Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-6890 — Use of default credentials vulnerability

A use of default credentials vulnerability in the Advantech ECU-1251D allows a remote attacker to gain unauthorised access to the device via SSH using the default root account with no password, as do…

| Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.9 MEDIUM
CVE-2026-6889 — Denial of service vulnerability

A denial of service vulnerability in the Advantech ECU-1251D allows a network-adjacent attacker to send a DNP3 signal to the Digital Output address of the device, causing the DNP3Daemon to invoke a n…

| Denial of Service
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.8 HIGH
CVE-2026-18157 — Yggdrasil-worker-package-manager: yggdrasil-worker-package-manager: remote code execution…

A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially c…

Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.0 HIGH
CVE-2026-14541 — Authentication Bypass and Audience Confusion in MCP Toolbox OAuth Provider

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabl…

Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.0 HIGH
CVE-2026-14540 — Server-Side Request Forgery via Unrestricted HTTP Redirection in MCP Toolbox

A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline inpu…

Remote | Server-Side Request Forgery
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.6 MEDIUM
CVE-2026-14539 — Denial of Service via Unrestricted Payload Buffering in MCP Toolbox

An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of …

Remote | Denial of Service
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.7 MEDIUM
CVE-2026-14538 — BigQuery Dataset Allowlist Bypass via Metadata Dry-Run in MCP Toolbox

An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to…

Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.1 HIGH
CVE-2026-14537 — Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequi…

Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
3.3 LOW
CVE-2026-58039 — Node.js Permission Model File Write Bypass

A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended s…

| Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.5 MEDIUM
CVE-2026-66720 — MZ Automation libiec61850 Out-of-bounds Read

The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame contain…

| Denial of Service
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
9.3 CRITICAL
CVE-2026-66421 — OpenClaw Dashboard Stored XSS via lastMessage Session Field

OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injectin…

Remote | Cross-Site Scripting
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.8 HIGH
CVE-2026-66420 — MeshCentral Cross-Site WebSocket Hijacking via Origin Validation Bypass on Self-Signed Ce…

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting …

Remote | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
6.5 MEDIUM
CVE-2026-66369 — MZ Automation libiec61850 Out-of-bounds Read

The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are p…

| Denial of Service
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
6.5 MEDIUM
CVE-2026-66364 — MZ Automation libiec61850 Out-of-bounds Read

The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an …

| Denial of Service
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.5 HIGH
CVE-2026-66360 — MZ Automation libiec61850 Out-of-bounds Read

The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an…

Remote | Memory Corruption
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
6.5 MEDIUM
CVE-2026-66349 — MZ Automation libiec61850 Out-of-bounds Read

The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established ses…

| Memory Corruption
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.8 HIGH
CVE-2026-65423 — o6 Automation open62541 Integer Overflow or Wraparound

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write.

Remote | Memory Corruption
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
6.5 MEDIUM
CVE-2026-65421 — MZ Automation libiec61850 Out-of-bounds Read

The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This lead…

| Memory Corruption
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
6.5 MEDIUM
CVE-2026-63550 — MZ Automation libiec61850 Out-of-bounds Read

The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS s…

Remote | Denial of Service
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
5.9 MEDIUM
CVE-2026-63362 — o6 Automation open62541 Integer Underflow

An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet.

Remote | Denial of Service
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
Showing 20 of 9618 Results