Search
289 CVEs · published 2026-07-15 to 2026-07-15
CVEs (289)
Showing 26–50 of 289
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-30623 | CRITICAL | 9.8 | 2026-07-15 | LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configur… | |
| CVE-2026-30618 | CRITICAL | 9.8 | 2026-07-15 | xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the publicly… | |
| CVE-2026-26719 | MEDIUM | 6.1 | 2026-07-15 | Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request containing a malicious script | |
| CVE-2026-26718 | CRITICAL | 9.1 | 2026-07-15 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue … | |
| CVE-2026-15921 | LOW | 3.1 | 2026-07-15 | Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.1 through 0.40.5, `nvm ls-remote` (and other command… | |
| CVE-2025-65720 | CRITICAL | 9.8 | 2026-07-15 | An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page. | |
| CVE-2026-62361 | MEDIUM | Patched | 5.5 | 2026-07-15 | listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscribers/export endpoint injects the user-controlled quer… |
| CVE-2026-62312 | HIGH | Patched | 8.8 | 2026-07-15 | 9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitrary code execution on the host operating system by co… |
| CVE-2026-59950 | HIGH | Patched | 8.1 | 2026-07-15 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_serve… |
| CVE-2026-56679 | NONE | Patched | — | 2026-07-15 | 9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body to persistent settings without a field whitelist, all… |
| CVE-2026-56678 | MEDIUM | Patched | 6.4 | 2026-07-15 | 9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key builds an upstream URL using a user-controlled regi… |
| CVE-2026-55608 | MEDIUM | Patched | 4.2 | 2026-07-15 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.57.4, multi-tenant HTTP mode with ENABLE_MULTI… |
| CVE-2026-55410 | MEDIUM | Patched | 6.7 | 2026-07-15 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.1.19, NocoBase @nocobase/plugin-backups restored… |
| CVE-2026-55399 | MEDIUM | Patched | 4.3 | 2026-07-15 | CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create… |
| CVE-2026-55398 | LOW | Patched | 3.7 | 2026-07-15 | CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with intimate knowledge of and total control over the tun… |
| CVE-2026-54052 | CRITICAL | Patched | 9.9 | 2026-07-15 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled … |
| CVE-2026-52888 | MEDIUM | Patched | 6.8 | 2026-07-15 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @nocobase/plugin-collection… |
| CVE-2026-52887 | CRITICAL | Patched | 10.0 | 2026-07-15 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-… |
| CVE-2026-51380 | CRITICAL | 9.8 | 2026-07-15 | Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code via … | |
| CVE-2026-49353 | HIGH | 7.5 | 2026-07-15 | 9Router is an AI router & token saver. In 0.4.45 and earlier, 9Router's src/dashboardGuard.js local-only access gate used Host and Origin headers in isLocalRequest() to pro… | |
| CVE-2026-49352 | CRITICAL | Patched | 9.8 | 2026-07-15 | 9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/r… |
| CVE-2026-46339 | CRITICAL | Patched | 10.0 | 2026-07-15 | 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated… |
| CVE-2026-38753 | MEDIUM | 4.9 | 2026-07-15 | A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. | |
| CVE-2026-33684 | MEDIUM | Patched | 5.3 | 2026-07-15 | WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in signUp API, which allows an… |
| CVE-2026-33445 | MEDIUM | Patched | 5.9 | 2026-07-15 | CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel proto… |