| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-14313 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is… | ||
| CVE-2026-14240 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control, allowing unauthenticated users to download the exported customers' personal information once an… | ||
| CVE-2026-14204 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2026 | The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and… | ||
| CVE-2026-13703 | Med | 0.35 | 5.4 | 0.00 | Aug 6, 2026 | The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any logged-in user such as a subscriber to read the site's configured 301 redirect rules, including their source and destination URLs. | ||
| CVE-2026-13154 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site… | ||
| CVE-2026-13153 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2026 | The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold… | ||
| CVE-2026-12713 | Cri | 0.59 | 9.1 | 0.00 | Aug 6, 2026 | The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by… | ||
| CVE-2026-11588 | Med | 0.40 | 6.1 | 0.00 | Aug 6, 2026 | The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API routes and disables HTML sanitisation before saving the post, allowing unauthenticated attackers to create administrator-attributed published posts containing… | ||
| CVE-2025-15678 | Med | 0.40 | 6.1 | 0.00 | Aug 6, 2026 | The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Author by default), allowing them to upload a file containing malicious JavaScript that executes when the file is accessed, leading to… | ||
| CVE-2026-19000 | Hig | 0.47 | 7.3 | 0.00 | Aug 6, 2026 | A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/chat/send of the component Anonymous Chat Attachment Parser. The manipulation leads to server-side request forgery. The attack can be initiated remotely. The… | ||
| CVE-2026-18998 | Med | 0.41 | 6.3 | 0.00 | Aug 6, 2026 | A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of the file src/core/sub-agent.ts of the component delegate_task Tool. Executing a manipulation can lead to improper authorization. It is possible to launch the… | ||
| CVE-2026-18997 | Med | 0.41 | 6.3 | 0.00 | Aug 6, 2026 | A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBgCommand of the file src/core/agent.ts of the component bg Command Handler. Performing a manipulation results in incorrect authorization. It is possible to… | ||
| CVE-2026-15459 | Hig | 0.53 | 8.1 | 0.01 | Aug 6, 2026 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys the WDP-AUTH request signature… | ||
| CVE-2026-18996 | Med | 0.41 | 6.3 | 0.00 | Aug 6, 2026 | A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function PermissionManager.checkShellCommand of the file src/capabilities/permissions.ts of the component run_command Handler. Such manipulation leads to incorrect… | ||
| CVE-2026-18995 | Med | 0.28 | 4.3 | 0.00 | Aug 6, 2026 | A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the file src/renderer/services/artifactParser.ts of the component MEDIA Path Handler. This manipulation causes information disclosure. The attack is possible to be… | ||
| CVE-2026-18993 | Med | 0.41 | 6.3 | 0.00 | Aug 6, 2026 | A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent/model_tools.py of the component Memory Toolset. The manipulation results in improper access controls. The attack can be executed… | ||
| CVE-2026-18992 | Med | 0.41 | 6.3 | 0.00 | Aug 6, 2026 | A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/executor.py of the component Self-Evolution Review Agent. Performing a manipulation results in incorrect authorization. The attack is… | ||
| CVE-2026-18909 | Med | 0.31 | 4.7 | 0.00 | Aug 6, 2026 | A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range… | ||
| CVE-2026-18325 | Hig | 0.47 | 7.2 | 0.00 | Aug 6, 2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record via Select Field in all versions up to, and including, 1.56.1 due to insufficient input sanitization and output… | ||
| CVE-2026-16636 | Hig | 0.47 | 7.2 | 0.00 | Aug 6, 2026 | The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95 due to… | ||
| CVE-2026-15991 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2026 | The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read… | ||
| CVE-2026-18991 | Hig | 0.47 | 7.3 | 0.00 | Aug 6, 2026 | A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp-tools/core.ts of the component send_file. Such manipulation leads to path traversal. The attack can be executed remotely. The… | ||
| CVE-2026-18990 | Hig | 0.47 | 7.3 | 0.00 | Aug 6, 2026 | A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation results in missing authentication. The attack may be performed from remote. The exploit is now public and… | ||
