Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-19327 — abracadabra50 claude-sesh enricher.ts enrichSession path traversal

A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession of the file src/services/enricher.ts. Executing a manipulation of the argument …

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
4.4 MEDIUM
CVE-2026-19326 — Jevon-Zhong Ai-doctor filemanagement.service.ts deleteImage path traversal

A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the file ai-doctor-server/src/filemanagement/filemanagement.service.ts. Performing …

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19325 — IncomeStreamSurfer roo-code-memory-bank-mcp-server read_memory_bank_file/append_memory_ba…

A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMem…

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
3.3 LOW
CVE-2026-19324 — HelloGGX shadcn-vue-mcp callback-server.ts fs.promises.readFile path traversal

A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by this issue is the function fs.promises.readFile of the file src/server/callback-s…

| Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
0.0 NA
CVE-2026-17510 — Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in …

Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destination buffer for a B…

| Memory Corruption
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.8 CRITICAL
CVE-2026-71993 — MSI Radix AXE6600 v781521 Command Injection via openvpn function

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device.…

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.8 CRITICAL
CVE-2026-71992 — MSI Radix AXE6600 v781521 Command Injection via macfilter

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected devic…

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.8 CRITICAL
CVE-2026-71991 — MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary …

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.8 CRITICAL
CVE-2026-71990 — MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary com…

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.8 CRITICAL
CVE-2026-71989 — MSI Radix AXE6600 v781521 Command Injection via porTrigger function

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected devi…

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.8 CRITICAL
CVE-2026-71988 — MSI Radix AXE6600 v781521 Command Injection via portFw function

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. …

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.8 CRITICAL
CVE-2026-71987 — MSI Radix AXE6600 v781521 Command Injection via alg function

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Att…

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.8 CRITICAL
CVE-2026-71986 — MSI Radix AXE6600 v781521 Command Injection via dmz Function

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Att…

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.8 CRITICAL
CVE-2026-71985 — MSI Radix AXE6600 v781521 Command Injection via accesscontrol Function

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected d…

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.8 CRITICAL
CVE-2026-71984 — MSI Radix AXE6600 v781521 Command Injection via urlfilter

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected devic…

Remote | Injection
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
5.3 MEDIUM
CVE-2026-19323 — azer react-analyzer-mcp analyze-projec index.ts generateProjectDocs path traversal

A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function generateProjectDocs of the file src/index…

react-analyzer-mcp | Path Traversal
Aug 09, 2026 Aug 09, 2026
Aug 09, 2026
Aug 09, 2026
9.8 CRITICAL
CVE-2026-71983 — MSI Radix AXE6600 v781521 Command Injection via wps.cgi

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious…

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
5.1 MEDIUM
CVE-2026-71502 — Unauthenticated Stored Vue Template Injection Leads to Cross-Site Scripting in CTI-Transm…

CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthentic…

Remote | Cross-Site Scripting
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71958 — D-Link DWR-M961 Buffer Overflow via quicksetup.cgi

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly…

Remote | Memory Corruption
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71957 — D-Link DWR-M961 Buffer Overflow via app.cgi

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly lon…

Remote | Memory Corruption
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
Showing 20 of 9714 Results