Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2981 articles · 185103 vulns · 37/41 feeds (7d)

Latest Security News

Recently analyzed articles from 41 RSS feeds across official advisories, government CERTs, security research, and community sources.

Tier A: Official
Tier B: Gov CERT
Tier C: Research
Tier D: News
Tier E: Community
Status:
AllAnalyzedQueuedSignal Only
C
CVE-2026-19365 | Ichigo3766 image-gen-mcp 0.1.0 upscale_images src/index.ts output_path path traversal
VulDB·8h ago·cve_linking
C
CVE-2026-19364 | itsourcecode Hospital Management System 1.0 viewdoctorconsultancycharge.php delid sql injection
VulDB·8h ago·cve_linking
C
CVE-2026-19363 | lmammino oidc-authorizer up to 0.4.0 Fixed Message src/handler.rs unwrap jwtClaims deserialization
VulDB·8h ago·cve_linking
C
CVE-2026-19362 | lmammino oidc-authorizer 0.4.0 Authorization Header Parsing parse_token_from_header.rs parse_token_from_header authorization_token denial of service
VulDB·8h ago·cve_linking
C
CVE-2026-19361 | macrozheng mall 0504e86 mall-portal /sso/getAuthCode password recovery (Issue 979)
VulDB·9h ago·cve_linking
C
CVE-2026-19360 | wongcyrus ExcelLexBot up to 0.0.3 Lambda Function ExcelLexBotS3TriggerFunction privileges management
VulDB·9h ago·cve_linking
C
CVE-2026-19359 | nxp-auto-goldvip gvip up to 1.4.0 Lambda Function SitewiseCustomFunction access control
VulDB·9h ago·cve_linking
C
CVE-2026-19358 | 3CORESec Trapdoor up to 1.2.2 DefaultFunction access control
VulDB·9h ago·cve_linking
C
CVE-2026-19357 | MingSoft MCMS up to 3.0.6 ms-mdiy /mdiy/form/get information disclosure
VulDB·9h ago·cve_linking
C
CVE-2026-19356 | MingSoft MCMS up to 3.0.6 ms-mdiy /mdiy/form/data/list information disclosure
VulDB·9h ago·cve_linking
C
CVE-2026-19355 | MingSoft MCMS up to 3.0.6 ms-mdiy /mdiy/form/data/list.do ModelDataImpl.queryDiyFormData formFields sql injection
VulDB·9h ago·cve_linking
C
CVE-2026-19354 | lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09 IN Clause message.go ids sql injection
VulDB·9h ago·cve_linking
C
CVE-2026-19353 | DedeCMS up to 5.7.118 UTF8SP2 Installation Wizard install/index.php _4_Setup file inclusion
VulDB·10h ago·cve_linking
C
CVE-2026-19352 | mifi lossless-cut up to 3.69.0 Built-in HTTP API Service src/main/httpServer.ts server-side request forgery
VulDB·11h ago·cve_linking
C
CVE-2026-19351 | dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28 Request Parameter lib/Select.js SelectQuery.from/SelectQuery.build sql injection
VulDB·12h ago·cve_linking
C
CVE-2026-19350 | Dolibarr ERP up to 23.0.3 TakePOS invoice.php fail authorization (Issue 38949)
VulDB·12h ago·cve_linking
C
CVE-2026-61899 | Apache Tapestry information disclosure
VulDB·13h ago·cve_linking
C
CVE-2026-63225 | redocly redocly-cli up to 2.32.2 Split Command iterate-components.ts path traversal (GHSA-657c-g7qc-r9j2)
VulDB·14h ago·cve_linking
C
CVE-2026-63325 | redocly redocly-cli up to 2.32.2 Arazzo Faker Runtime Expression get-value-from-context.ts code injection (GHSA-xw2f-5386-m542)
VulDB·14h ago·cve_linking
C
CVE-2026-19348 | Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a sprintf enable/name/mac command injection
VulDB·14h ago·cve_linking
C
CVE-2026-19347 | itsourcecode Hospital Management System 1.0 /viewdoctor.php delid sql injection
VulDB·14h ago·cve_linking
C
CVE-2026-19346 | Tenda CH22 1.0.0.1 /goform/CertListInfo formCertListInfo Name command injection
VulDB·15h ago·cve_linking
C
CVE-2026-19345 | code-projects Task Management System 1.0 UpdateTaskStatus.php task_id/val authorization
VulDB·15h ago·cve_linking
C
CVE-2026-19344 | code-projects Task Management System 1.0 comment_count_user.php task_id sql injection
VulDB·15h ago·cve_linking
C
CVE-2026-19343 | code-projects Task Management System 1.0 /admin/AdminLogin.php email/password sql injection
VulDB·15h ago·cve_linking
C