| CVE-2026-18980 | Med | 0.34 | 6.3 | 0.01 | Aug 6, 2026 | A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. The attack may be launched remotely. The exploit is publicly available and might… | ||
| CVE-2026-18976 | Med | 0.41 | 6.3 | 0.00 | Aug 6, 2026 | A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This manipulation causes incorrect privilege assignment. The attack may be… | ||
| CVE-2026-18974 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the component execute_tool_manually Endpoint. The manipulation of the argument tool_name/tool_params results in information disclosure. The… | ||
| CVE-2026-18973 | Hig | 0.47 | 7.3 | 0.00 | Aug 6, 2026 | A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component extension_proxy Route. The manipulation of the argument url leads to server-side request forgery. The attack… | ||
| CVE-2026-67873 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the… | ||
| CVE-2026-67872 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queue resize handling | ||
| CVE-2026-67871 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server | ||
| CVE-2026-67870 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing… | ||
| CVE-2026-67869 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata | ||
| CVE-2026-67531 | Cri | 0.53 | — | 0.01 | Aug 6, 2026 | FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), and because Zod v4 defines _zod as a non-configurable, non-writable own… | ||
| CVE-2026-52466 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2026 | Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not… | ||
| CVE-2026-19028 | Med | 0.44 | — | 0.00 | Aug 6, 2026 | H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a size_t underflow. This allows… | ||
| CVE-2026-19027 | Med | 0.45 | — | 0.00 | Aug 6, 2026 | The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5 through 2.3.0 advance a read index into the compressed chunk buffer without bounding it against the buffer's actual size. This allows… | ||
| CVE-2026-18970 | Hig | 0.47 | 7.3 | 0.00 | Aug 6, 2026 | A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of the file /dm/dispatch/user/findAll. Executing a manipulation of the argument Name can lead to sql injection. It is possible to… | ||
| CVE-2026-18969 | Hig | 0.47 | 7.3 | 0.00 | Aug 6, 2026 | A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the file /dm/dispatch/userinfo/upload. Performing a manipulation of the argument File results in unrestricted upload. It is possible to… | ||
| CVE-2026-18968 | Med | 0.28 | 4.3 | 0.00 | Aug 6, 2026 | A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue affects some unknown processing of the file /tags.php. Such manipulation of the argument day leads to cross site scripting. The attack may be performed from… | ||
| CVE-2023-54389 | — | 0.00 | — | — | Aug 6, 2026 | Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned. | ||
| CVE-2023-54388 | — | 0.00 | — | — | Aug 6, 2026 | Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned. | ||
| CVE-2023-54387 | — | 0.00 | — | — | Aug 6, 2026 | Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned. | ||
| CVE-2023-54386 | — | 0.00 | — | — | Aug 6, 2026 | Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned. | ||
| CVE-2023-54385 | — | 0.00 | — | — | Aug 6, 2026 | Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned. | ||
| CVE-2023-54384 | — | 0.00 | — | — | Aug 6, 2026 | Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned. | ||
| CVE-2023-54383 | — | 0.00 | — | — | Aug 6, 2026 | Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned. | ||
| CVE-2023-54382 | — | 0.00 | — | — | Aug 6, 2026 | Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE. | ||
| CVE-2023-54381 | — | 0.00 | — | — | Aug 6, 2026 | Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE. | ||
| CVE-2023-54380 | — | 0.00 | — | — | Aug 6, 2026 | Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE. | ||
| CVE-2023-54379 | — | 0.00 | — | — | Aug 6, 2026 | Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE. |
- risk 0.34cvss 5.3epss 0.00
PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is…
- risk 0.34cvss 5.3epss 0.00
The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control, allowing unauthenticated users to download the exported customers' personal information once an…
- risk 0.42cvss 6.5epss 0.00
The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and…
- risk 0.35cvss 5.4epss 0.00
The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any logged-in user such as a subscriber to read the site's configured 301 redirect rules, including their source and destination URLs.
