Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42275
Total
3446
Critical
12492
High
12441
Medium
CVE ID Severity Score Description Published
CVE-2026-82284 HIGH 8.1 Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' … Aug 28, 2026
CVE-2026-82283 HIGH 8.1 VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations. Attackers can read, modify, and … Aug 28, 2026
CVE-2026-82282 HIGH 8.0 Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect … Aug 28, 2026
CVE-2026-82281 HIGH 7.4 Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, … Aug 28, 2026
CVE-2026-82280 HIGH 7.1 Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared … Aug 28, 2026
CVE-2026-82279 HIGH 8.1 HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team … Aug 28, 2026
CVE-2026-82278 HIGH 8.8 BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code. Attackers can … Aug 28, 2026
CVE-2026-82277 CRITICAL 9.8 Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network … Aug 28, 2026
CVE-2026-82276 MEDIUM 5.3 StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override execute() directly instead of implementing executeWithoutPassword(). Attackers can access six … Aug 28, 2026
CVE-2026-82275 HIGH 7.5 Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories. Attackers can supply absolute … Aug 28, 2026
CVE-2026-82274 MEDIUM 4.7 Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback endpoint that treats the state query parameter as a redirect URL. Attackers can craft … Aug 28, 2026
CVE-2026-82273 MEDIUM 6.5 Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when mapUserToResourceId callback is omitted from configuration. Authenticated attackers can … Aug 28, 2026
CVE-2026-82272 MEDIUM 6.5 Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared … Aug 28, 2026
CVE-2026-82271 MEDIUM 6.5 R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can … Aug 28, 2026
CVE-2026-82270 HIGH 7.5 Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header … Aug 28, 2026
CVE-2026-82269 HIGH 8.1 Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these … Aug 28, 2026
CVE-2026-82268 HIGH 7.5 Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host … Aug 28, 2026
CVE-2026-82267 MEDIUM 5.4 Komodo through 2.3.2 discloses internal resource identifiers and writes audit entries before performing permission checks in the /execute and /execute/{variant} handlers. Authenticated users can guess … Aug 28, 2026
CVE-2026-82266 CRITICAL 9.8 Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without … Aug 28, 2026
CVE-2026-82265 MEDIUM 6.5 Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read … Aug 28, 2026
CVE-2026-82264 MEDIUM 6.8 Duplicacy through 3.2.5 contains a path traversal vulnerability in the restore function that fails to validate entry paths deserialized from snapshot files. Attackers can craft … Aug 28, 2026
CVE-2026-82263 MEDIUM 6.8 Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant … Aug 28, 2026
CVE-2026-82262 MEDIUM 6.8 Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation. Tenant administrators with Management … Aug 28, 2026
CVE-2026-82021 HIGH 8.3 Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code … Aug 28, 2026
CVE-2026-82020 MEDIUM 6.8 Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential … Aug 28, 2026