Security advisories — page 5
- CVE-2026-63312highCVE-2026-63312 updated by NVD
- CVE-2026-11816highCVE-2026-11816 updated by NVD
- CVE-2026-54788highCVE-2026-54788 updated by NVD
- CVE-2026-46584lowApache Camel-Mail: The mail producer applied attacker-supplied mail.smtp.* / mail.smtps.* message headers as J
- CVE-2026-25718criticalGitea template repository generation follows unsafe filesystem paths
- CVE-2026-44827highDiffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components
- CVE-2024-7040mediumWithdrawn Advisory: Open WebUI Access Control
- CVE-2026-63445highCVE-2026-63445 updated by NVD
- CVE-2025-66336highApache Doris MCP Server is vulnerable to SQL Injection via metadata query path
- CVE-2026-8769low@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue
- CVE-2026-47698criticalCVE-2026-47698 updated by NVD
- CVE-2024-53412highNietThijmen ShoppingCart: Command injection in the connect function
- CVE-2026-56817highCVE-2026-56817 updated by NVD
- CVE-2026-52802mediumGogs has an Open Redirect via redirect_to
- CVE-2026-4598highCVE-2026-4598 updated by NVD
- CVE-2025-71348highPicklescan is missing detection when calling pytorch function torch.utils._config_module.load_config
- CVE-2026-57516highRay: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load
- CVE-2026-55559criticalCVE-2026-55559 updated by NVD
- CVE-2026-55607highClaude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
- CVE-2026-48206mediumApache Camel-JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter
- CVE-2026-46453mediumApache Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP
- CVE-2025-55013mediumAssemblyline 4 service client vulnerable to Arbitrary Write through path traversal in Client code
- CVE-2026-71324highCVE-2026-71324 updated by NVD
- CVE-2026-46591highApache Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cy
- CVE-2026-84997highCVE-2026-84997 updated by NVD
- CVE-2026-61554highCVE-2026-61554 updated by NVD
- CVE-2026-73841highCVE-2026-73841 updated by NVD
- CVE-2026-37004criticalCVE-2026-37004 updated by NVD
- CVE-2026-52814mediumGogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustio
- CVE-2026-62900mediumCVE-2026-62900 updated by NVD
- CVE-2026-72717criticalCVE-2026-72717 updated by NVD
- CVE-2026-52830criticalfast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
- CVE-2026-59879highImmutable.js `List` 32-bit trie overflow → unrecoverable DoS
- CVE-2026-5497highCVE-2026-5497 updated by NVD
- CVE-2026-5241criticalCVE-2026-5241 updated by NVD
- CVE-2026-55843highSnipe-IT has an Improper Privilege Management issue
- CVE-2026-72781highCVE-2026-72781 updated by NVD
- CVE-2026-21884highReact Router SSR XSS in ScrollRestoration
- CVE-2026-47300highCVE-2026-47300 updated by NVD
- CVE-2024-29888mediumSaleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method
- CVE-2023-41052mediumincorrect order of evaluation of side effects for some builtins
- CVE-2026-63128highCVE-2026-63128 updated by NVD
- CVE-2026-88045highCVE-2026-88045 updated by NVD
- CVE-2026-65591highCVE-2026-65591 updated by NVD
- CVE-2026-65597highCVE-2026-65597 updated by NVD
- CVE-2026-11720criticalMCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints
- CVE-2026-66906criticalCVE-2026-66906 updated by NVD
- CVE-2026-75516highCVE-2026-75516 updated by NVD
- CVE-2026-54527highjupyterlab-git extension: Stored XSS leading to RCE
- CVE-2026-81891highCVE-2026-81891 updated by NVD
- CVE-2026-24779highCVE-2026-24779 updated by NVD
- CVE-2026-12198mediumCVE-2026-12198 updated by NVD
- CVE-2026-57584highPhalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated
- CVE-2026-56745highCVE-2026-56745 updated by NVD
- CVE-2026-55851highCVE-2026-55851 updated by NVD
- CVE-2026-62681criticalCVE-2026-62681 updated by NVD
- CVE-2026-72716criticalCVE-2026-72716 updated by NVD
- CVE-2026-70470criticalCVE-2026-70470 updated by NVD
