Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26383
Total
1955
Critical
7969
High
8219
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-42877 | MEDIUM | 5.4 | FacturaScripts is an open source accounting and invoicing software. In 2025.92 and earlier, a stored Cross-Site Scripting (XSS) vulnerability exists in the product search modal … | May 27, 2026 |
| CVE-2026-42197 | HIGH | 8.7 | RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a stored cross-site scripting vulnerability that allows any enrolled student to execute arbitrary … | May 27, 2026 |
| CVE-2026-33552 | LOW | 3.7 | Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control. | May 27, 2026 |
| CVE-2026-8716 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain … | May 27, 2026 |
| CVE-2026-6713 | MEDIUM | 5.3 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain … | May 27, 2026 |
| CVE-2026-5296 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that when foundational … | May 27, 2026 |
| CVE-2026-4868 | HIGH | 8.2 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain … | May 27, 2026 |
| CVE-2026-45046 | MEDIUM | 5.5 | Gryph provides a security layer for AI coding agents. Prior to 0.7.0, Gryph implements logging levels that determine what content is logged to a local … | May 27, 2026 |
| CVE-2026-44635 | HIGH | 7.5 | Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metacharacters (., [, ], *, **, ?). When … | May 27, 2026 |
| CVE-2026-42879 | MEDIUM | 6.3 | FacturaScripts is an open source accounting and invoicing software. In 2025.81 and earlier, an authenticated unrestricted file upload vulnerability exists in FacturaScripts' product image upload … | May 27, 2026 |
| CVE-2026-42878 | MEDIUM | 5.3 | FacturaScripts is an open source accounting and invoicing software. Prior to v2026, an unauthenticated information disclosure vulnerability in the Installer controller allows any remote attacker … | May 27, 2026 |
| CVE-2026-2601 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain … | May 27, 2026 |
| CVE-2026-1402 | MEDIUM | 6.5 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain … | May 27, 2026 |
| CVE-2026-5509 | UNKNOWN | — | An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an administrator to execute arbitrary system commands through … | May 27, 2026 |
| CVE-2026-4392 | MEDIUM | 5.3 | A vulnerability was detected in TeamSpeak 3 Server up to 3.13.7. This issue affects some unknown processing of the component clientek Handshake Handler. Performing a … | May 27, 2026 |
| CVE-2026-4391 | MEDIUM | 5.3 | A security vulnerability has been detected in TeamSpeak 3 Server up to 3.13.7. This vulnerability affects unknown code of the component ECC Key Parser. Such … | May 27, 2026 |
| CVE-2026-4390 | MEDIUM | 5.4 | A weakness has been identified in TeamSpeak 3 Server up to 3.13.7. This affects the function process_resend_queue of the component Connection State Management. This manipulation … | May 27, 2026 |
| CVE-2026-48153 | HIGH | 8.5 | Budibase is an open-source low-code platform. Prior to 3.39.0, fetchToken in the OAuth2 SDK makes a POST to a builder-supplied URL with plain node-fetch, skipping … | May 27, 2026 |
| CVE-2026-48152 | HIGH | 8.1 | Budibase is an open-source low-code platform. Prior to 3.39.0, the single-datasource GET and PUT routes are guarded by generic TABLE READ, not by Builder/Admin permission … | May 27, 2026 |
| CVE-2026-48151 | HIGH | 7.5 | Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schema-building endpoint is registered under builderRoutes, but the generic authorization middleware skips authorization for … | May 27, 2026 |
| CVE-2026-48150 | CRITICAL | 9.0 | Budibase is an open-source low-code platform. Prior to 3.39.0, /api/public/v1/roles/assign is guarded by the builderOrAdmin middleware, which passes any user who is a builder for … | May 27, 2026 |
| CVE-2026-48149 | HIGH | 8.1 | Budibase is an open-source low-code platform. Prior to 3.39.0, the Budibase Text component renders markdown by assigning marked.parse(markdown) straight to innerHTML with no sanitizer (packages/bbui/src/Markdown/MarkdownViewer.svelte:22). … | May 27, 2026 |
| CVE-2026-48148 | UNKNOWN | — | Budibase is an open-source low-code platform. Prior to 3.35.3, the VectorDB configuration endpoint in Budibase accepts a host parameter that undergoes no validation against internal … | May 27, 2026 |
| CVE-2026-48147 | MEDIUM | 6.5 | Budibase is an open-source low-code platform. Prior to 3.35.4, the buildMatcherRegex() / matches() functions in packages/backend-core/src/middleware/matchers.ts route patterns are compiled into unanchored regular expressions and … | May 27, 2026 |
| CVE-2026-48146 | HIGH | 7.7 | Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token fetch function in packages/server/src/sdk/workspace/oauth2/utils.ts uses raw fetch(config.url) with no SSRF protection. The safe … | May 27, 2026 |