Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42739
Total
3465
Critical
12744
High
12574
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81688 | HIGH | 7.5 | openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can read this hash without the … | Aug 27, 2026 |
| CVE-2026-81687 | MEDIUM | 5.5 | openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration counts specified in file metadata. Attackers can craft files with … | Aug 27, 2026 |
| CVE-2026-81686 | MEDIUM | 6.2 | openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method performs neither a polkit authorization check nor value validation. Any local user … | Aug 27, 2026 |
| CVE-2026-81685 | LOW | 3.3 | openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into the irreversible-removal … | Aug 27, 2026 |
| CVE-2026-81684 | MEDIUM | 6.2 | In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child process on the command line via … | Aug 27, 2026 |
| CVE-2026-81683 | HIGH | 8.4 | openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop … | Aug 27, 2026 |
| CVE-2026-81682 | MEDIUM | 6.2 | openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes decrypted plaintext with world-readable default permissions. Attackers can read … | Aug 27, 2026 |
| CVE-2026-81681 | MEDIUM | 4.6 | openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with AES-256-GCM encryption and write a marker declaring … | Aug 27, 2026 |
| CVE-2026-81680 | MEDIUM | 4.0 | openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can … | Aug 27, 2026 |
| CVE-2026-81679 | HIGH | 7.7 | OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API that allows per-realm tenant administrators to read all tenants' sent … | Aug 27, 2026 |
| CVE-2026-81678 | HIGH | 7.5 | AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract embedded IPv4 addresses from NAT64, 6to4, and Teredo … | Aug 27, 2026 |
| CVE-2026-81664 | MEDIUM | 5.3 | The OpenFaaS gateway registers GET /system/telemetry in gateway/main.go and, when basic_auth is enabled, wraps each administrative /system/* handler in auth.DecorateWithBasicAuth. TelemetryHandler was left out of … | Aug 27, 2026 |
| CVE-2026-81335 | HIGH | 7.5 | Baserow dispatches an Application Builder data source without acting on the result of its permission check. The dispatch and record-name views in backend/src/baserow/contrib/builder/api/data_sources/views.py are declared … | Aug 27, 2026 |
| CVE-2026-81334 | MEDIUM | 6.1 | darknet subscripts its layer array with an index taken from a configuration file without checking it against the array's length. The array is allocated in … | Aug 27, 2026 |
| CVE-2026-81102 | LOW | 3.1 | The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_server_dash.py constructed the server for its … | Aug 27, 2026 |
| CVE-2026-81101 | MEDIUM | 6.5 | The configure command accepted any endpoint URL and stored it beside the user's access token. ConfigureCommand.execute in src/cli.ts persisted the value given to its endpoint … | Aug 27, 2026 |
| CVE-2026-81100 | MEDIUM | 6.8 | tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the … | Aug 27, 2026 |
| CVE-2026-81099 | MEDIUM | 6.8 | tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. mcp/src/httpServer.ts called the shared httpServerFactory helper and never set the … | Aug 27, 2026 |
| CVE-2026-81098 | CRITICAL | 9.1 | The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path … | Aug 27, 2026 |
| CVE-2026-81097 | HIGH | 8.4 | The execute_ruby tool is documented as a read-only Ruby sandbox and is enforced by a pattern denylist together with replacements for the process-spawning methods on … | Aug 27, 2026 |
| CVE-2026-81096 | CRITICAL | 10.0 | ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in … | Aug 27, 2026 |
| CVE-2026-81095 | MEDIUM | 6.8 | pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the … | Aug 27, 2026 |
| CVE-2026-81094 | CRITICAL | 9.1 | The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts … | Aug 27, 2026 |
| CVE-2026-81093 | HIGH | 8.6 | The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. The handler in src/tools/common/get_html_skeleton.ts validated the url argument with isValidHttpUrl from … | Aug 27, 2026 |
| CVE-2026-81092 | MEDIUM | 6.8 | mcp-go accepted requests on its HTTP transports without checking the Host header. StreamableHTTPServer.ServeHTTP in server/streamable_http.go and SSEServer.ServeHTTP in server/sse.go served any request arriving over a … | Aug 27, 2026 |