Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47180
Total
3801
Critical
14071
High
13766
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-72856 | HIGH | 8.1 | Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/global/users/tenant/owner (changeTenantOwnerEmail) endpoint. On self-hosted instances (SELF_HOSTED or DISABLE_ACCOUNT_PORTAL set), the cloudRestricted middleware is … | Aug 13, 2026 |
| CVE-2026-72855 | HIGH | 8.5 | Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execution that allow authenticated builder-level users to bypass DNS pinning … | Aug 13, 2026 |
| CVE-2026-72853 | HIGH | 7.6 | Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. Attackers … | Aug 13, 2026 |
| CVE-2026-72851 | CRITICAL | 10.0 | Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint … | Aug 13, 2026 |
| CVE-2026-72850 | CRITICAL | 9.1 | Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers … | Aug 13, 2026 |
| CVE-2026-72849 | HIGH | 7.7 | Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a … | Aug 13, 2026 |
| CVE-2026-72842 | CRITICAL | 9.9 | luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit … | Aug 13, 2026 |
| CVE-2026-72841 | CRITICAL | 9.9 | luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended … | Aug 13, 2026 |
| CVE-2026-72840 | HIGH | 8.8 | OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users … | Aug 13, 2026 |
| CVE-2026-72839 | CRITICAL | 9.8 | filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit … | Aug 13, 2026 |
| CVE-2026-72776 | CRITICAL | 9.8 | AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the … | Aug 13, 2026 |
| CVE-2026-56865 | HIGH | 8.4 | A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and … | Aug 13, 2026 |
| CVE-2026-56864 | UNKNOWN | — | A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB … | Aug 13, 2026 |
| CVE-2026-56862 | HIGH | 7.5 | Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious … | Aug 13, 2026 |
| CVE-2026-56860 | UNKNOWN | — | Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high … | Aug 13, 2026 |
| CVE-2026-56859 | HIGH | 7.5 | Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. | Aug 13, 2026 |
| CVE-2026-56858 | MEDIUM | 6.1 | Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS. | Aug 13, 2026 |
| CVE-2026-56853 | HIGH | 7.5 | When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 … | Aug 13, 2026 |
| CVE-2026-33818 | HIGH | 7.5 | Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. | Aug 13, 2026 |
| CVE-2026-19752 | MEDIUM | 6.3 | A vulnerability was found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. This affects the function parse-pdf of the file src/index.ts of the component PDF Parsing. Performing … | Aug 13, 2026 |
| CVE-2026-19751 | MEDIUM | 6.3 | A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. The affected element is the function axios.get of the file src/index.ts of the component … | Aug 13, 2026 |
| CVE-2026-19750 | HIGH | 8.1 | A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing … | Aug 13, 2026 |
| CVE-2026-8715 | CRITICAL | 9.6 | Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may … | Aug 13, 2026 |
| CVE-2026-73480 | MEDIUM | 5.0 | gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers can craft malicious directory or file … | Aug 13, 2026 |
| CVE-2026-19749 | LOW | 3.7 | A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability … | Aug 13, 2026 |