
NVD · 实时热榜
- 01CVE-2026-71953 · CRITICAL 9.3
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges.
最高第 3 名01:24 达到01:24 首次观测上榜11:32 观测离榜累计约10小时8分 - 02CVE-2026-71954 · CRITICAL 9.3
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.
最高第 2 名01:24 达到01:24 首次观测上榜11:32 观测离榜累计约10小时8分 - 03CVE-2026-71955 · CRITICAL 9.3
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges.
最高第 1 名01:24 达到01:24 首次观测上榜11:32 观测离榜累计约10小时8分 - 04CVE-2026-71958 · CRITICAL 9.3
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
最高第 1 名02:28 达到02:28 首次观测上榜12:20 观测离榜累计约9小时52分 - 05CVE-2026-19337 · LOW 1.9
A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a manipulation of the argument url can lead to server-side request forgery. The attack is restricted to local execution. This patch is called f071d491b685011ca04e8ab8d586fc65f86bcee1. It is advisable to implement a patch to correct this issue.
最高第 1 名14:28 达到14:28 首次观测上榜当日结束时仍在榜累计约9小时20分 - 06CVE-2026-19336 · MEDIUM 4.8
A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the argument categoryName results in path traversal. The attack is only possible with local access. Upgrading to version 2.2.7 is capable of addressing this issue. The patch is named 9c7a7839e690bb4543f0e7481b5740d23808e5fe. It is advisable to upgrade the affected component.
最高第 2 名14:28 达到14:28 首次观测上榜23:32 观测离榜累计约9小时4分 - 07CVE-2026-71956 · CRITICAL 9.3
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges.
最高第 3 名02:28 达到02:28 首次观测上榜11:32 观测离榜累计约9小时4分 - 08CVE-2026-71957 · CRITICAL 9.3
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
最高第 2 名02:28 达到02:28 首次观测上榜11:32 观测离榜累计约9小时4分 - 09CVE-2026-71952 · CRITICAL 9.3
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in command execution with root privileges.
最高第 4 名01:24 达到01:24 首次观测上榜10:28 观测离榜累计约9小时4分 - 10CVE-2026-19288 · LOW 1.9
A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affects an unknown part of the file packages/mcp-server/src/tools/importRiveFile.ts of the component importRiveFile Flow. Such manipulation of the argument libraryId leads to path traversal. The attack needs to be performed locally. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.
最高第 1 名00:00 达到当日首次采集时已在榜08:20 观测离榜累计约8小时20分 - 11CVE-2026-19338 · LOW 1.9
A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component generate_mermaid_markdown. The manipulation of the argument folder/name leads to path traversal. The attack must be carried out locally.
最高第 4 名15:32 达到15:32 首次观测上榜当日结束时仍在榜累计约8小时16分 - 12CVE-2026-19339 · LOW 2.1
A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation of the argument request.params.uri results in server-side request forgery. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
最高第 3 名15:32 达到15:32 首次观测上榜当日结束时仍在榜累计约8小时16分 - 13CVE-2026-19340 · LOW 2.1
A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js of the component Webhooks API. This manipulation of the argument url causes server-side request forgery. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.
最高第 2 名15:32 达到15:32 首次观测上榜当日结束时仍在榜累计约8小时16分 - 14CVE-2026-19341 · HIGH 7.4
A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of the argument EncryptionMode leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
最高第 1 名15:32 达到15:32 首次观测上榜当日结束时仍在榜累计约8小时16分 - 15CVE-2026-42170 · HIGH 7.8
A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized heap buffer. Subsequent pixel data consumption at the real format's stride causes a write past the heap buffer boundary, leading to heap metadata corruption and potential code execution.
最高第 2 名00:20 达到00:20 首次观测上榜08:20 观测离榜累计约8小时 - 16CVE-2026-67620 · MEDIUM 6.3
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadata endpoint 100.100.100.200, allowing authenticated attackers to force the server to issue arbitrary GET requests to cloud instance metadata services. Attackers can send requests to the fetch-links API endpoint with a crafted URL parameter, bypassing deny-list validation including redirect-based bypasses, to reach instance metadata services and expose instance identity data and role credentials on Oracle Cloud Infrastructure or Alibaba Cloud deployments, with unauthenticated access possible when URL-fetching nodes exist in public chatflows.
最高第 1 名00:20 达到00:20 首次观测上榜08:20 观测离榜累计约8小时 - 17CVE-2026-18473 · UNKNOWN
The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
最高第 5 名14:28 达到14:28 首次观测上榜22:28 观测离榜累计约8小时 - 18CVE-2026-18603 · UNKNOWN
The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding the contents of a previous order to the cart, allowing unauthenticated users to disclose the contents of other customers' orders, as well as to clear and repopulate a logged in user's cart via a crafted link.
