Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42739
Total
3465
Critical
12744
High
12574
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81848 | LOW | 3.5 | A vulnerability was determined in cyberchitta scrapling-fetch-mcp up to 0.2.2. The impacted element is the function s_fetch_page/s_fetch_pattern of the file src/scrapling_fetch_mcp/_fetcher.py. Executing a manipulation can … | Aug 28, 2026 |
| CVE-2026-81847 | MEDIUM | 5.5 | A vulnerability was found in MAA-AI MaaMCP up to 1.1.1.dev6+g2e4a41287. The affected element is the function save_pipeline/load_pipeline of the file pipeline_tools.py. Performing a manipulation results … | Aug 28, 2026 |
| CVE-2026-81845 | MEDIUM | 6.3 | A vulnerability has been found in arben-adm mcp-sequential-thinking up to 0.5.0. Impacted is the function import_session/export_session of the file mcp_sequential_thinking/server.py of the component Import Session/Export … | Aug 28, 2026 |
| CVE-2026-81837 | MEDIUM | 6.3 | A flaw has been found in RooCodeInc Roo-Code up to 3.51.1. This issue affects the function path.resolve of the file src/core/tools/ApplyPatchTool.ts of the component ApplyPatchTool. … | Aug 28, 2026 |
| CVE-2026-81836 | LOW | 3.7 | A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file src/integrations/claude-code/oauth.ts of the component OAuth Callback. The … | Aug 28, 2026 |
| CVE-2026-81835 | MEDIUM | 5.5 | A security vulnerability has been detected in RooCodeInc Roo-Code up to 3.51.1. This affects the function fetch_instructions of the file malicious_mcp_server.py of the component MCP … | Aug 28, 2026 |
| CVE-2026-80179 | MEDIUM | 5.9 | A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed … | Aug 28, 2026 |
| CVE-2026-78239 | CRITICAL | 9.8 | Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. … | Aug 28, 2026 |
| CVE-2026-78037 | HIGH | 8.8 | Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands … | Aug 28, 2026 |
| CVE-2026-77977 | HIGH | 8.1 | Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive administrative actions when default credentials remain configured. An unauthenticated attacker on … | Aug 28, 2026 |
| CVE-2026-77358 | UNKNOWN | — | cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client frees the TLS session before closing the WebSocket that … | Aug 28, 2026 |
| CVE-2026-77341 | UNKNOWN | — | cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0, the chunked-response trailer output path writes trailer header names and values directly to the socket … | Aug 28, 2026 |
| CVE-2026-76945 | HIGH | 7.5 | The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An attacker may replay or manipulate authentication tokens to gain unauthorized access … | Aug 28, 2026 |
| CVE-2026-76943 | CRITICAL | 9.8 | Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. … | Aug 28, 2026 |
| CVE-2026-76940 | HIGH | 7.5 | The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout mechanisms. This could allow an attacker to perform automated … | Aug 28, 2026 |
| CVE-2026-76179 | CRITICAL | 9.8 | An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during … | Aug 28, 2026 |
| CVE-2026-76060 | HIGH | 8.8 | An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed … | Aug 28, 2026 |
| CVE-2026-75814 | HIGH | 8.8 | The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface. An unauthenticated remote attacker could persuade … | Aug 28, 2026 |
| CVE-2026-75813 | HIGH | 7.5 | Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access or modify sensitive device settings. This could result in full compromise … | Aug 28, 2026 |
| CVE-2026-75548 | MEDIUM | 5.4 | The affected Ebyte device web management interface does not restrict the interface from being rendered within an external frame. An unauthenticated remote attacker could use … | Aug 28, 2026 |
| CVE-2026-75419 | HIGH | 8.8 | go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/service/internal/data/data.go and app/app/service/internal/data/data.go returns a no-op authorization engine (noop.State{}), so the authz … | Aug 28, 2026 |
| CVE-2026-75418 | HIGH | 7.5 | A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.14 on Windows. An attacker with network access to the server can … | Aug 28, 2026 |
| CVE-2026-75417 | HIGH | 7.2 | A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within application/admin/controller/category.class.php, where the user-controlled parentid parameter is concatenated … | Aug 28, 2026 |
| CVE-2026-75339 | HIGH | 8.8 | The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload arbitrary files, and any anonymous attacker can download … | Aug 28, 2026 |
| CVE-2026-75337 | CRITICAL | 9.8 | The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-controlled path is concatenated to the preview root … | Aug 28, 2026 |