Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42275
Total
3446
Critical
12492
High
12441
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82284 | HIGH | 8.1 | Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' … | Aug 28, 2026 |
| CVE-2026-82283 | HIGH | 8.1 | VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations. Attackers can read, modify, and … | Aug 28, 2026 |
| CVE-2026-82282 | HIGH | 8.0 | Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect … | Aug 28, 2026 |
| CVE-2026-82281 | HIGH | 7.4 | Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, … | Aug 28, 2026 |
| CVE-2026-82280 | HIGH | 7.1 | Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared … | Aug 28, 2026 |
| CVE-2026-82279 | HIGH | 8.1 | HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team … | Aug 28, 2026 |
| CVE-2026-82278 | HIGH | 8.8 | BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code. Attackers can … | Aug 28, 2026 |
| CVE-2026-82277 | CRITICAL | 9.8 | Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network … | Aug 28, 2026 |
| CVE-2026-82276 | MEDIUM | 5.3 | StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override execute() directly instead of implementing executeWithoutPassword(). Attackers can access six … | Aug 28, 2026 |
| CVE-2026-82275 | HIGH | 7.5 | Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories. Attackers can supply absolute … | Aug 28, 2026 |
| CVE-2026-82274 | MEDIUM | 4.7 | Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback endpoint that treats the state query parameter as a redirect URL. Attackers can craft … | Aug 28, 2026 |
| CVE-2026-82273 | MEDIUM | 6.5 | Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when mapUserToResourceId callback is omitted from configuration. Authenticated attackers can … | Aug 28, 2026 |
| CVE-2026-82272 | MEDIUM | 6.5 | Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared … | Aug 28, 2026 |
| CVE-2026-82271 | MEDIUM | 6.5 | R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can … | Aug 28, 2026 |
| CVE-2026-82270 | HIGH | 7.5 | Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header … | Aug 28, 2026 |
| CVE-2026-82269 | HIGH | 8.1 | Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these … | Aug 28, 2026 |
| CVE-2026-82268 | HIGH | 7.5 | Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host … | Aug 28, 2026 |
| CVE-2026-82267 | MEDIUM | 5.4 | Komodo through 2.3.2 discloses internal resource identifiers and writes audit entries before performing permission checks in the /execute and /execute/{variant} handlers. Authenticated users can guess … | Aug 28, 2026 |
| CVE-2026-82266 | CRITICAL | 9.8 | Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without … | Aug 28, 2026 |
| CVE-2026-82265 | MEDIUM | 6.5 | Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read … | Aug 28, 2026 |
| CVE-2026-82264 | MEDIUM | 6.8 | Duplicacy through 3.2.5 contains a path traversal vulnerability in the restore function that fails to validate entry paths deserialized from snapshot files. Attackers can craft … | Aug 28, 2026 |
| CVE-2026-82263 | MEDIUM | 6.8 | Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant … | Aug 28, 2026 |
| CVE-2026-82262 | MEDIUM | 6.8 | Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation. Tenant administrators with Management … | Aug 28, 2026 |
| CVE-2026-82021 | HIGH | 8.3 | Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code … | Aug 28, 2026 |
| CVE-2026-82020 | MEDIUM | 6.8 | Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential … | Aug 28, 2026 |