Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-71950 — D-Link DWR-M961 Command Injection via /boafrm/formSmsManage

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker …

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71949 — D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker …

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71948 — D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote …

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71947 — D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A re…

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71946 — D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRun

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote a…

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71945 — D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocom

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remo…

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
9.8 CRITICAL
CVE-2026-71944 — D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectel

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remo…

Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
7.7 HIGH
CVE-2026-67620 — Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata…

flowise | Remote | Server-Side Request Forgery
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
7.8 HIGH
CVE-2026-42170 — Gimp: gimp dds plug-in heap-based buffer overflow via bpp mismatch in load_layer() (ddsre…

A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in…

enterprise_linux enterprise_linux | Memory Corruption
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
5.3 MEDIUM
CVE-2026-19288 — astralisone rive-mcp-server-core importRiveFile Flow importRiveFile.ts path traversal

A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affects an unknown part of the file packages/mcp-server/src/tools/importRiveFil…

rive-mcp-server-core | Path Traversal
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
5.3 MEDIUM
CVE-2026-19287 — abrinsmead mindpilot-mcp HistoryService path traversal

A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the component HistoryService. This manipulation of the argument ID causes path travers…

mindpilot-mcp | Path Traversal
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
5.3 MEDIUM
CVE-2026-19285 — aaronsb memory-graph memoryTools.ts JsonMemoryStorage.saveMemories path traversal

A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vulnerability is the function JsonMemoryStorage.createDomain/JsonMemoryStorage.ge…

memory-graph | Path Traversal
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
5.3 MEDIUM
CVE-2026-19284 — MauricioMilano coder-api Projects Endpoint projects.ts createProject command injection

A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. Affected is the function createProject of the file src/core/projects.ts of the component Projects Endpoint. The man…

coder-api | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
5.3 MEDIUM
CVE-2026-19282 — andreahaku llm_memory_mcp GitHooksManager.ts auto.capture command injection

A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the function auto.capture of the file src/autolearn/GitHooksManager.ts of the …

llm_memory_mcp | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
5.3 MEDIUM
CVE-2026-19281 — adolfosalasgomez3011 slidev-builder-mcp generateAssets Tool generateAssets.ts generateCha…

A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generateChart of the file src/tools/generateAssets.ts of the component generateAssets T…

slidev-builder-mcp | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
5.3 MEDIUM
CVE-2026-19279 — MIMICLab mcp-pdf-vision index.ts load_pdf command injection

A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0. The impacted element is the function load_pdf of the file src/index.ts. Such manipulation of the argument pdfPath/sessionId leads to c…

mcp-pdf-vision | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
0.0 NA
CVE-2026-68082 — libceph: fix two unsafe bare decodes in decode_lockers()

In the Linux kernel, the following vulnerability has been resolved: libceph: fix two unsafe bare decodes in decode_lockers() decode_lockers() in cls_lock_client.c contains two bare decode operation…

linux_kernel | Memory Corruption
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
0.0 NA
CVE-2026-68081 — KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state

In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state Put all vmcs12 pages if KVM synthesizes a nested …

linux_kernel | Memory Corruption
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
5.3 MEDIUM
CVE-2026-19270 — Hulupeep mcp-ui-probe Journey/Usage JourneyStorage.ts usage_stats path traversal

A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_journey/analyze_journey/usage_stats of the file src/journey/JourneyStorage.ts of …

mcp-ui-probe | Path Traversal
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
6.5 MEDIUM
CVE-2026-19268 — abdullah1854 MCPGateway Claude Usage Range Endpoint claude-usage.ts getUsageByDateRange c…

A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230. This impacts the function getUsageByDateRange of the file src/services/claude-usage.ts of the…

mcpgateway | Remote | Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
Showing 20 of 9735 Results