|
351
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/routes/llm.js of the component LLM Models API. Performi…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-7147
|
2026-04-28 04:25 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the argument fname can lead to sql injection. The attack …
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7148
|
2026-04-28 04:25 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d. This vulnerability affects the function prepare_kaggle_dataset of the file src/kaggle_mcp/server…
New
|
CWE-22
Path Traversal
|
CVE-2026-7149
|
2026-04-28 04:25 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the function generate_favicon_from_url of the file src/auto_favicon/server.py of th…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-7150
|
2026-04-28 04:25 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355
|
- |
|
-
|
-
|
AdaptiveGRC is vulnerable to Stored XSS via text type fields across the forms. Authenticated attacker can replace the value of the text field in the HTTP POST request. Improper parameter validation b…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-4313
|
2026-04-28 04:23 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356
|
7.5 |
HIGH
Network
|
getkirby
|
kirby
|
Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>` blocks. If the input value is already valid `CDATA`, it is not escaped a seco…
Update
|
CWE-91
Blind XPath Injection
|
CVE-2026-32870
|
2026-04-28 04:21 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357
|
8.1 |
HIGH
Network
|
getkirby
|
kirby
|
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control which user role is allowed to perform specific actions to content models in the …
Update
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-34587
|
2026-04-28 04:15 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358
|
6.5 |
MEDIUM
Network
|
getkirby
|
kirby
|
Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined …
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-40099
|
2026-04-28 04:12 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
359
|
8.8 |
HIGH
Network
|
getkirby
|
kirby
|
Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined …
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-41325
|
2026-04-28 04:07 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
360
|
- |
|
-
|
-
|
Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a tab, a vertical tab…
Update
|
CWE-400 CWE-674 CWE-835
Uncontrolled Resource Consumption Uncontrolled Recursion Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-41680
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|