Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41893
Total
3420
Critical
12384
High
12282
Medium
CVE ID Severity Score Description Published
CVE-2026-10196 CRITICAL 9.8 The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up … Sep 05, 2026
CVE-2025-9049 HIGH 8.8 The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the … Sep 05, 2026
CVE-2025-15647 MEDIUM 5.5 CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round outside adjacent … Sep 05, 2026
CVE-2025-15614 LOW 3.3 ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files … Sep 05, 2026
CVE-2026-86178 MEDIUM 5.4 Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential … Sep 05, 2026
CVE-2026-86177 HIGH 8.8 Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers … Sep 05, 2026
CVE-2026-86176 MEDIUM 4.3 NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions … Sep 05, 2026
CVE-2026-86175 MEDIUM 6.5 NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve … Sep 05, 2026
CVE-2026-86174 MEDIUM 4.3 Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to … Sep 05, 2026
CVE-2026-86173 HIGH 7.5 MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled … Sep 05, 2026
CVE-2026-86169 HIGH 8.8 Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security … Sep 05, 2026
CVE-2026-86124 CRITICAL 9.8 AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can … Sep 05, 2026
CVE-2026-86123 HIGH 8.7 SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to … Sep 05, 2026
CVE-2026-86122 MEDIUM 5.0 Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs at … Sep 05, 2026
CVE-2026-86121 CRITICAL 9.8 Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to … Sep 05, 2026
CVE-2026-86120 MEDIUM 4.3 APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions. Attackers with valid … Sep 05, 2026
CVE-2026-86119 HIGH 8.6 Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers … Sep 05, 2026
CVE-2026-86118 MEDIUM 4.3 gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attackers can repeatedly … Sep 05, 2026
CVE-2026-86117 HIGH 8.1 Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without … Sep 05, 2026
CVE-2026-86116 MEDIUM 6.5 Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glossary … Sep 05, 2026
CVE-2026-86115 MEDIUM 5.0 Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens. Authenticated … Sep 05, 2026
CVE-2026-86114 MEDIUM 6.5 Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. … Sep 05, 2026
CVE-2026-86113 MEDIUM 6.5 BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading records. Attackers can exploit … Sep 05, 2026
CVE-2026-86112 MEDIUM 5.4 BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite followers-only and direct … Sep 05, 2026
CVE-2026-86111 MEDIUM 6.5 BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating … Sep 05, 2026