Skip to main content

CWE archive

CWE-77 CVEs

Programmatic archive

3,626 CVEs tagged with CWE-77953 Critical, 1,471 High, 772 Medium, 428 Low, 2 Unrated.

CVE-2026-7730

Published May 4, 2026

A weakness has been identified in privsim mcp-test-runner 0.2.0. Impacted is the function child_process.spawn of the file src/index.ts of the component MCP Interface. Executing a…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-7721

Published May 4, 2026

A security vulnerability has been detected in Totolink WA300 5.2cu.7112_B20190227. This affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. Such manipulation of…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-7720

Published May 4, 2026

A weakness has been identified in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component POST R…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-7718

Published May 4, 2026

A vulnerability was identified in Totolink WA300 5.2cu.7112_B20190227. Impacted is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component POST Request Handle…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-7705

Published May 3, 2026

A flaw has been found in JD Cloud JDCOS 4.5.1.r4518. This vulnerability affects the function set_iptv_info of the file /jdcap of the component Service Interface. Executing a manip…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-7698

Published May 3, 2026

A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Affected by this vulnerability is an unknown functionality of the file /Easy7/rest/systemInfo…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2026-7687

Published May 3, 2026

A vulnerability was determined in langflow-ai langflow up to 1.8.4. Affected by this issue is the function CodeParser.parse_callable_details of the file src/lfx/src/lfx/custom/cod…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-7683

Published May 3, 2026

A weakness has been identified in Edimax BR-6428nC up to 1.16. This affects an unknown function of the file /goform/setWAN of the component Web Interface. This manipulation of the…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-7682

Published May 3, 2026

A security flaw has been discovered in Edimax BR-6208AC 1.02. The impacted element is the function setWAN of the file /goform/setWAN of the component L2TP Mode. The manipulation o…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-7653

Published May 2, 2026

A security flaw has been discovered in r-huijts mcp-server-rijksmuseum up to 1.0.4. Affected is the function open_image_in_browser of the file src/index.ts of the component MCP In…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-7642

Published May 2, 2026

A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the component MCP Interface. Perform…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-7629

Published May 2, 2026

A flaw has been found in kleneway awesome-cursor-mpc-server up to 2.0.1. Impacted is the function runCodeReviewTool of the file src/tools/codeReview.ts of the component Ccode-Revi…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-7628

Published May 2, 2026

A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function executeRepomix of the file src/repomix.ts of the component RepoM…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-7609

Published May 2, 2026

A flaw has been found in TRENDnet TEW-821DAP up to 1.12B01. The impacted element is the function tools_diagnostic of the file /tmp/diagnostic of the component Firmware Udpate. Thi…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-7608

Published May 2, 2026

A vulnerability was detected in TRENDnet TEW-821DAP up to 1.12B01. The affected element is the function tools_diagnostic. The manipulation results in os command injection. The exp…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-7600

Published May 2, 2026

A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This impacts the function yii_command_help/yii_execute_command of the file src/index.ts of the component MCP Interface. Ex…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-7593

Published May 1, 2026

A security vulnerability has been detected in Sunwood-ai-labs command-executor-mcp-server up to 0.1.0. This impacts the function execute_command of the file src/index.ts of the co…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-7590

Published May 1, 2026

A vulnerability was identified in eyal-gor p_69_branch_monkey_mcp up to 69bc71874ce40050ef45fde5a435855f18af3373. The affected element is an unknown function of the file branch_mo…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-26461

Published May 1, 2026

A Command Injection vulnerability in the web management interface in Aver PTC320UV2 0.1.0000.65 allows an unauthenticated attacker to execute arbitrary commands via a crafted web…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-7548

Published May 1, 2026

A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. This affects the function sub_41A68C of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the arg…

CVSS 7.4 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-7538

Published May 1, 2026

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function Vulnerability of the file /cgi-bin/cstecgi.cgi of the component CGI Handler…

CVSS 8.9 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-7246

Published Apr 30, 2026

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivile…

CVSS 7.2 · High
evidence mentions
8
Buzz score
40.0
Vendor/product tagsBeta · best-effort
Showing 276-300 of 3,626 CVEsPage 12 of 146