CVEs
Most recently published first. Full-text search is on the roadmap.
Year
Want to know when one of these hits your stack? Track the products you run and get alerted.
Create a free account| CVE | Severity | Published | Title |
|---|---|---|---|
| CVE-2026-94540 | HIGH7.7 | 21 Sep 2026 | DesktopSMS 1.11.0 Unauthorized Access via Local Service |
| CVE-2026-65980 | HIGH7.9 | 21 Sep 2026 | Chartbrew: SQL Injection via Missing Backslash Escaping in ClickHouse Variable Substitution |
| CVE-2026-61851 | MEDIUM6.5 | 21 Sep 2026 | Chartbrew: Incomplete Read-Only Keyword Blocklist in AI runQuery Tool |
| CVE-2026-61852 | MEDIUM5.8 | 21 Sep 2026 | Chartbrew: SQL Injection via row_limit Parameter in AI runQuery Tool |
| CVE-2026-61743 | MEDIUM6.3 | 21 Sep 2026 | Chartbrew: DNS Rebinding SSRF Bypass in Outbound Request Validation |
| CVE-2026-94536 | MEDIUM5.3 | 21 Sep 2026 | lamp-cloud through 5.10.0 Unauthorized Information Disclosure via /anyone/visible/resource |
| CVE-2026-94535 | HIGH7.1 | 21 Sep 2026 | lamp-cloud through 5.10.0 Unauthorized Notification Deletion |
| CVE-2026-94534 | HIGH7.1 | 21 Sep 2026 | lamp-cloud through 5.10.0 Unauthorized Profile Modification via PUT endpoints |
| CVE-2026-94533 | HIGH7.1 | 21 Sep 2026 | lamp-cloud through 5.10.0 Unauthorized File Download via /anyone/file |
| CVE-2026-94532 | HIGH7.1 | 21 Sep 2026 | lamp-cloud through 5.10.0 Unauthorized User Profile Access via getUserInfoById |
| CVE-2026-93340 | HIGH7.4 | 21 Sep 2026 | Gladys Assistant < 5.1.0 Password Reset Link Poisoning via forgot_password Endpoint |
| CVE-2026-61541 | MEDIUM6.9 | 21 Sep 2026 | Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service |
| CVE-2026-59830 | MEDIUM5.4 | 21 Sep 2026 | Discourse: Stored XSS via unescaped actor name in post actions |
| CVE-2026-46650 | MEDIUM4.4 | 21 Sep 2026 | Joplin: Stored XSS in public share viewer via javascript: URL bypass in isAcceptedUrl |
| CVE-2026-17054 | MEDIUM5.3 | 21 Sep 2026 | Out-of-bounds read and permanent loss of Wi-Fi reception in the ESP-hosted SPI driver's frame reassembly |
| CVE-2026-15890 | MEDIUM5.3 | 21 Sep 2026 | AEAD nonce reuse in Zephyr secure_storage ITS default nonce provider due to missing thread synchronization |
| CVE-2026-59815 | MEDIUM4.3 | 21 Sep 2026 | Joplin: Pending share recipients can write items into shared folders before accepting invitations |
| CVE-2026-55210 | HIGH7.4 | 21 Sep 2026 | Joplin: SAML SSO account takeover via email-based account linking (missing is_external check in ssoLogin) |
| CVE-2026-61652 | HIGH8.7 | 21 Sep 2026 | Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb) |
| CVE-2026-59814 | HIGH7.6 | 21 Sep 2026 | Joplin: Stored XSS via inline-served note attachment on published shares |
| CVE-2026-61647 | HIGH7.1 | 21 Sep 2026 | @roomi-fields/notebooklm-mcp has path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory |
| CVE-2026-55105 | HIGH7.7 | 21 Sep 2026 | Joplin: Fountain embeds allow arbitrary script execution in published notes and the note viewer |
| CVE-2026-46649 | CRITICAL9.1 | 21 Sep 2026 | Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected Endpoint |
| CVE-2026-55179 | MEDIUM6.5 | 21 Sep 2026 | Joplin: Logic error in Joplin Server allows a signed-in user to read any note from its internal server ID |
| CVE-2026-59816 | MEDIUM4.3 | 21 Sep 2026 | Joplin: Path traversal in transcribe proxy endpoint via URL-encoded slash |
| CVE-2026-49449 | LOW2.5 | 21 Sep 2026 | Joplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft via UNC path on Windows |
| CVE-2026-49453 | HIGH7 | 21 Sep 2026 | Joplin: Path traversal in resource sync — silent arbitrary file write outside the resource directory |
| CVE-2026-49450 | HIGH7.1 | 21 Sep 2026 | Joplin desktop Windows auto-updater accepts signed installer from any publisher because app-update.yml has no publisherName |
| CVE-2026-79919 | MEDIUM6.3 | 21 Sep 2026 | MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RTLD_NEXT) |
| CVE-2026-79918 | MEDIUM6.3 | 21 Sep 2026 | MaxKB: Sandbox escape via unhooked fexecve |
| CVE-2026-94588 | MEDIUM4.4 | 21 Sep 2026 | In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This i… |
| CVE-2026-77517 | MEDIUM5.4 | 21 Sep 2026 | MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in another knowledge base |
| CVE-2026-77521 | CRITICAL10 | 21 Sep 2026 | MaxKB: Prompt-injectable agent can lead to command execution |
| CVE-2026-94424 | CRITICAL9.3 | 21 Sep 2026 | Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140001000 heap-based overflow |
| CVE-2026-77522 | MEDIUM4.3 | 21 Sep 2026 | MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no internal-IP guard, non-blind) |
| CVE-2026-79917 | MEDIUM6.5 | 21 Sep 2026 | MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation |
| CVE-2026-77516 | MEDIUM5.4 | 21 Sep 2026 | MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path |
| CVE-2026-77523 | HIGH7.4 | 21 Sep 2026 | MaxKB: Cross-workspace model parameter form write |
| CVE-2026-77525 | MEDIUM4.2 | 21 Sep 2026 | MaxKB: Management chat-record routes trust path application_id but load ChatRecord by global chat_id |
| CVE-2026-77518 | MEDIUM5 | 21 Sep 2026 | MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflows |
| CVE-2026-79916 | CRITICAL9.1 | 21 Sep 2026 | MaxKB AWS Bedrock model credential injection leads to remote code execution |
| CVE-2026-58272 | MEDIUM5.3 | 21 Sep 2026 | Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory) |
| CVE-2026-58270 | MEDIUM6.5 | 21 Sep 2026 | Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters` |
| CVE-2026-77520 | MEDIUM5.4 | 21 Sep 2026 | MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to invoke another user's application |
| CVE-2026-77519 | MEDIUM5.4 | 21 Sep 2026 | MaxKB: Expired application API keys remain usable on `/chat/api/mcp` |
| CVE-2026-73511 | MEDIUM5.3 | 21 Sep 2026 | Envoy: Potential path-matching/authentication bypass when using Envoy in combination with a backend stripping per-segment path (matrix) parameters (e.g. Apache Tomcat) |
| CVE-2026-73553 | HIGH7.5 | 21 Sep 2026 | Envoy: RBAC Authorization Bypass via Path Parameters |
| CVE-2026-73551 | MEDIUM5.3 | 21 Sep 2026 | Envoy: Path normalization does not handle dot and dotdot segments with parameters |
| CVE-2026-94572 | CRITICAL9.4 | 21 Sep 2026 | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers fiel… |
| CVE-2026-93433 | MEDIUM5.5 | 21 Sep 2026 | Libstoragemgmt: libstoragemgmt: denial of service via stack buffer overflow in scsi vpd page parsing |