Vulnerabilities (CVE)

Total 397529 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-82112 2026-08-28 4.0 MEDIUM 3.5 LOW
A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component code_task_files. Executing a manipulation can lead to path traversal. The attack can be launched remotely. This patch is called 35d97bca0531894da36a85aedb95312da1bd5b7a. It is best practice to apply a patch to resolve this issue.
CVE-2026-81851 2026-08-28 N/A N/A
A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash the IKE daemon (iked), resulting in a denial of service, by saving a specially crafted configuration.
CVE-2026-81848 2026-08-28 4.0 MEDIUM 3.5 LOW
A vulnerability was determined in cyberchitta scrapling-fetch-mcp up to 0.2.2. The impacted element is the function s_fetch_page/s_fetch_pattern of the file src/scrapling_fetch_mcp/_fetcher.py. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. Upgrading to version 0.2.3 is sufficient to resolve this issue. This patch is called 9f6f34e92c55c3d95566ad9c62aca7327d24533a. Upgrading the affected component is advised.
CVE-2026-81847 2026-08-28 6.5 MEDIUM 5.5 MEDIUM
A vulnerability was found in MAA-AI MaaMCP up to 1.1.1.dev6+g2e4a41287. The affected element is the function save_pipeline/load_pipeline of the file pipeline_tools.py. Performing a manipulation results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named c93ef45cba75295eba26d9ff1ffb9202a91c6150. To fix this issue, it is recommended to deploy a patch.
CVE-2026-81837 2026-08-28 7.5 HIGH 6.3 MEDIUM
A flaw has been found in RooCodeInc Roo-Code up to 3.51.1. This issue affects the function path.resolve of the file src/core/tools/ApplyPatchTool.ts of the component ApplyPatchTool. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been published and may be used. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-81835 2026-08-28 6.5 MEDIUM 5.5 MEDIUM
A security vulnerability has been detected in RooCodeInc Roo-Code up to 3.51.1. This affects the function fetch_instructions of the file malicious_mcp_server.py of the component MCP Integration Trust Model. The manipulation leads to code injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-81834 2026-08-28 7.5 HIGH 6.3 MEDIUM
A weakness has been identified in RooCodeInc Roo-Code up to 3.51.1. Affected by this issue is the function ExecaTerminalProcess of the component README File Handler. Executing a manipulation can lead to code injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-81777 2026-08-28 N/A 5.3 MEDIUM
Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This issue affects Essential Addons for Elementor: from n/a through 6.8.0.
CVE-2026-81767 2026-08-28 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
CVE-2026-81761 2026-08-28 N/A 4.3 MEDIUM
Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.
CVE-2026-81760 2026-08-28 N/A 7.1 HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.
CVE-2026-81759 2026-08-28 N/A 5.4 MEDIUM
Contributor Broken Access Control in WpEvently <= 5.5.0 versions.
CVE-2026-81757 2026-08-28 N/A 7.2 HIGH
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
CVE-2026-81299 2026-08-28 N/A 4.3 MEDIUM
Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
CVE-2026-81285 2026-08-28 N/A 7.5 HIGH
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.
CVE-2026-81284 2026-08-28 N/A 4.3 MEDIUM
Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
CVE-2026-81276 2026-08-28 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
CVE-2026-80433 2026-08-28 N/A 7.5 HIGH
Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
CVE-2026-79988 2026-08-28 N/A N/A
The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities.
CVE-2026-79256 1 Google 2 Android, Chrome 2026-08-28 N/A 8.3 HIGH
Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)