CVE-2026-19342
A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the comp
CVSS
7.3
High
EPSS
0.4%
p33
KEV
—
Exploit Today
10
0-100
Published: Aug 9, 2026 · Last modified: Aug 9, 2026 · CWE-287
Not enough EPSS history yet.
A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Password results in improper authentication. The attack is possible to be carried out remotely. The exploit is now public and may be used.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-40920——
——0Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixes this issue.4hCVE-2026-480399.1 CRI27.0%
——8Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP requests to downstream MCP tool handlers without issuing a `401` response, allowing any network-reachable caller to invoke MCP tools without authentication. When no per-request credential is present, tool handlers fall back to the `META_ACCESS_TOKEN` environment variable, and when the downstream Meta Graph API call fails, `api.py:263–269` serialises the raw `httpx` request URL—including the operator's `access_token` as a query parameter—into the JSON-RPC response body, delivering the credential to the unauthenticated caller. Version 1.0.109 fixes the issue.3dCVE-2026-567937.7 HIG23.7%
——7Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.2dCVE-2026-160308.1 HIG13.3%
——4The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.3dCVE-2026-142059.8 CRI18.7%
——6The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.3dCVE-2026-628969.6 CRI30.9%
——9Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.3d