Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.3
CVE-2026-19347
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php…
No fix yet
HIGH 8.8
CVE-2026-19346
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This…
No fix yet
MEDIUM 6.5
CVE-2026-19345
A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manip…
No fix yet
HIGH 7.3
CVE-2026-19344
A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/co…
No fix yet
HIGH 7.3
CVE-2026-19343
A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/Admi…
No fix yet
HIGH 7.3
CVE-2026-19342
A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Log…
No fix yet
HIGH 8.8
CVE-2026-19341
A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobal…
No fix yet
MEDIUM 6.3
CVE-2026-19340
A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js …
No fix yet
MEDIUM 6.3
CVE-2026-19339
A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceReques…
No fix yet
MEDIUM 5.3
CVE-2026-19338
A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mc…
No fix yet
MEDIUM 5.3
CVE-2026-19337
A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component rea…
Patch available
MEDIUM 5.3
CVE-2026-19336
A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/to…
Patch available
MEDIUM 5.3
CVE-2026-19335
A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the fi…
No fix yet
MEDIUM 6.5
CVE-2026-18603
The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding …
No fix yet
CRITICAL 9.1
CVE-2026-18473
The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a…
No fix yet
MEDIUM 6.5
CVE-2026-18465
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthentica…
No fix yet
HIGH 7.5
CVE-2026-18464
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthentica…
No fix yet
HIGH 7.5
CVE-2026-18357
The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allo…
No fix yet
MEDIUM 6.5
CVE-2026-18037
The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and…
No fix yet
HIGH 8.6
CVE-2026-17044
The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading t…
No fix yet
HIGH 7.5
CVE-2026-18032
The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the …
No fix yet
MEDIUM 5.3
CVE-2026-17014
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions,…
No fix yet
HIGH 8.1
CVE-2026-17017
The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an A…
No fix yet
MEDIUM 6.5
CVE-2026-16992
The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that r…
No fix yet
HIGH 7.5
CVE-2026-16988
The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested list…
No fix yet
MEDIUM 6.1
CVE-2026-16032
The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before stori…
No fix yet
CRITICAL 9.8
CVE-2026-15038
The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remot…
No fix yet
MEDIUM 5.3
CVE-2026-19334
A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. …
No fix yet
MEDIUM 5.3
CVE-2026-19333
A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by…
No fix yet
MEDIUM 5.3
CVE-2026-19332
A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_…
No fix yet