Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55639
Total
4397
Critical
16518
High
16189
Medium
CVE ID Severity Score Description Published
CVE-2026-79918 MEDIUM 6.3 MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox hooks execve, execvpe, and execveat to prevent subprocess creation … Sep 21, 2026
CVE-2026-79917 MEDIUM 6.5 MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_id}/chat/{chat_id}/share_chat verifies that a conversation exists but does not verify that it … Sep 21, 2026
CVE-2026-79916 CRITICAL 9.1 MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject control characters into AWS Bedrock access_key_id and secret_access_key fields … Sep 21, 2026
CVE-2026-79317 MEDIUM 4.8 A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and authentication only checks that a … Sep 21, 2026
CVE-2026-79316 HIGH 7.6 An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger … Sep 21, 2026
CVE-2026-77525 MEDIUM 4.2 MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, management chat-record routes authorize the path application_id but load records using global chat_id … Sep 21, 2026
CVE-2026-77523 HIGH 7.4 MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the model parameter form route authorizes the path workspace but ModelSerializer.ModelParams loads … Sep 21, 2026
CVE-2026-77522 MEDIUM 4.3 MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the knowledge web-document import and synchronization crawler passes an authenticated workspace user's … Sep 21, 2026
CVE-2026-77521 CRITICAL 10.0 MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes … Sep 21, 2026
CVE-2026-77520 MEDIUM 5.4 MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal user in the same workspace can obtain another user's application_id from … Sep 21, 2026
CVE-2026-77519 MEDIUM 5.4 MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, the /chat/api/mcp authentication path looks up an ApplicationApiKey using only its secret and … Sep 21, 2026
CVE-2026-77518 MEDIUM 5.0 MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows another user's active MCP tool_id in the … Sep 21, 2026
CVE-2026-77517 MEDIUM 5.4 MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.10.2-lts, document and paragraph operate routes authorize only knowledge_id in the request path, … Sep 21, 2026
CVE-2026-77516 MEDIUM 5.4 MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member denied access to a tool by WorkspaceUserResourcePermission can … Sep 21, 2026
CVE-2026-73553 HIGH 7.5 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, When ignore_path_parameters_in_path_matching is enabled, Envoy's … Sep 21, 2026
CVE-2026-73551 MEDIUM 5.3 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not … Sep 21, 2026
CVE-2026-73511 MEDIUM 5.3 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw … Sep 21, 2026
CVE-2026-67827 UNKNOWN — Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to … Sep 21, 2026
CVE-2026-61647 UNKNOWN — NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories. Versions 1.6.0 through … Sep 21, 2026
CVE-2026-59816 MEDIUM 4.3 Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, the GET /api/transcribe/:id and POST /api/transcribe/:id … Sep 21, 2026
CVE-2026-58272 MEDIUM 5.3 Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1 contain an observable timing discrepancy in the login … Sep 21, 2026
CVE-2026-58270 MEDIUM 6.5 Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string … Sep 21, 2026
CVE-2026-55179 MEDIUM 6.5 Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /items/:id/content route in … Sep 21, 2026
CVE-2026-55105 HIGH 7.7 Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, packages/renderer/MdToHtml/rules/fountain.ts passes HTML generated … Sep 21, 2026
CVE-2026-49453 HIGH 7.0 Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, Joplin accepts synchronized resource … Sep 21, 2026