Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42683
Total
3463
Critical
12701
High
12563
Medium
CVE ID Severity Score Description Published
CVE-2026-82256 MEDIUM 5.3 SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation … Aug 28, 2026
CVE-2026-82255 MEDIUM 6.8 gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. … Aug 28, 2026
CVE-2026-82254 HIGH 7.5 gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data … Aug 28, 2026
CVE-2026-82253 HIGH 7.5 gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the … Aug 28, 2026
CVE-2026-82252 HIGH 7.5 gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious … Aug 28, 2026
CVE-2026-82251 HIGH 7.5 gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names … Aug 28, 2026
CVE-2026-82250 MEDIUM 6.5 gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious … Aug 28, 2026
CVE-2026-82249 LOW 3.1 gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to … Aug 28, 2026
CVE-2026-82248 MEDIUM 5.3 gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization (destination_is_initially_empty: … Aug 28, 2026
CVE-2026-82247 HIGH 7.5 gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, … Aug 28, 2026
CVE-2026-82246 HIGH 7.1 Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers … Aug 28, 2026
CVE-2026-82245 HIGH 8.1 Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license keys or manipulate offline tokens. Attackers … Aug 28, 2026
CVE-2026-82244 CRITICAL 9.1 Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a … Aug 28, 2026
CVE-2026-82243 HIGH 7.6 Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF … Aug 28, 2026
CVE-2026-82242 HIGH 7.7 Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated builders to inject tables, automations, queries, and screens … Aug 28, 2026
CVE-2026-82241 HIGH 7.1 Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/10 from its default SSRF blacklist (DEFAULT_BLACKLIST) used by REST datasource query … Aug 28, 2026
CVE-2026-82240 HIGH 8.1 Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant … Aug 28, 2026
CVE-2026-82239 HIGH 8.1 Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows … Aug 28, 2026
CVE-2026-82238 LOW 3.1 filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending … Aug 28, 2026
CVE-2026-82237 LOW 3.1 filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by … Aug 28, 2026
CVE-2026-82236 LOW 3.1 File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can … Aug 28, 2026
CVE-2026-82235 MEDIUM 5.9 filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing attackers to trigger blocking open syscalls. Authenticated users or … Aug 28, 2026
CVE-2026-82234 HIGH 8.2 SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_request and web_fetch agent tools that perform DNS resolution only at guard time … Aug 28, 2026
CVE-2026-82233 MEDIUM 5.7 SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolute file paths without workspace boundary validation. Attackers can … Aug 28, 2026
CVE-2026-82222 CRITICAL 10.0 Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1. Aug 28, 2026