Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2026-94089 — D-Link DIR-868L Authentication webfa_authentication.cgi strcpy stack-based overflow

A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulati…

Remote | Memory Corruption
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-94051 — 0717376 cowork_bench pdf-tools-mcp server.py ControlFlowNode server-side request forgery

A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulnerability is the function ControlFlowNode of the file local_servers/pdf-tools-mc…

Remote | Server-Side Request Forgery
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
5.3 MEDIUM
CVE-2026-94050 — D-Link DIR-X1860Z ubus JSON-RPC interface routerd.get_rand_key information disclosure

A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402. Affected is the function routerd.wificfg_get/routerd.get_rand_key of the component ubus JSON-RPC interface. Such manipul…

| Information Disclosure
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.3 MEDIUM
CVE-2026-94049 — 06ketan slideshot renderer.ts render_slides path traversal

A flaw has been found in 06ketan slideshot up to 4.4.0. This impacts the function render_slides of the file packages/cli/src/renderer.ts. This manipulation of the argument htmlPath causes path traver…

Remote | Path Traversal
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.6 MEDIUM
CVE-2026-94048 — CodeAstro QR Code Attendance Management System UserController.php save privileges managem…

A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument rol…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-94047 — samanhappy MCPHub Template Import Endpoint templateService.ts importTemplate privileges m…

A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32. The impacted element is the function importTemplate of the file src/services/templateService.ts of the component Template…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.3 MEDIUM
CVE-2026-94046 — 0215AndrewFeng ACE-MCP MCP Tool getFileSnippet.ts get_file_snippet path traversal

A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8. The affected element is the function get_file_snippet of the file getFileSnippet.ts of the component MCP Tool. Executing a manip…

Remote | Path Traversal
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.0 MEDIUM
CVE-2026-94045 — newbee-ltd newbee-mall Goods Save Endpoint UploadController.java cross site scripting

A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0. Impacted is an unknown function of the file controller/common/UploadController.java of the component Goods Save Endpoint. Pe…

Remote | Cross-Site Scripting
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
7.5 HIGH
CVE-2026-94044 — 03-lovepreetSingh MCP route.ts create_file path traversal

A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affects the function create_file of the file app/api/mcp/route.ts. Such manipulation…

Remote | Path Traversal
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
5.5 MEDIUM
CVE-2026-94043 — Free5GC Gmm handler.go race condition

A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handler.go of the component Gmm Handler. This …

Remote | Race Condition
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-94042 — AdithyaYelloju Restaurant Management System add_table.php mysqli_query sql injection

A vulnerability was found in AdithyaYelloju Restaurant Management System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/add_table.php. The ma…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-94041 — AdithyaYelloju Restaurant-Management-System add_menu.php sql injection

A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is some unknown functionality of the file admin/ad…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
9.4 CRITICAL
CVE-2026-88857 — Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in Orda…

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into…

Remote | Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
9.4 CRITICAL
CVE-2026-88856 — Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in Orda…

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_o…

Remote | Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
8.6 HIGH
CVE-2026-88855 — Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joo…

Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveGallery() passes form data through a hand-rolled…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
9.3 CRITICAL
CVE-2026-88854 — Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Galler…

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsea…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
5.5 MEDIUM
CVE-2026-94040 — vas3k TaxHacker actions.ts testLLMProviderAction server-side request forgery

A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderAction of the file app/(app)/apps/settings/actions.ts. Executing a manipulation of …

taxhacker | Remote | Server-Side Request Forgery
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
7.5 HIGH
CVE-2026-94039 — vas3k TaxHacker Invoice PDF Renderer actions.ts generateInvoicePDF server-side request fo…

A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer. Performing a mani…

taxhacker | Remote | Server-Side Request Forgery
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
7.5 HIGH
CVE-2026-94038 — NonceGeek dim-sum-app Deno Backend main.tsx textSearchV2Handler server-side request forge…

A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of the file deno/main.tsx of the component Deno Backend. Such manipulation of the ar…

Remote | Server-Side Request Forgery
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.3 MEDIUM
CVE-2026-94037 — 00Kisumi00 mcp-file-analyzer analyze_csv_data MCP tool main.py ControlFlowNode path trave…

A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405. This affects the function ControlFlowNode of the file main.py of the component analyze_c…

Remote | Path Traversal
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
Showing 20 of 13777 Results