Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55639
Total
4397
Critical
16518
High
16189
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-79918 | MEDIUM | 6.3 | MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox hooks execve, execvpe, and execveat to prevent subprocess creation … | Sep 21, 2026 |
| CVE-2026-79917 | MEDIUM | 6.5 | MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_id}/chat/{chat_id}/share_chat verifies that a conversation exists but does not verify that it … | Sep 21, 2026 |
| CVE-2026-79916 | CRITICAL | 9.1 | MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject control characters into AWS Bedrock access_key_id and secret_access_key fields … | Sep 21, 2026 |
| CVE-2026-79317 | MEDIUM | 4.8 | A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and authentication only checks that a … | Sep 21, 2026 |
| CVE-2026-79316 | HIGH | 7.6 | An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger … | Sep 21, 2026 |
| CVE-2026-77525 | MEDIUM | 4.2 | MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, management chat-record routes authorize the path application_id but load records using global chat_id … | Sep 21, 2026 |
| CVE-2026-77523 | HIGH | 7.4 | MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the model parameter form route authorizes the path workspace but ModelSerializer.ModelParams loads … | Sep 21, 2026 |
| CVE-2026-77522 | MEDIUM | 4.3 | MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the knowledge web-document import and synchronization crawler passes an authenticated workspace user's … | Sep 21, 2026 |
| CVE-2026-77521 | CRITICAL | 10.0 | MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes … | Sep 21, 2026 |
| CVE-2026-77520 | MEDIUM | 5.4 | MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal user in the same workspace can obtain another user's application_id from … | Sep 21, 2026 |
| CVE-2026-77519 | MEDIUM | 5.4 | MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, the /chat/api/mcp authentication path looks up an ApplicationApiKey using only its secret and … | Sep 21, 2026 |
| CVE-2026-77518 | MEDIUM | 5.0 | MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows another user's active MCP tool_id in the … | Sep 21, 2026 |
| CVE-2026-77517 | MEDIUM | 5.4 | MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.10.2-lts, document and paragraph operate routes authorize only knowledge_id in the request path, … | Sep 21, 2026 |
| CVE-2026-77516 | MEDIUM | 5.4 | MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member denied access to a tool by WorkspaceUserResourcePermission can … | Sep 21, 2026 |
| CVE-2026-73553 | HIGH | 7.5 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, When ignore_path_parameters_in_path_matching is enabled, Envoy's … | Sep 21, 2026 |
| CVE-2026-73551 | MEDIUM | 5.3 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not … | Sep 21, 2026 |
| CVE-2026-73511 | MEDIUM | 5.3 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw … | Sep 21, 2026 |
| CVE-2026-67827 | UNKNOWN | — | Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to … | Sep 21, 2026 |
| CVE-2026-61647 | UNKNOWN | — | NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories. Versions 1.6.0 through … | Sep 21, 2026 |
| CVE-2026-59816 | MEDIUM | 4.3 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, the GET /api/transcribe/:id and POST /api/transcribe/:id … | Sep 21, 2026 |
| CVE-2026-58272 | MEDIUM | 5.3 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1 contain an observable timing discrepancy in the login … | Sep 21, 2026 |
| CVE-2026-58270 | MEDIUM | 6.5 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string … | Sep 21, 2026 |
| CVE-2026-55179 | MEDIUM | 6.5 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /items/:id/content route in … | Sep 21, 2026 |
| CVE-2026-55105 | HIGH | 7.7 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, packages/renderer/MdToHtml/rules/fountain.ts passes HTML generated … | Sep 21, 2026 |
| CVE-2026-49453 | HIGH | 7.0 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, Joplin accepts synchronized resource … | Sep 21, 2026 |