- CVE-2026-27775highGitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write
- CVE-2026-22547criticalGitea repository creation accepts insufficiently validated fields
- CVE-2026-10732mediumCVE-2026-10732 updated by NVD
- CVE-2026-6321highCVE-2026-6321 updated by NVD
- CVE-2026-62240highCVE-2026-62240 updated by NVD
- CVE-2026-49099mediumApache Camel-Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter
- CVE-2026-71479criticalCVE-2026-71479 updated by NVD
- CVE-2026-10143highCVE-2026-10143 updated by NVD
- CVE-2026-44911lowApache NiFi allows read-only users to submit component configuration verification request
- CVE-2026-63760highCVE-2026-63760 updated by NVD
- CVE-2026-39006criticalSNMP4J-Agent allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component
- CVE-2023-39522mediumWithdrawn Advisory: Username enumeration attack in goauthentik
- CVE-2026-75594highCVE-2026-75594 updated by NVD
- CVE-2026-58473criticalCognee allows non-superusers to overwrite global LLM configuration
- CVE-2025-59057highReact Router has XSS Vulnerability
- CVE-2026-59834highSiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
- CVE-2026-77415criticalCVE-2026-77415 updated by NVD
- CVE-2026-56812mediumPhoenix: Presence keys colliding with `Object.prototype` members break existence checks
- CVE-2026-45822mediumdecode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
- CVE-2024-39896highDirectus Allows Single Sign-On User Enumeration
- CVE-2026-72818highCVE-2026-72818 updated by NVD
- CVE-2025-62198mediumApache Atlas UI: Authenticated User XSS
- CVE-2026-44503highKiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
- CVE-2026-75915highCVE-2026-75915 updated by NVD
- CVE-2026-39835mediumCVE-2026-39835 updated by NVD
- CVE-2026-72819highCVE-2026-72819 updated by NVD
- CVE-2026-73649criticalCVE-2026-73649 updated by NVD
- CVE-2026-62682criticalCVE-2026-62682 updated by NVD
- CVE-2026-81887mediumCVE-2026-81887 updated by NVD
- CVE-2026-67317mediumCVE-2026-67317 updated by NVD
- CVE-2026-52804mediumGogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation
- CVE-2026-55220criticalCVE-2026-55220 updated by NVD
- CVE-2026-4602highCVE-2026-4602 updated by NVD
- CVE-2026-86043highCVE-2026-86043 updated by NVD
- CVE-2026-26232criticalGitea OAuth2 authorization codes can be reused after expiry
- CVE-2026-26247criticalGitea OAuth2 PKCE S256 verifier bypass
- CVE-2026-67429criticalCVE-2026-67429 updated by NVD
- CVE-2026-88018criticalCVE-2026-88018 updated by NVD
- CVE-2026-55761highPortainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
- CVE-2026-63223criticalCVE-2026-63223 updated by NVD
- CVE-2026-56382highCraft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
- CVE-2026-88044criticalCVE-2026-88044 updated by NVD
- CVE-2026-54591highasyncssh has SCP Path Traversal to Arbitrary File Write
- CVE-2026-67309highCVE-2026-67309 updated by NVD
- CVE-2026-45799highCVE-2026-45799 updated by NVD
- CVE-2026-80205highCVE-2026-80205 updated by NVD
- CVE-2026-63506highCVE-2026-63506 updated by NVD
- CVE-2026-65594mediumCVE-2026-65594 updated by NVD
- CVE-2026-81176mediumCVE-2026-81176 updated by NVD
- CVE-2026-65589mediumCVE-2026-65589 updated by NVD
- CVE-2026-39414highCVE-2026-39414 updated by NVD
- CVE-2026-55640criticalCVE-2026-55640 updated by NVD
- CVE-2026-54092highFile Browser has a DoS Vulnerability via Public Login API
- CVE-2026-59149medium@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (pr
- CVE-2026-10050highCVE-2026-10050 updated by NVD
- CVE-2026-52807mediumGogs has DOM-based XSS via Milestone Name on New Issue Page
- CVE-2026-25038highGitea: Unauthorized Access to Labels of Private Organizations
- CVE-2026-24451highGitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private
- CVE-2026-64825criticalCVE-2026-64825 updated by NVD
- CVE-2026-25712highGitea organization permission APIs expose hidden membership and private organization data
