CVEs

Most recently published first. Full-text search is on the roadmap.

Year

Want to know when one of these hits your stack? Track the products you run and get alerted.

Create a free account
CVESeverityPublishedTitle
CVE-2026-94540HIGH7.721 Sep 2026DesktopSMS 1.11.0 Unauthorized Access via Local Service
CVE-2026-65980HIGH7.921 Sep 2026Chartbrew: SQL Injection via Missing Backslash Escaping in ClickHouse Variable Substitution
CVE-2026-61851MEDIUM6.521 Sep 2026Chartbrew: Incomplete Read-Only Keyword Blocklist in AI runQuery Tool
CVE-2026-61852MEDIUM5.821 Sep 2026Chartbrew: SQL Injection via row_limit Parameter in AI runQuery Tool
CVE-2026-61743MEDIUM6.321 Sep 2026Chartbrew: DNS Rebinding SSRF Bypass in Outbound Request Validation
CVE-2026-94536MEDIUM5.321 Sep 2026lamp-cloud through 5.10.0 Unauthorized Information Disclosure via /anyone/visible/resource
CVE-2026-94535HIGH7.121 Sep 2026lamp-cloud through 5.10.0 Unauthorized Notification Deletion
CVE-2026-94534HIGH7.121 Sep 2026lamp-cloud through 5.10.0 Unauthorized Profile Modification via PUT endpoints
CVE-2026-94533HIGH7.121 Sep 2026lamp-cloud through 5.10.0 Unauthorized File Download via /anyone/file
CVE-2026-94532HIGH7.121 Sep 2026lamp-cloud through 5.10.0 Unauthorized User Profile Access via getUserInfoById
CVE-2026-93340HIGH7.421 Sep 2026Gladys Assistant < 5.1.0 Password Reset Link Poisoning via forgot_password Endpoint
CVE-2026-61541MEDIUM6.921 Sep 2026Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service
CVE-2026-59830MEDIUM5.421 Sep 2026Discourse: Stored XSS via unescaped actor name in post actions
CVE-2026-46650MEDIUM4.421 Sep 2026Joplin: Stored XSS in public share viewer via javascript: URL bypass in isAcceptedUrl
CVE-2026-17054MEDIUM5.321 Sep 2026Out-of-bounds read and permanent loss of Wi-Fi reception in the ESP-hosted SPI driver's frame reassembly
CVE-2026-15890MEDIUM5.321 Sep 2026AEAD nonce reuse in Zephyr secure_storage ITS default nonce provider due to missing thread synchronization
CVE-2026-59815MEDIUM4.321 Sep 2026Joplin: Pending share recipients can write items into shared folders before accepting invitations
CVE-2026-55210HIGH7.421 Sep 2026Joplin: SAML SSO account takeover via email-based account linking (missing is_external check in ssoLogin)
CVE-2026-61652HIGH8.721 Sep 2026Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb)
CVE-2026-59814HIGH7.621 Sep 2026Joplin: Stored XSS via inline-served note attachment on published shares
CVE-2026-61647HIGH7.121 Sep 2026@roomi-fields/notebooklm-mcp has path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory
CVE-2026-55105HIGH7.721 Sep 2026Joplin: Fountain embeds allow arbitrary script execution in published notes and the note viewer
CVE-2026-46649CRITICAL9.121 Sep 2026Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected Endpoint
CVE-2026-55179MEDIUM6.521 Sep 2026Joplin: Logic error in Joplin Server allows a signed-in user to read any note from its internal server ID
CVE-2026-59816MEDIUM4.321 Sep 2026Joplin: Path traversal in transcribe proxy endpoint via URL-encoded slash
CVE-2026-49449LOW2.521 Sep 2026Joplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft via UNC path on Windows
CVE-2026-49453HIGH721 Sep 2026Joplin: Path traversal in resource sync — silent arbitrary file write outside the resource directory
CVE-2026-49450HIGH7.121 Sep 2026Joplin desktop Windows auto-updater accepts signed installer from any publisher because app-update.yml has no publisherName
CVE-2026-79919MEDIUM6.321 Sep 2026MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RTLD_NEXT)
CVE-2026-79918MEDIUM6.321 Sep 2026MaxKB: Sandbox escape via unhooked fexecve
CVE-2026-94588MEDIUM4.421 Sep 2026In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This i…
CVE-2026-77517MEDIUM5.421 Sep 2026MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in another knowledge base
CVE-2026-77521CRITICAL1021 Sep 2026MaxKB: Prompt-injectable agent can lead to command execution
CVE-2026-94424CRITICAL9.321 Sep 2026Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140001000 heap-based overflow
CVE-2026-77522MEDIUM4.321 Sep 2026MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no internal-IP guard, non-blind)
CVE-2026-79917MEDIUM6.521 Sep 2026MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation
CVE-2026-77516MEDIUM5.421 Sep 2026MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path
CVE-2026-77523HIGH7.421 Sep 2026MaxKB: Cross-workspace model parameter form write
CVE-2026-77525MEDIUM4.221 Sep 2026MaxKB: Management chat-record routes trust path application_id but load ChatRecord by global chat_id
CVE-2026-77518MEDIUM521 Sep 2026MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflows
CVE-2026-79916CRITICAL9.121 Sep 2026MaxKB AWS Bedrock model credential injection leads to remote code execution
CVE-2026-58272MEDIUM5.321 Sep 2026Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)
CVE-2026-58270MEDIUM6.521 Sep 2026Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`
CVE-2026-77520MEDIUM5.421 Sep 2026MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to invoke another user's application
CVE-2026-77519MEDIUM5.421 Sep 2026MaxKB: Expired application API keys remain usable on `/chat/api/mcp`
CVE-2026-73511MEDIUM5.321 Sep 2026Envoy: Potential path-matching/authentication bypass when using Envoy in combination with a backend stripping per-segment path (matrix) parameters (e.g. Apache Tomcat)
CVE-2026-73553HIGH7.521 Sep 2026Envoy: RBAC Authorization Bypass via Path Parameters
CVE-2026-73551MEDIUM5.321 Sep 2026Envoy: Path normalization does not handle dot and dotdot segments with parameters
CVE-2026-94572CRITICAL9.421 Sep 2026In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers fiel…
CVE-2026-93433MEDIUM5.521 Sep 2026Libstoragemgmt: libstoragemgmt: denial of service via stack buffer overflow in scsi vpd page parsing