Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

57083
Total
4536
Critical
16949
High
16800
Medium
CVE ID Severity Score Description Published
CVE-2026-55690 HIGH 7.5 The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video … Sep 15, 2026
CVE-2026-55149 HIGH 7.5 Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in pkg/cookie/cookie.go parses the total part … Sep 15, 2026
CVE-2026-54561 MEDIUM 6.2 MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath … Sep 15, 2026
CVE-2026-54503 MEDIUM 4.3 plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type. Prior to 2.0.2, 3.0.2, and 4.0.1, depending on … Sep 15, 2026
CVE-2026-53710 CRITICAL 10.0 MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes … Sep 15, 2026
CVE-2026-53658 UNKNOWN — Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP backend, Client.GetUser in lib/server/ldap/client.go inserts the … Sep 15, 2026
CVE-2026-46488 UNKNOWN — motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, … Sep 15, 2026
CVE-2026-44778 UNKNOWN — Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.28.0 … Sep 15, 2026
CVE-2026-21588 UNKNOWN — This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence … Sep 15, 2026
CVE-2026-21587 UNKNOWN — This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. This Improper Authorization vulnerability, with a CVSS Score … Sep 15, 2026
CVE-2026-21586 UNKNOWN — This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of … Sep 15, 2026
CVE-2026-19780 HIGH 8.8 Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required … Sep 15, 2026
CVE-2026-18111 UNKNOWN — Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete … Sep 15, 2026
CVE-2026-18110 UNKNOWN — Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" … Sep 15, 2026
CVE-2024-58385 CRITICAL 9.8 Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is … Sep 15, 2026
CVE-2023-54398 CRITICAL 9.8 Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending … Sep 15, 2026
CVE-2026-91992 MEDIUM 5.9 Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive … Sep 15, 2026
CVE-2026-91991 MEDIUM 5.4 Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword … Sep 15, 2026
CVE-2026-91990 HIGH 7.5 Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests … Sep 15, 2026
CVE-2026-91989 HIGH 7.5 atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal … Sep 15, 2026
CVE-2026-91988 HIGH 8.1 atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject … Sep 15, 2026
CVE-2026-91987 MEDIUM 6.5 atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers can … Sep 15, 2026
CVE-2026-91986 MEDIUM 5.4 gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can … Sep 15, 2026
CVE-2026-91985 HIGH 7.5 Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret … Sep 15, 2026
CVE-2026-91984 MEDIUM 4.3 Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project. Authenticated attackers can insert task position rows into … Sep 15, 2026