Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52113
Total
4140
Critical
15446
High
15158
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-53445 | UNKNOWN | — | Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan copyBoard Meteor DDP method in server/publications/boards.js copies a board by caller-supplied board … | Jul 15, 2026 |
| CVE-2026-53444 | UNKNOWN | — | Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/oidc_server.js, server/models/org.js, and server/models/team.js are globally callable without the … | Jul 15, 2026 |
| CVE-2026-52893 | UNKNOWN | — | Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into existing accounts when the … | Jul 15, 2026 |
| CVE-2026-52892 | MEDIUM | 6.5 | Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use read-level Authentication.checkBoardAccess instead of write-level Authentication.checkBoardWriteAccess for mutating … | Jul 15, 2026 |
| CVE-2026-52891 | CRITICAL | 9.9 | Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for … | Jul 15, 2026 |
| CVE-2026-52890 | HIGH | 7.1 | Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /attachments/insert … | Jul 15, 2026 |
| CVE-2026-50183 | MEDIUM | 4.7 | WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerability in the YouTubeAPI plugin. The plugin renders … | Jul 15, 2026 |
| CVE-2026-50182 | MEDIUM | 6.1 | WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerability through AVideo YouTubeAPI Gallery Pagination. The $_GET['search'] … | Jul 15, 2026 |
| CVE-2026-49279 | UNKNOWN | — | WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in the MessageSQLite WebSocket … | Jul 15, 2026 |
| CVE-2026-48795 | HIGH | 8.6 | AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart field payloads such as user.__proto__.polluted … | Jul 15, 2026 |
| CVE-2026-45313 | HIGH | 7.7 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and hproc fields from a GUI_WND_HOOK_REGISTER … | Jul 15, 2026 |
| CVE-2026-38974 | UNKNOWN | — | Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py. | Jul 15, 2026 |
| CVE-2026-38755 | HIGH | 7.5 | A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. | Jul 15, 2026 |
| CVE-2026-38754 | HIGH | 7.5 | A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. | Jul 15, 2026 |
| CVE-2026-38752 | HIGH | 7.5 | A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted … | Jul 15, 2026 |
| CVE-2026-36590 | UNKNOWN | — | An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component | Jul 15, 2026 |
| CVE-2026-30623 | CRITICAL | 9.8 | LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON … | Jul 15, 2026 |
| CVE-2026-30618 | CRITICAL | 9.8 | xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the … | Jul 15, 2026 |
| CVE-2026-26719 | UNKNOWN | — | Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request containing a malicious script | Jul 15, 2026 |
| CVE-2026-26718 | UNKNOWN | — | A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell … | Jul 15, 2026 |
| CVE-2026-15921 | LOW | 3.1 | Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.1 through 0.40.5, `nvm ls-remote` (and other commands that … | Jul 15, 2026 |
| CVE-2025-65720 | UNKNOWN | — | An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML … | Jul 15, 2026 |
| CVE-2026-62361 | MEDIUM | 5.5 | listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscribers/export endpoint injects the user-controlled query parameter into QuerySubscribersForExport in … | Jul 15, 2026 |
| CVE-2026-62312 | HIGH | 8.8 | 9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitrary code execution on the host … | Jul 15, 2026 |
| CVE-2026-59950 | UNKNOWN | — | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport … | Jul 15, 2026 |