Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47870
Total
3850
Critical
14243
High
13921
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-73658 | HIGH | 8.2 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-controlled … | Aug 13, 2026 |
| CVE-2026-73657 | MEDIUM | 4.2 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp/app/routes/api.v1.runs.$runParam.replay.ts uses `prisma.taskRun.findUnique({ where: … | Aug 13, 2026 |
| CVE-2026-73489 | MEDIUM | 4.3 | Russh is a Rust SSH client & server library. Prior to 0.62.4, an authenticated SSH client can cause a denial of service by sending a … | Aug 13, 2026 |
| CVE-2026-73479 | MEDIUM | 5.0 | dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attackers can craft file names containing OSC/CSI escape … | Aug 13, 2026 |
| CVE-2026-73428 | MEDIUM | 4.6 | Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to stored cross-site scripting when crafted HTML is pasted … | Aug 13, 2026 |
| CVE-2026-73421 | UNKNOWN | — | NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned … | Aug 13, 2026 |
| CVE-2026-73420 | UNKNOWN | — | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by the email and magic-link sign-in flow validates … | Aug 13, 2026 |
| CVE-2026-73417 | UNKNOWN | — | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook … | Aug 13, 2026 |
| CVE-2026-73416 | UNKNOWN | — | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.5.0 until 4.5.10 and 4.6.2, in jupyterlab/extensions/manager.py and … | Aug 13, 2026 |
| CVE-2026-73408 | HIGH | 7.6 | Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName into a DESCRIBE statement. An attacker able to … | Aug 13, 2026 |
| CVE-2026-73305 | HIGH | 8.8 | Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in packages/server/src/api/controllers/public/globalRoleValidation.ts. An app-scoped builder could scope … | Aug 13, 2026 |
| CVE-2026-73304 | MEDIUM | 4.9 | Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id returned user objects processed by packages/server/src/utilities/global.ts without removing oauth2.accessToken or oauth2.refreshToken. … | Aug 13, 2026 |
| CVE-2026-73302 | UNKNOWN | — | Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolved an email without getEmailVerified or an email_verified requirement, and packages/backend-core/src/middleware/passport/sso/sso.ts … | Aug 13, 2026 |
| CVE-2026-73039 | MEDIUM | 5.4 | streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete other users' viewing status records. Attackers can … | Aug 13, 2026 |
| CVE-2026-72857 | HIGH | 7.7 | Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys … | Aug 13, 2026 |
| CVE-2026-72856 | HIGH | 8.1 | Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/global/users/tenant/owner (changeTenantOwnerEmail) endpoint. On self-hosted instances (SELF_HOSTED or DISABLE_ACCOUNT_PORTAL set), the cloudRestricted middleware is … | Aug 13, 2026 |
| CVE-2026-72855 | HIGH | 8.5 | Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execution that allow authenticated builder-level users to bypass DNS pinning … | Aug 13, 2026 |
| CVE-2026-72853 | HIGH | 7.6 | Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. Attackers … | Aug 13, 2026 |
| CVE-2026-72851 | CRITICAL | 10.0 | Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint … | Aug 13, 2026 |
| CVE-2026-72850 | CRITICAL | 9.1 | Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers … | Aug 13, 2026 |
| CVE-2026-72849 | HIGH | 7.7 | Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a … | Aug 13, 2026 |
| CVE-2026-72842 | CRITICAL | 9.9 | luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit … | Aug 13, 2026 |
| CVE-2026-72841 | CRITICAL | 9.9 | luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended … | Aug 13, 2026 |
| CVE-2026-72840 | HIGH | 8.8 | OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users … | Aug 13, 2026 |
| CVE-2026-72839 | CRITICAL | 9.8 | filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit … | Aug 13, 2026 |