|
651
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in geldata gel-mcp 0.1.0. This impacts the function list_rules/fetch_rule of the file src/gel_mcp/server.py. The manipulation of the argument rule_name results in …
New
|
CWE-22
Path Traversal
|
CVE-2026-7403
|
2026-04-30 06:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
652
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.p…
New
|
CWE-22 CWE-23
Path Traversal Relative Path Traversal
|
CVE-2026-7404
|
2026-04-30 06:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
653
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /pizzafy/admin/ajax.php?action=save…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7407
|
2026-04-30 06:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
654
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Performing a manipulation r…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7408
|
2026-04-30 06:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
655
|
4.4 |
MEDIUM
Local
|
-
|
-
|
A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path of the file tools/file_tools.py. The manipulation results in symlink following.…
New
|
CWE-59 CWE-61
Link Following UNIX Symbolic Link (Symlink) Following
|
CVE-2026-7397
|
2026-04-30 06:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
656
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54. This vulnerability affects the function Upload of the file bioinfo_mcp_platform/app.py of…
New
|
CWE-22
Path Traversal
|
CVE-2026-7398
|
2026-04-30 06:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
657
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is_path_allowed of the file server.py of the component read_file_tool/write_file_…
New
|
CWE-22
Path Traversal
|
CVE-2026-7400
|
2026-04-30 06:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
658
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=register of the com…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-7401
|
2026-04-30 06:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
659
|
7.5 |
HIGH
Network
|
-
|
-
|
PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/files/:uploadId` validates the mounted request path using the still-encoded `re…
Update
|
CWE-22
Path Traversal
|
CVE-2026-41180
|
2026-04-30 06:08 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
660
|
8.2 |
HIGH
Network
|
-
|
-
|
Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaustion. An attacker can upload a specially crafted i…
Update
|
CWE-400 CWE-770
Uncontrolled Resource Consumption Allocation of Resources Without Limits or Throttling
|
CVE-2026-41309
|
2026-04-30 05:56 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|