Common Vulnerabilities and Exposures (CVE)

CVE-2026-19964

Aug 16, 2026 23:45:08 UTC

A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/python_repr.py of the component jm_check. The manipulation of the argument code results in code injection. It is possibl...

CVE-2026-19963

Aug 16, 2026 23:30:10 UTC

A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function stainfo of the file /goform/stainfo. The manipulation of the argument interface leads to command injection. It is possible to initiate the atta...

CVE-2026-19962

Aug 16, 2026 23:15:11 UTC

A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /goform/setWAN. Executing a manipulation of the argument pppUserName/pptpUserName/L2TPUserName can lead to command injection....

CVE-2026-19961

Aug 16, 2026 23:00:15 UTC

A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to ...

CVE-2026-19960

Aug 16, 2026 22:45:09 UTC

A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file /goform/formWlbasic. Such manipulation of the argument rootAPmac leads to command injection. The attack can be executed ...

CVE-2026-11973

Aug 16, 2026 22:40:14 UTC

The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.8.8 due to insufficient escaping on the user supplied parameter and lack of sufficie...

CVE-2026-19959

Aug 16, 2026 22:30:15 UTC

A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitati...

CVE-2026-19958

Aug 16, 2026 22:15:12 UTC

A security flaw has been discovered in iatsiuk pptr-mcp up to 0.2.7. The impacted element is the function executeCode of the file src/vm-executor.ts of the component execute Tool. The manipulation results in code injection. The attack may b...

CVE-2026-19957

Aug 16, 2026 22:00:12 UTC

A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetch of the file src/tools.ts of the component ssrf-test Endpoint. Such manipulation of the argument url leads to server-side request forgery. ...

CVE-2026-19956

Aug 16, 2026 20:15:13 UTC

A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file server.py. Such manipulation leads to server-side request forgery. The attack can be launched...

CVE-2026-19955

Aug 16, 2026 20:00:11 UTC

A vulnerability was detected in TrailDB 0.6. Impacted is the function tdb_open of the file /src/tdb.c of the component TOC Validation. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit...

CVE-2025-7195

Aug 16, 2026 19:39:39 UTC

Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/pass...

CVE-2026-9165

Aug 16, 2026 19:00:10 UTC

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested q...

CVE-2026-59124

Aug 16, 2026 18:48:36 UTC

Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.

CVE-2026-62869

Aug 16, 2026 18:48:35 UTC

Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.