|
631
|
8.8 |
HIGH
Network
|
coze
|
coze_studio
|
A vulnerability was detected in ByteDance coze-studio up to 0.5.1. Affected by this vulnerability is the function ExecuteSQL of the file backend/domain/memory/database/service/database_impl.go of the…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7023
|
2026-05-2 05:27 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
632
|
5.6 |
MEDIUM
Network
|
ollama
|
ollama
|
A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The mani…
|
CWE-22
Path Traversal
|
CVE-2026-7020
|
2026-05-2 05:24 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
633
|
9.8 |
CRITICAL
Network
|
sipeed
|
picoclaw
|
A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher Management Plane. Performing a manipulation result…
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-6987
|
2026-05-2 05:24 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
634
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in ghantakiran splunk-mcp-integration up to 0b86b09d5e5adf0433acd43c975951224613a1a6. Impacted is the function create_csv_export of the file services/csv-export-service…
|
CWE-22
Path Traversal
|
CVE-2026-7589
|
2026-05-2 05:21 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
635
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in eyal-gor p_69_branch_monkey_mcp up to 69bc71874ce40050ef45fde5a435855f18af3373. The affected element is an unknown function of the file branch_monkey_mcp/bridge_and_…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7590
|
2026-05-2 05:21 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
636
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in TimBroddin astro-mcp-server up to 1.1.1. The impacted element is an unknown function of the file src/index.ts of the component MCP Tool Query Construction. Perf…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7591
|
2026-05-2 05:21 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
637
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in itsourcecode Courier Management System 1.0. This affects an unknown function of the file /edit_staff.php. Executing a manipulation of the argument ID can lead to sql…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7592
|
2026-05-2 05:21 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
638
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-2052. Reason: This candidate is a reservation duplicate of CVE-2026-2052 Notes: All CVE users should reference CVE…
|
-
|
CVE-2025-8903
|
2026-05-2 05:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
639
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-6526
|
2026-05-2 04:29 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
640
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-6527
|
2026-05-2 04:28 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|