Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57306
Total
4581
Critical
17028
High
16895
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-88621 | UNKNOWN | — | OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability in the Api::upload() method in class/Api.php. An authenticated administrator can submit a non-HTML upload filename matching … | Sep 15, 2026 |
| CVE-2026-88620 | UNKNOWN | — | SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint. The endpoint does not enforce the required function-level permission or … | Sep 15, 2026 |
| CVE-2026-88619 | HIGH | 8.1 | 1024-lab SmartAdmin v3.30.0 contains a missing authorization vulnerability in the scheduled-job management module. The AdminSmartJobController exposes scheduled-job management endpoints without method-level permission checks, allowing a … | Sep 15, 2026 |
| CVE-2026-87793 | UNKNOWN | — | The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated attacker to execute arbitrary JavaScript … | Sep 15, 2026 |
| CVE-2026-87792 | UNKNOWN | — | The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access … | Sep 15, 2026 |
| CVE-2026-87791 | UNKNOWN | — | A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated … | Sep 15, 2026 |
| CVE-2026-85013 | HIGH | 7.3 | A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the … | Sep 15, 2026 |
| CVE-2026-77972 | UNKNOWN | — | Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS responses to reach internal network destinations that validation rejected. … | Sep 15, 2026 |
| CVE-2026-77866 | UNKNOWN | — | Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reach internal network destinations the library is configured … | Sep 15, 2026 |
| CVE-2026-65831 | HIGH | 7.7 | ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with language: js because PolyglotQueryEngine.command, PolyglotQueryEngine.analyze, and PolyglotQueryEngine.registerFunctions do not … | Sep 15, 2026 |
| CVE-2026-59973 | HIGH | 8.5 | FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1 until 1.5.0, libs/adapters/src/openapi/openapi.adapter.ts … | Sep 15, 2026 |
| CVE-2026-59965 | HIGH | 7.1 | Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default guard … | Sep 15, 2026 |
| CVE-2026-59157 | MEDIUM | 6.5 | webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authentication forwarded … | Sep 15, 2026 |
| CVE-2026-58196 | MEDIUM | 4.7 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.31.0, remote.Handler.Authenticate in pkg/auth/remote/handler.go invokes discovery.DetectAuthenticationFromServer … | Sep 15, 2026 |
| CVE-2026-55887 | UNKNOWN | — | MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image … | Sep 15, 2026 |
| CVE-2026-55864 | UNKNOWN | — | GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/tools/ogc/sld accepted a caller-supplied WMS server URL and performed … | Sep 15, 2026 |
| CVE-2026-55828 | UNKNOWN | — | qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for … | Sep 15, 2026 |
| CVE-2026-55776 | MEDIUM | 6.5 | OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server … | Sep 15, 2026 |
| CVE-2026-55775 | UNKNOWN | — | OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities on /sys/namespaces/root within a non-root namespace could exploit special … | Sep 15, 2026 |
| CVE-2026-55774 | UNKNOWN | — | OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a … | Sep 15, 2026 |
| CVE-2026-55770 | MEDIUM | 6.8 | OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP … | Sep 15, 2026 |
| CVE-2026-55701 | UNKNOWN | — | The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/config.go RequiredHeaders configuration at startup, but receiver/githubreceiver/trace_receiver.go … | Sep 15, 2026 |
| CVE-2026-55636 | MEDIUM | 5.7 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.6, charts/capsule/templates/configuration.yaml configures the validating webhook with namespace/finalize instead of the Kubernetes resource … | Sep 15, 2026 |
| CVE-2026-55630 | NONE | — | Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating … | Sep 15, 2026 |
| CVE-2026-55591 | MEDIUM | 5.8 | Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, … | Sep 15, 2026 |