Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55714
Total
4403
Critical
16544
High
16275
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-49450 | HIGH | 7.1 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Desktop for Windows omits publisherName … | Sep 21, 2026 |
| CVE-2026-49449 | LOW | 2.5 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 until 3.7.2, packages/renderer/MdToHtml/rules/katex.ts enables KaTeX's trust option … | Sep 21, 2026 |
| CVE-2026-46649 | UNKNOWN | — | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts … | Sep 21, 2026 |
| CVE-2026-85219 | LOW | 3.7 | Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause unconstrained memory usage. | Sep 21, 2026 |
| CVE-2026-81469 | HIGH | 7.8 | Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially … | Sep 21, 2026 |
| CVE-2026-79320 | UNKNOWN | — | Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime. When a downstream application enables the experimental slot fixes option and … | Sep 21, 2026 |
| CVE-2026-79319 | UNKNOWN | — | Stencil core 4.43.5 is vulnerable to Incorrect Access Control. | Sep 21, 2026 |
| CVE-2026-79318 | MEDIUM | 6.5 | web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py). | Sep 21, 2026 |
| CVE-2026-73552 | HIGH | 7.5 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy HTTP RBAC accepts RFC-valid … | Sep 21, 2026 |
| CVE-2026-73550 | HIGH | 7.5 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy copies every decoded HTTP/2 … | Sep 21, 2026 |
| CVE-2026-73549 | MEDIUM | 5.3 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's Utility::copyInternetAddressAndPort and QUIC client-address … | Sep 21, 2026 |
| CVE-2026-73548 | HIGH | 7.5 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy forwards data for a … | Sep 21, 2026 |
| CVE-2026-73547 | HIGH | 7.5 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that … | Sep 21, 2026 |
| CVE-2026-73546 | HIGH | 7.4 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses … | Sep 21, 2026 |
| CVE-2026-73513 | HIGH | 7.5 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's optional oghttp2 upstream HTTP/2 … | Sep 21, 2026 |
| CVE-2026-73512 | HIGH | 7.5 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current … | Sep 21, 2026 |
| CVE-2026-62247 | MEDIUM | 6.5 | Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authorization does not correctly honor the per-extension presence.read row-level security policy … | Sep 21, 2026 |
| CVE-2026-58271 | MEDIUM | 6.8 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/app/sync/register` accepts credentials and a TOTP code … | Sep 21, 2026 |
| CVE-2026-58269 | HIGH | 8.1 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, … | Sep 21, 2026 |
| CVE-2026-55897 | HIGH | 8.8 | luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot … | Sep 21, 2026 |
| CVE-2026-55159 | HIGH | 8.8 | luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts … | Sep 21, 2026 |
| CVE-2026-54915 | MEDIUM | 5.4 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /auth/redirect endpoint in plexpy/webauth.py removes forward slashes … | Sep 21, 2026 |
| CVE-2026-52835 | UNKNOWN | — | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the import_config handler and the database_file branch of import_database … | Sep 21, 2026 |
| CVE-2026-50572 | MEDIUM | 5.9 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HTTP external-authorization client can … | Sep 21, 2026 |
| CVE-2026-49995 | UNKNOWN | — | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the newsletter cron field stored in the newsletters table … | Sep 21, 2026 |