Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28297
Total
2180
Critical
8507
High
8806
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-45707 | HIGH | 8.1 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_TENANT=true, the HTTP transport … | May 29, 2026 |
| CVE-2026-45620 | MEDIUM | 5.3 | WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: … | May 29, 2026 |
| CVE-2026-45619 | MEDIUM | 6.5 | WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the $resolvedIP out-param of isSSRFSafeURL() … | May 29, 2026 |
| CVE-2026-45615 | HIGH | 8.2 | mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated by asn1c (specifically … | May 29, 2026 |
| CVE-2026-45610 | MEDIUM | 5.7 | WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts … | May 29, 2026 |
| CVE-2026-45582 | MEDIUM | 6.5 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.3, the workflow telemetry sanitizer could … | May 29, 2026 |
| CVE-2026-45580 | MEDIUM | 5.4 | WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-style" view renders … | May 29, 2026 |
| CVE-2026-45578 | HIGH | 8.8 | WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds … | May 29, 2026 |
| CVE-2026-45555 | HIGH | 7.8 | Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.0.9 to 1.17.0, the get_diagnostics MCP tool loads … | May 29, 2026 |
| CVE-2026-44698 | HIGH | 8.3 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he … | May 29, 2026 |
| CVE-2026-44239 | UNKNOWN | — | FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input … | May 29, 2026 |
| CVE-2026-44238 | UNKNOWN | — | FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort … | May 29, 2026 |
| CVE-2026-44237 | UNKNOWN | — | FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials during token issuance. … | May 29, 2026 |
| CVE-2026-40528 | LOW | 3.8 | OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attackers to … | May 29, 2026 |
| CVE-2026-40510 | LOW | 3.8 | OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory … | May 29, 2026 |
| CVE-2026-10075 | MEDIUM | 5.3 | DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary path by exploiting an Absolute Path … | May 29, 2026 |
| CVE-2026-10074 | MEDIUM | 4.9 | DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to exploit Relative Path Traversal to download arbitrary system files. | May 29, 2026 |
| CVE-2026-10073 | HIGH | 7.5 | DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to exploit Relative Path Traversal to download arbitrary system files. | May 29, 2026 |
| CVE-2026-10072 | HIGH | 7.2 | DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code … | May 29, 2026 |
| CVE-2026-10061 | MEDIUM | 6.3 | A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in … | May 29, 2026 |
| CVE-2026-10060 | MEDIUM | 6.3 | A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gateway leads … | May 29, 2026 |
| CVE-2026-9509 | UNKNOWN | — | An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to cause a denial of service … | May 29, 2026 |
| CVE-2026-9508 | UNKNOWN | — | Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the … | May 29, 2026 |
| CVE-2026-8326 | UNKNOWN | — | Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected … | May 29, 2026 |
| CVE-2026-49324 | MEDIUM | 4.6 | Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with … | May 29, 2026 |