Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41870
Total
3419
Critical
12379
High
12272
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-15550 | MEDIUM | 4.3 | The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to … | Sep 05, 2026 |
| CVE-2026-12843 | MEDIUM | 5.4 | The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly verifying … | Sep 05, 2026 |
| CVE-2026-10196 | CRITICAL | 9.8 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up … | Sep 05, 2026 |
| CVE-2025-9049 | HIGH | 8.8 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the … | Sep 05, 2026 |
| CVE-2025-15647 | MEDIUM | 5.5 | CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round outside adjacent … | Sep 05, 2026 |
| CVE-2025-15614 | LOW | 3.3 | ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files … | Sep 05, 2026 |
| CVE-2026-86178 | MEDIUM | 5.4 | Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential … | Sep 05, 2026 |
| CVE-2026-86177 | HIGH | 8.8 | Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers … | Sep 05, 2026 |
| CVE-2026-86176 | MEDIUM | 4.3 | NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions … | Sep 05, 2026 |
| CVE-2026-86175 | MEDIUM | 6.5 | NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve … | Sep 05, 2026 |
| CVE-2026-86174 | MEDIUM | 4.3 | Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to … | Sep 05, 2026 |
| CVE-2026-86173 | HIGH | 7.5 | MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled … | Sep 05, 2026 |
| CVE-2026-86169 | HIGH | 8.8 | Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security … | Sep 05, 2026 |
| CVE-2026-86124 | CRITICAL | 9.8 | AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can … | Sep 05, 2026 |
| CVE-2026-86123 | HIGH | 8.7 | SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to … | Sep 05, 2026 |
| CVE-2026-86122 | MEDIUM | 5.0 | Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs at … | Sep 05, 2026 |
| CVE-2026-86121 | CRITICAL | 9.8 | Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to … | Sep 05, 2026 |
| CVE-2026-86120 | MEDIUM | 4.3 | APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions. Attackers with valid … | Sep 05, 2026 |
| CVE-2026-86119 | HIGH | 8.6 | Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers … | Sep 05, 2026 |
| CVE-2026-86118 | MEDIUM | 4.3 | gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attackers can repeatedly … | Sep 05, 2026 |
| CVE-2026-86117 | HIGH | 8.1 | Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without … | Sep 05, 2026 |
| CVE-2026-86116 | MEDIUM | 6.5 | Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glossary … | Sep 05, 2026 |
| CVE-2026-86115 | MEDIUM | 5.0 | Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens. Authenticated … | Sep 05, 2026 |
| CVE-2026-86114 | MEDIUM | 6.5 | Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. … | Sep 05, 2026 |
| CVE-2026-86113 | MEDIUM | 6.5 | BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading records. Attackers can exploit … | Sep 05, 2026 |