Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-19350 — Dolibarr ERP TakePOS invoice.php fail authorization

A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing a…

erp | Remote | Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
10.0 HIGH
CVE-2026-19348 — Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection

A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&na…

m300_wi-fi_repeater | Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
6.5 MEDIUM
CVE-2026-19347 — itsourcecode Hospital Management System viewdoctor.php sql injection

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php. Such manipulation of the argument delid leads to…

hospital_management_system | Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.0 HIGH
CVE-2026-19346 — Tenda CH22 CertListInfo formCertListInfo command injection

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command …

ch22_firmware ch22 | Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
6.5 MEDIUM
CVE-2026-19345 — code-projects Task Management System UpdateTaskStatus.php authorization

A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in mis…

task_management_system | Remote | Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
7.5 HIGH
CVE-2026-19344 — code-projects Task Management System comment_count_user.php sql injection

A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/comment_count_user.php. The manipulation of the argu…

task_management_system | Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
7.5 HIGH
CVE-2026-19343 — code-projects Task Management System AdminLogin.php sql injection

A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a manipulation of the argume…

task_management_system | Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
7.3 HIGH
CVE-2026-19342 — code-projects Task Management System Login index.php improper authentication

A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Pass…

task_management_system | Remote | Authentication
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.0 HIGH
CVE-2026-19341 — UTT HiPER 1200GW pptpSrvGlobalConfig strcpy stack-based overflow

A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of the argument Encrypti…

hiper_1200gw | Remote | Memory Corruption
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
6.5 MEDIUM
CVE-2026-19340 — anubissbe ProjectHub-Mcp Webhooks API complete_backend.js server-side request forgery

A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js of the component Webhooks API. This manipulation o…

projecthub-mcp | Remote | Server-Side Request Forgery
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
6.5 MEDIUM
CVE-2026-19339 — aliyun alibabacloud-dataworks-mcp-server initResources.ts ReadResourceRequestSchema serve…

A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts…

alibabacloud-dataworks-mcp-server | Remote | Server-Side Request Forgery
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19338 — automateyournetwork MCPyATS generate_mermaid_markdown index.ts processGenerateRequest pat…

A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component genera…

mcpyats | Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19337 — adenot mcp-google-search read_webpage index.ts server-side request forgery

A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a manipulation of the argumen…

mcp-google-search | Server-Side Request Forgery
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19336 — Pimzino spec-workflow-mcp approvals.ts ApprovalStorage.createApproval path traversal

A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the…

spec-workflow-mcp | Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19335 — Jane-xiaoer skill-vision-control config.ts getSkillVersionsDir path traversal

A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the file src/svc/utils/config.ts. Such manipulation of t…

skill-vision-control | Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-18603 — Cancel Order & Request Woocommerce < 1.3.4.34 - Unauthenticated Order Content Disclosure …

The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding the contents of a previous order to the cart, allo…

| Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-18473 — WP Directory Kit < 1.5.5 - Unauthenticated SQL Injection via 'field_search' Parameter

The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated user…

| Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-18465 — WP Maps Pro < 6.1.3 - Unauthenticated Local File Inclusion

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-c…

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-18464 — WP Maps Pro < 6.1.3 - Unauthenticated Denial of Service

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it …

| Denial of Service
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-18357 — WPC Order Tip for WooCommerce < 3.3.1 - Unauthenticated Order Data Disclosure

The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated attackers to retrieve sensiti…

| Authorization
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
Showing 20 of 9469 Results