Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52113
Total
4140
Critical
15446
High
15158
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-56679 | UNKNOWN | — | 9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body to persistent settings without a … | Jul 15, 2026 |
| CVE-2026-56678 | MEDIUM | 6.4 | 9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key builds an upstream URL using a user-controlled … | Jul 15, 2026 |
| CVE-2026-55608 | MEDIUM | 4.2 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.57.4, multi-tenant HTTP mode with ENABLE_MULTI_TENANT=true … | Jul 15, 2026 |
| CVE-2026-55410 | MEDIUM | 6.7 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.1.19, NocoBase @nocobase/plugin-backups restored PostgreSQL backups by interpolating the database.schema … | Jul 15, 2026 |
| CVE-2026-55399 | MEDIUM | 4.3 | CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create … | Jul 15, 2026 |
| CVE-2026-55398 | LOW | 3.7 | CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with intimate knowledge of and total control over the … | Jul 15, 2026 |
| CVE-2026-54052 | CRITICAL | 9.9 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy … | Jul 15, 2026 |
| CVE-2026-52888 | MEDIUM | 6.8 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @nocobase/plugin-collection-sql used the checkSQL() function in packages/plugins/@nocobase/plugin-collection-sql/src/server/utils.ts … | Jul 15, 2026 |
| CVE-2026-52887 | CRITICAL | 10.0 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value … | Jul 15, 2026 |
| CVE-2026-51380 | CRITICAL | 9.8 | Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code via … | Jul 15, 2026 |
| CVE-2026-49353 | HIGH | 7.5 | 9Router is an AI router & token saver. In 0.4.45 and earlier, 9Router's src/dashboardGuard.js local-only access gate used Host and Origin headers in isLocalRequest() to … | Jul 15, 2026 |
| CVE-2026-49352 | CRITICAL | 9.8 | 9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/route.js, src/middleware.js, and later … | Jul 15, 2026 |
| CVE-2026-46339 | CRITICAL | 10.0 | 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of … | Jul 15, 2026 |
| CVE-2026-38753 | HIGH | 7.5 | A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. | Jul 15, 2026 |
| CVE-2026-33684 | MEDIUM | 5.3 | WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in signUp API, which allows … | Jul 15, 2026 |
| CVE-2026-33445 | MEDIUM | 5.9 | CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel … | Jul 15, 2026 |
| CVE-2026-33444 | LOW | 3.7 | CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol … | Jul 15, 2026 |
| CVE-2026-56743 | MEDIUM | 5.4 | Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy specifications using CIDR-based ipBlock rules without pod or namespace selectors … | Jul 15, 2026 |
| CVE-2026-56742 | MEDIUM | 5.9 | Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create … | Jul 15, 2026 |
| CVE-2026-52870 | HIGH | 7.6 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed … | Jul 15, 2026 |
| CVE-2026-52869 | HIGH | 7.1 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful … | Jul 15, 2026 |
| CVE-2026-50144 | HIGH | 7.1 | ncnn is a high-performance neural network inference framework optimized for the mobile platform. In commit e54f7b1f88434e1d844ea0551b880a1cfb079ce1 and earlier, ncnn allows an out-of-bounds heap write in … | Jul 15, 2026 |
| CVE-2026-50124 | UNKNOWN | — | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Excel upload API … | Jul 15, 2026 |
| CVE-2026-50030 | UNKNOWN | — | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL preview exposes DatasetDataApi.previewSql/previewSqlCheck through /de2api/datasetData/previewSql, accepts PreviewSqlDTO.sql, PreviewSqlDTO.datasourceId, and PreviewSqlDTO.isCross, … | Jul 15, 2026 |
| CVE-2026-49867 | UNKNOWN | — | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template static resources let authenticated users submit TemplateManageRequest.staticResource through POST /de2api/templateManage/save … | Jul 15, 2026 |