Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50169
Total
4054
Critical
14909
High
14667
Medium
CVE ID Severity Score Description Published
CVE-2026-67334 LOW 3.8 better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is … Aug 01, 2026
CVE-2026-67333 HIGH 7.2 better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the deprecated oidc-provider plugin and the mcp … Aug 01, 2026
CVE-2026-67332 MEDIUM 6.4 @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources. Attackers can complete an OAuth … Aug 01, 2026
CVE-2026-67331 HIGH 8.3 better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' … Aug 01, 2026
CVE-2026-67330 CRITICAL 9.9 @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not … Aug 01, 2026
CVE-2026-67329 HIGH 7.1 @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the … Aug 01, 2026
CVE-2026-67328 HIGH 8.1 @better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit … Aug 01, 2026
CVE-2026-67327 HIGH 8.3 better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link … Aug 01, 2026
CVE-2026-67326 HIGH 7.0 GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can … Aug 01, 2026
CVE-2026-67325 HIGH 8.8 GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options … Aug 01, 2026
CVE-2026-67324 CRITICAL 9.8 GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application … Aug 01, 2026
CVE-2026-67323 HIGH 8.4 GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as … Aug 01, 2026
CVE-2026-67322 HIGH 7.5 GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on … Aug 01, 2026
CVE-2026-67321 UNKNOWN axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and … Aug 01, 2026
CVE-2026-67320 UNKNOWN axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype … Aug 01, 2026
CVE-2026-67319 UNKNOWN axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already been polluted … Aug 01, 2026
CVE-2026-67318 UNKNOWN axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because … Aug 01, 2026
CVE-2026-67317 UNKNOWN axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can … Aug 01, 2026
CVE-2026-67316 UNKNOWN axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In … Aug 01, 2026
CVE-2026-67315 UNKNOWN axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can … Aug 01, 2026
CVE-2026-67314 UNKNOWN axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is already affected by a … Aug 01, 2026
CVE-2026-67313 UNKNOWN axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with … Aug 01, 2026
CVE-2026-67312 UNKNOWN axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData … Aug 01, 2026
CVE-2026-67311 MEDIUM 6.8 Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects against the IP blacklist. Attackers … Aug 01, 2026
CVE-2026-67310 MEDIUM 5.4 OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of AlarmResourceImpl. The realm access check validates only a … Aug 01, 2026