CVE-2026-19342 | code-projects Task Management System 1.0 Login /index.php Password improper authentication
VulDB·15h ago·cve_linking
C
CVE-2026-19341 | UTT HiPER 1200GW up to 2.5.3-170306 pptpSrvGlobalConfig strcpy EncryptionMode stack-based overflow
VulDB·17h ago·cve_linking
C
CVE-2026-19340 | anubissbe ProjectHub-Mcp up to 5.0.0 Webhooks API complete_backend.js url server-side request forgery (Issue 176)
VulDB·17h ago·cve_linking
C
CVE-2026-19339 | aliyun alibabacloud-dataworks-mcp-server up to 1.0.43 initResources.ts ReadResourceRequestSchema request.params.uri server-side request forgery
VulDB·17h ago·cve_linking
C
CVE-2026-19338 | automateyournetwork MCPyATS up to 0.1.4 generate_mermaid_markdown index.ts processGenerateRequest folder/name path traversal
VulDB·18h ago·cve_linking
C
CVE-2026-19337 | adenot mcp-google-search up to 0.3.1 read_webpage src/index.ts url server-side request forgery
VulDB·18h ago·cve_linking
C
CVE-2026-19336 | Pimzino spec-workflow-mcp up to 2.2.6 src/tools/approvals.ts ApprovalStorage.createApproval categoryName path traversal
VulDB·18h ago·cve_linking
C
CVE-2026-19335 | Jane-xiaoer skill-vision-control up to 1.3.0 src/svc/utils/config.ts getSkillVersionsDir skillName path traversal
VulDB·18h ago·cve_linking
C
CVE-2026-19334 | NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9 src/index.ts name/modelfile/source/destination command injection
VulDB·18h ago·cve_linking
C
CVE-2026-19333 | NightTrek Supabase-MCP generate_types schema command injection
VulDB·18h ago·cve_linking
C
CVE-2026-19332 | NellyW8 MCP4EDA 1.0.0 run_openlane/view_waveform design_name/vcd_file command injection
VulDB·18h ago·cve_linking
C
CVE-2026-19331 | bazylhorsey obsidian-mcp-server 1.0.0 CanvasService.ts readCanvas/writeCanvas path traversal
VulDB·19h ago·cve_linking
C
CVE-2026-19330 | angrysky56 advanced-reasoning-mcp 1.0.0 src/index.ts path traversal
VulDB·19h ago·cve_linking
C
CVE-2026-19329 | andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390 ask MCP Tool codex-process-simple.ts model command injection
VulDB·19h ago·cve_linking
C
CVE-2026-19328 | aktsmm skill-ninja-mcp-server 0.1.0 src/installer.ts workspacePath path traversal
VulDB·19h ago·cve_linking
C
CVE-2026-19327 | abracadabra50 claude-sesh 1.0.0 src/services/enricher.ts getEnrichedData/enrichSession sessionId path traversal
VulDB·19h ago·cve_linking
C
CVE-2026-19326 | Jevon-Zhong Ai-doctor 0.0.1 filemanagement.service.ts deleteImage imagePath path traversal
VulDB·19h ago·cve_linking
C
CVE-2026-68081: KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state
Linux Kernel CVEs·19h ago·cve_linking
C
CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers()
Linux Kernel CVEs·19h ago·cve_linking
C
CVE-2026-19325 | IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e read_memory_bank_file/append_memory_bank_entry src/index.ts readMemoryBankFile/appendMemoryBankEntry file_name path traversal
VulDB·19h ago·cve_linking
C
CVE-2026-19324 | HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38 callback-server.ts fs.promises.readFile filepath path traversal
VulDB·19h ago·cve_linking
C
CVE-2026-19323 | azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0 analyze-projec src/index.ts generateProjectDocs projectName path traversal
VulDB·19h ago·cve_linking
C
CVE-2026-19288 | astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e importRiveFile Flow importRiveFile.ts libraryId path traversal
VulDB·1d ago·cve_linking
C
CVE-2026-19287 | abrinsmead mindpilot-mcp 0.5.0 HistoryService ID path traversal
VulDB·1d ago·cve_linking
C
CVE-2026-19285 | aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c src/tools/memoryTools.ts path traversal
VulDB·1d ago·cve_linking
Articles are automatically fetched from RSS feeds, pre-filtered for security relevance, and analyzed by LLM for vulnerability extraction. View feed sources