Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26398
Total
1955
Critical
7975
High
8226
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-54358 | UNKNOWN | — | An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same organization through the administrative email functionality. … | Jun 12, 2026 |
| CVE-2026-54357 | UNKNOWN | — | An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify user settings belonging to site administrator accounts within the same … | Jun 12, 2026 |
| CVE-2026-54055 | MEDIUM | 5.0 | Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmission protocol where a … | Jun 12, 2026 |
| CVE-2026-50552 | MEDIUM | 6.3 | Koel is a free, open-source music streaming solution. Prior to version 9.7.1, Koel contains a Server-Side Request Forgery (SSRF) vulnerability in the radio station creation … | Jun 12, 2026 |
| CVE-2026-50287 | UNKNOWN | — | AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with --http or … | Jun 12, 2026 |
| CVE-2026-47260 | HIGH | 7.7 | Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via the SafeUrl rule (DNS resolution + … | Jun 12, 2026 |
| CVE-2026-43872 | UNKNOWN | — | Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path traversal vulnerability. Version 26.5.0 fixes the issue. | Jun 12, 2026 |
| CVE-2026-42890 | UNKNOWN | — | Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing … | Jun 12, 2026 |
| CVE-2026-42851 | HIGH | 7.8 | Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote … | Jun 12, 2026 |
| CVE-2026-42850 | UNKNOWN | — | Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty error. A … | Jun 12, 2026 |
| CVE-2026-42604 | UNKNOWN | — | Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= 26.4.0 exposes the full OpenID Connect configuration—including the … | Jun 12, 2026 |
| CVE-2026-53726 | UNKNOWN | — | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a … | Jun 12, 2026 |
| CVE-2026-53725 | UNKNOWN | — | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.5, … | Jun 12, 2026 |
| CVE-2026-53724 | UNKNOWN | — | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.79 and 9.9.1-alpha.4, the … | Jun 12, 2026 |
| CVE-2026-53408 | HIGH | 8.1 | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated … | Jun 12, 2026 |
| CVE-2026-53407 | HIGH | 8.1 | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated … | Jun 12, 2026 |
| CVE-2026-50244 | MEDIUM | 5.3 | The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account identifier, without validating any ownership … | Jun 12, 2026 |
| CVE-2026-50108 | HIGH | 7.5 | The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the legitimate device or owner. … | Jun 12, 2026 |
| CVE-2026-50101 | HIGH | 8.1 | Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each boot. Because this credential remains valid … | Jun 12, 2026 |
| CVE-2026-50099 | MEDIUM | 4.6 | During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in cleartext to an exposed UART console on production … | Jun 12, 2026 |
| CVE-2026-50008 | UNKNOWN | — | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.3, … | Jun 12, 2026 |
| CVE-2026-47248 | UNKNOWN | — | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.78 and 9.9.1-alpha.2, Parse … | Jun 12, 2026 |
| CVE-2026-47236 | MEDIUM | 4.3 | Solidtime is an open-source time-tracking app. Prior to version 0.12.2, Solidtime defines an explicit invitations:view and members:view permissions that gates the official invitations and members … | Jun 12, 2026 |
| CVE-2026-47138 | UNKNOWN | — | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1, an … | Jun 12, 2026 |
| CVE-2026-42947 | HIGH | 8.8 | A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. Because … | Jun 12, 2026 |