Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50353
Total
4061
Critical
14946
High
14711
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-63220 | MEDIUM | 4.8 | CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an … | Jul 31, 2026 |
| CVE-2026-62323 | MEDIUM | 6.3 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI access token and does … | Jul 31, 2026 |
| CVE-2026-55502 | HIGH | 7.1 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and … | Jul 31, 2026 |
| CVE-2026-55499 | MEDIUM | 4.3 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent … | Jul 31, 2026 |
| CVE-2026-55497 | MEDIUM | 6.5 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do … | Jul 31, 2026 |
| CVE-2026-55496 | MEDIUM | 4.3 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at … | Jul 31, 2026 |
| CVE-2026-55495 | MEDIUM | 4.3 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than … | Jul 31, 2026 |
| CVE-2026-43833 | UNKNOWN | — | Full details and mitigation steps are currently restricted and will be published at a later date. | Jul 31, 2026 |
| CVE-2026-43832 | HIGH | 7.5 | Full details and mitigation steps are currently restricted and will be published at a later date. | Jul 31, 2026 |
| CVE-2026-43831 | HIGH | 7.5 | Full details and mitigation steps are currently restricted and will be published at a later date. | Jul 31, 2026 |
| CVE-2026-43830 | CRITICAL | 9.8 | Full details and mitigation steps are currently restricted and will be published at a later date. | Jul 31, 2026 |
| CVE-2026-43829 | HIGH | 7.5 | Full details and mitigation steps are currently restricted and will be published at a later date. | Jul 31, 2026 |
| CVE-2026-6890 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jul 31, 2026 |
| CVE-2026-6889 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jul 31, 2026 |
| CVE-2026-18157 | HIGH | 7.8 | A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. … | Jul 31, 2026 |
| CVE-2026-14541 | UNKNOWN | — | An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized … | Jul 31, 2026 |
| CVE-2026-14540 | UNKNOWN | — | A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox … | Jul 31, 2026 |
| CVE-2026-14539 | UNKNOWN | — | An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker … | Jul 31, 2026 |
| CVE-2026-14538 | UNKNOWN | — | An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass … | Jul 31, 2026 |
| CVE-2026-14537 | UNKNOWN | — | Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected … | Jul 31, 2026 |
| CVE-2026-58039 | LOW | 3.3 | A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of … | Jul 31, 2026 |
| CVE-2026-66720 | MEDIUM | 6.5 | The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame … | Jul 30, 2026 |
| CVE-2026-66421 | CRITICAL | 9.3 | OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML … | Jul 30, 2026 |
| CVE-2026-66420 | HIGH | 8.8 | MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early … | Jul 30, 2026 |
| CVE-2026-66369 | MEDIUM | 6.5 | The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific … | Jul 30, 2026 |