5.3

CVSS4.0

CVE-2026-7600 - ArtMin96 yii2-mcp-server MCP index.ts yii_execute_command os command injection

A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This impacts the function yii_command_help/yii_execute_command of the file src/index.ts of the component MCP Interface. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exploit has been publi…

πŸ“… Published: May 2, 2026, 12:15 a.m. πŸ”„ Last Modified: May 4, 2026, 5:10 p.m.

0.0

CVE-2026-43058 - media: vidtv: fix pass-by-value structs causing MSAN warnings

In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix pass-by-value structs causing MSAN warnings vidtv_ts_null_write_into() and vidtv_ts_pcr_write_into() take their argument structs by value, causing MSAN to report uninit-value warnings. While only vidtv_ts_null_w…

πŸ“… Published: May 2, 2026, midnight πŸ”„ Last Modified: May 4, 2026, 2:30 p.m.

5.3

CVSS4.0

CVE-2026-7599 - Dayoooun hwpx-mcp MCP index.ts export_to_html path traversal

A vulnerability was detected in Dayoooun hwpx-mcp 0.2.0. This affects the function save_document/export_to_text/export_to_html of the file mcp-server/src/index.ts of the component MCP Interface. Performing a manipulation of the argument output_path results in path traversal. Remote exploitation of …

πŸ“… Published: May 1, 2026, 9:45 p.m. πŸ”„ Last Modified: May 4, 2026, 5:52 p.m.

6.9

CVSS4.0

CVE-2026-7598 - libssh2 userauth.c userauth_password integer overflow

A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is…

πŸ“… Published: May 1, 2026, 9:30 p.m. πŸ”„ Last Modified: May 4, 2026, 2:16 p.m.

5.3

CVSS4.0

CVE-2026-7597 - mem0ai mem0 faiss.py pickle.dump deserialization

A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public and could be used.…

πŸ“… Published: May 1, 2026, 9:15 p.m. πŸ”„ Last Modified: May 4, 2026, 4:07 p.m.

5.3

CVSS4.0

CVE-2026-7596 - nextlevelbuilder ui-ux-pro-max-skill Slide Generator generate-slide.py data.get cross site scripting

A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the function data.get of the file .claude/skills/design-system/scripts/generate-slide.py of the component Slide Generator. Such manipulation leads to cross site scripting. The attack may be…

πŸ“… Published: May 1, 2026, 9 p.m. πŸ”„ Last Modified: May 4, 2026, 4:07 p.m.

5.3

CVSS4.0

CVE-2026-7595 - nextlevelbuilder ui-ux-pro-max-skill Tailwind Config Generator tailwind_config_gen.py _format_plugi…

A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the function _format_plugins of the file .claude/skills/ui-styling/scripts/tailwind_config_gen.py of the component Tailwind Config Generator. This manipulation causes code injection. The att…

πŸ“… Published: May 1, 2026, 8:45 p.m. πŸ”„ Last Modified: May 4, 2026, 4:12 p.m.

6.3

CVSS4.0

CVE-2026-39805 - CL.CL HTTP request smuggling via duplicate Content-Length in bandit

Inconsistent Interpretation of HTTP Requests vulnerability in mtrudel bandit allows HTTP request smuggling via duplicate Content-Length headers. 'Elixir.Bandit.Headers':get_content_length/1 in lib/bandit/headers.ex uses List.keyfind/3, which returns only the first matching header. When a request c…

πŸ“… Published: May 1, 2026, 8:34 p.m. πŸ”„ Last Modified: May 2, 2026, 1:21 a.m.

8.2

CVSS4.0

CVE-2026-39804 - WebSocket permessage-deflate inflate has no output-size cap in bandit

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion when WebSocket permessage-deflate compression is enabled. 'Elixir.Bandit.WebSocket.PerMessageDeflate':inflate/2 in lib/bandit/websocket/permess…

πŸ“… Published: May 1, 2026, 8:34 p.m. πŸ”„ Last Modified: May 2, 2026, 1:19 a.m.

6.3

CVSS4.0

CVE-2026-39807 - Client-supplied URI scheme trusted without transport verification in bandit

Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-state spoofing on plaintext HTTP connections. 'Elixir.Bandit.Pipeline':determine_scheme/2 in lib/bandit/pipeline.ex returns the client-supplied URI scheme verbatim, ignoring the tra…

πŸ“… Published: May 1, 2026, 8:34 p.m. πŸ”„ Last Modified: May 2, 2026, 1:18 a.m.
Total resulsts: 349182
Page 155 of 34,919
Β« previous page Β» next page
Filters