6.9

CVSS4.0

CVE-2026-7159 - douinc mkdocs-mcp-plugin server.py list_documents path traversal

A vulnerability was found in douinc mkdocs-mcp-plugin up to 0.4.1. This affects the function read_document/list_documents of the file server.py. Performing a manipulation of the argument docs_dir/file_path results in path traversal. The attack is possible to be carried out remotely. The exploit has…

πŸ“… Published: April 27, 2026, 9:15 p.m. πŸ”„ Last Modified: April 28, 2026, 9:16 a.m.

6.9

CVSS4.0

CVE-2026-7158 - dmitryglhf mcp-url-downloader server.py _validate_url_safe server-side request forgery

A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6. Affected by this issue is the function _validate_url_safe of the file src/mcp_url_downloader/server.py. Such manipulation of the argument url leads to server-side request forgery. The att…

πŸ“… Published: April 27, 2026, 9 p.m. πŸ”„ Last Modified: April 28, 2026, 3 p.m.

6

CVSS4.0

CVE-2026-3087 - shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

πŸ“… Published: April 27, 2026, 8:46 p.m. πŸ”„ Last Modified: April 29, 2026, 3:29 p.m.

6.9

CVSS4.0

CVE-2026-7157 - disler aider-mcp-server aider_ai_code server.py command injection

A flaw has been found in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc. Affected by this vulnerability is an unknown functionality of the file src/aider_mcp_server/server.py of the component aider_ai_code. This manipulation of the argument relative_editable_files causes com…

πŸ“… Published: April 27, 2026, 8:45 p.m. πŸ”„ Last Modified: April 29, 2026, 2:01 p.m.

9.3

CVSS4.0

CVE-2026-7156 - Totolink A8000RU CGI cstecgi.cgi CsteSystem os command injection

A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument HTTP results in os command injection. The attack may be launched remotely. The exploit is now pub…

πŸ“… Published: April 27, 2026, 8:30 p.m. πŸ”„ Last Modified: April 28, 2026, 2:10 p.m.

4.8

CVSS4.0

CVE-2026-5362 - Pimcore Platform v12.3.3 - Stored XSS in Document Editable Embed rendering

An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed editable and cause script execution when the published page is rendered. This issue affects pimcore: v12.3.3.

πŸ“… Published: April 27, 2026, 8:16 p.m. πŸ”„ Last Modified: April 27, 2026, 8:16 p.m.

9.3

CVSS4.0

CVE-2026-7155 - Totolink A8000RU CGI cstecgi.cgi setLoginPasswordCfg os command injection

A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setLoginPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument admpass leads to os command injection. The attack may be initiated remote…

πŸ“… Published: April 27, 2026, 8:15 p.m. πŸ”„ Last Modified: April 28, 2026, 8:24 p.m.

8.6

CVSS4.0

CVE-2026-7191 - Arbitrary Code Execution via Sandbox Bypass in the open source solution QnABot on AWS

Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may allow an authenticated administrator to execute arbitrary code within the fulfillment Lambda execution context by injecting a crafted conditional chaining expression via the Content …

πŸ“… Published: April 27, 2026, 8:08 p.m. πŸ”„ Last Modified: April 28, 2026, 2:36 p.m.

9.3

CVSS4.0

CVE-2026-7154 - Totolink A8000RU CGI cstecgi.cgi setAdvancedInfoShow os command injection

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setAdvancedInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument tty_server can lead to os command injection. The attack can be launched remot…

πŸ“… Published: April 27, 2026, 8 p.m. πŸ”„ Last Modified: April 28, 2026, 2:36 p.m.

9.3

CVSS4.0

CVE-2026-7153 - Totolink A8000RU CGI cstecgi.cgi setMiniuiHomeInfoShow os command injection

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setMiniuiHomeInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument sys_info results in os command injection. The attack can b…

πŸ“… Published: April 27, 2026, 7:45 p.m. πŸ”„ Last Modified: April 28, 2026, 12:49 p.m.
Total resulsts: 347814
Page 101 of 34,782
Β« previous page Β» next page
Filters