6.9

CVSS4.0

CVE-2026-7216 - donchelo processing-claude-mcp-bridge create_sketch Tool processing_server.py path traversal

A weakness has been identified in donchelo processing-claude-mcp-bridge up to e017b20a4b592a45531a6392f494007f04e661bd. Impacted is an unknown function of the file processing_server.py of the component create_sketch Tool. This manipulation of the argument sketch_name causes path traversal. Remote e…

πŸ“… Published: April 28, 2026, 2:15 a.m. πŸ”„ Last Modified: April 28, 2026, 2:15 a.m.

7.2

CVSS3.1

CVE-2026-1460 -

A post-authentication command injection vulnerability in the β€œDomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected de…

πŸ“… Published: April 28, 2026, 2:06 a.m. πŸ”„ Last Modified: April 28, 2026, 2:06 a.m.

6.9

CVSS4.0

CVE-2026-7215 - egtai gmx-vmd-mcp VMD Launch mcp_server.py launch_vmd_gui_tool command injection

A security flaw has been discovered in egtai gmx-vmd-mcp up to 0.1.0. This issue affects the function launch_vmd_gui_tool of the file mcp_server.py of the component VMD Launch Handler. The manipulation of the argument structure_file/trajectory_file results in command injection. The attack may be la…

πŸ“… Published: April 28, 2026, 2 a.m. πŸ”„ Last Modified: April 28, 2026, 2 a.m.

6.8

CVSS3.1

CVE-2026-0711 -

A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device.

πŸ“… Published: April 28, 2026, 1:57 a.m. πŸ”„ Last Modified: April 28, 2026, 1:57 a.m.

6.9

CVSS4.0

CVE-2026-7214 - eghuzefa engineer-your-data server.py file_inf path traversal

A vulnerability was identified in eghuzefa engineer-your-data up to 0.1.3. This vulnerability affects the function read_file/write_file/list_files/file_inf of the file src/server.py. The manipulation of the argument WORKSPACE_PATH leads to path traversal. The attack may be initiated remotely. The e…

πŸ“… Published: April 28, 2026, 1:45 a.m. πŸ”„ Last Modified: April 28, 2026, 1:45 a.m.

6.9

CVSS4.0

CVE-2026-7213 - ef10007 MLOps_MCP save_file Tool fastmcp_server.py path traversal

A vulnerability was detected in ef10007 MLOps_MCP 1.0.0. This impacts an unknown function of the file fastmcp_server.py of the component save_file Tool. The manipulation of the argument filename/destination results in path traversal. The attack may be performed from remote. The exploit is now publi…

πŸ“… Published: April 28, 2026, 1:30 a.m. πŸ”„ Last Modified: April 28, 2026, 1:30 a.m.

6.9

CVSS4.0

CVE-2026-7212 - edvardlindelof notes-mcp notes_mcp.py path traversal

A security vulnerability has been detected in edvardlindelof notes-mcp up to 0.1.4. This affects an unknown function of the file notes_mcp.py. The manipulation of the argument root_dir/path leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed pu…

πŸ“… Published: April 28, 2026, 1:15 a.m. πŸ”„ Last Modified: April 28, 2026, 1:15 a.m.

6.9

CVSS4.0

CVE-2026-7211 - dvladimirov MCP Git Search API mcp_server.py GitSearchRequest command injection

A weakness has been identified in dvladimirov MCP up to 0.1.0. The impacted element is the function GitSearchRequest of the file mcp_server.py of the component Git Search API. Executing a manipulation of the argument repo_url/pattern can lead to command injection. The attack can be executed remotel…

πŸ“… Published: April 28, 2026, 1 a.m. πŸ”„ Last Modified: April 28, 2026, 1 a.m.

6.9

CVSS4.0

CVE-2026-7206 - dubydu sqlite-mcp entry.py extract_to_json sql injection

A security flaw has been discovered in dubydu sqlite-mcp up to 0.1.0. The affected element is the function extract_to_json of the file src/entry.py. Performing a manipulation of the argument output_filename results in sql injection. Remote exploitation of the attack is possible. The exploit has bee…

πŸ“… Published: April 28, 2026, 12:45 a.m. πŸ”„ Last Modified: April 28, 2026, 12:45 a.m.

6.9

CVSS4.0

CVE-2026-7205 - duartium papers-mcp-server main.py search_papers path traversal

A vulnerability was identified in duartium papers-mcp-server 9ceb3812a6458ba7922ca24a7406f8807bc55598. Impacted is the function search_papers of the file src/main.py. Such manipulation of the argument topic leads to path traversal. The attack may be launched remotely. The exploit is publicly availa…

πŸ“… Published: April 28, 2026, 12:30 a.m. πŸ”„ Last Modified: April 28, 2026, 12:30 a.m.
Total resulsts: 347742
Page 88 of 34,775
Β« previous page Β» next page
Filters