Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

52113
Total
4140
Critical
15446
High
15158
Medium
CVE ID Severity Score Description Published
CVE-2026-53445 UNKNOWN — Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan copyBoard Meteor DDP method in server/publications/boards.js copies a board by caller-supplied board … Jul 15, 2026
CVE-2026-53444 UNKNOWN — Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/oidc_server.js, server/models/org.js, and server/models/team.js are globally callable without the … Jul 15, 2026
CVE-2026-52893 UNKNOWN — Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into existing accounts when the … Jul 15, 2026
CVE-2026-52892 MEDIUM 6.5 Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use read-level Authentication.checkBoardAccess instead of write-level Authentication.checkBoardWriteAccess for mutating … Jul 15, 2026
CVE-2026-52891 CRITICAL 9.9 Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for … Jul 15, 2026
CVE-2026-52890 HIGH 7.1 Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /attachments/insert … Jul 15, 2026
CVE-2026-50183 MEDIUM 4.7 WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerability in the YouTubeAPI plugin. The plugin renders … Jul 15, 2026
CVE-2026-50182 MEDIUM 6.1 WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerability through AVideo YouTubeAPI Gallery Pagination. The $_GET['search'] … Jul 15, 2026
CVE-2026-49279 UNKNOWN — WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in the MessageSQLite WebSocket … Jul 15, 2026
CVE-2026-48795 HIGH 8.6 AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart field payloads such as user.__proto__.polluted … Jul 15, 2026
CVE-2026-45313 HIGH 7.7 Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and hproc fields from a GUI_WND_HOOK_REGISTER … Jul 15, 2026
CVE-2026-38974 UNKNOWN — Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py. Jul 15, 2026
CVE-2026-38755 HIGH 7.5 A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. Jul 15, 2026
CVE-2026-38754 HIGH 7.5 A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. Jul 15, 2026
CVE-2026-38752 HIGH 7.5 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted … Jul 15, 2026
CVE-2026-36590 UNKNOWN — An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component Jul 15, 2026
CVE-2026-30623 CRITICAL 9.8 LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON … Jul 15, 2026
CVE-2026-30618 CRITICAL 9.8 xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the … Jul 15, 2026
CVE-2026-26719 UNKNOWN — Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request containing a malicious script Jul 15, 2026
CVE-2026-26718 UNKNOWN — A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell … Jul 15, 2026
CVE-2026-15921 LOW 3.1 Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.1 through 0.40.5, `nvm ls-remote` (and other commands that … Jul 15, 2026
CVE-2025-65720 UNKNOWN — An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML … Jul 15, 2026
CVE-2026-62361 MEDIUM 5.5 listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscribers/export endpoint injects the user-controlled query parameter into QuerySubscribersForExport in … Jul 15, 2026
CVE-2026-62312 HIGH 8.8 9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitrary code execution on the host … Jul 15, 2026
CVE-2026-59950 UNKNOWN — The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport … Jul 15, 2026