Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57083
Total
4536
Critical
16949
High
16800
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-55690 | HIGH | 7.5 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video … | Sep 15, 2026 |
| CVE-2026-55149 | HIGH | 7.5 | Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in pkg/cookie/cookie.go parses the total part … | Sep 15, 2026 |
| CVE-2026-54561 | MEDIUM | 6.2 | MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath … | Sep 15, 2026 |
| CVE-2026-54503 | MEDIUM | 4.3 | plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type. Prior to 2.0.2, 3.0.2, and 4.0.1, depending on … | Sep 15, 2026 |
| CVE-2026-53710 | CRITICAL | 10.0 | MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes … | Sep 15, 2026 |
| CVE-2026-53658 | UNKNOWN | — | Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP backend, Client.GetUser in lib/server/ldap/client.go inserts the … | Sep 15, 2026 |
| CVE-2026-46488 | UNKNOWN | — | motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, … | Sep 15, 2026 |
| CVE-2026-44778 | UNKNOWN | — | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.28.0 … | Sep 15, 2026 |
| CVE-2026-21588 | UNKNOWN | — | This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence … | Sep 15, 2026 |
| CVE-2026-21587 | UNKNOWN | — | This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. This Improper Authorization vulnerability, with a CVSS Score … | Sep 15, 2026 |
| CVE-2026-21586 | UNKNOWN | — | This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of … | Sep 15, 2026 |
| CVE-2026-19780 | HIGH | 8.8 | Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required … | Sep 15, 2026 |
| CVE-2026-18111 | UNKNOWN | — | Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete … | Sep 15, 2026 |
| CVE-2026-18110 | UNKNOWN | — | Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" … | Sep 15, 2026 |
| CVE-2024-58385 | CRITICAL | 9.8 | Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is … | Sep 15, 2026 |
| CVE-2023-54398 | CRITICAL | 9.8 | Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending … | Sep 15, 2026 |
| CVE-2026-91992 | MEDIUM | 5.9 | Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive … | Sep 15, 2026 |
| CVE-2026-91991 | MEDIUM | 5.4 | Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword … | Sep 15, 2026 |
| CVE-2026-91990 | HIGH | 7.5 | Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests … | Sep 15, 2026 |
| CVE-2026-91989 | HIGH | 7.5 | atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal … | Sep 15, 2026 |
| CVE-2026-91988 | HIGH | 8.1 | atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject … | Sep 15, 2026 |
| CVE-2026-91987 | MEDIUM | 6.5 | atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers can … | Sep 15, 2026 |
| CVE-2026-91986 | MEDIUM | 5.4 | gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can … | Sep 15, 2026 |
| CVE-2026-91985 | HIGH | 7.5 | Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret … | Sep 15, 2026 |
| CVE-2026-91984 | MEDIUM | 4.3 | Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project. Authenticated attackers can insert task position rows into … | Sep 15, 2026 |