Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49177
Total
3940
Critical
14579
High
14345
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19376 | HIGH | 7.3 | A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The … | Aug 10, 2026 |
| CVE-2026-19375 | MEDIUM | 6.3 | A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_article of the file news_scraper_mcp/server.py. The manipulation of the argument url results … | Aug 10, 2026 |
| CVE-2026-19374 | HIGH | 7.3 | A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy … | Aug 09, 2026 |
| CVE-2026-19373 | MEDIUM | 5.3 | A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfigSchema. … | Aug 09, 2026 |
| CVE-2026-19372 | MEDIUM | 5.3 | A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSync of the file src/index.ts of the component … | Aug 09, 2026 |
| CVE-2026-19371 | MEDIUM | 5.3 | A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the component comfy_upload_image. Such manipulation of the … | Aug 09, 2026 |
| CVE-2026-12372 | LOW | 3.7 | A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting … | Aug 09, 2026 |
| CVE-2026-19370 | MEDIUM | 5.3 | A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component geminithinking. This manipulation of the … | Aug 09, 2026 |
| CVE-2026-19369 | MEDIUM | 5.3 | A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the … | Aug 09, 2026 |
| CVE-2026-19368 | LOW | 3.3 | A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component gemini_search/gemini_reason/gemini_process/gemini_analyze. The … | Aug 09, 2026 |
| CVE-2026-19367 | MEDIUM | 6.3 | A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality of the file src/tools/rangeConfig.ts of the component read_range_config. … | Aug 09, 2026 |
| CVE-2026-70395 | UNKNOWN | — | Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot … | Aug 09, 2026 |
| CVE-2026-19366 | MEDIUM | 5.3 | A flaw has been found in NocteDefensor LudusMCP up to 1.0.24. Affected is an unknown function of the file src/tools/insertCredsRangeConfig.ts of the component insert_creds_range_config. Executing … | Aug 09, 2026 |
| CVE-2026-19365 | MEDIUM | 5.3 | A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the file src/index.ts of the component upscale_images. Such manipulation … | Aug 09, 2026 |
| CVE-2026-69659 | UNKNOWN | — | Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions … | Aug 09, 2026 |
| CVE-2026-19364 | MEDIUM | 6.3 | A vulnerability was determined in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /viewdoctorconsultancycharge.php. This manipulation of the … | Aug 09, 2026 |
| CVE-2026-19363 | MEDIUM | 5.3 | A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs of the component Lambda Authorizer. The … | Aug 09, 2026 |
| CVE-2026-19362 | MEDIUM | 5.3 | A vulnerability has been found in lmammino oidc-authorizer 0.4.0. This issue affects the function parse_token_from_header of the file src/parse_token_from_header.rs of the component Authorization Header Parsing. … | Aug 09, 2026 |
| CVE-2026-19361 | LOW | 3.7 | A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a … | Aug 09, 2026 |
| CVE-2026-15534 | UNKNOWN | — | Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear … | Aug 09, 2026 |
| CVE-2026-19360 | MEDIUM | 4.7 | A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a manipulation results … | Aug 09, 2026 |
| CVE-2026-19359 | MEDIUM | 4.7 | A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function … | Aug 09, 2026 |
| CVE-2026-19358 | MEDIUM | 6.3 | A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation causes improper access controls. … | Aug 09, 2026 |
| CVE-2026-19357 | MEDIUM | 5.3 | A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy. … | Aug 09, 2026 |
| CVE-2026-19356 | MEDIUM | 5.3 | A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation … | Aug 09, 2026 |