Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42775
Total
3467
Critical
12772
High
12580
Medium
CVE ID Severity Score Description Published
CVE-2026-81102 LOW 3.1 The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_server_dash.py constructed the server for its … Aug 27, 2026
CVE-2026-81101 MEDIUM 6.5 The configure command accepted any endpoint URL and stored it beside the user's access token. ConfigureCommand.execute in src/cli.ts persisted the value given to its endpoint … Aug 27, 2026
CVE-2026-81100 MEDIUM 6.8 tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the … Aug 27, 2026
CVE-2026-81099 MEDIUM 6.8 tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. mcp/src/httpServer.ts called the shared httpServerFactory helper and never set the … Aug 27, 2026
CVE-2026-81098 CRITICAL 9.1 The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path … Aug 27, 2026
CVE-2026-81097 HIGH 8.4 The execute_ruby tool is documented as a read-only Ruby sandbox and is enforced by a pattern denylist together with replacements for the process-spawning methods on … Aug 27, 2026
CVE-2026-81096 CRITICAL 10.0 ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in … Aug 27, 2026
CVE-2026-81095 MEDIUM 6.8 pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the … Aug 27, 2026
CVE-2026-81094 CRITICAL 9.1 The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts … Aug 27, 2026
CVE-2026-81093 HIGH 8.6 The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. The handler in src/tools/common/get_html_skeleton.ts validated the url argument with isValidHttpUrl from … Aug 27, 2026
CVE-2026-81092 MEDIUM 6.8 mcp-go accepted requests on its HTTP transports without checking the Host header. StreamableHTTPServer.ServeHTTP in server/streamable_http.go and SSEServer.ServeHTTP in server/sse.go served any request arriving over a … Aug 27, 2026
CVE-2026-81091 HIGH 8.6 The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names. mountMcpProxy in libraries/typescript/packages/inspector/src/server/proxy/mcp-proxy.ts read the target from the X-Target-URL header or … Aug 27, 2026
CVE-2026-80213 MEDIUM 4.0 An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length into a single octet without checking its … Aug 27, 2026
CVE-2026-80212 HIGH 7.5 An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::Resource.get_class, Resolv::DNS::Resource::Generic.create, and Resolv::DNS::SvcParam::Generic.create generate a new class for each unknown DNS resource … Aug 27, 2026
CVE-2026-80211 MEDIUM 5.9 FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_POST['password']) to add_user() and update_user_password(), admin/change_current_user_password.php does the same when a … Aug 27, 2026
CVE-2026-80210 MEDIUM 6.5 FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the _token hidden field in every form it renders, but … Aug 27, 2026
CVE-2026-80209 MEDIUM 4.3 The updateWorkspace handler in mods/identity/src/workspaces/createUpdateWorkspace.ts in Fonoster through 0.22.7 invokes the gRPC callback with PERMISSION_DENIED when createIsWorkspaceMember reports that the caller is not a member … Aug 27, 2026
CVE-2026-80208 HIGH 8.2 APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in InternalUserController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API … Aug 27, 2026
CVE-2026-80207 MEDIUM 5.3 APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key … Aug 27, 2026
CVE-2026-79988 UNKNOWN The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed … Aug 27, 2026
CVE-2026-79720 UNKNOWN Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse … Aug 27, 2026
CVE-2026-79719 UNKNOWN Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse … Aug 27, 2026
CVE-2026-79718 UNKNOWN Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse … Aug 27, 2026
CVE-2026-79653 UNKNOWN In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage with config key enable.attachment.store.to.file.system, the attacker … Aug 27, 2026
CVE-2026-78251 UNKNOWN DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file … Aug 27, 2026