Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26398
Total
1955
Critical
7975
High
8226
Medium
CVE ID Severity Score Description Published
CVE-2026-54358 UNKNOWN An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same organization through the administrative email functionality. … Jun 12, 2026
CVE-2026-54357 UNKNOWN An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify user settings belonging to site administrator accounts within the same … Jun 12, 2026
CVE-2026-54055 MEDIUM 5.0 Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmission protocol where a … Jun 12, 2026
CVE-2026-50552 MEDIUM 6.3 Koel is a free, open-source music streaming solution. Prior to version 9.7.1, Koel contains a Server-Side Request Forgery (SSRF) vulnerability in the radio station creation … Jun 12, 2026
CVE-2026-50287 UNKNOWN AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with --http or … Jun 12, 2026
CVE-2026-47260 HIGH 7.7 Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via the SafeUrl rule (DNS resolution + … Jun 12, 2026
CVE-2026-43872 UNKNOWN Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path traversal vulnerability. Version 26.5.0 fixes the issue. Jun 12, 2026
CVE-2026-42890 UNKNOWN Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing … Jun 12, 2026
CVE-2026-42851 HIGH 7.8 Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote … Jun 12, 2026
CVE-2026-42850 UNKNOWN Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty error. A … Jun 12, 2026
CVE-2026-42604 UNKNOWN Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= 26.4.0 exposes the full OpenID Connect configuration—including the … Jun 12, 2026
CVE-2026-53726 UNKNOWN Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a … Jun 12, 2026
CVE-2026-53725 UNKNOWN Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.5, … Jun 12, 2026
CVE-2026-53724 UNKNOWN Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.79 and 9.9.1-alpha.4, the … Jun 12, 2026
CVE-2026-53408 HIGH 8.1 Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated … Jun 12, 2026
CVE-2026-53407 HIGH 8.1 Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated … Jun 12, 2026
CVE-2026-50244 MEDIUM 5.3 The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account identifier, without validating any ownership … Jun 12, 2026
CVE-2026-50108 HIGH 7.5 The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the legitimate device or owner. … Jun 12, 2026
CVE-2026-50101 HIGH 8.1 Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each boot. Because this credential remains valid … Jun 12, 2026
CVE-2026-50099 MEDIUM 4.6 During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in cleartext to an exposed UART console on production … Jun 12, 2026
CVE-2026-50008 UNKNOWN Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.3, … Jun 12, 2026
CVE-2026-47248 UNKNOWN Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.78 and 9.9.1-alpha.2, Parse … Jun 12, 2026
CVE-2026-47236 MEDIUM 4.3 Solidtime is an open-source time-tracking app. Prior to version 0.12.2, Solidtime defines an explicit invitations:view and members:view permissions that gates the official invitations and members … Jun 12, 2026
CVE-2026-47138 UNKNOWN Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1, an … Jun 12, 2026
CVE-2026-42947 HIGH 8.8 A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. Because … Jun 12, 2026