Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54367
Total
4306
Critical
16164
High
15850
Medium
CVE ID Severity Score Description Published
CVE-2026-100614 HIGH 8.8 Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image object keys from mutable database rows without validating ownership. An … Sep 26, 2026
CVE-2026-100613 MEDIUM 5.3 capgo.app is an over-the-air (OTA) update platform for Capacitor apps. In all versions up to and including the current release (no patch available at time … Sep 26, 2026
CVE-2026-100612 HIGH 7.2 Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control fix for the public.sso_providers table. Migration 20260826100000_sso_providers_block_direct_active_insert.sql installs a BEFORE UPDATE guard (enforce_sso_provider_client_update_guard()) that freezes only … Sep 26, 2026
CVE-2026-100611 MEDIUM 6.5 Capgo (capgo.app backend, versions ≤ 12.261.0) improperly restricts which roles the apikey_manager organization role may bind to newly created API keys. When an authenticated user … Sep 26, 2026
CVE-2026-100610 HIGH 7.5 Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permission checks, and the backing service performs no workspace or ownership validation. getAllUpsertHistory() returns … Sep 26, 2026
CVE-2026-100609 MEDIUM 6.8 Flowise (npm packages `flowise` and `flowise-components`) through 3.1.4 looks up credentials by ID without filtering on the requesting user's workspace (findOneBy({ id: credentialId }) with … Sep 26, 2026
CVE-2026-100608 HIGH 8.3 Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server runs in queue mode with the dashboard enabled and not … Sep 26, 2026
CVE-2026-100607 HIGH 7.7 Flowise through 3.1.4 resolves SSO and local-password users solely by email without storing provider or subject identifier bindings, allowing attackers to authenticate as any existing … Sep 26, 2026
CVE-2026-100606 HIGH 7.7 Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login path. When an SSO callback arrives with an email … Sep 26, 2026
CVE-2026-100605 HIGH 7.1 Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API keys to read and delete chat history. Attackers with … Sep 26, 2026
CVE-2026-100604 MEDIUM 5.4 ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an organization-owned skill retains the ownerUserId of its original publisher, and transfer and lifecycle … Sep 26, 2026
CVE-2026-100603 MEDIUM 5.4 ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic … Sep 26, 2026
CVE-2026-100602 MEDIUM 6.5 ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A signed-in caller can invoke the public skills:generateChangelogPreview action for a skill … Sep 26, 2026
CVE-2026-100601 MEDIUM 5.3 ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile preview's image fetching. The preview accepts a user-supplied image URL and checks … Sep 26, 2026
CVE-2026-100600 MEDIUM 5.3 ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identity, so all direct anonymous API requests share a single … Sep 26, 2026
CVE-2026-100315 HIGH 7.3 A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file mydetailsfaculty.php. The manipulation of the argument myfid … Sep 26, 2026
CVE-2026-100314 HIGH 7.3 A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatedetailsfromstudent.php. The manipulation of the … Sep 26, 2026
CVE-2026-100313 MEDIUM 4.3 A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequery.php. Executing a manipulation of the … Sep 26, 2026
CVE-2026-98163 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: cgroup: Avoid iteration of dying tasks with zero refcount The commit 260fbcb92bbea ("cgroup: Move dying_tasks … Sep 26, 2026
CVE-2026-100312 MEDIUM 6.3 A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file /updateguest.php. Performing a … Sep 26, 2026
CVE-2026-100311 LOW 3.5 A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The affected element is an unknown function of the file managevideos2.php of the component Faculty … Sep 26, 2026
CVE-2026-96533 MEDIUM 5.8 The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, … Sep 26, 2026
CVE-2026-96532 HIGH 7.5 The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users … Sep 26, 2026
CVE-2026-96531 MEDIUM 6.8 The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users … Sep 26, 2026
CVE-2026-96526 LOW 2.7 The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of its workflow REST routes, allowing users … Sep 26, 2026