Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42900
Total
3476
Critical
12865
High
12603
Medium
CVE ID Severity Score Description Published
CVE-2026-81491 HIGH 7.3 A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead … Aug 27, 2026
CVE-2026-16895 UNKNOWN A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service interface. When an exception occurs during the database health check … Aug 27, 2026
CVE-2026-81486 MEDIUM 5.3 A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_context of the file src/index.ts of the component Path Resolution. … Aug 27, 2026
CVE-2026-81485 MEDIUM 5.3 A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the function fs.readFileSync of the file src/tools/campaign-management.ts of the component … Aug 27, 2026
CVE-2026-19398 UNKNOWN “unsupported-when-assigned.” An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local administrator to cause a system crash (BSOD) … Aug 27, 2026
CVE-2026-81421 HIGH 7.3 A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the … Aug 27, 2026
CVE-2026-80183 UNKNOWN In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a … Aug 27, 2026
CVE-2026-47874 MEDIUM 5.3 The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount … Aug 27, 2026
CVE-2026-47863 MEDIUM 5.9 In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - … Aug 27, 2026
CVE-2026-47862 MEDIUM 5.4 An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the resulting .zip archive to … Aug 27, 2026
CVE-2026-47861 MEDIUM 6.3 An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an … Aug 27, 2026
CVE-2026-47860 MEDIUM 6.5 An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single … Aug 27, 2026
CVE-2026-47859 MEDIUM 5.4 RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied octet count of an … Aug 27, 2026
CVE-2026-47857 MEDIUM 5.9 In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - … Aug 27, 2026
CVE-2026-47856 MEDIUM 6.3 Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with … Aug 27, 2026
CVE-2026-47852 HIGH 7.5 A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI … Aug 27, 2026
CVE-2026-47851 HIGH 7.5 Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI … Aug 27, 2026
CVE-2026-47850 MEDIUM 4.3 Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT against an immutable target type. … Aug 27, 2026
CVE-2026-47845 MEDIUM 5.3 In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, … Aug 27, 2026
CVE-2026-81203 HIGH 7.3 A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of … Aug 26, 2026
CVE-2026-80158 MEDIUM 5.5 A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when … Aug 26, 2026
CVE-2026-75340 CRITICAL 9.1 The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF). Aug 26, 2026
CVE-2026-75338 CRITICAL 9.8 disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authentication. The … Aug 26, 2026
CVE-2026-75336 CRITICAL 9.8 Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json. Aug 26, 2026
CVE-2026-75332 CRITICAL 9.1 Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download(). Aug 26, 2026