Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.6 CVE-2026-11719

CVE-2026-11719_CVE-2026-11719

An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol hand...

Google MCP Toolbox for Databases (googleapis/mcp-toolbox) 1.3.0 CVE
CRITICAL 9.3 CVE-2026-11718

CVE-2026-11718_CVE-2026-11718

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When th...

Google MCP Toolbox for Databases (googleapis/mcp-toolbox) 1.0.0 CVE
CRITICAL 9.3 CVE-2026-11717

CVE-2026-11717_CVE-2026-11717

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When ve...

Google MCP Toolbox for Databases (googleapis/mcp-toolbox) 1.0.0 CVE
HIGH 7.1 CVE-2026-54224

Denial of Service in UBB.threads_CVE-2026-54224

UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile on instances with many regis...

UBB Systems UBB.threads CVE
HIGH 8.6 CVE-2026-54223

Remote Code Execution via arbitrary file read and write in UBB.threads_CVE-2026-54223

UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any file on the application’s se...

UBB Systems UBB.threads CVE
HIGH 8.6 CVE-2026-54222

Blind SQL Injection in UBB.threads_CVE-2026-54222

UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to interact with the underlying da...

UBB Systems UBB.threads CVE
MEDIUM 5.1 CVE-2026-54221

Reflected XSS in UBB.threads_CVE-2026-54221

UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling attackers to execute arbitr...

UBB Systems UBB.threads CVE
HIGH 8.6 CVE-2026-54220

Cross-Site Request Forgery in UBB.threads_CVE-2026-54220

uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an attacker to trick an authen...

UBB Systems UBB.threads CVE
MEDIUM 5.1 CVE-2026-54219

Stored XSS in UBB.threads_CVE-2026-54219

UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly sanitize user input, allowing low...

UBB Systems UBB.threads CVE
MEDIUM 5.2 CVE-2026-9158

CVE-2026-9158_CVE-2026-9158

In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling po...

Eclipse Foundation Eclipse 4diac 3.0.0 CVE