Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56054
Total
4437
Critical
16638
High
16408
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-62182 | HIGH | 8.8 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.21.0 until 1.21.2, 1.22.2, and 1.23.1, ConfigUpdateJob … | Sep 21, 2026 |
| CVE-2026-61745 | MEDIUM | 4.3 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the POST /api/machine/{pk}/restart/ endpoint in src/backend/InvenTree/machine/api.py uses IsAuthenticatedOrReadScope without requiring the ADMIN role used … | Sep 21, 2026 |
| CVE-2026-61612 | MEDIUM | 5.7 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerUrl` (added for CVE-2026-33060, extended for … | Sep 21, 2026 |
| CVE-2026-55473 | UNKNOWN | — | HomeBox is a home inventory and organization system. Prior to 0.26.0, the default-on BlockBogonNets and BlockCloudMetadata notifier SSRF protections in backend/internal/sys/validate/notifier_url.go do not inspect IPv4 … | Sep 21, 2026 |
| CVE-2026-48976 | HIGH | 8.1 | HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data/repo/repo_notifier.go updates a notifier through UpdateOneID(id) without requiring the record's user ID … | Sep 21, 2026 |
| CVE-2026-48975 | HIGH | 8.1 | HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceEntryRepository.Delete in backend/internal/data/repo/repo_maintenance_entry.go use UpdateOneID(id) and DeleteOneID(id) without verifying that the maintenance … | Sep 21, 2026 |
| CVE-2026-48974 | MEDIUM | 5.4 | HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner … | Sep 21, 2026 |
| CVE-2026-48826 | HIGH | 8.1 | HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of the … | Sep 21, 2026 |
| CVE-2026-94449 | HIGH | 7.5 | A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices. … | Sep 21, 2026 |
| CVE-2026-84990 | HIGH | 8.8 | ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua allow any authenticated non-admin user to list and download system-configuration backups … | Sep 21, 2026 |
| CVE-2026-83621 | HIGH | 8.1 | ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.editList for any authenticated … | Sep 21, 2026 |
| CVE-2026-79920 | CRITICAL | 9.9 | Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or … | Sep 21, 2026 |
| CVE-2026-77582 | UNKNOWN | — | Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local … | Sep 21, 2026 |
| CVE-2026-77561 | MEDIUM | 5.3 | Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST /api/user/login requests with 257 distinct nonexistent usernames to … | Sep 21, 2026 |
| CVE-2026-77560 | HIGH | 8.1 | Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated … | Sep 21, 2026 |
| CVE-2026-76898 | UNKNOWN | — | draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.3.8, src/main/java/com/mxgraph/online/Utils.java checks IPv6 Unique Local Addresses in Utils.sanitizeUrl() by comparing the text prefixes … | Sep 21, 2026 |
| CVE-2026-63416 | LOW | 3.7 | draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, src/main/java/com/mxgraph/online/ExportProxyServlet.java uses request.getPathInfo() to build a proxyPath and appends it directly to EXPORT_URL … | Sep 21, 2026 |
| CVE-2026-63373 | MEDIUM | 4.2 | draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, the OAuth callback handler in src/main/java/com/mxgraph/online/AbsAuth.java skips comparison of stateToken and cookieToken whenever … | Sep 21, 2026 |
| CVE-2026-63334 | MEDIUM | 6.8 | draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, deployments with ENABLE_DRAWIO_PROXY=1 are vulnerable to server-side request forgery because src/main/java/com/mxgraph/online/Utils.java performs the … | Sep 21, 2026 |
| CVE-2026-63116 | HIGH | 8.8 | deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. From 10.1.0 until 10.1.1, src/services/permission/valve/rules-map.ts … | Sep 21, 2026 |
| CVE-2026-62987 | MEDIUM | 5.8 | Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for … | Sep 21, 2026 |
| CVE-2026-62866 | MEDIUM | 6.2 | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.2, selector/lexer/tokenize.go parseCurRune advances the input index across … | Sep 21, 2026 |
| CVE-2026-62371 | HIGH | 8.8 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the … | Sep 21, 2026 |
| CVE-2026-62370 | MEDIUM | 6.5 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.0.0 until 1.21.2, 1.22.2, and 1.23.1, Reader.Read … | Sep 21, 2026 |
| CVE-2026-61674 | UNKNOWN | — | Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0 until 5.0.8, plugins/out_forward/forward.c secure_forward_pong copies … | Sep 21, 2026 |