Threats Tagged 'cve'
View all threats tagged with 'cve'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-19270: Path Traversal in Hulupeep mcp-ui-probeCVE-2026-19270 0 CVE-2026-19270 is a medium severity path traversal vulnerability in Hulupeep mcp-ui-probe versions 0.1 and 0.2.0. It affects several functions in the Journey/Usage component, allowing local attackers to manipulate file paths via the journeyId or filename arguments. The vulnerability requires local access and no user interaction. No official fix or patch has been released yet, and the vendor has not responded to the issue report. Join the discussion | CVE Database V5 | 08/08/2026, 07:45:11 UTC Added: 08/08/2026, 07:56:49 UTC |
CVE-2026-19268: Command Injection in abdullah1854 MCPGatewayCVE-2026-19268 0 CVE-2026-19268 is a command injection vulnerability in the abdullah1854 MCPGateway product affecting the getUsageByDateRange function in src/services/claude-usage.ts. The vulnerability allows remote attackers to inject commands via the 'since' argument. The product uses continuous delivery with rolling releases, so no specific affected or fixed versions are available. The vulnerability has a medium severity with a CVSS 4.0 score of 5.3. The vendor has been informed but has not yet responded or provided a fix. Public exploit code is available, but no known exploitation in the wild has been reported. Join the discussion | CVE Database V5 | 08/08/2026, 07:30:09 UTC Added: 08/08/2026, 07:56:49 UTC |
CVE-2026-19266: Command Injection in Kirachon context-engineCVE-2026-19266 0 CVE-2026-19266 is a command injection vulnerability in the Kirachon context-engine up to version 1.9.0. It affects the execGitCommand function in the src/mcp/utils/gitUtils.ts file within the review-git-diff endpoint. Manipulating the argument 'args' can lead to command injection. Upgrading to version 1.9.1 mitigates this issue. The vulnerability has a medium severity with a CVSS score of 5.1. Join the discussion | CVE Database V5 | 08/08/2026, 07:15:11 UTC Added: 08/08/2026, 07:41:58 UTC |
CVE-2026-19263: Command Injection in INQUIRELAB mcp-bridge-apiCVE-2026-19263 0 CVE-2026-19263 is a command injection vulnerability in the INQUIRELAB mcp-bridge-api affecting an unknown function in the mcp-bridge.js file of the Servers Endpoint component. The vulnerability allows remote attackers to manipulate command or argument inputs to execute arbitrary commands. The product uses a rolling release model, so specific affected or fixed versions are not available. A fix is pending acceptance in a pull request. The CVSS 4.0 base score is 6.9, indicating medium severity. Join the discussion | CVE Database V5 | 08/08/2026, 06:45:09 UTC Added: 08/08/2026, 07:11:49 UTC |
CVE-2026-19259: Heap-based Buffer Overflow in MZ Automation libiec61850CVE-2026-19259 0 CVE-2026-19259 is a heap-based buffer overflow vulnerability in MZ Automation libiec61850 versions 1.6.0 and 1.6.1. It occurs in the function MmsMapping_varAccessSpecToObjectReference within the MMS Protocol Workflow component when handling the argument GetNamedVariableListAttributesResponse.itemId. Exploitation requires local access and no user interaction. The vulnerability has been publicly disclosed, but the vendor has not yet responded or issued a fix. Join the discussion | CVE Database V5 | 08/08/2026, 06:00:09 UTC Added: 08/08/2026, 06:26:52 UTC |
CVE-2026-16955: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in AI EngineCVE-2026-16955 0 CVE-2026-16955 is a path traversal vulnerability in the AI Engine WordPress plugin before version 3.6.6. It allows users with subscriber-level accounts to read arbitrary files on the server and exfiltrate their contents if a non-default public API feature is enabled. Without this feature enabled, the vulnerability can be exploited by administrators, which on multisite installations allows non-super subsite administrators to access network-shared configuration files and secrets. Join the discussion | CVE Database V5 | 08/08/2026, 06:00:13 UTC Added: 08/08/2026, 06:26:52 UTC |
CVE-2026-16953: CWE-639 Authorization Bypass Through User-Controlled Key in AI EngineCVE-2026-16953 0 CVE-2026-16953 is a vulnerability in the AI Engine WordPress plugin before version 3.6.4. The plugin fails to verify ownership of uploaded chatbot files before allowing their deletion, relying solely on a client-supplied session cookie for authorization. This flaw allows an unauthenticated attacker who obtains a victim's session identifier and file reference to delete the victim's uploaded files. Join the discussion | CVE Database V5 | 08/08/2026, 06:00:13 UTC Added: 08/08/2026, 06:26:52 UTC |
CVE-2026-16948: CWE-284 Improper Access Control in Solace ExtraCVE-2026-16948 0 CVE-2026-16948 is a vulnerability in the Solace Extra WordPress plugin versions before 1.6.1. It lacks proper capability checks on several AJAX actions and exposes the nonce protecting these actions on admin pages accessible to low-privileged users. This flaw allows users with the Subscriber role to modify site-wide presentation settings and delete imported site-builder content. Join the discussion | CVE Database V5 | 08/08/2026, 06:00:13 UTC Added: 08/08/2026, 06:26:52 UTC |
CVE-2026-16608: CWE-862 Missing Authorization in Download MonitorCVE-2026-16608 0 The Download Monitor WordPress plugin before version 5.2.6 has a missing authorization vulnerability in one of its download-logging AJAX actions. This flaw allows unauthenticated users to inject arbitrary download log entries by exploiting the exposed nonce, which can inflate a site's download statistics. Join the discussion | CVE Database V5 | 08/08/2026, 06:00:12 UTC Added: 08/08/2026, 06:26:52 UTC |
CVE-2026-16595: CWE-200 Information Exposure in WP Directory KitCVE-2026-16595 0 The WP Directory Kit WordPress plugin before version 1.5.5 contains an information exposure vulnerability. It fails to perform authorization or nonce checks on an authenticated AJAX action, allowing any authenticated user, including low-privileged roles like Subscribers, to access the site's user list and unpublished listings of other users. Join the discussion | CVE Database V5 | 08/08/2026, 06:00:12 UTC Added: 08/08/2026, 06:26:52 UTC |
Showing 1 to 10 of 8258 results