Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49177
Total
3940
Critical
14579
High
14345
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-71947 | CRITICAL | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can … | Aug 08, 2026 |
| CVE-2026-71946 | CRITICAL | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can … | Aug 08, 2026 |
| CVE-2026-71945 | CRITICAL | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can … | Aug 08, 2026 |
| CVE-2026-71944 | CRITICAL | 9.8 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can … | Aug 08, 2026 |
| CVE-2026-67620 | HIGH | 7.7 | Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata … | Aug 08, 2026 |
| CVE-2026-42170 | HIGH | 7.8 | A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but … | Aug 08, 2026 |
| CVE-2026-19288 | MEDIUM | 5.3 | A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affects an unknown part of the file packages/mcp-server/src/tools/importRiveFile.ts of the component importRiveFile Flow. … | Aug 08, 2026 |
| CVE-2026-19287 | MEDIUM | 5.3 | A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the component HistoryService. This manipulation of the … | Aug 08, 2026 |
| CVE-2026-19285 | MEDIUM | 5.3 | A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vulnerability is the function JsonMemoryStorage.createDomain/JsonMemoryStorage.getMemories/JsonMemoryStorage.saveMemories of the file src/tools/memoryTools.ts. The manipulation results … | Aug 08, 2026 |
| CVE-2026-19284 | MEDIUM | 5.3 | A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. Affected is the function createProject of the file src/core/projects.ts of the component Projects … | Aug 08, 2026 |
| CVE-2026-19282 | MEDIUM | 5.3 | A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the function auto.capture of the file src/autolearn/GitHooksManager.ts of the component llm_memory_mcp. Executing … | Aug 08, 2026 |
| CVE-2026-19281 | MEDIUM | 5.3 | A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generateChart of the file src/tools/generateAssets.ts of the component generateAssets Tool. Performing … | Aug 08, 2026 |
| CVE-2026-19279 | MEDIUM | 5.3 | A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0. The impacted element is the function load_pdf of the file src/index.ts. Such manipulation of the argument pdfPath/sessionId … | Aug 08, 2026 |
| CVE-2026-68082 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: libceph: fix two unsafe bare decodes in decode_lockers() decode_lockers() in cls_lock_client.c contains two bare decode … | Aug 08, 2026 |
| CVE-2026-68081 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state Put … | Aug 08, 2026 |
| CVE-2026-19270 | MEDIUM | 5.3 | A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_journey/analyze_journey/usage_stats of the file src/journey/JourneyStorage.ts of the component Journey/Usage. … | Aug 08, 2026 |
| CVE-2026-19268 | MEDIUM | 6.3 | A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230. This impacts the function getUsageByDateRange of the file src/services/claude-usage.ts of the component Claude Usage Range … | Aug 08, 2026 |
| CVE-2026-19266 | MEDIUM | 5.5 | A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component review-git-diff Endpoint. Executing … | Aug 08, 2026 |
| CVE-2026-19263 | HIGH | 7.3 | A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted element is an unknown function of the file mcp-bridge.js of the component Servers … | Aug 08, 2026 |
| CVE-2026-19259 | MEDIUM | 5.3 | A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping_varAccessSpecToObjectReference of the file src/iec61850/common/iec61850_common.c of the … | Aug 08, 2026 |
| CVE-2026-16955 | UNKNOWN | — | The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, … | Aug 08, 2026 |
| CVE-2026-16953 | UNKNOWN | — | The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a … | Aug 08, 2026 |
| CVE-2026-16948 | UNKNOWN | — | The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them … | Aug 08, 2026 |
| CVE-2026-16608 | UNKNOWN | — | The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it … | Aug 08, 2026 |
| CVE-2026-16595 | UNKNOWN | — | The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated … | Aug 08, 2026 |