NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-45609 mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to ... 2026-05-29 7.2 NETWORK HIGH NVD
CVE-2026-41159 Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's defaul... 2026-05-29 5.3 NETWORK MEDIUM NVD
CVE-2026-41150 Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial... 2026-05-29 5.3 NETWORK MEDIUM NVD
CVE-2026-10063 A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipu... 2026-05-29 8.8 NETWORK HIGH NVD
CVE-2026-10062 A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSet... 2026-05-29 8.8 NETWORK HIGH NVD
CVE-2026-47696 WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits the logged-in user's wallet bas... 2026-05-29 7.1 NETWORK HIGH NVD
CVE-2026-47694 WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input and later renders category_desc... 2026-05-29 5.4 NETWORK MEDIUM NVD
CVE-2026-46510 form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys (e.g. name[sub]) into nested o... 2026-05-29 8.2 NETWORK HIGH NVD
CVE-2026-46376 FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) ... 2026-05-29 9.3 NETWORK CRITICAL NVD
CVE-2026-46337 WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary image files anywhere on disk ... 2026-05-29 6.9 NETWORK MEDIUM NVD
CVE-2026-45731 WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relative path under updatedb/ and p... 2026-05-29 6.9 NETWORK MEDIUM NVD
CVE-2026-45707 n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_... 2026-05-29 8.1 NETWORK HIGH NVD
CVE-2026-45620 WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an en... 2026-05-29 5.3 NETWORK MEDIUM NVD
CVE-2026-45619 WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the ... 2026-05-29 6.5 NETWORK MEDIUM NVD
CVE-2026-45615 mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated b... 2026-05-29 8.2 NETWORK HIGH NVD