Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49177
Total
3940
Critical
14579
High
14345
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-18037 | UNKNOWN | — | The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and that … | Aug 09, 2026 |
| CVE-2026-18032 | UNKNOWN | — | The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the … | Aug 09, 2026 |
| CVE-2026-17044 | UNKNOWN | — | The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to … | Aug 09, 2026 |
| CVE-2026-17017 | UNKNOWN | — | The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX … | Aug 09, 2026 |
| CVE-2026-17014 | UNKNOWN | — | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, … | Aug 09, 2026 |
| CVE-2026-17011 | UNKNOWN | — | The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at … | Aug 09, 2026 |
| CVE-2026-16992 | UNKNOWN | — | The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route … | Aug 09, 2026 |
| CVE-2026-16988 | UNKNOWN | — | The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users … | Aug 09, 2026 |
| CVE-2026-16965 | UNKNOWN | — | The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such … | Aug 09, 2026 |
| CVE-2026-16957 | UNKNOWN | — | The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read … | Aug 09, 2026 |
| CVE-2026-16032 | UNKNOWN | — | The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before storing it and rendering it … | Aug 09, 2026 |
| CVE-2026-15038 | UNKNOWN | — | The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress … | Aug 09, 2026 |
| CVE-2026-19334 | MEDIUM | 5.3 | A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. This manipulation of the argument … | Aug 09, 2026 |
| CVE-2026-19333 | MEDIUM | 5.3 | A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by this issue is some unknown functionality of the component generate_types. The manipulation of the argument … | Aug 09, 2026 |
| CVE-2026-19332 | MEDIUM | 5.3 | A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of … | Aug 09, 2026 |
| CVE-2026-19331 | MEDIUM | 5.3 | A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanvas of the file src/services/CanvasService.ts. Such manipulation leads to path traversal. An attack … | Aug 09, 2026 |
| CVE-2026-19330 | MEDIUM | 5.3 | A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_system_json/create_library to get_system_json/switch_memory_library of the file src/index.ts. This manipulation causes path … | Aug 09, 2026 |
| CVE-2026-19329 | MEDIUM | 5.3 | A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element is an unknown function of the file src/codex-process-simple.ts of the component ask … | Aug 09, 2026 |
| CVE-2026-10595 | HIGH | 7.5 | A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling … | Aug 09, 2026 |
| CVE-2026-19328 | MEDIUM | 5.3 | A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file src/installer.ts. The manipulation of the argument workspacePath leads … | Aug 09, 2026 |
| CVE-2026-19327 | MEDIUM | 5.3 | A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession of the file src/services/enricher.ts. Executing a manipulation of the argument … | Aug 09, 2026 |
| CVE-2026-19326 | MEDIUM | 4.4 | A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the file ai-doctor-server/src/filemanagement/filemanagement.service.ts. Performing a manipulation of the argument imagePath … | Aug 09, 2026 |
| CVE-2026-19325 | MEDIUM | 5.3 | A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMemoryBankEntry of the file src/index.ts of the component read_memory_bank_file/append_memory_bank_entry. … | Aug 09, 2026 |
| CVE-2026-19324 | LOW | 3.3 | A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by this issue is the function fs.promises.readFile of the file src/server/callback-server.ts. This manipulation … | Aug 09, 2026 |
| CVE-2026-17510 | UNKNOWN | — | Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destination buffer for … | Aug 09, 2026 |