|
131
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in PrefectHQ prefect up to 3.6.21. This impacts the function endswith of the file /api/health of the component Health Check API. Performing a manipulation results in impr…
New
|
CWE-287
Improper Authentication
|
CVE-2026-7722
|
2026-05-5 00:18 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
132
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in PrefectHQ prefect up to 3.6.13. Affected is an unknown function of the file /api/events/in of the component WebSocket Endpoint. Executing a manipulation can lead to missing a…
New
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-7723
|
2026-05-5 00:18 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
133
|
5.0 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in PrefectHQ prefect up to 3.6.28.dev1. Affected by this vulnerability is the function validate_restricted_url of the component Webhook/Notification. The manipulation l…
New
|
CWE-362 CWE-367
Race Condition Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-7724
|
2026-05-5 00:18 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
134
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in PrefectHQ prefect up to 3.6.25.dev6. Affected by this issue is some unknown functionality of the file src/prefect/runner/storage.py of the component GitRepository Pull Ha…
New
|
CWE-74 CWE-88
Injection Argument Injection
|
CVE-2026-7725
|
2026-05-5 00:18 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
135
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in Shandong Hoteam Software PDM Product Data Management System up to 8.3.9. This affects the function GetQueryMachineGridOnePageData of the file /Base/BaseService.asmx/…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7727
|
2026-05-5 00:18 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
136
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in ryanjoachim mcp-rtfm 0.1.0. This vulnerability affects the function get_doc_content/read_doc/update_doc of the component MCP Interface. Such manipulation of the argu…
New
|
CWE-22
Path Traversal
|
CVE-2026-7728
|
2026-05-5 00:18 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
137
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in pixelsock directus-mcp 1.0.0. This issue affects the function validateUrl of the file index.ts of the component MCP Interface. Performing a manipulation of the …
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-7729
|
2026-05-5 00:18 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
138
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in privsim mcp-test-runner 0.2.0. Impacted is the function child_process.spawn of the file src/index.ts of the component MCP Interface. Executing a manipulation of the …
New
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7730
|
2026-05-5 00:18 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
139
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. The affected element is an unknown function of the file get_state.php. The manipulation of the argument G_ST…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7731
|
2026-05-5 00:18 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
140
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function of the file request_blood.php. The manipulation results in unrestricted upload…
New
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-7732
|
2026-05-5 00:18 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|