Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55255
Total
4360
Critical
16420
High
16093
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-87902 | HIGH | 8.1 | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both … | Sep 22, 2026 |
| CVE-2026-86062 | MEDIUM | 6.1 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieval/ChatMessage.tsx renders answer and thinking content with react-markdown, rehypeRaw, and skipHtml=false without an HTML sanitizer. … | Sep 22, 2026 |
| CVE-2026-86059 | CRITICAL | 9.6 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Git provider access can retrieve plaintext provider credentials … | Sep 22, 2026 |
| CVE-2026-85740 | HIGH | 7.1 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py evaluates the literal resolved address with ipaddress.is_global without consistently classifying an IPv4 … | Sep 22, 2026 |
| CVE-2026-85734 | CRITICAL | 9.1 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.py does not impose a rate limit, account lockout, delay, … | Sep 22, 2026 |
| CVE-2026-85725 | MEDIUM | 5.9 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plaintext AUTH_ACCOUNTS password values with Python's == operator. The comparison can … | Sep 22, 2026 |
| CVE-2026-85709 | MEDIUM | 5.3 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, … | Sep 22, 2026 |
| CVE-2026-84301 | MEDIUM | 6.3 | FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios request interceptor in packages/service/common/api/axios.ts validates … | Sep 22, 2026 |
| CVE-2026-83803 | UNKNOWN | — | Sentry is an error tracking and performance monitoring tool. From 23.11.0 until 26.7.0, Sentry instances with the relocation feature enabled unsafely deserialize a legacy database … | Sep 22, 2026 |
| CVE-2026-83603 | HIGH | 8.4 | Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged … | Sep 22, 2026 |
| CVE-2026-83602 | MEDIUM | 6.5 | Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api/v3/web_api_v3.c with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, causing unauthenticated PUT requests handled … | Sep 22, 2026 |
| CVE-2026-83601 | MEDIUM | 6.5 | Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized DIMENSION SLOT value that str2ull_encoded passes to … | Sep 22, 2026 |
| CVE-2026-83600 | MEDIUM | 6.5 | Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART SLOT value that str2ull_encoded passes to … | Sep 22, 2026 |
| CVE-2026-83599 | HIGH | 7.5 | Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate before authentication, and src/web/websocket/websocket-compression.c allows websocket_client_decompress_message() to grow decompressed … | Sep 22, 2026 |
| CVE-2026-83598 | HIGH | 7.8 | Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and … | Sep 22, 2026 |
| CVE-2026-76819 | UNKNOWN | — | Rejected reason: Further research determined the issue results from a dependency. | Sep 22, 2026 |
| CVE-2026-76805 | MEDIUM | 5.3 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime … | Sep 22, 2026 |
| CVE-2026-76804 | MEDIUM | 5.5 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enforce the -file … | Sep 22, 2026 |
| CVE-2026-76803 | MEDIUM | 5.3 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not enforce the local-file sandbox … | Sep 22, 2026 |
| CVE-2026-76802 | MEDIUM | 4.7 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned … | Sep 22, 2026 |
| CVE-2026-56682 | MEDIUM | 5.3 | 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper use … | Sep 22, 2026 |
| CVE-2026-13087 | HIGH | 8.8 | A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c. When a crafted RPC-over-RDMA client sends a large … | Sep 22, 2026 |
| CVE-2026-95806 | UNKNOWN | — | MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point. The phar stream wrapper causes PHP … | Sep 22, 2026 |
| CVE-2026-95805 | UNKNOWN | — | A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string 'theming_enabled*' (with a … | Sep 22, 2026 |
| CVE-2026-95655 | HIGH | 8.1 | Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attackers can submit … | Sep 22, 2026 |