- CVE-2026-20779highGitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
- CVE-2026-73414criticalCVE-2026-73414 updated by NVD
- CVE-2025-71378mediumPicklescan is missing detection when calling built-in Python cProfile.runctx
- CVE-2026-33582mediumCVE-2026-33582 updated by NVD
- CVE-2026-71869criticalCVE-2026-71869 updated by NVD
- CVE-2026-71871criticalCVE-2026-71871 updated by NVD
- CVE-2026-71867criticalCVE-2026-71867 updated by NVD
- CVE-2026-71868criticalCVE-2026-71868 updated by NVD
- CVE-2026-71865criticalCVE-2026-71865 updated by NVD
- CVE-2026-71864criticalCVE-2026-71864 updated by NVD
- CVE-2026-71866criticalCVE-2026-71866 updated by NVD
- CVE-2026-56746mediumCVE-2026-56746 updated by NVD
- CVE-2026-52808highGogs's write-level collaborators can mutate admin-only repository settings via API
- CVE-2026-40575criticalOAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
- CVE-2026-50880criticalYouTransfer has an issue in the sendmail transport integration that allows arbitrary code execution
- CVE-2026-4599criticalCVE-2026-4599 updated by NVD
- CVE-2026-6322highCVE-2026-6322 updated by NVD
- CVE-2026-73089highCVE-2026-73089 updated by NVD
- CVE-2026-63643mediumCVE-2026-63643 updated by NVD
- CVE-2026-52811criticalGogs: UploadRepoFiles writes outside repo working tree via committed parent sym
- CVE-2024-58358mediumCVE-2024-58358 updated by NVD
- CVE-2026-54350criticalBudibase has nonymous NoSQL operator injection via published-app query templates
- CVE-2026-54091highFile Browser has incorrect access control for public directory shares via rule path rebasing
- CVE-2026-63490highCVE-2026-63490 updated by NVD
- CVE-2026-50629mediumCVE-2026-50629 updated by NVD
- CVE-2026-63421highCVE-2026-63421 updated by NVD
- CVE-2026-53437mediumCVE-2026-53437 updated by NVD
- CVE-2026-63481mediumCVE-2026-63481 updated by NVD
- CVE-2026-64868highCVE-2026-64868 updated by NVD
- CVE-2026-12481highKeras: Lambda deserialization can bypass safe mode and execute code
- CVE-2026-44745highCVE-2026-44745 updated by NVD
- CVE-2026-59832highSiyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets
- CVE-2026-56818mediumCVE-2026-56818 updated by NVD
- CVE-2026-64859criticalCVE-2026-64859 updated by NVD
- CVE-2026-22874criticalGitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter
- CVE-2026-34755mediumCVE-2026-34755 updated by NVD
- CVE-2026-50559highCVE-2026-50559 updated by NVD
- CVE-2026-79752criticalCVE-2026-79752 updated by NVD
- CVE-2026-61793mediumCVE-2026-61793 updated by NVD
- CVE-2023-54366highCVE-2023-54366 updated by NVD
- CVE-2026-75592mediumCVE-2026-75592 updated by NVD
- CVE-2026-71300criticalCVE-2026-71300 updated by NVD
- CVE-2026-73507highCVE-2026-73507 updated by NVD
- CVE-2026-73418highCVE-2026-73418 updated by NVD
- CVE-2026-54351highBudibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override
- CVE-2026-69147mediumCVE-2026-69147 updated by NVD
- CVE-2026-69218highCVE-2026-69218 updated by NVD
- CVE-2026-69203highCVE-2026-69203 updated by NVD
- CVE-2026-56368mediumImageMagick: Memory Leak in multiple coders that write raw pixel data
- CVE-2025-64076highcbor2 C extension decoder flaws can cause denial of service
- CVE-2026-54687mediumCVE-2026-54687 updated by NVD
- CVE-2026-50645highCVE-2026-50645 updated by NVD
- CVE-2026-56341highAVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, an
- CVE-2026-15074highCVE-2026-15074 updated by NVD
- CVE-2026-62388highCVE-2026-62388 updated by NVD
- CVE-2026-55565criticalCVE-2026-55565 updated by NVD
- CVE-2026-34742highCVE-2026-34742 updated by NVD
- CVE-2026-48204criticalApache Camel: camel-mongodb-gridfs producer allows GridFS operation override and NoSQL operator injection via
- CVE-2026-69153mediumCVE-2026-69153 updated by NVD
- CVE-2026-28705mediumGitea release asset dumps permit path traversal through crafted names
