Vulnerabilities
Summary — last 7 days
New vulnerabilities2,687▼ 646 vs. last week
Critical / high1,266▼ 292 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)250▼ 252 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Low (1.9) | 1.1% | — | Dedeveloper23 Codebase-mcpAI | 3/29/2026 | 6/17/2026 | A vulnerability has been found in DeDeveloper23 codebase-mcp up to 3ec749d237dd8eabbeef48657cf917275792fde6. This vulnerability affects the function getCodebase/getRemoteCodebase/saveCodebase of the file src/tools/codebase.ts of the component RepoMix Command Handler. Such manipulation leads to os command injection.… | |
| Modified | Medium (4.6) | 0.55% | — | Magic Edeveloper | 12/17/2001 | 6/16/2026 | Magic eDeveloper Enterprise Edition 8.30-5 and earlier allows local users to overwrite arbitrary files and possibly execute code via a symlink attack on temporary files created by the (1) mkuserproc, (2) mgrnt, and (3) mgdatasrvr.sc scripts. |