|
941
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_order of the file /admin/ajax.php?action=save_order. Performing a manipulation of the argument…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-7296
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
942
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-7297
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
943
|
3.7 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/JobLogController.jav…
|
CWE-99
Resource Injection
|
CVE-2026-7303
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
944
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-7305
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
945
|
5.6 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function of the file xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/Open…
|
CWE-320 CWE-321
Key Management Errors Use of Hard-coded Cryptographic Key
|
CVE-2026-7306
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
946
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file src/spire_doc_mcp/api/base.py. Performing a manipulation of the argument docume…
|
CWE-22
Path Traversal
|
CVE-2026-7314
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
947
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in eiceblue spire-pdf-mcp-server 0.1.1. This impacts the function get_pdf_path of the file src/spire_pdf_mcp/server.py of the component PDF File Handler. Executing a manipulatio…
|
CWE-22
Path Traversal
|
CVE-2026-7315
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
948
|
5.9 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file research_server.py. The manipulation of the argument topic results in path trave…
|
CWE-22
Path Traversal
|
CVE-2026-7318
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
949
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in elinsky execution-system-mcp 0.1.0. The impacted element is the function _get_context_file_path of the file src/execution_system_mcp/server.py of the component add_action Too…
|
CWE-22
Path Traversal
|
CVE-2026-7319
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
950
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in eiliyaabedini aider-mcp up to 667b914301aada695aab0e46d1fb3a7d5e32c8af. Affected is an unknown function of the file aider_mcp.py of the component code_with_ai. The m…
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-7316
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|