Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

28297
Total
2180
Critical
8507
High
8806
Medium
CVE ID Severity Score Description Published
CVE-2026-45627 HIGH 8.2 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query … May 29, 2026
CVE-2026-45626 MEDIUM 6.3 Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /environments/{id}/volumes/{volumeName}/browse accepts a path query parameter that is … May 29, 2026
CVE-2026-45625 CRITICAL 9.9 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and … May 29, 2026
CVE-2026-45577 UNKNOWN Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app … May 29, 2026
CVE-2026-44697 HIGH 8.6 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any peer that … May 29, 2026
CVE-2026-43917 UNKNOWN Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.19.0 and earlier, the protectedProcedure middleware only verifies the user is authenticated - it … May 29, 2026
CVE-2026-10108 HIGH 7.5 xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_path:path} endpoint that allows unauthenticated attackers to read arbitrary files outside the intended music … May 29, 2026
CVE-2026-10107 HIGH 7.7 MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated attackers to request arbitrary URLs by supplying a resource_token … May 29, 2026
CVE-2026-10105 HIGH 8.3 agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata … May 29, 2026
CVE-2026-10070 MEDIUM 4.7 A vulnerability was found in macrozheng mall up to 1.0.3. This affects an unknown function of the file /admin/update/ of the component Super Admin Password … May 29, 2026
CVE-2026-9194 UNKNOWN Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … May 29, 2026
CVE-2026-48501 HIGH 7.4 GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors … May 29, 2026
CVE-2026-45663 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. … May 29, 2026
CVE-2026-45662 HIGH 8.8 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} without … May 29, 2026
CVE-2026-44962 CRITICAL 9.9 Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This … May 29, 2026
CVE-2026-39276 HIGH 7.2 The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious … May 29, 2026
CVE-2026-39229 MEDIUM 6.5 Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated attacker with low-level privileges can exploit this … May 29, 2026
CVE-2026-36324 UNKNOWN SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of user supplied input in the user registration functionality … May 29, 2026
CVE-2026-35674 HIGH 8.8 OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope … May 29, 2026
CVE-2026-35673 MEDIUM 6.5 OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked tabs. Attackers with access … May 29, 2026
CVE-2026-35630 HIGH 8.0 OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval … May 29, 2026
CVE-2026-34507 MEDIUM 5.4 OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowFrom policy checks. Attackers can … May 29, 2026
CVE-2026-33386 UNKNOWN QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based plugin‑fetching mechanism. A malicious attacker can perform a Man‑in‑the‑Middle (MITM) attack by impersonating the … May 29, 2026
CVE-2026-33384 UNKNOWN QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables … May 29, 2026
CVE-2026-32906 MEDIUM 4.3 OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-authorized users to resolve plugin approvals through the exec approver gate. … May 29, 2026