Total CVEs

142,250

Critical Severity

3,947

High Severity

14,209

Last 7 Days

1,911
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 16,581 - 16,600 of 38,655 CVEs
CVE-2026-7445 MEDIUM - 6.3

A security vulnerability has been detected in ZachHandley ZMCPTools up to 0.2.2. Affected by this issue is some unknown functionality of the file src/managers/ResourceManager.ts of the component MCP Log Resource Handler. The manipulation of the argument dirname leads to path traversal. Remote exploi...

Published: Apr 30, 2026
Source: NVD
CVE-2026-7443 HIGH - 7.3

A weakness has been identified in BurtTheCoder mcp-dnstwist up to 1.0.4. Affected by this vulnerability is the function fuzz_domain of the file src/index.ts of the component MCP Interface. Executing a manipulation of the argument Request can lead to os command injection. The attack may be launched r...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7420 HIGH - 8.8

A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file route/goform/ConfigAdvideo. The manipulation of the argument Profile results in buffer overflow. The attack can be executed remotely. The exploit has been released to the pu...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7419 HIGH - 8.8

A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of the file route/goform/formTaskEdit_ap. The manipulation of the argument Profile leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly ava...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7381 CRITICAL - 9.1

Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the variation setting (sendfile type) to be set by the client via the X-Sendfile-Type header, if it is not considered in the middleware constructor or the Pl...

Published: Apr 29, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Apr 29, 2026
Source: NVD
CVE-2026-42031 HIGH - 9.8

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to inject SQL in order to gain access to private resources and PostgreSQL system information This vulnerability is fixed...

Vendor: pip
Product: ckan
Published: Apr 29, 2026
Source: GitHub

Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.91.1, the BetaLocalFilesystemMemoryTool in the Anthropic TypeScript SDK created memory files and directories using the Node.js default modes (0o...

Vendor: npm
Product: @anthropic-ai/sdk
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42353 HIGH - 8.2

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware passes the user-controlled lng and ns values from getResourcesHandler directly into i18next.services.backendConnector.load(languag...

Vendor: npm
Product: i18next-http-middleware
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42352 HIGH - 8.6

pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, OGC API process execution requests can use the subscriber object to requests to internal HTTP services. This issue has been patched in version 0.23.3.

Vendor: pip
Product: pygeoapi
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42351 HIGH - 7.5

pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, a raw string path concatenation vulnerability in pygeoapi's STAC FileSystemProvider plugin can allow for requests to STAC collection based collections to expose directorie...

Vendor: pip
Product: pygeoapi
Published: Apr 29, 2026
Source: GitHub
CVE-2026-7418 HIGH - 8.8

A vulnerability was determined in UTT HiPER 1250GW up to 3.2.7-210907-180535. This vulnerability affects the function strcpy of the file route/goform/NTP. Executing a manipulation of the argument Profile can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly ...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7417 HIGH - 7.3

A vulnerability was found in Algovate xhs-mcp 0.8.11. This affects the function xhs_publish_content of the file src/server/mcp.server.ts of the component MCP Interface. Performing a manipulation of the argument media_paths results in server-side request forgery. The attack may be initiated remotely....

Published: Apr 29, 2026
Source: NVD
CVE-2026-7416 HIGH - 7.3

A vulnerability was found in PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests of the file src/index.ts of the component MCP Interface. The manipulation of the argument Request results in os command injection. The attack may be launched remotely. The exploit ...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7410 MEDIUM - 6.3

A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to ...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7409 MEDIUM - 4.7

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.

Published: Apr 29, 2026
Source: NVD
CVE-2026-41671 MEDIUM - 6.8

Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modules/sso/index.php/oidc/introspect) always returns {"active": true} for every request, regardless of whether a valid token is provided, whether the token is expired, revok...

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41670 HIGH - 8.2

Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO module uses the AssertionConsumerServiceURL value directly from incoming SAML AuthnRequest messages as the destination for the SAML response, without validating it against th...

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41669 HIGH - 8.2

Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implementation discards the return value of its validateSignature() method at both call sites (handleSSORequest() line 418 and handleSLORequest() line 613). The method returns error strings...

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub

Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio's preferences module (database backup, test email, htaccess generation) fire via GET requests with no CSRF token validation. Because SameSite=Lax cookies travel with top-leve...

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub