Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42400
Total
3455
Critical
12534
High
12466
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82248 | MEDIUM | 5.3 | gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization (destination_is_initially_empty: … | Aug 28, 2026 |
| CVE-2026-82247 | HIGH | 7.5 | gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, … | Aug 28, 2026 |
| CVE-2026-82246 | HIGH | 7.1 | Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers … | Aug 28, 2026 |
| CVE-2026-82245 | HIGH | 8.1 | Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license keys or manipulate offline tokens. Attackers … | Aug 28, 2026 |
| CVE-2026-82244 | CRITICAL | 9.1 | Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a … | Aug 28, 2026 |
| CVE-2026-82243 | HIGH | 7.6 | Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF … | Aug 28, 2026 |
| CVE-2026-82242 | HIGH | 7.7 | Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated builders to inject tables, automations, queries, and screens … | Aug 28, 2026 |
| CVE-2026-82241 | HIGH | 7.1 | Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/10 from its default SSRF blacklist (DEFAULT_BLACKLIST) used by REST datasource query … | Aug 28, 2026 |
| CVE-2026-82240 | HIGH | 8.1 | Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant … | Aug 28, 2026 |
| CVE-2026-82239 | HIGH | 8.1 | Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows … | Aug 28, 2026 |
| CVE-2026-82238 | LOW | 3.1 | filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending … | Aug 28, 2026 |
| CVE-2026-82237 | LOW | 3.1 | filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by … | Aug 28, 2026 |
| CVE-2026-82236 | LOW | 3.1 | File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can … | Aug 28, 2026 |
| CVE-2026-82235 | MEDIUM | 5.9 | filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing attackers to trigger blocking open syscalls. Authenticated users or … | Aug 28, 2026 |
| CVE-2026-82234 | HIGH | 8.2 | SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_request and web_fetch agent tools that perform DNS resolution only at guard time … | Aug 28, 2026 |
| CVE-2026-82233 | MEDIUM | 5.7 | SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolute file paths without workspace boundary validation. Attackers can … | Aug 28, 2026 |
| CVE-2026-82222 | CRITICAL | 10.0 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1. | Aug 28, 2026 |
| CVE-2026-82111 | MEDIUM | 4.3 | A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The affected element is the function fs.readFileSync of the file src/index.ts of the component upload_image. … | Aug 28, 2026 |
| CVE-2026-81777 | MEDIUM | 5.3 | Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This issue affects Essential Addons for Elementor: from n/a through 6.8.0. | Aug 28, 2026 |
| CVE-2026-81733 | UNKNOWN | — | WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that a user … | Aug 28, 2026 |
| CVE-2026-81732 | UNKNOWN | — | WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, allowing unauthenticated access to user registration statistics. Attackers can send … | Aug 28, 2026 |
| CVE-2026-78073 | UNKNOWN | — | Joomla Extension - mrvinoth.com - Reflected XSS in All Video Share 1.0.0-4.5.0 - Various user supplied inputs lacked escaping, leading to reflected XSS vectors | Aug 28, 2026 |
| CVE-2026-78072 | UNKNOWN | — | Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1 | Aug 28, 2026 |
| CVE-2026-78071 | UNKNOWN | — | Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2 - Location title is rendered in data attribute without escaping … | Aug 28, 2026 |
| CVE-2026-78070 | UNKNOWN | — | Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Saving an article can trigger a blind SQL … | Aug 28, 2026 |