Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57083
Total
4536
Critical
16949
High
16800
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-57442 | UNKNOWN | — | MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored … | Sep 15, 2026 |
| CVE-2026-57441 | UNKNOWN | — | MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, PathFilter in src/pathfilter.ts compiles restricted-directory … | Sep 15, 2026 |
| CVE-2026-56831 | MEDIUM | 6.5 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes … | Sep 15, 2026 |
| CVE-2026-56830 | MEDIUM | 6.5 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check … | Sep 15, 2026 |
| CVE-2026-56829 | HIGH | 8.1 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable because it lacks … | Sep 15, 2026 |
| CVE-2026-56827 | HIGH | 8.1 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/src/Livewire/Pages/Attribute/Browse.php, packages/admin/src/Livewire/Pages/Tag/Index.php, packages/admin/src/Livewire/Pages/Brand/Index.php, packages/admin/src/Livewire/Pages/Category/Index.php, and packages/admin/src/Livewire/Pages/Supplier/Index.php omit server-side authorization while the pages require … | Sep 15, 2026 |
| CVE-2026-56825 | HIGH | 8.1 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Collection/CollectionProducts.php exposes Action::make('delete') and DeleteBulkAction::make() without delete_collections authorization, while public Collection $collection remains client mutable … | Sep 15, 2026 |
| CVE-2026-55375 | MEDIUM | 5.3 | canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQueryParams() places app_id, app_secret, refresh_token, and code in the … | Sep 15, 2026 |
| CVE-2026-55374 | MEDIUM | 4.8 | canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUrl() joins values returned by Request::getPathVariables() without encoding individual … | Sep 15, 2026 |
| CVE-2026-55226 | MEDIUM | 5.4 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, deploying only … | Sep 15, 2026 |
| CVE-2026-55225 | HIGH | 8.0 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker … | Sep 15, 2026 |
| CVE-2026-54689 | MEDIUM | 6.3 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, the web_url_read URL policy … | Sep 15, 2026 |
| CVE-2026-54688 | MEDIUM | 6.5 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, web_url_read passes a caller-supplied … | Sep 15, 2026 |
| CVE-2026-54549 | HIGH | 8.3 | Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, the upload_ad_image tool in … | Sep 15, 2026 |
| CVE-2026-54547 | HIGH | 7.4 | Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, AuthInjectionMiddleware in meta_ads_mcp/core/http_auth_integration.py rejects … | Sep 15, 2026 |
| CVE-2026-54251 | UNKNOWN | — | netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0.23.Final, the OHTTP gateway decryption path in codec-ohttp/src/main/java/io/netty/incubator/codec/ohttp/OHttpRequestResponseContext.java allocates a pooled direct … | Sep 15, 2026 |
| CVE-2026-54050 | MEDIUM | 6.5 | Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/profile/image endpoint allows an authenticated user to delete another … | Sep 15, 2026 |
| CVE-2026-53954 | MEDIUM | 4.3 | Bugsink is a self-hosted error tracking tool. Prior to version 2.2.2, Bugsink stores every set of custom tags supplied with an incoming event, allowing a … | Sep 15, 2026 |
| CVE-2026-53941 | UNKNOWN | — | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.27.0 … | Sep 15, 2026 |
| CVE-2026-53459 | UNKNOWN | — | Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and prior to version 0.2.4.4, a fail-open … | Sep 15, 2026 |
| CVE-2026-52484 | HIGH | 8.8 | An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code via the /cgi-bin/device-management-utilities-internet.cgi component | Sep 15, 2026 |
| CVE-2026-48785 | MEDIUM | 4.8 | Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefix matching to the limit container paths directive in apptainer.conf, so … | Sep 15, 2026 |
| CVE-2026-45579 | CRITICAL | 9.9 | DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, the RequestManagementSystem/Service/ReqManagerHandler.py export_getRequestCountersWeb function passes an authenticated … | Sep 15, 2026 |
| CVE-2026-44300 | UNKNOWN | — | OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpoint in pkg/costmodel/router.go allows a network client to invoke … | Sep 15, 2026 |
| CVE-2026-40058 | HIGH | 8.8 | CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious … | Sep 15, 2026 |