- CVE-2026-27657highGitea primary email ownership bypass allows cross-user email changes
- CVE-2026-24690highGitea pull request branch permission checks allow unauthorized updates and rebases
- CVE-2026-27660highGitea draft releases and attachments are exposed without write permission
- CVE-2026-53836highCVE-2026-53836 updated by NVD
- CVE-2026-63222highCVE-2026-63222 updated by NVD
- CVE-2026-73294criticalCVE-2026-73294 updated by NVD
- CVE-2026-62675highCVE-2026-62675 updated by NVD
- CVE-2026-55634criticalCVE-2026-55634 updated by NVD
- CVE-2026-25700highApache Answer: AdminToken not invalidated after admin deactivation
- CVE-2026-55245highCVE-2026-55245 updated by NVD
- CVE-2026-72778highCVE-2026-72778 updated by NVD
- CVE-2026-34487highApache Tomcat vulnerable to Insertion of Sensitive Information into Log File
- CVE-2026-62677highCVE-2026-62677 updated by NVD
- CVE-2026-54171mediumCVE-2026-54171 updated by NVD
- CVE-2026-65015highCVE-2026-65015 updated by NVD
- CVE-2026-50627criticalCVE-2026-50627 updated by NVD
- CVE-2024-6875mediumInfinispan Potential Out of Memory Error via REST Compare API Buffer API
- CVE-2026-55585highCVE-2026-55585 updated by NVD
- CVE-2026-70477criticalCVE-2026-70477 updated by NVD
- CVE-2026-39852highCVE-2026-39852 updated by NVD
- CVE-2026-55092highTrivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
- CVE-2026-49486highCVE-2026-49486 updated by NVD
- CVE-2026-86000mediumCVE-2026-86000 updated by NVD
- CVE-2026-69202highCVE-2026-69202 updated by NVD
- CVE-2026-73232highCVE-2026-73232 updated by NVD
- CVE-2026-55068criticalCVE-2026-55068 updated by NVD
- CVE-2026-63188highCVE-2026-63188 updated by NVD
- CVE-2026-65590mediumCVE-2026-65590 updated by NVD
- CVE-2026-15529mediumPyOD persistence.load deserializes untrusted artifacts before validation
- CVE-2026-61449mediumGrav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
- CVE-2026-54658criticalCVE-2026-54658 updated by NVD
- CVE-2025-64719mediumGogs has a Denial of Service in repository/wiki file listing web pages
- CVE-2026-59823mediumCVE-2026-59823 updated by NVD
- CVE-2026-73088highCVE-2026-73088 updated by NVD
- CVE-2026-55466mediumSnipe-IT vulnerable to stored XSS via inline-served attachment
- CVE-2026-55460highSnipe-IT has an authorization bypass on bulk editing users
- CVE-2026-71320highCVE-2026-71320 updated by NVD
- CVE-2026-49755highCVE-2026-49755 updated by NVD
- CVE-2026-44727criticalCVE-2026-44727 updated by NVD
- CVE-2026-5422highCVE-2026-5422 updated by NVD
- CVE-2026-86003highCVE-2026-86003 updated by NVD
- CVE-2026-67432highCVE-2026-67432 updated by NVD
- CVE-2026-59892highOpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed heade
- CVE-2026-39904highGophish contains a denial of service vulnerability
- CVE-2026-67313mediumCVE-2026-67313 updated by NVD
- CVE-2026-73561highCVE-2026-73561 updated by NVD
- CVE-2026-75602mediumCVE-2026-75602 updated by NVD
- CVE-2026-55677highEcho: Encoded slash (%2F) bypasses route-level protection and exposes static files
- CVE-2026-12771lowLiteLLM: M2M JWT Handler Has Improper Authorization
- CVE-2026-78677highCVE-2026-78677 updated by NVD
- CVE-2026-55596highPlate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
- CVE-2026-8763criticalCVE-2026-8763 updated by NVD
- CVE-2026-41699highCVE-2026-41699 updated by NVD
- CVE-2025-71330highimage-size: ICNS parser allows denial of service through an infinite loop
- CVE-2025-71329highimage-size: JXL and HEIF parsers allow denial of service through infinite loops
- CVE-2026-24000mediumFleet has a rate limiting bypass via untrusted client IP headers
- CVE-2026-53551mediumCVE-2026-53551 updated by NVD
- CVE-2026-67318mediumCVE-2026-67318 updated by NVD
- CVE-2026-52798highGogs has Stored XSS in `.ipynb` Preview
- CVE-2026-55552highCVE-2026-55552 updated by NVD