最高第 4 名14:28 达到14:28 首次观测上榜22:28 观测离榜累计约8小时 - 19CVE-2026-19335 · LOW 1.9
A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the file src/svc/utils/config.ts. Such manipulation of the argument skillName leads to path traversal. The attack can only be performed from a local environment. The project was informed of the problem early through an issue report but has not responded yet.
最高第 3 名14:28 达到14:28 首次观测上榜22:28 观测离榜累计约8小时 - 20CVE-2026-19287 · LOW 1.9
A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the component HistoryService. This manipulation of the argument ID causes path traversal. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.
最高第 2 名00:00 达到当日首次采集时已在榜07:32 观测离榜累计约7小时32分 - 21CVE-2026-19342 · MEDIUM 5.5
A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Password results in improper authentication. The attack is possible to be carried out remotely. The exploit is now public and may be used.
最高第 2 名16:20 达到16:20 首次观测上榜当日结束时仍在榜累计约7小时28分 - 22CVE-2026-19343 · MEDIUM 5.5
A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a manipulation of the argument email/password can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.
最高第 1 名16:20 达到16:20 首次观测上榜当日结束时仍在榜累计约7小时28分 - 23CVE-2026-18464 · UNKNOWN
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.
最高第 7 名14:28 达到14:28 首次观测上榜21:24 观测离榜累计约6小时56分 - 24CVE-2026-18465 · UNKNOWN
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-controlled path before using it in a file inclusion, allowing unauthenticated attackers to include and execute arbitrary existing local PHP files on the server.
最高第 6 名14:28 达到14:28 首次观测上榜21:24 观测离榜累计约6小时56分 - 25CVE-2026-71944 · CRITICAL 9.3
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.
最高第 12 名01:24 达到01:24 首次观测上榜08:20 观测离榜累计约6小时56分 - 26CVE-2026-71945 · CRITICAL 9.3
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.
最高第 11 名01:24 达到01:24 首次观测上榜08:20 观测离榜累计约6小时56分 - 27CVE-2026-71946 · CRITICAL 9.3
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.
最高第 10 名01:24 达到01:24 首次观测上榜08:20 观测离榜累计约6小时56分 - 28CVE-2026-71947 · CRITICAL 9.3
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges.
最高第 9 名01:24 达到01:24 首次观测上榜08:20 观测离榜累计约6小时56分 - 29CVE-2026-71948 · CRITICAL 9.3
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.
最高第 8 名01:24 达到01:24 首次观测上榜08:20 观测离榜累计约6小时56分 - 30CVE-2026-71949 · CRITICAL 9.3
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue fields, resulting in command execution with root privileges.
最高第 7 名01:24 达到01:24 首次观测上榜08:20 观测离榜累计约6小时56分 - 31CVE-2026-71950 · CRITICAL 9.3
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting in command execution with root privileges.
最高第 6 名01:24 达到01:24 首次观测上榜08:20 观测离榜累计约6小时56分 - 32CVE-2026-71951 · CRITICAL 9.3
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in command execution with root privileges.
最高第 5 名01:24 达到01:24 首次观测上榜08:20 观测离榜累计约6小时56分 - 33CVE-2026-19285 · LOW 1.9
A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vulnerability is the function JsonMemoryStorage.createDomain/JsonMemoryStorage.getMemories/JsonMemoryStorage.saveMemories of the file src/tools/memoryTools.ts. The manipulation results in path traversal. The attack must be initiated from a local position. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.
最高第 3 名00:00 达到当日首次采集时已在榜06:28 观测离榜累计约6小时28分 - 34CVE-2026-71987 · CRITICAL 9.3
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
最高第 7 名08:20 达到08:20 首次观测上榜14:28 观测离榜累计约6小时8分 - 35CVE-2026-71988 · CRITICAL 9.3
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
最高第 6 名08:20 达到08:20 首次观测上榜14:28 观测离榜累计约6小时8分 - 36CVE-2026-71989 · CRITICAL 9.3
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
最高第 5 名08:20 达到08:20 首次观测上榜14:28 观测离榜累计约6小时8分 - 37CVE-2026-71990 · CRITICAL 9.3
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the SSH configuration interface to inject malicious commands and obtain root privileges on the underlying system.
