Search
12,997 CVEs
CVEs (12,997, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 12,997 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-19367 | MEDIUM | 6.3 | 2026-08-09 | A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality of the file src/tools/rangeConfig.ts of the comp… | |
| CVE-2026-19368 | LOW | 3.3 | 2026-08-09 | A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component ge… | |
| CVE-2026-19369 | MEDIUM | 5.3 | 2026-08-09 | A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. … | |
| CVE-2026-19370 | MEDIUM | 5.3 | 2026-08-09 | A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the compon… | |
| CVE-2026-12372 | LOW | 3.7 | 2026-08-09 | A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, in… | |
| CVE-2026-19371 | MEDIUM | 5.3 | 2026-08-09 | A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the component comfy_upload_i… | |
| CVE-2026-19372 | MEDIUM | 5.3 | 2026-08-09 | A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSync of the file src/inde… | |
| CVE-2026-19373 | MEDIUM | 5.3 | 2026-08-09 | A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component Ba… | |
| CVE-2026-19374 | HIGH | 7.3 | 2026-08-09 | A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy… | |
| CVE-2026-19375 | MEDIUM | 6.3 | 2026-08-10 | A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_article of the file news_scraper_mcp/server.py. The mani… | |
| CVE-2026-19376 | HIGH | 7.3 | 2026-08-10 | A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File … | |
| CVE-2026-19378 | MEDIUM | 4.3 | 2026-08-10 | A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php. The manipulation of the… | |
| CVE-2026-19379 | HIGH | 7.3 | 2026-08-10 | A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the … | |
| CVE-2026-19380 | LOW | 2.3 | 2026-08-10 | A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to… | |
| CVE-2026-19381 | HIGH | 7.8 | 2026-08-10 | A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the … | |
| CVE-2026-19382 | LOW | 2.3 | 2026-08-10 | A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a… | |
| CVE-2026-19383 | MEDIUM | 4.7 | 2026-08-10 | A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_exec of the file /app/saipackage/install/upload of the… | |
| CVE-2026-19384 | HIGH | 7.3 | 2026-08-10 | A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_a… | |
| CVE-2026-19387 | HIGH | 7.6 | 2026-08-10 | A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-b… | |
| CVE-2026-19389 | HIGH | 7.1 | 2026-08-10 | Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WM… | |
| CVE-2026-72522 | MEDIUM | Patched | 6.2 | 2026-08-10 | libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the … |
| CVE-2026-17519 | NONE | — | 2026-08-10 | Rejected reason: This is rejected. | |
| CVE-2026-12570 | MEDIUM | 5.5 | 2026-08-10 | A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model… | |
| CVE-2026-12971 | LOW | Patched | 2.2 | 2026-08-10 | The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the serv… |
| CVE-2026-13133 | NONE | — | 2026-08-10 | A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search… |