Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44895
Total
3603
Critical
13333
High
13202
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-68901 | MEDIUM | 6.5 | Wekan is open source kanban built with Meteor. Prior to 10.38, the /api/boards/:boardId/export, /api/boards/:boardId/attachments/:attachmentId/export, /api/boards/:boardId/export/csv, and /api/boards/:boardId/exportExcel handlers in models/export.js and models/exportExcel.js looked up a … | Aug 19, 2026 |
| CVE-2026-68900 | HIGH | 7.6 | Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js read a card title and body through textContent, which decoded … | Aug 19, 2026 |
| CVE-2026-68899 | HIGH | 8.7 | Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation.js used the Unix file command for content-based MIME detection, but detectMimeFromFile() … | Aug 19, 2026 |
| CVE-2026-68561 | HIGH | 8.8 | Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permissions/boards.js called canUpdateBoardSort in server/lib/utils.js, which authorized … | Aug 19, 2026 |
| CVE-2026-68560 | UNKNOWN | — | Wekan is open source kanban built with Meteor. Prior to 9.75, models/fileValidation.js interpolated the uploaded fileObj.path into the administrator-configured externalCommandLine at its {file} placeholder and … | Aug 19, 2026 |
| CVE-2026-68559 | MEDIUM | 6.5 | Wekan is open source kanban built with Meteor. From 9.57 until 9.74, the /api/boards/:boardId/exportExcel route in models/exportExcel.js called the asynchronous exporterExcel.canExport(user) authorization guard from models/server/ExporterExcel.js … | Aug 19, 2026 |
| CVE-2026-68558 | HIGH | 8.5 | Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integration URL validator in models/integrations.js checked only the literal URL.hostname … | Aug 19, 2026 |
| CVE-2026-67189 | MEDIUM | 6.1 | pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned … | Aug 19, 2026 |
| CVE-2026-63722 | CRITICAL | 9.8 | ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation … | Aug 19, 2026 |
| CVE-2026-63188 | UNKNOWN | — | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto Tunnel npm package enabled createStaticFileProxy from packages/tunnel/src/commands/tunnel/index.ts and … | Aug 19, 2026 |
| CVE-2026-63187 | MEDIUM | 6.3 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto's .github/workflows/commitlint.yml directly interpolated github.event.pull_request.title into the Commitlint on … | Aug 19, 2026 |
| CVE-2026-62317 | HIGH | 7.5 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's email subaddressing blocklist in packages/core/src/libraries/sign-in-experience/email-blocklist-policy.ts used the attacker-controlled domain … | Aug 19, 2026 |
| CVE-2026-61712 | UNKNOWN | — | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, BuildKit read attacker-controlled /etc/passwd … | Aug 19, 2026 |
| CVE-2026-61711 | UNKNOWN | — | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could … | Aug 19, 2026 |
| CVE-2026-55090 | UNKNOWN | — | Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/ExportHtml.ts interpolates values from the exportHtmlAdditionalTagsWithData plugin hook into span data attributes without HTML … | Aug 19, 2026 |
| CVE-2026-55089 | CRITICAL | 9.9 | Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in the authorization_code OAuth path by using requiredClaims with … | Aug 19, 2026 |
| CVE-2026-55088 | MEDIUM | 6.8 | Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts uses POST /tokenTransfer to store an author token for transfer between browsers and … | Aug 19, 2026 |
| CVE-2026-55087 | MEDIUM | 6.1 | Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/hooks/express/admin.ts when substituting paths into HTML, JavaScript, … | Aug 19, 2026 |
| CVE-2026-55086 | MEDIUM | 4.2 | Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts derive temporary filenames from Math.random() and place them in os.tmpdir(). On a host … | Aug 19, 2026 |
| CVE-2026-55085 | CRITICAL | 9.6 | Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a numbered list directly into an unquoted ol … | Aug 19, 2026 |
| CVE-2026-54742 | UNKNOWN | — | Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.20, a community moderator can feature or unfeature posts in … | Aug 19, 2026 |
| CVE-2026-22306 | CRITICAL | 10.0 | Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on … | Aug 19, 2026 |
| CVE-2026-19509 | UNKNOWN | — | Improper input validation in `ajaxSet_wireless_network_configuration.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows an authenticated attacker to cause denial of service via a crafted `ssid_number` parameter. | Aug 19, 2026 |
| CVE-2026-19508 | UNKNOWN | — | Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause memory corruption and denial … | Aug 19, 2026 |
| CVE-2026-19507 | UNKNOWN | — | Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause denial of service via excessively large password values. | Aug 19, 2026 |