Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54367
Total
4306
Critical
16164
High
15850
Medium
CVE ID Severity Score Description Published
CVE-2026-100689 MEDIUM 5.9 GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules. While a prior fix (GHSA-hmq2-w58f-27jc) added Submodule._validated_name() … Sep 26, 2026
CVE-2026-100688 MEDIUM 6.5 Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/:appId/appPackage endpoint that allows authenticated users to read another tenant's application metadata … Sep 26, 2026
CVE-2026-100687 MEDIUM 5.5 Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to the Builder collaboration websocket room. Attackers with Builder access … Sep 26, 2026
CVE-2026-100686 HIGH 8.1 Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder … Sep 26, 2026
CVE-2026-100685 HIGH 7.7 Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in … Sep 26, 2026
CVE-2026-100684 HIGH 8.1 Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming … Sep 26, 2026
CVE-2026-100683 HIGH 8.0 Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a … Sep 26, 2026
CVE-2026-100682 HIGH 8.8 Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. … Sep 26, 2026
CVE-2026-100681 MEDIUM 5.4 Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability in the Microsoft Teams webhook endpoint that accepts forged Bot Framework activities … Sep 26, 2026
CVE-2026-100680 HIGH 8.1 Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers … Sep 26, 2026
CVE-2026-100679 HIGH 8.8 stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket … Sep 26, 2026
CVE-2026-100678 MEDIUM 6.5 stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP codes with only … Sep 26, 2026
CVE-2026-100677 MEDIUM 5.3 stoatchat before 0.15.5 contains an account enumeration vulnerability in the login endpoint that exposes source file locations in error responses. Unauthenticated attackers can distinguish between … Sep 26, 2026
CVE-2026-100676 HIGH 8.2 January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG <image href> values as local filesystem paths when a fetched resource … Sep 26, 2026
CVE-2026-100675 MEDIUM 6.5 stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that processes mass mention messages. Authenticated users can send five crafted … Sep 26, 2026
CVE-2026-100674 MEDIUM 4.3 stoatchat before 0.15.5 fails to revalidate usernames after Unicode sanitization, allowing attackers to create usernames with forbidden characters by submitting Unicode letters that transform into … Sep 26, 2026
CVE-2026-100673 HIGH 8.2 The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter … Sep 26, 2026
CVE-2026-100672 HIGH 7.5 The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The … Sep 26, 2026
CVE-2026-100671 HIGH 8.0 Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig has been explicitly … Sep 26, 2026
CVE-2026-100670 HIGH 8.8 Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` … Sep 26, 2026
CVE-2026-100669 HIGH 7.5 Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts, user_data, user_error_redirect, … Sep 26, 2026
CVE-2026-100668 MEDIUM 6.5 Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) is on the sandbox allowlist but is … Sep 26, 2026
CVE-2026-100667 MEDIUM 5.3 grav-plugin-login (the Grav CMS Login plugin) versions >= 3.8.7 and < 3.9.7 allow the two-factor authentication challenge to be bypassed for content gated by the … Sep 26, 2026
CVE-2026-100666 HIGH 7.3 Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versions up to and including 4.1.136.Final pairs each outbound response with an inbound request by … Sep 26, 2026
CVE-2026-100665 HIGH 7.5 Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback … Sep 26, 2026