|
581
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function of the file /viewappointment.php. This manipulation of the argument delid cause…
Update
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7632
|
2026-05-6 04:15 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
582
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to…
Update
|
CWE-73
External Control of File Name or Path
|
CVE-2026-7633
|
2026-05-6 04:15 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
583
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallServiceProvider::boot of the file innopacks/install/src/InstallServiceProvider.php of …
Update
|
CWE-287
Improper Authentication
|
CVE-2026-7630
|
2026-05-6 04:15 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
584
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the component MCP Interface. Performing a manipulation o…
Update
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7642
|
2026-05-6 04:15 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
585
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of the component API Endpoint. Executing a manipulation can lead to permissive cros…
Update
|
CWE-346 CWE-942
Origin Validation Error Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-7643
|
2026-05-6 04:15 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
586
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The manipulation leads to improper authorization. Remote …
Update
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-7644
|
2026-05-6 04:15 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
587
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in ruvnet sublinear-time-solver 1.5.0. Affected by this vulnerability is the function export_state of the file src/consciousness-explorer/mcp/server.js of the component MCP …
Update
|
CWE-22
Path Traversal
|
CVE-2026-7645
|
2026-05-6 04:15 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
588
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in r-huijts mcp-server-rijksmuseum up to 1.0.4. Affected is the function open_image_in_browser of the file src/index.ts of the component MCP Interface. Performing …
Update
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7653
|
2026-05-6 04:15 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
589
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in kerwincui FastBee up to 1.2.1. The affected element is the function ToolController.download of the file springboot/fastbee-open-api/src/main/java/com/fastbee/data/control…
New
|
CWE-22
Path Traversal
|
CVE-2026-7676
|
2026-05-6 04:15 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
590
|
5.6 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transf…
New
|
CWE-74 CWE-94
Injection Code Injection
|
CVE-2026-7669
|
2026-05-6 04:15 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|