Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54305
Total
4306
Critical
16147
High
15838
Medium
CVE ID Severity Score Description Published
CVE-2026-101088 MEDIUM 5.3 Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/singleton/servicesentinel.go) contains an incomplete fix for … Sep 27, 2026
CVE-2026-101087 MEDIUM 4.3 Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs, but the denylist did not cover IPv6 … Sep 27, 2026
CVE-2026-101086 MEDIUM 6.5 Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged … Sep 27, 2026
CVE-2026-101085 MEDIUM 6.5 Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in … Sep 27, 2026
CVE-2026-101084 CRITICAL 9.6 obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if … Sep 27, 2026
CVE-2026-101065 CRITICAL 9.8 Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts … Sep 27, 2026
CVE-2026-101064 HIGH 7.6 Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. … Sep 27, 2026
CVE-2026-101063 MEDIUM 5.3 Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is enabled. Unauthenticated attackers can read registry metadata … Sep 27, 2026
CVE-2026-101062 HIGH 8.8 Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs … Sep 27, 2026
CVE-2026-100880 LOW 3.5 A weakness has been identified in zhistaredu StarTraining up to 3.8.1. This vulnerability affects unknown code of the file du-common/src/main/java/com/edu/common/utils/file/MimeTypeUtils.java of the component Upload Endpoint. … Sep 27, 2026
CVE-2026-100879 MEDIUM 4.3 A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the function checkRoleAllowed of the file SysRoleServiceImpl.java of the component dataScope … Sep 27, 2026
CVE-2026-100878 MEDIUM 6.3 A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Affected by this issue is the function SysUser.isAdmin of the file edu-common/src/main/java/com/edu/common/core/domain/entity/SysUser.java of the component … Sep 27, 2026
CVE-2026-100877 MEDIUM 4.3 A vulnerability was determined in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file registrationform.php. Executing a manipulation … Sep 27, 2026
CVE-2026-96279 MEDIUM 6.5 A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI … Sep 27, 2026
CVE-2026-100876 MEDIUM 6.3 A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file loginlinkstudent.php. Performing a manipulation of the argument … Sep 27, 2026
CVE-2026-100875 HIGH 7.3 A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatedetailsfromfaculty.php. Such manipulation of the argument … Sep 27, 2026
CVE-2026-100874 HIGH 7.3 A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file addnewstudent.php. This manipulation causes sql injection. … Sep 27, 2026
CVE-2026-100873 MEDIUM 4.3 A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function. The manipulation results in cross-site request forgery. The … Sep 27, 2026
CVE-2026-101061 MEDIUM 4.7 utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incomplete application of CVE-2026-44661 fixes. The GraphQL plugin uses a vulnerable … Sep 27, 2026
CVE-2026-101060 HIGH 8.2 python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initial tool URL but follows HTTP redirects without re-validating the … Sep 27, 2026
CVE-2026-101059 HIGH 7.1 utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attackers to redirect credential submission to arbitrary endpoints. When a … Sep 27, 2026
CVE-2026-101058 MEDIUM 6.9 python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual point at the agent's own loopback interface … Sep 27, 2026
CVE-2026-101057 LOW 3.1 utcp-mcp (the MCP plugin of python-utcp) through 1.1.2 connects to the HTTP and WebSocket MCP server URLs given in a call template's mcpServers configuration without … Sep 27, 2026
CVE-2026-101056 MEDIUM 5.3 Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had valid share access can … Sep 27, 2026
CVE-2026-101051 LOW 3.1 Cloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders, allowing authenticated users to create files outside the selected destination directory. Attackers … Sep 27, 2026