Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 351–375 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85636 MEDIUM 5.3 2026-09-04 A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. …
CVE-2026-85626 HIGH 7.5 2026-09-04 git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log, git_diff, and git_show tools that lack leading-dash validati…
CVE-2026-85625 HIGH 8.1 2026-09-04 sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where. The $where oper…
CVE-2026-85624 MEDIUM 6.5 2026-09-04 Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that performs no ownership verification on supplied note identif…
CVE-2026-85623 HIGH 8.8 2026-09-04 goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute …
CVE-2026-85622 MEDIUM 5.3 2026-09-04 AppFlowy-Cloud through 0.9.64 fails to validate workspace membership when establishing WebSocket connections in the establish_ws_connection_v2 handler, allowing authenticat…
CVE-2026-85621 MEDIUM 6.5 2026-09-04 LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platform webhook signatures in the QQ and Feishu adapters. The webhook route (/api/agent/webhooks/:platform) …
CVE-2026-85620 HIGH 8.6 2026-09-04 Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can e…
CVE-2026-85619 HIGH 7.5 2026-09-04 AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database row…
CVE-2026-85618 MEDIUM 6.5 2026-09-04 ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xelatex converter that allows authenticated users to read files by uploading LaTeX files with input dir…
CVE-2026-85617 HIGH Patched 8.8 2026-09-04 snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside thei…
CVE-2026-85616 HIGH Patched 8.5 2026-09-04 Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authentica…
CVE-2026-85615 MEDIUM Patched 6.4 2026-09-04 Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboar…
CVE-2026-85614 HIGH Patched 8.6 2026-09-04 OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled …
CVE-2026-85613 HIGH Patched 8.2 2026-09-04 OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute…
CVE-2026-85612 HIGH Patched 7.5 2026-09-04 OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied ur…
CVE-2026-85611 MEDIUM Patched 6.4 2026-09-04 OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to …
CVE-2026-85610 HIGH Patched 8.8 2026-09-04 OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering…
CVE-2026-85609 HIGH Patched 7.5 2026-09-04 Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET /tools/site-checker endpoint (apps/api/src/controll…
CVE-2026-85608 HIGH 7.5 2026-09-04 Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthen…
CVE-2026-85607 HIGH 8.8 2026-09-04 Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/r…
CVE-2026-85606 HIGH 7.5 2026-09-04 firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory …
CVE-2026-85605 MEDIUM Patched 5.3 2026-09-04 Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/c…
CVE-2026-85604 HIGH Patched 8.8 2026-09-04 Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes&hellip;
CVE-2026-85603 MEDIUM Patched 6.5 2026-09-04 Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticate&hellip;