- CVE-2026-76904criticalCVE-2026-76904 updated by NVD
- CVE-2026-54543mediumCVE-2026-54543 updated by NVD
- CVE-2026-53632mediumlaunch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
- CVE-2026-78329criticalCVE-2026-78329 updated by NVD
- CVE-2026-61594criticalCVE-2026-61594 updated by NVD
- CVE-2026-69215mediumCVE-2026-69215 updated by NVD
- CVE-2026-88056highCVE-2026-88056 updated by NVD
- CVE-2026-78676criticalCVE-2026-78676 updated by NVD
- CVE-2026-71493mediumCVE-2026-71493 updated by NVD
- CVE-2026-79675criticalCVE-2026-79675 updated by NVD
- CVE-2026-55673highCVE-2026-55673 updated by NVD
- CVE-2026-54680criticalCVE-2026-54680 updated by NVD
- CVE-2026-12799lowBerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure
- CVE-2026-61833highCVE-2026-61833 updated by NVD
- CVE-2026-68904highCVE-2026-68904 updated by NVD
- CVE-2026-75914highCVE-2026-75914 updated by NVD
- CVE-2026-71485criticalCVE-2026-71485 updated by NVD
- CVE-2026-59939highCVE-2026-59939 updated by NVD
- CVE-2026-55215highCVE-2026-55215 updated by NVD
- CVE-2026-71321highCVE-2026-71321 updated by NVD
- CVE-2026-59733highCVE-2026-59733 updated by NVD
- CVE-2026-52799highGogs Missing Authorization in Attachment Download
- CVE-2026-48798highCVE-2026-48798 updated by NVD
- CVE-2026-48824mediumCVE-2026-48824 updated by NVD
- CVE-2026-41134highCVE-2026-41134 updated by NVD
- CVE-2026-62993mediumCVE-2026-62993 updated by NVD
- CVE-2026-54635highCVE-2026-54635 updated by NVD
- CVE-2026-59230mediumCVE-2026-59230 updated by NVD
- CVE-2026-28222mediumWagtail Vulnerable to Cross-site Scripting in TableBlock class attributes
- CVE-2026-59178criticalCVE-2026-59178 updated by NVD
- CVE-2026-68924mediumCVE-2026-68924 updated by NVD
- CVE-2026-53503highCVE-2026-53503 updated by NVD
- CVE-2026-16756highCVE-2026-16756 updated by NVD
- CVE-2026-84372criticalCVE-2026-84372 updated by NVD
- CVE-2026-84304highCVE-2026-84304 updated by NVD
- CVE-2026-54721highCVE-2026-54721 updated by NVD
- CVE-2026-50137highBudibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pr
- CVE-2026-75859highCVE-2026-75859 updated by NVD
- CVE-2026-56668highZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
- CVE-2026-82393highCVE-2026-82393 updated by NVD
- CVE-2026-55208highPimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database d
- CVE-2026-16723criticalCVE-2026-16723 updated by NVD
- CVE-2026-54904highCVE-2026-54904 updated by NVD
- CVE-2026-55404highyt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
- CVE-2026-65592highCVE-2026-65592 updated by NVD
- CVE-2026-77301highCVE-2026-77301 updated by NVD
- CVE-2026-77412highCVE-2026-77412 updated by NVD
- CVE-2026-77411criticalCVE-2026-77411 updated by NVD
- CVE-2026-77410highCVE-2026-77410 updated by NVD
- CVE-2026-77408criticalCVE-2026-77408 updated by NVD
- CVE-2026-77406highCVE-2026-77406 updated by NVD
- CVE-2026-77403highCVE-2026-77403 updated by NVD
- CVE-2026-85715highCVE-2026-85715 updated by NVD
- CVE-2026-63472criticalCVE-2026-63472 updated by NVD
- CVE-2026-63460highCVE-2026-63460 updated by NVD
- CVE-2026-61598highCVE-2026-61598 updated by NVD
- CVE-2026-27878mediumGrafana Tempo vulnerable to an out-of-memory crash
- CVE-2026-54097highFile Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
- CVE-2026-55546criticalCVE-2026-55546 updated by NVD
- CVE-2026-65600highCVE-2026-65600 updated by NVD
- CVE-2026-84361highCVE-2026-84361 updated by NVD
- CVE-2026-66908highCVE-2026-66908 updated by NVD
- CVE-2026-77413criticalCVE-2026-77413 updated by NVD
- CVE-2026-88057mediumCVE-2026-88057 updated by NVD
- CVE-2026-72920criticalCVE-2026-72920 updated by NVD
- CVE-2026-42577highNetty epoll transport denial of service via RST on half-closed TCP connection
- CVE-2026-69208highCVE-2026-69208 updated by NVD
- CVE-2026-84376mediumCVE-2026-84376 updated by NVD
- CVE-2026-54293highCVE-2026-54293 updated by NVD
