Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57083
Total
4536
Critical
16949
High
16800
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-88616 | HIGH | 8.8 | An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, Warm-Flow TaskService.skip, POST /workflow/task/completeTask … | Sep 15, 2026 |
| CVE-2026-79551 | UNKNOWN | — | Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key. | Sep 15, 2026 |
| CVE-2026-79425 | HIGH | 8.1 | An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows attackers to scan internal resources via a crafted POST request. | Sep 15, 2026 |
| CVE-2026-79303 | UNKNOWN | — | kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dynamic SQL statements are generated without the required data validation and without using parameterized … | Sep 15, 2026 |
| CVE-2026-63696 | CRITICAL | 9.1 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could … | Sep 15, 2026 |
| CVE-2026-63695 | CRITICAL | 9.8 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading … | Sep 15, 2026 |
| CVE-2026-61549 | UNKNOWN | — | Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.go copies that pipeline-step value directly into the … | Sep 15, 2026 |
| CVE-2026-59971 | CRITICAL | 10.0 | MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct … | Sep 15, 2026 |
| CVE-2026-57586 | HIGH | 8.6 | CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls … | Sep 15, 2026 |
| CVE-2026-55650 | MEDIUM | 4.4 | Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget … | Sep 15, 2026 |
| CVE-2026-55617 | UNKNOWN | — | Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic in packages/hydrooj/src/service/layers/base.ts creates a replacement session token without deleting … | Sep 15, 2026 |
| CVE-2026-55178 | HIGH | 7.5 | GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1.2.3, multiple read and link … | Sep 15, 2026 |
| CVE-2026-55158 | CRITICAL | 9.1 | Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git … | Sep 15, 2026 |
| CVE-2026-54637 | UNKNOWN | — | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4-rc.3, the scheduler's default unauthenticated v1 gRPC flow accepts attacker-controlled PeerHost.Ip … | Sep 15, 2026 |
| CVE-2026-54254 | UNKNOWN | — | Cyberdrop-DL is a bulk asynchronous downloader for multiple file hosts. From 8.5.0 until 9.14.0, the Pixeldrain crawler uses substring host matching instead of requiring the … | Sep 15, 2026 |
| CVE-2026-54168 | MEDIUM | 6.5 | Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App … | Sep 15, 2026 |
| CVE-2026-54167 | HIGH | 8.2 | Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App … | Sep 15, 2026 |
| CVE-2026-53966 | UNKNOWN | — | XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live Data edit REST API allows a user who … | Sep 15, 2026 |
| CVE-2026-53957 | HIGH | 7.7 | Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in … | Sep 15, 2026 |
| CVE-2026-52724 | UNKNOWN | — | Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and … | Sep 15, 2026 |
| CVE-2026-50166 | UNKNOWN | — | Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and … | Sep 15, 2026 |
| CVE-2026-49446 | MEDIUM | 6.1 | Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior … | Sep 15, 2026 |
| CVE-2026-49254 | UNKNOWN | — | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4, manager/router/router.go registers GET /api/v1/oauth and GET /api/v1/oauth/:id without jwt.MiddlewareFunc() or … | Sep 15, 2026 |
| CVE-2026-48987 | MEDIUM | 6.5 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload/core/managers/event_manager.py appends a Client object to the clients list … | Sep 15, 2026 |
| CVE-2026-48737 | MEDIUM | 4.9 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in src/pyload/core/utils/web/check.py relies on Python's global-address classification without examining IPv4 … | Sep 15, 2026 |