Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55255
Total
4360
Critical
16420
High
16093
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-77520 | MEDIUM | 5.4 | MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal user in the same workspace can obtain another user's application_id from … | Sep 21, 2026 |
| CVE-2026-77519 | MEDIUM | 5.4 | MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, the /chat/api/mcp authentication path looks up an ApplicationApiKey using only its secret and … | Sep 21, 2026 |
| CVE-2026-77518 | MEDIUM | 5.0 | MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows another user's active MCP tool_id in the … | Sep 21, 2026 |
| CVE-2026-77517 | MEDIUM | 5.4 | MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.10.2-lts, document and paragraph operate routes authorize only knowledge_id in the request path, … | Sep 21, 2026 |
| CVE-2026-77516 | MEDIUM | 5.4 | MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member denied access to a tool by WorkspaceUserResourcePermission can … | Sep 21, 2026 |
| CVE-2026-73553 | HIGH | 7.5 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, When ignore_path_parameters_in_path_matching is enabled, Envoy's … | Sep 21, 2026 |
| CVE-2026-73551 | MEDIUM | 5.3 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not … | Sep 21, 2026 |
| CVE-2026-73511 | MEDIUM | 5.3 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw … | Sep 21, 2026 |
| CVE-2026-67827 | UNKNOWN | — | Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to … | Sep 21, 2026 |
| CVE-2026-61647 | UNKNOWN | — | NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories. Versions 1.6.0 through … | Sep 21, 2026 |
| CVE-2026-59816 | MEDIUM | 4.3 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, the GET /api/transcribe/:id and POST /api/transcribe/:id … | Sep 21, 2026 |
| CVE-2026-58272 | MEDIUM | 5.3 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1 contain an observable timing discrepancy in the login … | Sep 21, 2026 |
| CVE-2026-58270 | MEDIUM | 6.5 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string … | Sep 21, 2026 |
| CVE-2026-55179 | MEDIUM | 6.5 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /items/:id/content route in … | Sep 21, 2026 |
| CVE-2026-55105 | HIGH | 7.7 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, packages/renderer/MdToHtml/rules/fountain.ts passes HTML generated … | Sep 21, 2026 |
| CVE-2026-49453 | HIGH | 7.0 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, Joplin accepts synchronized resource … | Sep 21, 2026 |
| CVE-2026-49450 | HIGH | 7.1 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Desktop for Windows omits publisherName … | Sep 21, 2026 |
| CVE-2026-49449 | LOW | 2.5 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 until 3.7.2, packages/renderer/MdToHtml/rules/katex.ts enables KaTeX's trust option … | Sep 21, 2026 |
| CVE-2026-46649 | UNKNOWN | — | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts … | Sep 21, 2026 |
| CVE-2026-85219 | LOW | 3.7 | Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause unconstrained memory usage. | Sep 21, 2026 |
| CVE-2026-81469 | HIGH | 7.8 | Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially … | Sep 21, 2026 |
| CVE-2026-79320 | UNKNOWN | — | Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime. When a downstream application enables the experimental slot fixes option and … | Sep 21, 2026 |
| CVE-2026-79319 | UNKNOWN | — | Stencil core 4.43.5 is vulnerable to Incorrect Access Control. | Sep 21, 2026 |
| CVE-2026-79318 | MEDIUM | 6.5 | web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py). | Sep 21, 2026 |
| CVE-2026-73552 | HIGH | 7.5 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy HTTP RBAC accepts RFC-valid … | Sep 21, 2026 |