Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-94953 — TOTOLINK N150RT Stack-Based Buffer Overflow

A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formAjaxSet using t…

| Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.8 CRITICAL
CVE-2026-79538 — MetaMCP Remote Code Execution

metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-pro…

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-79537 — MetaMCP Insecure Direct Object Reference (IDOR) Vulnerability

metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed on…

| Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-79536 — Bytebase DBHub SQL Injection Vulnerability

bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability in the /utils/sql-parser.ts component. This vulnerability allows attackers to access sensitive databse information via a …

| Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-79535 — VoiceMode OS Command Injection

mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the "voicemode config set" CLI) writes a caller-supplied value into ~/.voicemode/voicemode.env witho…

| Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-79534 — mark3labs mcp-filesystem-server Directory Traversal Vulnerability

mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks return…

| Path Traversal
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-79417 — ArgusMonitor Improper Access Control Vulnerability

Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, low-privileged users to bypass device handle access restrictions via a TOCTOU condition in…

| Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-79403 — Kilo Code Arbitrary Code Execution Vulnerability

An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint

| Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.3 MEDIUM
CVE-2026-79348 — KitchenAsty Broken Object Level Authorization Vulnerability

KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate…

Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
2.7 LOW
CVE-2026-76738 — Authenticated Buffer Overflow Vulnerability in the API Endpoint of HPE Networking Instant…

A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Success…

Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
3.0 LOW
CVE-2026-76737 — Authenticated Local Path Traversal Vulnerability Leads to Denial-of-Service in HPE Networ…

An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a…

| Path Traversal
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
3.3 LOW
CVE-2026-76736 — Authenticated Local Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Netwo…

A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt t…

| Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.1 MEDIUM
CVE-2026-76735 — Authenticated Local Sensitive Information Disclosure in HPE Networking Instant On

A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high …

| Information Disclosure
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.8 MEDIUM
CVE-2026-76734 — Unauthenticated Memory Corruption Vulnerability leads to Denial-of-Service in HPE Network…

A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation …

Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.9 MEDIUM
CVE-2026-76733 — Authenticated Denial-of-Service Vulnerability in HPE Networking Instant On API Endpoint

A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Succe…

Remote | Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.4 MEDIUM
CVE-2026-76732 — Authenticated Local Privilege Escalation Vulnerability in a Daemon of HPE Networking Inst…

A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achie…

| Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.5 MEDIUM
CVE-2026-76731 — Authentication Bypass in the Captive Portal of HPE Networking Instant On

An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exp…

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.5 MEDIUM
CVE-2026-76730 — Improper PAPI Packet handling leads to unauthorized access in HPE Networking Instant ON A…

An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication control…

| Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.6 MEDIUM
CVE-2026-76729 — Authenticated Format String Vulnerability allows Memory Corruption in HPE Networking Inst…

A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. …

Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.2 HIGH
CVE-2026-76728 — Authenticated Server-Side Request Forgery Leading to Remote Code Execution in HPE Network…

A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successf…

Remote | Server-Side Request Forgery
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
Showing 20 of 14688 Results