Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.9 CRITICAL
CVE-2026-54052 — n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT…

n8n-mcp | Remote | Authorization
Jul 15, 2026 Jul 18, 2026
Jul 15, 2026
Jul 18, 2026
10.0 CRITICAL
CVE-2026-52887 — NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /ap…

Remote | Injection
Jul 15, 2026 Jul 16, 2026
Jul 15, 2026
Jul 16, 2026
9.8 CRITICAL
CVE-2026-51380 — Tenda AC10 Buffer Overflow Vulnerability

Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code via the /cgi-bin/UploadCfg endp…

Remote | Memory Corruption
Jul 15, 2026 Jul 16, 2026
Jul 15, 2026
Jul 16, 2026
9.8 CRITICAL
CVE-2026-49352 — 9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass

9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/route.js, src/middleware.js,…

Remote | Authentication
Jul 15, 2026 Jul 16, 2026
Jul 15, 2026
Jul 16, 2026
10.0 CRITICAL
CVE-2026-46339 — 9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes

9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of customPlug…

Remote | Authentication
Jul 15, 2026 Jul 16, 2026
Jul 15, 2026
Jul 16, 2026
9.2 CRITICAL
CVE-2026-49445 — Cilium: Sensitive information disclosure and cluster disruption via local Envoy admin soc…

Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy instance creates a world-…

cilium | Misconfiguration
Jul 15, 2026 Jul 17, 2026
Jul 15, 2026
Jul 17, 2026
9.5 CRITICAL
CVE-2026-46684 — DataEase: Unauthorized Command Execution Vulnerability

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to TokenUtils.validate(), w…

Remote | Authentication
Jul 15, 2026 Jul 17, 2026
Jul 15, 2026
Jul 17, 2026
9.0 CRITICAL
CVE-2026-45534 — DataEase: RCE Vulnerability

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configuration from System.getProper…

Remote | Misconfiguration
Jul 15, 2026 Jul 16, 2026
Jul 15, 2026
Jul 16, 2026
9.3 CRITICAL
CVE-2026-46421 — Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres…

The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, …

Remote | Supply Chain
Jul 15, 2026 Jul 15, 2026
Jul 15, 2026
Jul 15, 2026
9.6 CRITICAL
CVE-2026-62948 — OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN h…

OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c statefiles_wri…

Remote | Injection
Jul 15, 2026 Jul 15, 2026
Jul 15, 2026
Jul 15, 2026
9.6 CRITICAL
CVE-2026-53513 — Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/s…

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints accept attacker-co…

better_auth | Remote | Server-Side Request Forgery
Jul 15, 2026 Jul 15, 2026
Jul 15, 2026
Jul 15, 2026
9.1 CRITICAL
CVE-2026-53512 — Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provide…

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticate…

better_auth | Remote | Authentication
Jul 15, 2026 Jul 18, 2026
Jul 15, 2026
Jul 18, 2026
9.3 CRITICAL
CVE-2026-50562 — FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows

FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/workflows/preview-doc…

Remote | Misconfiguration
Jul 15, 2026 Jul 15, 2026
Jul 15, 2026
Jul 15, 2026
9.8 CRITICAL
CVE-2026-14960 — CVE-2026-14960

Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_READ` and `TDE_IOCTL_INDEXIO_W…

Remote | Misconfiguration
Jul 15, 2026 Jul 16, 2026
Jul 15, 2026
Jul 16, 2026
9.0 CRITICAL
CVE-2026-62378 — RustFS Console: Critical Stored XSS in Preview Modal leading to Administrative Account Ta…

RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/preview-modal.tsx and components/object/pdf-viewer.tsx…

Remote | Cross-Site Scripting
Jul 15, 2026 Jul 16, 2026
Jul 15, 2026
Jul 16, 2026
9.3 CRITICAL
CVE-2026-52843 — Lightpanda: fetch() and XMLHttpRequest attach session cookies to cross-origin requests re…

Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest unconditionally attached session cookies to every HTTP request, ignoring credent…

Remote | Authentication
Jul 15, 2026 Jul 15, 2026
Jul 15, 2026
Jul 15, 2026
9.3 CRITICAL
CVE-2026-52842 — Lightpanda:URL parser misidentifies page origin for URLs containing @ in the path - Same-…

Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ across the entire URL string instead of only the authority component when computing a page o…

Remote | Misconfiguration
Jul 15, 2026 Jul 15, 2026
Jul 15, 2026
Jul 15, 2026
10.0 CRITICAL
CVE-2026-50148 — Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write

Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to ad…

Remote | Misconfiguration
Jul 15, 2026 Jul 15, 2026
Jul 15, 2026
Jul 15, 2026
9.9 CRITICAL
CVE-2026-44986 — Penpot: Pre-authenticated account takeover via team-invitation token + prepare-register-p…

Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing prof…

Remote | Authentication
Jul 15, 2026 Jul 15, 2026
Jul 15, 2026
Jul 15, 2026
9.3 CRITICAL
CVE-2026-61740 — LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status d…

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, X-API-Key protection can be bypassed bec…

lightrag | Remote | Authentication
Jul 15, 2026 Jul 15, 2026
Jul 15, 2026
Jul 15, 2026
Showing 20 of 945 Results