Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49177
Total
3940
Critical
14579
High
14345
Medium
CVE ID Severity Score Description Published
CVE-2026-19355 HIGH 7.3 A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a … Aug 09, 2026
CVE-2026-19354 MEDIUM 6.3 A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown function of the file controllers/messages/message.go of the component IN … Aug 09, 2026
CVE-2026-19353 MEDIUM 5.0 A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component … Aug 09, 2026
CVE-2026-19352 LOW 3.1 A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component … Aug 09, 2026
CVE-2026-19351 HIGH 7.3 A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter … Aug 09, 2026
CVE-2026-19350 MEDIUM 6.3 A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. … Aug 09, 2026
CVE-2026-19348 CRITICAL 9.8 A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation … Aug 09, 2026
CVE-2026-19347 MEDIUM 6.3 A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php. Such manipulation of the argument … Aug 09, 2026
CVE-2026-19346 HIGH 8.8 A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes … Aug 09, 2026
CVE-2026-19345 MEDIUM 6.5 A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val … Aug 09, 2026
CVE-2026-19344 HIGH 7.3 A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/comment_count_user.php. The manipulation … Aug 09, 2026
CVE-2026-19343 HIGH 7.3 A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a … Aug 09, 2026
CVE-2026-19342 HIGH 7.3 A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a … Aug 09, 2026
CVE-2026-19341 HIGH 8.8 A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of … Aug 09, 2026
CVE-2026-19340 MEDIUM 6.3 A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js of the component Webhooks API. … Aug 09, 2026
CVE-2026-19339 MEDIUM 6.3 A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation … Aug 09, 2026
CVE-2026-19338 MEDIUM 5.3 A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component generate_mermaid_markdown. … Aug 09, 2026
CVE-2026-19337 MEDIUM 5.3 A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a … Aug 09, 2026
CVE-2026-19336 MEDIUM 5.3 A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the … Aug 09, 2026
CVE-2026-19335 MEDIUM 5.3 A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the file src/svc/utils/config.ts. Such manipulation of the … Aug 09, 2026
CVE-2026-18603 UNKNOWN The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding the contents of … Aug 09, 2026
CVE-2026-18473 UNKNOWN The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to … Aug 09, 2026
CVE-2026-18465 UNKNOWN The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to … Aug 09, 2026
CVE-2026-18464 UNKNOWN The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to … Aug 09, 2026
CVE-2026-18357 UNKNOWN The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated … Aug 09, 2026