- CVE-2026-25688mediumCVE-2026-25688 updated by NVD
- CVE-2026-25699mediumCVE-2026-25699 updated by NVD
- CVE-2026-4525highHashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
- CVE-2026-62871highCVE-2026-62871 updated by NVD
- CVE-2026-62886highCVE-2026-62886 updated by NVD
- CVE-2026-55445criticalQinglong has an incomplete fix for CVE-2026-3965: Improper Authentication
- CVE-2026-61712lowCVE-2026-61712 updated by NVD
- CVE-2026-23879highpy7zr: Arbitrary File Write Vulnerability
- CVE-2026-50630mediumCVE-2026-50630 updated by NVD
- CVE-2026-88062criticalCVE-2026-88062 updated by NVD
- CVE-2026-61704highCVE-2026-61704 updated by NVD
- CVE-2026-34031mediumCVE-2026-34031 updated by NVD
- CVE-2026-62673highCVE-2026-62673 updated by NVD
- CVE-2026-56695highOpenHarness remote resume commands expose other users' saved session snapshots
- CVE-2026-47267highGogs has SSRF in webhook deliveries
- CVE-2026-73293highCVE-2026-73293 updated by NVD
- CVE-2026-55830highRestrictedPython guard hooks can be shadowed via positional-only arguments
- CVE-2026-54523criticalCVE-2026-54523 updated by NVD
- CVE-2026-46608highGlances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-
- CVE-2026-71314highCVE-2026-71314 updated by NVD
- CVE-2026-12797lowBerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type
- CVE-2026-12798lowBerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
- CVE-2026-12772lowLiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
- CVE-2026-69219highCVE-2026-69219 updated by NVD
- CVE-2026-69220highCVE-2026-69220 updated by NVD
- CVE-2026-63746highCVE-2026-63746 updated by NVD
- CVE-2026-41842highCVE-2026-41842 updated by NVD
- CVE-2026-82404highCVE-2026-82404 updated by NVD
- CVE-2026-55509highCVE-2026-55509 updated by NVD
- CVE-2026-82392highCVE-2026-82392 updated by NVD
- CVE-2026-44221criticalCVE-2026-44221 updated by NVD
- CVE-2026-69205highCVE-2026-69205 updated by NVD
- CVE-2026-53510highCVE-2026-53510 updated by NVD
- CVE-2026-73500highCVE-2026-73500 updated by NVD
- CVE-2026-73648mediumCVE-2026-73648 updated by NVD
- CVE-2026-64684mediumCVE-2026-64684 updated by NVD
- CVE-2026-59903mediumCVE-2026-59903 updated by NVD
- CVE-2026-61609highCVE-2026-61609 updated by NVD
- CVE-2026-47427highCVE-2026-47427 updated by NVD
- CVE-2026-59161highExcelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
- CVE-2026-54590mediumasyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory
- CVE-2026-41729highCVE-2026-41729 updated by NVD
- CVE-2026-77615highCVE-2026-77615 updated by NVD
- CVE-2026-48748highCVE-2026-48748 updated by NVD
- CVE-2025-71357highPicklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand
- CVE-2024-9675highCVE-2024-9675 updated by NVD
- CVE-2026-71439mediumCVE-2026-71439 updated by NVD
- CVE-2026-56876highextract-zip unvalidated symlink path traversal
- CVE-2026-69256criticalCVE-2026-69256 updated by NVD
- CVE-2026-25782mediumGitea tracked-time deletion is not scoped to the requested issue
- CVE-2026-55485highCVE-2026-55485 updated by NVD
- CVE-2026-62949mediumCVE-2026-62949 updated by NVD
- CVE-2026-84364mediumCVE-2026-84364 updated by NVD
- CVE-2026-54061criticalDgraph Alpha group stores can be replaced via unauthenticated external snapshot import
- CVE-2026-73559mediumCVE-2026-73559 updated by NVD
- CVE-2026-54345mediumCVE-2026-54345 updated by NVD
- CVE-2026-73565mediumCVE-2026-73565 updated by NVD
- CVE-2026-45713highCVE-2026-45713 updated by NVD
- CVE-2026-62672mediumCVE-2026-62672 updated by NVD
- CVE-2026-55678mediumCVE-2026-55678 updated by NVD
- CVE-2026-55539highCVE-2026-55539 updated by NVD
- CVE-2026-70354highCVE-2026-70354 updated by NVD
- CVE-2026-62669highCVE-2026-62669 updated by NVD
- CVE-2026-54755criticalCVE-2026-54755 updated by NVD
- CVE-2026-47691highCVE-2026-47691 updated by NVD
- CVE-2026-59162mediumExcelize: Negative shared-string index causes panic in GetCellValue and GetRows