- risk 0.49cvss 7.5epss 0.00
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site…
- risk 0.49cvss 7.5epss 0.01
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold…
- risk 0.59cvss 9.1epss 0.00
The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by…
- risk 0.40cvss 6.1epss 0.00
The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API routes and disables HTML sanitisation before saving the post, allowing unauthenticated attackers to create administrator-attributed published posts containing…
- risk 0.40cvss 6.1epss 0.00
The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Author by default), allowing them to upload a file containing malicious JavaScript that executes when the file is accessed, leading to…
- risk 0.47cvss 7.3epss 0.00
A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/chat/send of the component Anonymous Chat Attachment Parser. The manipulation leads to server-side request forgery. The attack can be initiated remotely. The…
- risk 0.41cvss 6.3epss 0.00
A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of the file src/core/sub-agent.ts of the component delegate_task Tool. Executing a manipulation can lead to improper authorization. It is possible to launch the…
- risk 0.41cvss 6.3epss 0.00
A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBgCommand of the file src/core/agent.ts of the component bg Command Handler. Performing a manipulation results in incorrect authorization. It is possible to…
- risk 0.53cvss 8.1epss 0.01
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys the WDP-AUTH request signature…
- risk 0.41cvss 6.3epss 0.00
A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function PermissionManager.checkShellCommand of the file src/capabilities/permissions.ts of the component run_command Handler. Such manipulation leads to incorrect…
- risk 0.28cvss 4.3epss 0.00
A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the file src/renderer/services/artifactParser.ts of the component MEDIA Path Handler. This manipulation causes information disclosure. The attack is possible to be…
- risk 0.41cvss 6.3epss 0.00
A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent/model_tools.py of the component Memory Toolset. The manipulation results in improper access controls. The attack can be executed…
- risk 0.41cvss 6.3epss 0.00
A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/executor.py of the component Self-Evolution Review Agent. Performing a manipulation results in incorrect authorization. The attack is…
- risk 0.31cvss 4.7epss 0.00
A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range…
- risk 0.47cvss 7.2epss 0.00
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record via Select Field in all versions up to, and including, 1.56.1 due to insufficient input sanitization and output…
- risk 0.47cvss 7.2epss 0.00
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95 due to…
- risk 0.57cvss 8.8epss 0.01
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read…
- risk 0.47cvss 7.3epss 0.00
A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp-tools/core.ts of the component send_file. Such manipulation leads to path traversal. The attack can be executed remotely. The…
- risk 0.47cvss 7.3epss 0.00
A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation results in missing authentication. The attack may be performed from remote. The exploit is now public and…
- risk 0.34cvss 6.3epss 0.01
A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. The attack may be launched remotely. The exploit is publicly available and might…
- risk 0.41cvss 6.3epss 0.00
A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This manipulation causes incorrect privilege assignment. The attack may be…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the component execute_tool_manually Endpoint. The manipulation of the argument tool_name/tool_params results in information disclosure. The…
- risk 0.47cvss 7.3epss 0.00
A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component extension_proxy Route. The manipulation of the argument url leads to server-side request forgery. The attack…
- risk 0.64cvss 9.8epss 0.00
A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the…
- risk 0.49cvss 7.5epss 0.00
An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queue resize handling
- risk 0.49cvss 7.5epss 0.00
Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server
- risk 0.64cvss 9.8epss 0.01
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing…
- risk 0.49cvss 7.5epss 0.00
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata
- risk 0.53cvss —epss 0.01
FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), and because Zod v4 defines _zod as a non-configurable, non-writable own…
- risk 0.64cvss 9.8epss 0.00
Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not…
- risk 0.44cvss —epss 0.00
H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a size_t underflow. This allows…
- risk 0.45cvss —epss 0.00
The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5 through 2.3.0 advance a read index into the compressed chunk buffer without bounding it against the buffer's actual size. This allows…
- risk 0.47cvss 7.3epss 0.00
A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of the file /dm/dispatch/user/findAll. Executing a manipulation of the argument Name can lead to sql injection. It is possible to…
- risk 0.47cvss 7.3epss 0.00
A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the file /dm/dispatch/userinfo/upload. Performing a manipulation of the argument File results in unrestricted upload. It is possible to…
- risk 0.28cvss 4.3epss 0.00
A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue affects some unknown processing of the file /tags.php. Such manipulation of the argument day leads to cross site scripting. The attack may be performed from…
- CVE-2023-54389Aug 6, 2026risk 0.00cvss —epss —
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
- CVE-2023-54388Aug 6, 2026risk 0.00cvss —epss —
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
- CVE-2023-54387Aug 6, 2026risk 0.00cvss —epss —
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
- CVE-2023-54386Aug 6, 2026risk 0.00cvss —epss —
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
- CVE-2023-54385Aug 6, 2026risk 0.00cvss —epss —
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
- CVE-2023-54384Aug 6, 2026risk 0.00cvss —epss —
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
- CVE-2023-54383Aug 6, 2026risk 0.00cvss —epss —
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
- CVE-2023-54382Aug 6, 2026risk 0.00cvss —epss —
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
- CVE-2023-54381Aug 6, 2026risk 0.00cvss —epss —
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
- CVE-2023-54380Aug 6, 2026risk 0.00cvss —epss —
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
- CVE-2023-54379Aug 6, 2026risk 0.00cvss —epss —
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.