A vulnerability marked as critical has been reported in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc. Affected by this vulnerability is an unknown functionality of the file src/aider_mcp_server/server.py of the component aider_ai_code. This manipulation of the argument relative_editable_files causes command injection.
This vulnerability is registered as CVE-2026-7157. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability labeled as critical has been found in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument HTTP results in os command injection.
This vulnerability is cataloged as CVE-2026-7156. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability identified as critical has been detected in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setLoginPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument admpass leads to os command injection.
This vulnerability is listed as CVE-2026-7155. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability categorized as critical has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setAdvancedInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument tty_server can lead to os command injection.
This vulnerability is tracked as CVE-2026-7154. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. It has been rated as critical. The impacted element is the function setMiniuiHomeInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument sys_info results in os command injection.
This vulnerability is identified as CVE-2026-7153. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. It has been declared as critical. The affected element is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument telnet_enabled leads to os command injection.
This vulnerability is referenced as CVE-2026-7152. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability was found in Tenda HG3 2.0. It has been classified as critical. Impacted is the function formUploadConfig of the file /boaform/formIPv6Routing. This manipulation of the argument destNet causes stack-based buffer overflow.
The identification of this vulnerability is CVE-2026-7151. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b and classified as critical. This issue affects the function generate_favicon_from_url of the file src/auto_favicon/server.py of the component MCP Tool. The manipulation of the argument image_url results in server-side request forgery.
This vulnerability was named CVE-2026-7150. The attack may be performed from remote. In addition, an exploit is available.
This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d and classified as critical. This vulnerability affects the function prepare_kaggle_dataset of the file src/kaggle_mcp/server.py. The manipulation of the argument competition_id leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-7149. The attack is possible to be carried out remotely. Moreover, an exploit is present.
This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability, which was classified as critical, was found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the argument fname can lead to sql injection.
This vulnerability is handled as CVE-2026-7148. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability, which was classified as critical, has been found in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/routes/llm.js of the component LLM Models API. Performing a manipulation of the argument req.query.base_url results in server-side request forgery.
This vulnerability is known as CVE-2026-7147. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.