- CVE-2026-84375highCVE-2026-84375 updated by NVD
- CVE-2026-54917highSeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
- CVE-2026-14794mediumCraft CMS: Missing authorization check allows non-admin control panel users access to user registration metric
- CVE-2026-63671highCVE-2026-63671 updated by NVD
- CVE-2026-55099highCVE-2026-55099 updated by NVD
- CVE-2026-73080criticalCVE-2026-73080 updated by NVD
- CVE-2026-73564highCVE-2026-73564 updated by NVD
- CVE-2026-55575highLiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
- CVE-2026-13676highCVE-2026-13676 updated by NVD
- CVE-2026-49296mediumCVE-2026-49296 updated by NVD
- CVE-2026-52805highGogs has a Migration Redirect Bypass that Leads to Internal Repository Theft
- CVE-2026-12479mediumKeras: DiskIOStore permits path traversal through crafted layer names
- CVE-2026-55187mediumMailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms
- CVE-2026-73645mediumCVE-2026-73645 updated by NVD
- CVE-2026-85730highCVE-2026-85730 updated by NVD
- CVE-2026-63376highCVE-2026-63376 updated by NVD
- CVE-2026-64679highCVE-2026-64679 updated by NVD
- CVE-2026-70610mediumCVE-2026-70610 updated by NVD
- CVE-2026-69258highCVE-2026-69258 updated by NVD
- CVE-2026-40999highCVE-2026-40999 updated by NVD
- CVE-2026-54347highCVE-2026-54347 updated by NVD
- CVE-2026-55100highCVE-2026-55100 updated by NVD
- CVE-2026-68500highCVE-2026-68500 updated by NVD
- CVE-2026-70478criticalCVE-2026-70478 updated by NVD
- CVE-2026-73300criticalCVE-2026-73300 updated by NVD
- CVE-2026-43973highCVE-2026-43973 updated by NVD
- CVE-2026-43974highCVE-2026-43974 updated by NVD
- CVE-2026-71310mediumCVE-2026-71310 updated by NVD
- CVE-2026-85732mediumCVE-2026-85732 updated by NVD
- CVE-2026-67445mediumCVE-2026-67445 updated by NVD
- CVE-2026-63462highCVE-2026-63462 updated by NVD
- CVE-2026-73566highCVE-2026-73566 updated by NVD
- CVE-2026-52746highCVE-2026-52746 updated by NVD
- CVE-2024-6533lowDirectus has a DOM-Based cross-site scripting (XSS) via layout_options
- CVE-2026-8657highjsondiffpatch patch APIs are vulnerable to prototype pollution
- CVE-2026-69197highCVE-2026-69197 updated by NVD
- CVE-2026-61599highCVE-2026-61599 updated by NVD
- CVE-2026-61595highCVE-2026-61595 updated by NVD
- CVE-2026-54550highCVE-2026-54550 updated by NVD
- CVE-2026-63221criticalCVE-2026-63221 updated by NVD
- CVE-2026-53573mediumCVE-2026-53573 updated by NVD
- CVE-2026-73646highCVE-2026-73646 updated by NVD
- CVE-2026-15736highSnowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities
- CVE-2026-61690mediumCVE-2026-61690 updated by NVD
- CVE-2026-55516highSnipe-IT vulnerable to cross-company asset maintenance re-parenting via API update
- CVE-2026-8147highMLflow: trace API endpoints lack proper authorization validators
- CVE-2026-84373mediumCVE-2026-84373 updated by NVD
- CVE-2026-70486highCVE-2026-70486 updated by NVD
- CVE-2026-69089highCVE-2026-69089 updated by NVD
- CVE-2026-73406highCVE-2026-73406 updated by NVD
- CVE-2026-55604high@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
- CVE-2026-67447mediumCVE-2026-67447 updated by NVD
- CVE-2026-45819mediumCVE-2026-45819 updated by NVD
- CVE-2026-73509highCVE-2026-73509 updated by NVD
- CVE-2026-59220mediumOpen WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
- CVE-2026-54352criticalBudibase has arbitrary file read by workspace-builder via PWA-zip symlink upload
- CVE-2026-50635highCVE-2026-50635 updated by NVD
- CVE-2026-34033mediumCVE-2026-34033 updated by NVD
- CVE-2026-10224mediumCVE-2026-10224 updated by NVD
- CVE-2026-26062highFleet server may terminate unexpectedly when handling certain gRPC requests
- CVE-2026-58657mediumGrav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
- CVE-2026-67446mediumCVE-2026-67446 updated by NVD
- CVE-2026-54909mediumCVE-2026-54909 updated by NVD
