Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-19369 — KS-GEN-AI jira-mcp-server add_attachment_from_public_url index.ts axios.get server-side r…

A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the arg…

| Server-Side Request Forgery
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-19368 — PV-Bhat gemsuite-mcp gemini_search unified-gemini.ts path traversal

A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component gemini_search/gemini_reason/g…

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
6.5 MEDIUM
CVE-2026-19367 — NocteDefensor LudusMCP read_range_config rangeConfig.ts server-side request forgery

A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality of the file src/tools/rangeConfig.ts of the component read_range_config. Th…

ludusmcp | Remote | Server-Side Request Forgery
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
2.1 LOW
CVE-2026-70395 — Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys…

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name, and to recover the secret val…

ash | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19366 — NocteDefensor LudusMCP insert_creds_range_config insertCredsRangeConfig.ts path traversal

A flaw has been found in NocteDefensor LudusMCP up to 1.0.24. Affected is an unknown function of the file src/tools/insertCredsRangeConfig.ts of the component insert_creds_range_config. Executing a m…

ludusmcp | Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19365 — Ichigo3766 image-gen-mcp upscale_images index.ts path traversal

A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the file src/index.ts of the component upscale_images. Such manipulation of the argume…

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.9 MEDIUM
CVE-2026-69659 — Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.…

Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination de…

ash | Denial of Service
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
6.5 MEDIUM
CVE-2026-19364 — itsourcecode Hospital Management System viewdoctorconsultancycharge.php sql injection

A vulnerability was determined in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /viewdoctorconsultancycharge.php. This manipulation of the argum…

hospital_management_system | Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.5 MEDIUM
CVE-2026-19363 — lmammino oidc-authorizer Fixed Message handler.rs unwrap deserialization

A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is the function unwrap of the file src/handler.rs of the component Fixed Message Handler. The manipulation of the argument …

Remote | Information Disclosure
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.5 MEDIUM
CVE-2026-19362 — lmammino oidc-authorizer Authorization Header Parsing parse_token_from_header.rs parse_to…

A vulnerability has been found in lmammino oidc-authorizer 0.4.0. This issue affects the function parse_token_from_header of the file src/parse_token_from_header.rs of the component Authorization Hea…

Remote | Denial of Service
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
3.7 LOW
CVE-2026-19361 — macrozheng mall mall-portal getAuthCode password recovery

A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a manipulation can lead to weak p…

mall | Remote | Authentication
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-15534 — Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expr…

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds…

| Memory Corruption
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.8 MEDIUM
CVE-2026-19360 — wongcyrus ExcelLexBot Lambda Function ExcelLexBotS3TriggerFunction privileges management

A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a manipulation results i…

Remote | Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.8 MEDIUM
CVE-2026-19359 — nxp-auto-goldvip gvip Lambda Function SitewiseCustomFunction access control

A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function Handler. Such manipulat…

Remote | Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
6.5 MEDIUM
CVE-2026-19358 — 3CORESec Trapdoor DefaultFunction access control

A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation causes improper access controls. The attack can be i…

Remote | Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.5 MEDIUM
CVE-2026-19357 — MingSoft MCMS ms-mdiy get information disclosure

A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy. The manipulation results in information disclosu…

mcms | Remote | Information Disclosure
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.5 MEDIUM
CVE-2026-19356 — MingSoft MCMS ms-mdiy list information disclosure

A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosu…

mcms | Remote | Information Disclosure
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
7.5 HIGH
CVE-2026-19355 — MingSoft MCMS ms-mdiy list.do ModelDataImpl.queryDiyFormData sql injection

A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipul…

mcms | Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
6.5 MEDIUM
CVE-2026-19354 — lock-upme OPMS IN Clause message.go sql injection

A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown function of the file controllers/messages/message.go of the component IN…

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.0 MEDIUM
CVE-2026-19353 — DedeCMS Installation Wizard index.php _4_Setup file inclusion

A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation le…

dedecms | Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
Showing 20 of 9586 Results