Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50353
Total
4061
Critical
14946
High
14711
Medium
CVE ID Severity Score Description Published
CVE-2026-63220 MEDIUM 4.8 CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an … Jul 31, 2026
CVE-2026-62323 MEDIUM 6.3 Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI access token and does … Jul 31, 2026
CVE-2026-55502 HIGH 7.1 Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and … Jul 31, 2026
CVE-2026-55499 MEDIUM 4.3 Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent … Jul 31, 2026
CVE-2026-55497 MEDIUM 6.5 Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do … Jul 31, 2026
CVE-2026-55496 MEDIUM 4.3 Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at … Jul 31, 2026
CVE-2026-55495 MEDIUM 4.3 Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than … Jul 31, 2026
CVE-2026-43833 UNKNOWN — Full details and mitigation steps are currently restricted and will be published at a later date. Jul 31, 2026
CVE-2026-43832 HIGH 7.5 Full details and mitigation steps are currently restricted and will be published at a later date. Jul 31, 2026
CVE-2026-43831 HIGH 7.5 Full details and mitigation steps are currently restricted and will be published at a later date. Jul 31, 2026
CVE-2026-43830 CRITICAL 9.8 Full details and mitigation steps are currently restricted and will be published at a later date. Jul 31, 2026
CVE-2026-43829 HIGH 7.5 Full details and mitigation steps are currently restricted and will be published at a later date. Jul 31, 2026
CVE-2026-6890 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Jul 31, 2026
CVE-2026-6889 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Jul 31, 2026
CVE-2026-18157 HIGH 7.8 A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. … Jul 31, 2026
CVE-2026-14541 UNKNOWN — An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized … Jul 31, 2026
CVE-2026-14540 UNKNOWN — A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox … Jul 31, 2026
CVE-2026-14539 UNKNOWN — An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker … Jul 31, 2026
CVE-2026-14538 UNKNOWN — An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass … Jul 31, 2026
CVE-2026-14537 UNKNOWN — Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected … Jul 31, 2026
CVE-2026-58039 LOW 3.3 A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of … Jul 31, 2026
CVE-2026-66720 MEDIUM 6.5 The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame … Jul 30, 2026
CVE-2026-66421 CRITICAL 9.3 OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML … Jul 30, 2026
CVE-2026-66420 HIGH 8.8 MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early … Jul 30, 2026
CVE-2026-66369 MEDIUM 6.5 The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific … Jul 30, 2026