Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42739
Total
3465
Critical
12744
High
12574
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-54687 | UNKNOWN | — | n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1.node.ts exposes the db_path database file path as a node … | Aug 27, 2026 |
| CVE-2026-53580 | HIGH | 8.1 | Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the automatic image-download feature accepts file:// URLs in a note's img tags and … | Aug 27, 2026 |
| CVE-2026-53579 | UNKNOWN | — | Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes … | Aug 27, 2026 |
| CVE-2026-53578 | UNKNOWN | — | Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes … | Aug 27, 2026 |
| CVE-2026-48996 | UNKNOWN | — | Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter does not sanitize note titles, and … | Aug 27, 2026 |
| CVE-2026-47727 | UNKNOWN | — | Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the default-on "Safe import" filter fails to neutralize the shareTemplate relation because that … | Aug 27, 2026 |
| CVE-2026-37198 | UNKNOWN | — | An integer overflow in the SMF component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted GTP packet. | Aug 27, 2026 |
| CVE-2026-37073 | UNKNOWN | — | Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from the configured SMPT server on the … | Aug 27, 2026 |
| CVE-2026-37072 | UNKNOWN | — | Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php. | Aug 27, 2026 |
| CVE-2026-37071 | UNKNOWN | — | Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take … | Aug 27, 2026 |
| CVE-2026-37070 | UNKNOWN | — | Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as … | Aug 27, 2026 |
| CVE-2026-37069 | UNKNOWN | — | Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to know in which system directory the application code is … | Aug 27, 2026 |
| CVE-2026-37068 | UNKNOWN | — | Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php … | Aug 27, 2026 |
| CVE-2026-37067 | UNKNOWN | — | Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards … | Aug 27, 2026 |
| CVE-2026-37066 | UNKNOWN | — | Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role … | Aug 27, 2026 |
| CVE-2026-37065 | UNKNOWN | — | Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=. | Aug 27, 2026 |
| CVE-2026-37064 | UNKNOWN | — | User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST … | Aug 27, 2026 |
| CVE-2026-37012 | UNKNOWN | — | A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 1.0.0 allows remote attackers to disclose sensitive user telemetry data via hardcoded API credentials. | Aug 27, 2026 |
| CVE-2026-37009 | UNKNOWN | — | A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 allows a remote attacker to execute arbitrary SQL commands via an unsanitized sql_query argument. | Aug 27, 2026 |
| CVE-2026-37007 | UNKNOWN | — | A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via malicious path traversal sequences in the filename argument. | Aug 27, 2026 |
| CVE-2026-37006 | UNKNOWN | — | A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Context Protocol … | Aug 27, 2026 |
| CVE-2026-37004 | UNKNOWN | — | BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotprompt_content parameter … | Aug 27, 2026 |
| CVE-2026-37003 | UNKNOWN | — | Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and ShellTools components pass unsanitized, LLM-generated arguments … | Aug 27, 2026 |
| CVE-2026-36102 | UNKNOWN | — | An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to … | Aug 27, 2026 |
| CVE-2026-35869 | UNKNOWN | — | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insufficient validation … | Aug 27, 2026 |