π¨ CVE-2026-15055
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
π@cveNotify
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
π@cveNotify
GitHub
Bound PBES2 scrypt/PBKDF2 cost when decrypting PKCS#8 private keys Β· bcgit/bc-java@7ab4ee6
Bouncy Castle Java Distribution (Mirror). Contribute to bcgit/bc-java development by creating an account on GitHub.
π¨ CVE-2026-59638
In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).
π@cveNotify
In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).
π@cveNotify
GitHub
updated release note for JSSE hostname check feature Β· bcgit/bc-java@5ac5535
Bouncy Castle Java Distribution (Mirror). Contribute to bcgit/bc-java development by creating an account on GitHub.
π¨ CVE-2026-81202
A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD Operation Handler. Executing a manipulation of the argument action can lead to missing authentication. The attack may be performed from remote. The exploit has been published and may be used.
π@cveNotify
A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD Operation Handler. Executing a manipulation of the argument action can lead to missing authentication. The attack may be performed from remote. The exploit has been published and may be used.
π@cveNotify
GitHub
itsourcecode Payroll System V1.0 /ajax.php Missing Authentication on All API Endpoints (CWE-306, CVSS 9.8) Β· Issue #7 Β· microwaveabi/vul
Description The ajax.php file dispatches ALL CRUD operations (create/read/update/delete for users, employees, departments, positions, payroll, attendance, settings) without ANY authentication check...
π¨ CVE-2026-81203
A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
π@cveNotify
A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
π@cveNotify
GitHub
sourcecodester Simple Online Food Ordering System using PHP/MySQL V1.0 /fos/admin/ajax.php?action=login2 SQL injection Β· Issueβ¦
sourcecodester Simple Online Food Ordering System using PHP/MySQL V1.0 /fos/admin/ajax.php?action=login2 SQL injection NAME OF AFFECTED PRODUCT(S) Simple Online Food Ordering System using PHP/MySQL...
π¨ CVE-2026-81421
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - ddfourtwo/sentry-selfhosted-mcp: An MCP server for self-hosted sentry.
An MCP server for self-hosted sentry. Contribute to ddfourtwo/sentry-selfhosted-mcp development by creating an account on GitHub.
π¨ CVE-2026-81485
A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the function fs.readFileSync of the file src/tools/campaign-management.ts of the component Media Upload. Such manipulation of the argument filePath leads to path traversal. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the function fs.readFileSync of the file src/tools/campaign-management.ts of the component Media Upload. Such manipulation of the argument filePath leads to path traversal. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - danielpopamd/linkedin-ads-mcp: MCP server for LinkedIn Ads - access and analyze advertising data using Claude AI
MCP server for LinkedIn Ads - access and analyze advertising data using Claude AI - danielpopamd/linkedin-ads-mcp
π¨ CVE-2026-81486
A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_context of the file src/index.ts of the component Path Resolution. Performing a manipulation of the argument path results in path traversal. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_context of the file src/index.ts of the component Path Resolution. Performing a manipulation of the argument path results in path traversal. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - bsmi021/mcp-file-context-server: A Model Context Protocol (MCP) server that provides file system context to Large Languageβ¦
A Model Context Protocol (MCP) server that provides file system context to Large Language Models (LLMs). This server enables LLMs to read, search, and analyze code files with advanced caching and r...
π¨ CVE-2026-81491
A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
Arbitrary File Read, Write, and Delete Vulnerability in with-context-mcp Β· Issue #2 Β· boxpositron/with-context-mcp
Arbitrary File Read, Write, and Delete Vulnerability in with-context-mcp 1) CNA / Submission Type Submission type: Report a vulnerability (CVE ID request) Reporter role: Independent security resear...
π¨ CVE-2026-27330
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
π@cveNotify
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress Mobile App for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-32479
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
π@cveNotify
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
π@cveNotify
Patchstack
SQL Injection in WordPress Visitor Traffic Real Time Statistics Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-32564
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
π@cveNotify
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
π@cveNotify
Patchstack
SQL Injection in WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-32566
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
π@cveNotify
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
π@cveNotify
Patchstack
Privilege Escalation in WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78257
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
π@cveNotify
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
π@cveNotify
Patchstack
PHP Object Injection in WordPress Booking and Rental Manager Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78261
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Realtyna Organic IDX plugin Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78273
Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.
π@cveNotify
Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Fluent Boards Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78274
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
π@cveNotify
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
π@cveNotify
Patchstack
Arbitrary File Upload in WordPress Fluent Boards Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78275
Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.
π@cveNotify
Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.
π@cveNotify
Patchstack
Arbitrary File Deletion in WordPress Fluent Boards Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78281
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress CP Media Player Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.