|
1241
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-7305
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1242
|
5.6 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function of the file xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/Open…
|
CWE-320 CWE-321
Key Management Errors Use of Hard-coded Cryptographic Key
|
CVE-2026-7306
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1243
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in eiliyaabedini aider-mcp up to 667b914301aada695aab0e46d1fb3a7d5e32c8af. Affected is an unknown function of the file aider_mcp.py of the component code_with_ai. The m…
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-7316
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1244
|
5.0 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of…
|
CWE-20 CWE-502
Improper Input Validation Deserialization of Untrusted Data
|
CVE-2026-7317
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1245
|
5.9 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file research_server.py. The manipulation of the argument topic results in path trave…
|
CWE-22
Path Traversal
|
CVE-2026-7318
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1246
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in elinsky execution-system-mcp 0.1.0. The impacted element is the function _get_context_file_path of the file src/execution_system_mcp/server.py of the component add_action Too…
|
CWE-22
Path Traversal
|
CVE-2026-7319
|
2026-04-29 10:00 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1247
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2026-5822
|
2026-04-29 08:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1248
|
4.7 |
MEDIUM
Local
|
-
|
-
|
Mojic is a CLI tool to transform readable C code into an unrecognizable chaotic stream of emojis. Prior to 2.1.4, the CipherEngine uses a standard equality operator (!==) to verify the HMAC-SHA256 in…
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-41244
|
2026-04-29 06:18 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1249
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
NFC: nxp-nci: allow GPIOs to sleep
Allow the firmware and enable GPIOs to sleep.
This fixes a `WARN_ON' and allows the driver to…
|
NVD-CWE-noinfo
|
CVE-2026-31545
|
2026-04-29 05:53 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1250
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: bonding: fix NULL deref in bond_debug_rlb_hash_show
rlb_clear_slave intentionally keeps RLB hash-table entries on
the rx_has…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-31546
|
2026-04-29 05:48 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|