6.9

CVSS4.0

CVE-2026-7212 - edvardlindelof notes-mcp notes_mcp.py path traversal

A security vulnerability has been detected in edvardlindelof notes-mcp up to 0.1.4. This affects an unknown function of the file notes_mcp.py. The manipulation of the argument root_dir/path leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed pu…

πŸ“… Published: April 28, 2026, 1:15 a.m. πŸ”„ Last Modified: April 29, 2026, 2:13 p.m.

6.9

CVSS4.0

CVE-2026-7211 - dvladimirov MCP Git Search API mcp_server.py GitSearchRequest command injection

A weakness has been identified in dvladimirov MCP up to 0.1.0. The impacted element is the function GitSearchRequest of the file mcp_server.py of the component Git Search API. Executing a manipulation of the argument repo_url/pattern can lead to command injection. The attack can be executed remotel…

πŸ“… Published: April 28, 2026, 1 a.m. πŸ”„ Last Modified: April 28, 2026, 12:59 p.m.

6.9

CVSS4.0

CVE-2026-7206 - dubydu sqlite-mcp entry.py extract_to_json sql injection

A security flaw has been discovered in dubydu sqlite-mcp up to 0.1.0. The affected element is the function extract_to_json of the file src/entry.py. Performing a manipulation of the argument output_filename results in sql injection. Remote exploitation of the attack is possible. The exploit has bee…

πŸ“… Published: April 28, 2026, 12:45 a.m. πŸ”„ Last Modified: April 28, 2026, 2:35 p.m.

6.9

CVSS4.0

CVE-2026-7205 - duartium papers-mcp-server main.py search_papers path traversal

A vulnerability was identified in duartium papers-mcp-server 9ceb3812a6458ba7922ca24a7406f8807bc55598. Impacted is the function search_papers of the file src/main.py. Such manipulation of the argument topic leads to path traversal. The attack may be launched remotely. The exploit is publicly availa…

πŸ“… Published: April 28, 2026, 12:30 a.m. πŸ”„ Last Modified: April 28, 2026, 9:16 a.m.

9.3

CVSS4.0

CVE-2026-7204 - Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injection

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument enable causes os command injection. The attack may be initiated remotely. The exp…

πŸ“… Published: April 28, 2026, 12:15 a.m. πŸ”„ Last Modified: April 28, 2026, 12:39 p.m.

9.3

CVSS4.0

CVE-2026-7203 - Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injection

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable results in os command injection. The attack can be launched remotely. T…

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 2:01 p.m.

6.5

CVSS3.1

CVE-2026-41525 - Dolphin Flatpak Confinement Bypass via FileManager1 Path Spoofing

KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of the FileManager1 protocol allows the path given to be any type of file, including scripts or executa…

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 1:40 p.m.

7.5

CVSS3.1

CVE-2025-67223 - Unrestricted Access to Sensitive Files via Predictable Log Names in Aranda File Server

The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls…

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 10:11 a.m.

8.2

CVSS3.1

CVE-2026-38651 -

Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attacker can forge a JWT signed with any arbitrary key and use it to impersonate any host in the network, …

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 2:30 a.m.

6.1

CVSS3.1

CVE-2026-37750 -

A reflected Cross-Site Scripting (XSS) vulnerability in School Management System by mahmoudai1 allows unauthenticated remote attackers to execute arbitrary JavaScript in victim's browsers via the unsanitized type parameter in register.php.

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 30, 2026, 4:15 a.m.
Total resulsts: 349182
Page 229 of 34,919
Β« previous page Β» next page
Filters