VulnSea

CWE-74

CVEs classified under CWE-74, newest first.

437 CVEsRSS

CVE-2026-19355High· 7.3
1mo ago

A vulnerability was determined in MingSoft MCMS up to 3.0.6

A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can l…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-19354Medium· 6.3
1mo ago

A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09

A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown function of the file controllers/messages/message.go of the component IN Clause Handler. Performing a manipula…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-19351High· 7.3
1mo ago

A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28

A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. …

▾ TwilightEPSS 0.53%via NVD
CVE-2026-19348Critical· 9.8
1mo ago

A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a

A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipul…

▾ MidnightEPSS 3.6%via NVD
CVE-2026-19347Medium· 6.3
1mo ago

A vulnerability was identified in itsourcecode Hospital Management System 1.0

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php. Such manipulation of the argument delid leads to sql injection. The attack can be laun…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-19346High· 8.8
1mo ago

A vulnerability was determined in Tenda CH22 1.0.0.1

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated…

▾ TwilightEPSS 2.7%via NVD
CVE-2026-19344High· 7.3
1mo ago

A vulnerability has been found in code-projects Task Management System 1.0

A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/comment_count_user.php. The manipulation of the argument task_id leads to sql injection. I…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-19343High· 7.3
1mo ago

A flaw has been found in code-projects Task Management System 1.0

A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a manipulation of the argument email/password can lead to sql inje…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-19334Medium· 5.3
1mo ago

A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9

A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. This manipulation of the argument name/modelfile/source/destination causes command injec…

▾ SunlitEPSS 1.1%via NVD
CVE-2026-19333Medium· 5.3
1mo ago

A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66

A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by this issue is some unknown functionality of the component generate_types. The manipulat…

▾ SunlitEPSS 1.1%via NVD
CVE-2026-19332Medium· 5.3
1mo ago

A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0

A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of the argument design_name/vcd_file leads to c…

▾ SunlitEPSS 1.1%via NVD
CVE-2026-19329Medium· 5.3
1mo ago

A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390

A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element is an unknown function of the file src/codex-process-simple.ts of the component ask MCP Tool. The manipulation of the …

▾ SunlitEPSS 1.1%via NVD
CVE-2026-19284Medium· 5.3
1mo ago

A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0

A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. Affected is the function createProject of the file src/core/projects.ts of the component Projects Endpoint. The manipulation leads to command injection. …

▾ SunlitEPSS 1.1%via NVD
CVE-2026-19282Medium· 5.3
1mo ago

A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0

A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the function auto.capture of the file src/autolearn/GitHooksManager.ts of the component llm_memory_mcp. Executing a …

▾ SunlitEPSS 1.1%via NVD
CVE-2026-19281Medium· 5.3
1mo ago

A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0

A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generateChart of the file src/tools/generateAssets.ts of the component generateAssets Tool. Performing a manipulation of the …

▾ SunlitEPSS 1.1%via NVD
CVE-2026-19279Medium· 5.3
1mo ago

A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0

A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0. The impacted element is the function load_pdf of the file src/index.ts. Such manipulation of the argument pdfPath/sessionId leads to command injection. The attack can only …

▾ SunlitEPSS 1.1%via NVD
CVE-2026-19268Medium· 6.3
1mo ago

A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230

A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230. This impacts the function getUsageByDateRange of the file src/services/claude-usage.ts of the component Claude Usage Range Endpoint…

▾ SunlitEPSS 1.8%via NVD
CVE-2026-19266Medium· 5.5
1mo ago

A vulnerability was determined in Kirachon context-engine up to 1.9.0

A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component review-git-diff Endpoint. Executing a manipulation of the argument arg…

▾ SunlitEPSS 3.9%via NVD
CVE-2026-19263High· 7.3
1mo ago

A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114

A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted element is an unknown function of the file mcp-bridge.js of the component Servers Endpoint. Performing a manipulation of …

▾ TwilightEPSS 2.1%via NVD
CVE-2026-48120High· 8.6
1mo ago

Kakoune is a code editor

Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening …

▾ TwilightEPSS 0.20%via NVD
GHSA-jm78-9fvv-mhgrHigh· 8.8
1mo ago

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

▾ TwilightGitPython · GitPythonvia GHSA
CVE-2026-19067Medium· 6.3
1mo ago

A security flaw has been discovered in itsourcecode Hospital Management System 1.0

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /treatment.php. Performing a manipulation of the argument editid results in sql injection. Remote…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-19047Medium· 5.3
1mo ago

A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24

A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/executeCommand of the file src/ludusMCP/cliWrapper.ts of the component ludus_cli_execute. Performing a manipulation of…

▾ SunlitEPSS 1.1%via NVD
CVE-2026-20272Critical· 9.8
1mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that …

▾ Midnightcisco · ios_xeEPSS 0.57%via NVD
CVE-2026-71320High· 8.1
1mo ago

Nuxt is an open-source web development framework for Vue.js

Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, ca…

▾ Twilightnuxt · nuxtEPSS 0.71%via NVD
CVE-2026-69097High· 7.0
1mo ago

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerou…

▾ Twilightgitpython_project · gitpythonEPSS 0.27%via NVD
CVE-2026-16729Medium· 4.8
1mo ago

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

▾ Sunlitundici · undiciEPSS 0.19%via GHSA
CVE-2026-55100High
1mo ago

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query …

▾ Twilighthashi-vault-js · hashi-vault-jsEPSS 0.56%via NVD
CVE-2026-54680Critical· 9.9
2mo ago

Logging operator automates the deployment and configuration of Kubernetes logging pipelines

Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record…

▾ Midnightkube-logging · github.com/kube-logging/logging-operatorEPSS 0.78%via NVD
CVE-2026-54662High· 8.3
2mo ago

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.48%via GHSA
CWE-74 vulnerabilities (CVEs) — page 9 · VulnSea