- CVE-2026-73569highCVE-2026-73569 updated by NVD
- CVE-2026-50623mediumCVE-2026-50623 updated by NVD
- CVE-2026-53673highCVE-2026-53673 updated by NVD
- CVE-2026-88007criticalCVE-2026-88007 updated by NVD
- CVE-2026-75856criticalCVE-2026-75856 updated by NVD
- CVE-2026-55553highCVE-2026-55553 updated by NVD
- CVE-2026-55410mediumNocoBase backup restore schema name allows command injection
- CVE-2026-67320highCVE-2026-67320 updated by NVD
- CVE-2026-48205criticalApache Camel DNS Has Improper Input Validation, Leading to Server-Side Request Forgery (SSRF)
- CVE-2026-56696mediumOpenHarness remote project-context commands allow persistent prompt poisoning
- CVE-2026-55520highCVE-2026-55520 updated by NVD
- CVE-2026-73562mediumCVE-2026-73562 updated by NVD
- CVE-2026-73247highCVE-2026-73247 updated by NVD
- CVE-2026-77401mediumCVE-2026-77401 updated by NVD
- CVE-2026-54659mediumCVE-2026-54659 updated by NVD
- CVE-2026-71494mediumCVE-2026-71494 updated by NVD
- CVE-2026-62385highCVE-2026-62385 updated by NVD
- CVE-2026-63735highCVE-2026-63735 updated by NVD
- CVE-2026-54786lowWasmtime has a leak in WASIp1 `fd_renumber` implementation
- CVE-2026-54332mediumCVE-2026-54332 updated by NVD
- CVE-2026-59935highpypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
- CVE-2026-27761mediumGitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repositor
- CVE-2025-71344highPicklescan is missing detection when calling built-in python ensurepip._run_pip
- CVE-2026-69222highCVE-2026-69222 updated by NVD
- CVE-2026-55620highCVE-2026-55620 updated by NVD
- CVE-2026-40997mediumCVE-2026-40997 updated by NVD
- CVE-2026-56819highCVE-2026-56819 updated by NVD
- CVE-2026-73499highCVE-2026-73499 updated by NVD
- CVE-2026-67314mediumCVE-2026-67314 updated by NVD
- CVE-2026-42812criticalApache Polaris has an Improper Input Validation issue
- CVE-2025-66024highCVE-2025-66024 updated by NVD
- CVE-2025-1057mediumKeylime registrar is vulnerable to Denial-of-Service attack when updated to version 7.12.0
- CVE-2026-86074mediumCVE-2026-86074 updated by NVD
- CVE-2026-54713lowCVE-2026-54713 updated by NVD
- CVE-2026-63642mediumCVE-2026-63642 updated by NVD
- CVE-2026-62992mediumCVE-2026-62992 updated by NVD
- CVE-2026-71327highCVE-2026-71327 updated by NVD
- CVE-2026-65596mediumCVE-2026-65596 updated by NVD
- CVE-2026-65016highCVE-2026-65016 updated by NVD
- CVE-2026-65593mediumCVE-2026-65593 updated by NVD
- CVE-2026-59730lowCVE-2026-59730 updated by NVD
- CVE-2026-13149highbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
- CVE-2026-11779mediumPayload CMS default account-unlock access allows authenticated users to reset other accounts' lockouts
- CVE-2025-30402highExecuTorch vulnerable to Heap-based Buffer Overflow attack
- CVE-2026-81722highCVE-2026-81722 updated by NVD
- CVE-2026-64866mediumCVE-2026-64866 updated by NVD
- CVE-2026-54526highCVE-2026-54526 updated by NVD
- CVE-2026-41695highCVE-2026-41695 updated by NVD
- CVE-2026-45045mediumGoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
- CVE-2026-41716highCVE-2026-41716 updated by NVD
- CVE-2026-66393highCVE-2026-66393 updated by NVD
- CVE-2026-84306mediumCVE-2026-84306 updated by NVD
- CVE-2026-55523highCVE-2026-55523 updated by NVD
- CVE-2026-69254criticalCVE-2026-69254 updated by NVD
- CVE-2026-55389highCVE-2026-55389 updated by NVD
- CVE-2026-59221highopen-webui terminal proxy path traversal guard bypass via 9x encoded traversal
- CVE-2026-56326mediumNuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execu
- CVE-2026-69213highCVE-2026-69213 updated by NVD
- CVE-2026-86077mediumCVE-2026-86077 updated by NVD
- CVE-2026-55549mediumCVE-2026-55549 updated by NVD
- CVE-2026-55521highCVE-2026-55521 updated by NVD
- CVE-2026-70612mediumCVE-2026-70612 updated by NVD
- CVE-2026-54650highCVE-2026-54650 updated by NVD
- CVE-2026-55390highCVE-2026-55390 updated by NVD