6.4

CVSS3.1

CVE-2026-6551 - Timeline Blocks for Gutenberg <= 1.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting …

The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute of the timeline-blocks/tb-timeline-blocks block in all versions up to, and including, 1.1.10 due to insufficient input sanitization and output escaping on user supplied a…

πŸ“… Published: April 28, 2026, 4:28 a.m. πŸ”„ Last Modified: April 28, 2026, 4:28 a.m.

6.9

CVSS4.0

CVE-2026-7224 - SourceCodester Pizzafy Ecommerce System ajax.php delete_cart sql injection

A security flaw has been discovered in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function delete_cart of the file /admin/ajax.php?action=delete_cart. Performing a manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been…

πŸ“… Published: April 28, 2026, 4:15 a.m. πŸ”„ Last Modified: April 28, 2026, 4:15 a.m.

6.9

CVSS4.0

CVE-2026-7223 - BigSweetPotatoStudio HyperChat AI Proxy Middleware aiProxyMiddleware.mts fetch server-side request …

A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. Affected by this issue is the function fetch of the file packages/core/src/http/aiProxyMiddleware.mts of the component AI Proxy Middleware. Such manipulation of the argument baseurl leads to server-side request f…

πŸ“… Published: April 28, 2026, 4 a.m. πŸ”„ Last Modified: April 28, 2026, 4 a.m.

5.1

CVSS4.0

CVE-2026-7222 - code-projects Coaching Management System Complaint Form complaint.php cross site scripting

A vulnerability was determined in code-projects Coaching Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /cims/modules/student/complaint.php of the component Complaint Form Page. This manipulation of the argument Complaint causes cross site scripting. T…

πŸ“… Published: April 28, 2026, 3:45 a.m. πŸ”„ Last Modified: April 28, 2026, 3:45 a.m.

6.9

CVSS4.0

CVE-2026-7221 - TencentCloudBase CloudBase-MCP open-url API Endpoint interactive-server.ts openUrl server-side requ…

A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affected is the function openUrl of the file mcp/src/interactive-server.ts of the component open-url API Endpoint. The manipulation of the argument req.body.url results in server-side request forgery. It is possible to launch…

πŸ“… Published: April 28, 2026, 3:30 a.m. πŸ”„ Last Modified: April 28, 2026, 3:30 a.m.

6.9

CVSS4.0

CVE-2026-7220 - jackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injection

A vulnerability has been found in jackwrichards FastlyMCP up to 6f3d0b0e654fc51076badc7fa16c03c461f95620. This impacts an unknown function of the file fastly-mcp.mjs of the component fastly_cli Tool. The manipulation of the argument command leads to os command injection. It is possible to initiate …

πŸ“… Published: April 28, 2026, 3:15 a.m. πŸ”„ Last Modified: April 28, 2026, 3:15 a.m.

8.6

CVSS4.0

CVE-2026-7219 - Totolink N300RT formIpQoS buffer overflow

A flaw has been found in Totolink N300RT 3.4.0-B20250430. This affects an unknown function of the file /boafrm/formIpQoS. Executing a manipulation of the argument entry_name can lead to buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.

πŸ“… Published: April 28, 2026, 3 a.m. πŸ”„ Last Modified: April 28, 2026, 3 a.m.

8.6

CVSS4.0

CVE-2026-7218 - Totolink N300RT libapmib.so formWsc is_cmd_string_valid buffer overflow

A vulnerability was detected in Totolink N300RT 3.4.0-B20250430. The impacted element is the function is_cmd_string_valid of the file /boafrm/formWsc of the component libapmib.so. Performing a manipulation of the argument localPin results in buffer overflow. The attack is possible to be carried out…

πŸ“… Published: April 28, 2026, 2:45 a.m. πŸ”„ Last Modified: April 28, 2026, 2:45 a.m.

6.9

CVSS4.0

CVE-2026-7217 - Deepractice PromptX Document File index.ts read_pdf absolute path traversal

A security vulnerability has been detected in Deepractice PromptX up to 2.4.0. The affected element is the function read_docx/read_xlsx/read_pptx/list_xlsx_sheets/read_pdf of the file packages/mcp-office/src/index.ts of the component Document File Handler. Such manipulation of the argument path lea…

πŸ“… Published: April 28, 2026, 2:30 a.m. πŸ”„ Last Modified: April 28, 2026, 2:30 a.m.

6.9

CVSS4.0

CVE-2026-7216 - donchelo processing-claude-mcp-bridge create_sketch Tool processing_server.py path traversal

A weakness has been identified in donchelo processing-claude-mcp-bridge up to e017b20a4b592a45531a6392f494007f04e661bd. Impacted is an unknown function of the file processing_server.py of the component create_sketch Tool. This manipulation of the argument sketch_name causes path traversal. Remote e…

πŸ“… Published: April 28, 2026, 2:15 a.m. πŸ”„ Last Modified: April 28, 2026, 2:15 a.m.
Total resulsts: 347741
Page 87 of 34,775
Β« previous page Β» next page
Filters