Total CVEs

125,793

Critical Severity

2,272

High Severity

7,857

Last 7 Days

1,137
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 41 - 60 of 7,557 CVEs
CVE-2026-7417 HIGH - 7.3

A vulnerability was found in Algovate xhs-mcp 0.8.11. This affects the function xhs_publish_content of the file src/server/mcp.server.ts of the component MCP Interface. Performing a manipulation of the argument media_paths results in server-side request forgery. The attack may be initiated remotely....

Published: Apr 29, 2026
Source: NVD
CVE-2026-7416 HIGH - 7.3

A vulnerability was found in PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests of the file src/index.ts of the component MCP Interface. The manipulation of the argument Request results in os command injection. The attack may be launched remotely. The exploit ...

Published: Apr 29, 2026
Source: NVD
CVE-2026-41670 HIGH - 8.2

Admidio Sends SAML Response to Unvalidated Assertion Consumer Service URL from AuthnRequest

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41669 HIGH - 8.2

Admidio Ignores SAML Signature Validation Result, Processes Forged AuthnRequests and LogoutRequests

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41660 HIGH - 7.1

Admidio has Inverted 2FA Reset Authorization Check that Lets Group Leaders Strip Admin TOTP

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42235 HIGH - 8.2

n8n Vulnerable to XSS via MCP OAuth client

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42226 HIGH - 8.5

n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42234 HIGH - 7.5

n8n has a Python Task Runner Sandbox Escape Vulnerability

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub

n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-7404 HIGH - 7.3

A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.py. This manipulation of the argument detail causes relative path traversal. It is possible to initiat...

Published: Apr 29, 2026
Source: NVD
CVE-2025-50328 HIGH - 7.3

A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of the Web (MotW) protections. When an archive is downloaded from the internet and extracted using B1 Free Archiver, the software fails to propagate the 'Zone.Identifier' alte...

Published: Apr 29, 2026
Source: NVD
CVE-2026-42224 HIGH - 7.7

ipl/web is vulnerable to reflected XSS by malformed search requests

Vendor: composer
Product: ipl/web
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41643 HIGH - 7.5

GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE

Vendor: go
Product: github.com/osrg/gobgp/v4
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41642 HIGH - 7.5

GoBGP has Remote Denial of Service (Panic) via Malformed Well-known Path Attribute

Vendor: go
Product: github.com/osrg/gobgp/v4
Published: Apr 29, 2026
Source: GitHub

CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: Apr 29, 2026
Source: GitHub
CVE-2026-40902 HIGH - 7.5

PhpSpreadsheet has CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 29, 2026
Source: GitHub
CVE-2026-40863 HIGH - 7.5

PhpSpreadsheet has CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 29, 2026
Source: GitHub

PhpSpreadsheet has SSRF/RCE in IOFactory::load when $filename is user controlled

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 29, 2026
Source: GitHub
CVE-2026-7426 HIGH - 8.1

Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by sending a crafted Router Advertisement with a prefix length value exceeding the maximum valid length...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7400 HIGH - 7.3

A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is_path_allowed of the file server.py of the component read_file_tool/write_file_tool. Such manipulation leads to path traversal. The attack can be launched remotely. The exploit has...

Published: Apr 29, 2026
Source: NVD