Vulnerability index

Browse CVEs

8,883 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Unclassified MEDIUM 5.3
CVE-2026-7403

A security flaw has been discovered in geldata gel-mcp 0.1.0. This impacts the function list_rules/fetch_rule of the file src/gel_mcp/server.py. The …

Mitigation only
Fix from $1,600 2026-04-29
Unclassified HIGH 7.3
CVE-2026-7404

A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_si…

Mitigation only
Fix from $1,950 2026-04-29
Unclassified HIGH 7.3
CVE-2026-7400

A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is_path_allowed of the file ser…

Patch available
Fix from $1,950 2026-04-29
Unclassified HIGH 8.8
CVE-2018-25308

BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files…

No fix yet
Fix from $1,950 2026-04-29
Unclassified MEDIUM 6.5
CVE-2018-25311

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows attackers with valid credentials …

No fix yet
Fix from $1,600 2026-04-29
Unclassified MEDIUM 6.5
CVE-2018-25312

LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and upload arbitrary files by man…

No fix yet
Fix from $1,600 2026-04-29
Unclassified HIGH 7.3
CVE-2026-7398

A weakness has been identified in florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54. This vulnerability affects the function…

Mitigation only
Fix from $1,950 2026-04-29
Wazuh CRITICAL 9.9
CVE-2026-30893

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path tra…

Fix: 4.14.4+
Fix from $2,300 2026-04-29
Unclassified MEDIUM 5.3
CVE-2026-7396

A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms…

Mitigation only
Fix from $1,600 2026-04-29
Unclassified HIGH 7.3
CVE-2026-7386

A flaw has been found in fatbobman mail-mcp-bridge up to 1.3.3. Affected is an unknown function of the file src/mail_mcp_server.py. Executing a manip…

Patch available
Fix from $1,950 2026-04-29
Unclassified CRITICAL 9.6
CVE-2026-5166

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software Technologies Research Institu…

Mitigation only
Fix from $2,300 2026-04-29
Unclassified MEDIUM 6.5
CVE-2026-38993

Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows authenticated attackers to write…

Mitigation only
Fix from $1,600 2026-04-29
Unclassified HIGH 7.3
CVE-2026-7384

A vulnerability was detected in ezequiroga mcp-bases 357ca19c7a49a9b9cb2ef639b366f03aba8bea39/c630b8ab0f970614d42da8e566e9c0d15a16414c. This impacts …

Mitigation only
Fix from $1,950 2026-04-29
Credentials Binding HIGH 7.5
CVE-2026-42520

Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers …

Fix: after 719.v80e905ef14eb
Fix from $1,950 2026-04-29
Ollama CRITICAL 9.8
CVE-2026-42249

Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP respon…

Fix: after 0.17.5
Fix from $2,300 2026-04-29
Unclassified HIGH 7.3
CVE-2026-7319

A flaw has been found in elinsky execution-system-mcp 0.1.0. The impacted element is the function _get_context_file_path of the file src/execution_sy…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7314

A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file src/spire_doc_mcp/api/base.py…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7315

A flaw has been found in eiceblue spire-pdf-mcp-server 0.1.1. This impacts the function get_pdf_path of the file src/spire_pdf_mcp/server.py of the c…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified MEDIUM 5.9
CVE-2026-7318

A vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file research_server.py. The manipu…

Mitigation only
Fix from $1,600 2026-04-28
Openclaw MEDIUM 6.5
CVE-2026-41911

OpenClaw before 2026.4.8 contains a filesystem policy bypass vulnerability in docx upload processing that allows local file reads outside workspace b…

Fix: 2026.4.8+
Fix from $1,600 2026-04-28
Openclaw HIGH 8.1
CVE-2026-41383

OpenClaw before 2026.4.2 contains an arbitrary directory deletion vulnerability in mirror mode that allows attackers to delete remote directories by …

Fix: 2026.4.2+
Fix from $1,950 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7272

A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected element is the function genera…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified MEDIUM 5.3
CVE-2026-7271

A vulnerability was detected in DV0x creative-ad-agent up to 751b9e5146604dc65049bd0f62dcbdad6212f8a3. Impacted is an unknown function of the file se…

Patch available
Fix from $1,600 2026-04-28
Unclassified MEDIUM 5.3
CVE-2026-7235

A security vulnerability has been detected in ErlichLiu claude-agent-sdk-master up to b185aa7ff0d864581257008077b4010fca1747bf. Affected by this vuln…

Mitigation only
Fix from $1,600 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7237

A vulnerability was detected in AgiFlow scaffold-mcp up to 1.0.27. Affected by this issue is some unknown functionality of the file packages/scaffold…

Patch available
Fix from $1,950 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7234

A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith of the file scripts/componen…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7216

A weakness has been identified in donchelo processing-claude-mcp-bridge up to e017b20a4b592a45531a6392f494007f04e661bd. Impacted is an unknown functi…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified MEDIUM 5.3
CVE-2026-7217

A security vulnerability has been detected in Deepractice PromptX up to 2.4.0. The affected element is the function read_docx/read_xlsx/read_pptx/lis…

Mitigation only
Fix from $1,600 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7212

A security vulnerability has been detected in edvardlindelof notes-mcp up to 0.1.4. This affects an unknown function of the file notes_mcp.py. The ma…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified HIGH 7.3
CVE-2026-7213

A vulnerability was detected in ef10007 MLOps_MCP 1.0.0. This impacts an unknown function of the file fastmcp_server.py of the component save_file To…

Mitigation only
Fix from $1,950 2026-04-28