Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52066
Total
4132
Critical
15433
High
15137
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-47085 | MEDIUM | 4.0 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a … | Jul 16, 2026 |
| CVE-2026-47084 | MEDIUM | 6.5 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user could invoke the … | Jul 16, 2026 |
| CVE-2026-47083 | MEDIUM | 4.3 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated … | Jul 16, 2026 |
| CVE-2026-47082 | MEDIUM | 5.4 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user whose vacation Sieve script … | Jul 16, 2026 |
| CVE-2026-47081 | LOW | 3.1 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user … | Jul 16, 2026 |
| CVE-2026-46515 | UNKNOWN | — | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pinsets, fm_show_context, fm_get_mcp_config, fm_backup_status, fm_whos_calling, … | Jul 16, 2026 |
| CVE-2026-46514 | MEDIUM | 6.5 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword.php:48-53 returned a plaintext password and fm_add_extension in Tools/AddExtension.php:172 returned … | Jul 16, 2026 |
| CVE-2026-46513 | HIGH | 7.4 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by Tools/CreateApiToken.php:33-36 as raw bin2hex(random_bytes(32)) strings in … | Jul 16, 2026 |
| CVE-2026-46512 | CRITICAL | 9.9 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, dest, url, extension, code, and file, … | Jul 16, 2026 |
| CVE-2026-46404 | MEDIUM | 6.8 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly restrict access to site local and link local addresses. … | Jul 16, 2026 |
| CVE-2026-46378 | MEDIUM | 6.2 | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the selector lexer matchRegexPattern closure in (*Tokenizer).parseCurRune … | Jul 16, 2026 |
| CVE-2026-46377 | MEDIUM | 6.2 | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the escape sequence handler in (*Tokenizer).parseCurRune in … | Jul 16, 2026 |
| CVE-2026-46353 | HIGH | 8.1 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUrl parameter was supplied to API request handling … | Jul 16, 2026 |
| CVE-2026-46351 | HIGH | 8.1 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values with insufficiently secure randomness in bbb-common-web/src/main/java/org/bigbluebutton/api/Util.java and bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy, allowing a session … | Jul 16, 2026 |
| CVE-2026-46338 | MEDIUM | 4.3 | PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in … | Jul 16, 2026 |
| CVE-2026-46687 | UNKNOWN | — | Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter from api_controller.php without validation, … | Jul 16, 2026 |
| CVE-2026-46686 | UNKNOWN | — | Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user search module's keyword parameter from admin/user.php is processed with … | Jul 16, 2026 |
| CVE-2026-46341 | MEDIUM | 6.1 | The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior … | Jul 16, 2026 |
| CVE-2026-46336 | HIGH | 7.1 | Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. From 0.96.0 until 0.140.0, authenticated … | Jul 16, 2026 |
| CVE-2026-45336 | CRITICAL | 10.0 | HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded Flask … | Jul 16, 2026 |
| CVE-2026-44970 | LOW | 3.1 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_called_event() in src/dbt_mcp/tracking/tracking.py serialized every MCP tool call's complete arguments dictionary … | Jul 16, 2026 |
| CVE-2026-44969 | LOW | 2.5 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary at INFO level … | Jul 16, 2026 |
| CVE-2026-44968 | MEDIUM | 6.3 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/dbt_cli/tools.py appended unsanitized node_selection and resource_type values to the … | Jul 16, 2026 |
| CVE-2026-15945 | MEDIUM | 4.3 | A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated … | Jul 16, 2026 |
| CVE-2026-15737 | MEDIUM | 5.7 | AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. Unintended … | Jul 16, 2026 |