Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26383
Total
1955
Critical
7969
High
8219
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-54513 | HIGH | 8.1 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based … | Jun 23, 2026 |
| CVE-2026-54512 | HIGH | 8.1 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary … | Jun 23, 2026 |
| CVE-2026-53931 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the spreadsheet-import endpoint axiosRequestMake could be used as a generic HTTP proxy. Before the … | Jun 23, 2026 |
| CVE-2026-53930 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the base-migration endpoint accepted a caller-supplied URL that the migration worker dereferenced without enforcing … | Jun 23, 2026 |
| CVE-2026-53929 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, with NC_SECURE_ATTACHMENTS=true, an authenticated uploader could deliver .html or .svg attachments that the browser … | Jun 23, 2026 |
| CVE-2026-53928 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a stolen refresh token survived a password-forgot flow and could be used to mint … | Jun 23, 2026 |
| CVE-2026-53927 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the spreadsheet-fetch endpoint (axiosRequestMake) accepted URLs whose path contained a permitted extension anywhere in … | Jun 23, 2026 |
| CVE-2026-53926 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, revokeAllOAuthTokensByUser in the users service is an empty stub being called from passwordChange, passwordForgot, … | Jun 23, 2026 |
| CVE-2026-50193 | UNKNOWN | — | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested … | Jun 23, 2026 |
| CVE-2026-47388 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a low-privilege MCP token holder with knowledge of an attachment path could read any … | Jun 23, 2026 |
| CVE-2026-47387 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared form-view submit handler (packages/nc-gui/composables/useSharedFormViewStore.ts) in NocoDB writes the form's redirect_url to window.location.href … | Jun 23, 2026 |
| CVE-2026-47386 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, two concurrent token-exchange requests using the same OAuth authorization code could each mint a … | Jun 23, 2026 |
| CVE-2026-47385 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with base-create permission can attach a SQLite source pointing at an … | Jun 23, 2026 |
| CVE-2026-47384 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with column-create permission can inject SQL into the bulk groupBy endpoint … | Jun 23, 2026 |
| CVE-2026-47383 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated commenter could store HTML in row comments that executed as script when … | Jun 23, 2026 |
| CVE-2026-47382 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the connection-test endpoint opened a raw TCP socket to the user-supplied database host without … | Jun 23, 2026 |
| CVE-2026-47381 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a user in one workspace could exercise another workspace's integration through the testConnection endpoint … | Jun 23, 2026 |
| CVE-2026-47380 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, sign-in response timing differed between known and unknown email addresses because the unknown-user branch … | Jun 23, 2026 |
| CVE-2026-47379 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared-view password check fell back to strict-equality (===) comparison for legacy plaintext passwords, … | Jun 23, 2026 |
| CVE-2026-47378 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, Public shared-view endpoints exposed values from columns that the view owner had hidden, via … | Jun 23, 2026 |
| CVE-2026-47377 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the client-side hashRedirect plugin called window.location.replace() on a path extracted from the URL hash … | Jun 23, 2026 |
| CVE-2026-47376 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the password-reset page rendered the URL token directly into a JavaScript string literal in … | Jun 23, 2026 |
| CVE-2026-47375 | MEDIUM | 6.0 | NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, an authenticated user with columnAdd permission on a Postgres-backed base can inject arbitrary SQL … | Jun 23, 2026 |
| CVE-2026-47279 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints accepted a caller-supplied column ID without verifying that the … | Jun 23, 2026 |
| CVE-2026-46554 | UNKNOWN | — | NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, deleted API tokens continued to authenticate requests until their cache entry expired, because the … | Jun 23, 2026 |