Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,682 CVEs · Medium severity

CVEs (3,682, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 3,682 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-19323 MEDIUM 5.3 2026-08-09 A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function generateProjec…
CVE-2026-19325 MEDIUM 5.3 2026-08-09 A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function r…
CVE-2026-19326 MEDIUM 4.4 2026-08-09 A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the file ai-doctor-server/src/filemanagement/filemanagem…
CVE-2026-19327 MEDIUM 5.3 2026-08-09 A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession of the file src/services/enricher.ts. Executing a ma…
CVE-2026-19328 MEDIUM 5.3 2026-08-09 A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file sr…
CVE-2026-19329 MEDIUM 5.3 2026-08-09 A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element is an unknown function of the file src/codex-process-…
CVE-2026-19330 MEDIUM 5.3 2026-08-09 A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_system_json/create_library to get_system_json/switch_…
CVE-2026-19331 MEDIUM 5.3 2026-08-09 A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanvas of the file src/services/CanvasService.ts. Such ma…
CVE-2026-19332 MEDIUM 5.3 2026-08-09 A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform.…
CVE-2026-19333 MEDIUM 5.3 2026-08-09 A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by this issue is some unk…
CVE-2026-19334 MEDIUM 5.3 2026-08-09 A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. This manipulation of th…
CVE-2026-16032 MEDIUM Patched 6.1 2026-08-09 The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before storing it and rendering it …
CVE-2026-16965 MEDIUM Patched 4.3 2026-08-09 The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber …
CVE-2026-16992 MEDIUM Patched 6.5 2026-08-09 The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publi…
CVE-2026-17014 MEDIUM Patched 5.3 2026-08-09 The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticat…
CVE-2026-18037 MEDIUM Patched 6.5 2026-08-09 The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and that route additionall…
CVE-2026-18465 MEDIUM Patched 6.5 2026-08-09 The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not…
CVE-2026-18603 MEDIUM Patched 6.5 2026-08-09 The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding the contents of a previ…
CVE-2026-19335 MEDIUM 5.3 2026-08-09 A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the file src/svc/utils/config…
CVE-2026-19336 MEDIUM 5.3 2026-08-09 A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Perfo…
CVE-2026-19337 MEDIUM 5.3 2026-08-09 A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a …
CVE-2026-19338 MEDIUM 5.3 2026-08-09 A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index…
CVE-2026-19339 MEDIUM 6.3 2026-08-09 A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src…
CVE-2026-19340 MEDIUM 6.3 2026-08-09 A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js of the component Webhoo…
CVE-2026-19345 MEDIUM 6.5 2026-08-09 A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument…