Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42739
Total
3465
Critical
12744
High
12574
Medium
CVE ID Severity Score Description Published
CVE-2026-81848 LOW 3.5 A vulnerability was determined in cyberchitta scrapling-fetch-mcp up to 0.2.2. The impacted element is the function s_fetch_page/s_fetch_pattern of the file src/scrapling_fetch_mcp/_fetcher.py. Executing a manipulation can … Aug 28, 2026
CVE-2026-81847 MEDIUM 5.5 A vulnerability was found in MAA-AI MaaMCP up to 1.1.1.dev6+g2e4a41287. The affected element is the function save_pipeline/load_pipeline of the file pipeline_tools.py. Performing a manipulation results … Aug 28, 2026
CVE-2026-81845 MEDIUM 6.3 A vulnerability has been found in arben-adm mcp-sequential-thinking up to 0.5.0. Impacted is the function import_session/export_session of the file mcp_sequential_thinking/server.py of the component Import Session/Export … Aug 28, 2026
CVE-2026-81837 MEDIUM 6.3 A flaw has been found in RooCodeInc Roo-Code up to 3.51.1. This issue affects the function path.resolve of the file src/core/tools/ApplyPatchTool.ts of the component ApplyPatchTool. … Aug 28, 2026
CVE-2026-81836 LOW 3.7 A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file src/integrations/claude-code/oauth.ts of the component OAuth Callback. The … Aug 28, 2026
CVE-2026-81835 MEDIUM 5.5 A security vulnerability has been detected in RooCodeInc Roo-Code up to 3.51.1. This affects the function fetch_instructions of the file malicious_mcp_server.py of the component MCP … Aug 28, 2026
CVE-2026-80179 MEDIUM 5.9 A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed … Aug 28, 2026
CVE-2026-78239 CRITICAL 9.8 Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. … Aug 28, 2026
CVE-2026-78037 HIGH 8.8 Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands … Aug 28, 2026
CVE-2026-77977 HIGH 8.1 Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive administrative actions when default credentials remain configured. An unauthenticated attacker on … Aug 28, 2026
CVE-2026-77358 UNKNOWN cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client frees the TLS session before closing the WebSocket that … Aug 28, 2026
CVE-2026-77341 UNKNOWN cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0, the chunked-response trailer output path writes trailer header names and values directly to the socket … Aug 28, 2026
CVE-2026-76945 HIGH 7.5 The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An attacker may replay or manipulate authentication tokens to gain unauthorized access … Aug 28, 2026
CVE-2026-76943 CRITICAL 9.8 Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. … Aug 28, 2026
CVE-2026-76940 HIGH 7.5 The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout mechanisms. This could allow an attacker to perform automated … Aug 28, 2026
CVE-2026-76179 CRITICAL 9.8 An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during … Aug 28, 2026
CVE-2026-76060 HIGH 8.8 An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed … Aug 28, 2026
CVE-2026-75814 HIGH 8.8 The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface. An unauthenticated remote attacker could persuade … Aug 28, 2026
CVE-2026-75813 HIGH 7.5 Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access or modify sensitive device settings. This could result in full compromise … Aug 28, 2026
CVE-2026-75548 MEDIUM 5.4 The affected Ebyte device web management interface does not restrict the interface from being rendered within an external frame. An unauthenticated remote attacker could use … Aug 28, 2026
CVE-2026-75419 HIGH 8.8 go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/service/internal/data/data.go and app/app/service/internal/data/data.go returns a no-op authorization engine (noop.State{}), so the authz … Aug 28, 2026
CVE-2026-75418 HIGH 7.5 A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.14 on Windows. An attacker with network access to the server can … Aug 28, 2026
CVE-2026-75417 HIGH 7.2 A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within application/admin/controller/category.class.php, where the user-controlled parentid parameter is concatenated … Aug 28, 2026
CVE-2026-75339 HIGH 8.8 The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload arbitrary files, and any anonymous attacker can download … Aug 28, 2026
CVE-2026-75337 CRITICAL 9.8 The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-controlled path is concatenated to the preview root … Aug 28, 2026