Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54367
Total
4306
Critical
16164
High
15850
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-100614 | HIGH | 8.8 | Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image object keys from mutable database rows without validating ownership. An … | Sep 26, 2026 |
| CVE-2026-100613 | MEDIUM | 5.3 | capgo.app is an over-the-air (OTA) update platform for Capacitor apps. In all versions up to and including the current release (no patch available at time … | Sep 26, 2026 |
| CVE-2026-100612 | HIGH | 7.2 | Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control fix for the public.sso_providers table. Migration 20260826100000_sso_providers_block_direct_active_insert.sql installs a BEFORE UPDATE guard (enforce_sso_provider_client_update_guard()) that freezes only … | Sep 26, 2026 |
| CVE-2026-100611 | MEDIUM | 6.5 | Capgo (capgo.app backend, versions ≤ 12.261.0) improperly restricts which roles the apikey_manager organization role may bind to newly created API keys. When an authenticated user … | Sep 26, 2026 |
| CVE-2026-100610 | HIGH | 7.5 | Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permission checks, and the backing service performs no workspace or ownership validation. getAllUpsertHistory() returns … | Sep 26, 2026 |
| CVE-2026-100609 | MEDIUM | 6.8 | Flowise (npm packages `flowise` and `flowise-components`) through 3.1.4 looks up credentials by ID without filtering on the requesting user's workspace (findOneBy({ id: credentialId }) with … | Sep 26, 2026 |
| CVE-2026-100608 | HIGH | 8.3 | Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server runs in queue mode with the dashboard enabled and not … | Sep 26, 2026 |
| CVE-2026-100607 | HIGH | 7.7 | Flowise through 3.1.4 resolves SSO and local-password users solely by email without storing provider or subject identifier bindings, allowing attackers to authenticate as any existing … | Sep 26, 2026 |
| CVE-2026-100606 | HIGH | 7.7 | Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login path. When an SSO callback arrives with an email … | Sep 26, 2026 |
| CVE-2026-100605 | HIGH | 7.1 | Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API keys to read and delete chat history. Attackers with … | Sep 26, 2026 |
| CVE-2026-100604 | MEDIUM | 5.4 | ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an organization-owned skill retains the ownerUserId of its original publisher, and transfer and lifecycle … | Sep 26, 2026 |
| CVE-2026-100603 | MEDIUM | 5.4 | ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic … | Sep 26, 2026 |
| CVE-2026-100602 | MEDIUM | 6.5 | ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A signed-in caller can invoke the public skills:generateChangelogPreview action for a skill … | Sep 26, 2026 |
| CVE-2026-100601 | MEDIUM | 5.3 | ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile preview's image fetching. The preview accepts a user-supplied image URL and checks … | Sep 26, 2026 |
| CVE-2026-100600 | MEDIUM | 5.3 | ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identity, so all direct anonymous API requests share a single … | Sep 26, 2026 |
| CVE-2026-100315 | HIGH | 7.3 | A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file mydetailsfaculty.php. The manipulation of the argument myfid … | Sep 26, 2026 |
| CVE-2026-100314 | HIGH | 7.3 | A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatedetailsfromstudent.php. The manipulation of the … | Sep 26, 2026 |
| CVE-2026-100313 | MEDIUM | 4.3 | A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequery.php. Executing a manipulation of the … | Sep 26, 2026 |
| CVE-2026-98163 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: cgroup: Avoid iteration of dying tasks with zero refcount The commit 260fbcb92bbea ("cgroup: Move dying_tasks … | Sep 26, 2026 |
| CVE-2026-100312 | MEDIUM | 6.3 | A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file /updateguest.php. Performing a … | Sep 26, 2026 |
| CVE-2026-100311 | LOW | 3.5 | A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The affected element is an unknown function of the file managevideos2.php of the component Faculty … | Sep 26, 2026 |
| CVE-2026-96533 | MEDIUM | 5.8 | The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, … | Sep 26, 2026 |
| CVE-2026-96532 | HIGH | 7.5 | The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users … | Sep 26, 2026 |
| CVE-2026-96531 | MEDIUM | 6.8 | The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users … | Sep 26, 2026 |
| CVE-2026-96526 | LOW | 2.7 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of its workflow REST routes, allowing users … | Sep 26, 2026 |