIUM
CVE-2026-4790 — Premium Addons for Elementor <= 4.11.70 - Authenticated (Contributor+) Stored Cross-Site …

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_svg' parameter in versions up to, and inclu…

Remote | Cross-Site Scripting
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.1 HIGH
CVE-2026-4100 — Paid Memberships Pro <= 3.6.5 - Missing Authorization to Authenticated (Subscriber+) Stri…

The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versions up to, and including, 3.6.5. This is due to mis…

Remote | Authentication
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-4062 — Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'object_ids' Paramet…

The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_ids' parameters in all versions up to, and including, 1.13.18. This is due to in…

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
7.5 HIGH
CVE-2026-4061 — Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'map_post_type' Para…

The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all versions up to, and including, 1.13.18. This is due to the `SearchResults` hook …

Remote | Injection
May 02, 2026 May 02, 2026
May 02, 2026
May 02, 2026
Showing 20 of 5564 Results