最高第 4 名08:20 达到08:20 首次观测上榜14:28 观测离榜累计约6小时8分 - 38CVE-2026-71991 · CRITICAL 9.3
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the Telnet configuration interface to inject malicious commands and obtain root privileges on the underlying system.
最高第 3 名08:20 达到08:20 首次观测上榜14:28 观测离榜累计约6小时8分 - 39CVE-2026-71992 · CRITICAL 9.3
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.
最高第 2 名08:20 达到08:20 首次观测上榜14:28 观测离榜累计约6小时8分 - 40CVE-2026-71993 · CRITICAL 9.3
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.
最高第 1 名08:20 达到08:20 首次观测上榜14:28 观测离榜累计约6小时8分 - 41CVE-2026-18357 · UNKNOWN
The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated attackers to retrieve sensitive order data belonging to any customer of the store, such as billing names, order IDs and statuses, fee amounts and order dates.
最高第 8 名14:28 达到14:28 首次观测上榜20:20 观测离榜累计约5小时52分 - 42CVE-2026-71502 · MEDIUM 5.1
CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can create a public conversion whose name or description contains a malicious Vue expression using the application's configured [[ ... ]] delimiters. User profile names may provide an additional injection vector. Although Jinja HTML escaping is applied, the resulting value is subsequently included in a DOM region compiled by Vue. Vue interprets the attacker-controlled value as a template expression rather than ordinary text. By accessing the JavaScript Function constructor from within the expression, an attacker can execute arbitrary JavaScript in the security context of the CTI-Transmute origin. The application's nonce-based Content Security Policy does not prevent exploitation because the Vue runtime compiler requires the unsafe-eval policy exception. The malicious payload is stored by the application and executed whenever another user opens an affected page, such as the public conversion detail page. The victim may be a normal user or an administrator. Successful exploitation could allow the attacker to: * Access data available to the victim through the application. * Extract API keys, tokens, or other sensitive information exposed to the page. * Perform authenticated actions using the victim's session. * Modify conversions or other application data. * Escalate the impact by targeting an administrator. A demonstrated payload can use [].constructor.constructor(...) to obtain the JavaScript Function constructor and execute arbitrary code. The regression tests also show that a short first-stage payload could retrieve an uncapped conversion description and evaluate a larger second-stage payload. The patch addresses the vulnerability by registering a global Jinja finalize hook that inserts a zero-width Unicode word joiner inside every Vue delimiter found in server-rendered values. This prevents Vue from recognizing the values as template expressions while preserving their visible representation.
最高第 1 名06:28 达到06:28 首次观测上榜12:20 观测离榜累计约5小时52分 - 43CVE-2026-19344 · MEDIUM 5.5
A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/comment_count_user.php. The manipulation of the argument task_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
最高第 3 名18:28 达到18:28 首次观测上榜当日结束时仍在榜累计约5小时20分 - 44CVE-2026-19345 · MEDIUM 5.5
A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in missing authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used.
最高第 2 名18:28 达到18:28 首次观测上榜当日结束时仍在榜累计约5小时20分 - 45CVE-2026-19346 · HIGH 7.4
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
最高第 1 名18:28 达到18:28 首次观测上榜当日结束时仍在榜累计约5小时20分 - 46CVE-2026-19323 · LOW 1.9
A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function generateProjectDocs of the file src/index.ts of the component analyze-projec. The manipulation of the argument projectName results in path traversal. The attack is only possible with local access. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.
最高第 11 名08:20 达到08:20 首次观测上榜13:24 观测离榜累计约5小时4分 - 47CVE-2026-71984 · CRITICAL 9.3
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function to inject malicious commands and obtain root privileges on the underlying system.
最高第 10 名08:20 达到08:20 首次观测上榜13:24 观测离榜累计约5小时4分 - 48CVE-2026-71985 · CRITICAL 9.3
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the accesscontrol function to execute malicious commands and obtain root privileges on the underlying system.
最高第 9 名08:20 达到08:20 首次观测上榜13:24 观测离榜累计约5小时4分 - 49CVE-2026-71986 · CRITICAL 9.3
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the dmz function to execute malicious commands and obtain root privileges on the underlying system.
最高第 8 名08:20 达到08:20 首次观测上榜13:24 观测离榜累计约5小时4分 - 50CVE-2026-17044 · UNKNOWN
The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.
最高第 11 名14:28 达到14:28 首次观测上榜19:32 观测离榜累计约5小时4分


































































































