Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54499
Total
4309
Critical
16193
High
15930
Medium
CVE ID Severity Score Description Published
CVE-2026-81455 HIGH 8.6 Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this … Sep 24, 2026
CVE-2026-77321 MEDIUM 4.3 TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is registered for scoped OAuth MCP tokens without requiring trips:read and … Sep 24, 2026
CVE-2026-77320 MEDIUM 5.3 TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns days, assignments, dayNotes, and places through GET /api/shared/:token even when the trip … Sep 24, 2026
CVE-2026-77294 HIGH 8.1 TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the … Sep 24, 2026
CVE-2026-77293 HIGH 7.1 TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint authorizes an authenticated user against the attacker-controlled tripId but deleteNoteFile in server/src/services/collabService.ts … Sep 24, 2026
CVE-2026-65827 MEDIUM 6.5 Docmost is open-source collaborative wiki and documentation software. From 0.21.0 until 0.95.0, any authenticated workspace member with edit rights to a space can upload an … Sep 24, 2026
CVE-2026-62286 MEDIUM 4.3 Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go applies a restricted user's label filter to container lists but … Sep 24, 2026
CVE-2026-61825 HIGH 8.7 code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in `SharpEditorFormField`: attacker-controlled content … Sep 24, 2026
CVE-2026-61823 HIGH 7.3 code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in the rich-text editor … Sep 24, 2026
CVE-2026-57440 HIGH 7.5 The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video … Sep 24, 2026
CVE-2026-56792 MEDIUM 4.4 Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this … Sep 24, 2026
CVE-2026-52853 MEDIUM 5.2 Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace ADMIN can use the workspace invitation flow to invite an external … Sep 24, 2026
CVE-2026-52850 MEDIUM 4.3 Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace member who does not belong to a private space can call … Sep 24, 2026
CVE-2026-48073 MEDIUM 4.3 Docmost is open-source collaborative wiki and documentation software. From 0.70.0 until 0.80.1, a low-privileged authenticated user who can edit an exportable page can embed a … Sep 24, 2026
CVE-2026-48072 MEDIUM 5.3 Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, the public avatar and logo image endpoint accepts attacker-controlled fileName path segments and resolves … Sep 24, 2026
CVE-2026-48070 HIGH 7.1 Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reused by avatar cleanup … Sep 24, 2026
CVE-2026-13249 CRITICAL 9.8 An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of … Sep 24, 2026
CVE-2026-13248 HIGH 8.8 An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial … Sep 24, 2026
CVE-2026-13016 UNKNOWN — ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, … Sep 24, 2026
CVE-2026-97233 LOW 3.5 A vulnerability was identified in volotat Anagnorisis up to 0.4.11. Affected by this issue is the function html of the file PlaylistManager.js of the component … Sep 24, 2026
CVE-2026-97232 MEDIUM 6.3 A vulnerability was determined in volotat Anagnorisis up to 0.4.2. Affected by this vulnerability is the function get_file_content/save_file_content/move_files/start_streaming of the file page.html. This manipulation causes … Sep 24, 2026
CVE-2026-95985 HIGH 8.8 The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When … Sep 24, 2026
CVE-2026-93405 MEDIUM 6.1 Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, DOCX, and XLSX attachments with Snarkdown, Mammoth, and SheetJS … Sep 24, 2026
CVE-2026-91121 MEDIUM 5.0 Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, attacker-controlled upload filenames used in chat message excerpts were rendered as unescaped … Sep 24, 2026
CVE-2026-91120 MEDIUM 5.4 Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, provider-controlled video titles in lazy video embeds could be reparsed as HTML … Sep 24, 2026