Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-79747 — MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary URLs and re…

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, an authentica…

mcphub | Remote | Server-Side Request Forgery
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
8.1 HIGH
CVE-2026-79746 — MCPHub: Server-scoped bearer key gains access to an entire group via partial (any-overlap…

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.31, when a bearer…

mcphub | Remote | Authorization
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-79745 — MCPHub: Missing Authorization on Built-in Prompt & Resource CRUD (Unauthorized Tampering …

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, the built-in …

mcphub | Remote | Authorization
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
8.8 HIGH
CVE-2026-79744 — MCPHub: Missing Authorization on `PUT /api/system-config` Lets Any Non-Admin Rewrite Glob…

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.29, MCPHub's PUT …

mcphub | Remote | Authorization
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
6.9 MEDIUM
CVE-2026-79743 — MCPHub: Path Traversal via Malicious MCPB Manifest Name

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.13, MCPB File Up…

mcphub | Remote | Path Traversal
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
9.1 CRITICAL
CVE-2026-51730 — TOTOLINK T6 Incorrect Access Control

Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin…

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
9.1 CRITICAL
CVE-2026-51729 — TOTOLINK T6 Improper Access Control

Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a crafted POST reque…

Remote | Authorization
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-51728 — TOTOLINK Unauthenticated Firmware Upload Vulnerability

Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to upload a crafted firmware image via sending a crafted POST request…

Remote | Authorization
Aug 31, 2026 Sep 02, 2026
Aug 31, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-51727 — TOTOLINK SystemSettings Improper Access Control

Incorrect access control in the SystemSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve administrative import and export endpoint information via sen…

Remote | Authorization
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
9.1 CRITICAL
CVE-2026-51726 — TOTOLINK T6 Parental Control Rule Unauthorized Deletion

Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending a crafted POST request to …

Remote | Authorization
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
9.1 CRITICAL
CVE-2026-51725 — TOTOLINK T6 Improper Access Control

Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bi…

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
6.5 MEDIUM
CVE-2026-19953 — URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labe…

URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep. nameprep lowercases each host label but performs no Unicode normali…

Remote | Misconfiguration
Aug 31, 2026 Sep 03, 2026
Aug 31, 2026
Sep 03, 2026
Showing 20 of 14952 Results