Skip to main content

Year archive

CVEs published in 2026

Archive summary

47,678 CVEs published in 2026 — 5,246 Critical, 18,963 High, 19,005 Medium, 3,884 Low, 580 Unrated.

CVE-2026-72522

Published Aug 10, 2026

libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf…

CVSS 6.2 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-19389

Published Aug 10, 2026

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or W…

CVSS 7.1 · High
evidence mentions
5
Buzz score
30.9

CVE-2026-19387

Published Aug 10, 2026

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sa…

CVSS 7.6 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-19384

Published Aug 10, 2026

A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointm…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
27.5

CVE-2026-19383

Published Aug 10, 2026

A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_exec of the file /app/saipackage/install/upload of the compon…

CVSS 2.0 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-19382

Published Aug 10, 2026

A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a manipu…

CVSS 1.8 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-19381

Published Aug 10, 2026

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the compone…

CVSS 7.1 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-19380

Published Aug 10, 2026

A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improp…

CVSS 1.8 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-19379

Published Aug 10, 2026

A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argumen…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-19378

Published Aug 10, 2026

A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php. The manipulation of the argume…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-19376

Published Aug 10, 2026

A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. Th…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-19375

Published Aug 10, 2026

A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_article of the file news_scraper_mcp/server.py. The manipulatio…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-19374

Published Aug 9, 2026

A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-19373

Published Aug 9, 2026

A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfi…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-19372

Published Aug 9, 2026

A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSync of the file src/index.ts of…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-19371

Published Aug 9, 2026

A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the component comfy_upload_image. S…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-12372

Published Aug 9, 2026

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-19370

Published Aug 9, 2026

A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component gem…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-19369

Published Aug 9, 2026

A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The man…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-19368

Published Aug 9, 2026

A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component gemini_se…

CVSS 4.8 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-19367

Published Aug 9, 2026

A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality of the file src/tools/rangeConfig.ts of the component r…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-70395

Published Aug 9, 2026

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name, and to re…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.6

CVE-2026-19366

Published Aug 9, 2026

A flaw has been found in NocteDefensor LudusMCP up to 1.0.24. Affected is an unknown function of the file src/tools/insertCredsRangeConfig.ts of the component insert_creds_range_c…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-19365

Published Aug 9, 2026

A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the file src/index.ts of the component upscale_images. Such manipu…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-69659

Published Aug 9, 2026

Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with…

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
27.6
Showing 1-25 of 47,678 CVEsPage 1 of 1908