Vulnerabilities
Summary — last 7 days
New vulnerabilities3,043▲ 582 vs. last week
Critical / high1,452▲ 283 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)393▲ 186 vs. last week
6 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Critical (10) | 0.78% | — | Ui-tars-desktop Mcp-http-serverAIAgent-infra Mcp-server-commandsAIAgent-infra Mcp-server-filesystemAI | 8/27/2026 | 9/23/2026 | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authentication middleware was optional: middlewares are applied only when a… | |
| Awaiting Analysis | High (8.7) | 0.75% | — | Amazon Aws-smithy-http-serverAI | 7/23/2026 | 8/12/2026 | Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets… | |
| Analyzed | Medium (6.1) | 0.32% | — | Adonisjs Http-serverAdonisjs Core | 4/16/2026 | 6/17/2026 | AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In @adonisjs/http-server versions prior to 7.8.1 and 8.0.0-next.0 through 8.1.3, and @adonisjs/core versions prior to 7.4.0, the response.redirect().back() method reads the Referer header from the incoming HTTP request and… | |
| Modified | Critical (9.8) | 1.7% | — | Http-server-node Project Http-server-node | 12/17/2021 | 6/17/2026 | All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is. | |
| Modified | Medium (5.4) | 0.71% | — | Min-http-server Project Min-http-server | 7/30/2019 | 6/17/2026 | Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser. | |
| Modified | Medium (6.5) | 1.5% | — | Angular-http-server Project Angular-http-server | 6/7/2018 | 6/17/2026 | angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilename, which allows a malicious user to read content of any file with known path. |