Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.8 MEDIUM
CVE-2026-108858 — Predibase LoRAX through 0.12.1 API Token Exposure via Router Logs

Predibase LoRAX through 0.12.1 contains a sensitive information exposure vulnerability that writes the caller-supplied api_token from POST /generate request bodies into router logs. Attackers with ac…

| Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.8 MEDIUM
CVE-2026-108857 — Hugging Face Text Embeddings Inference through 1.9.4 Cleartext API Key Logging

Hugging Face Text Embeddings Inference through 1.9.4 contains a cleartext logging vulnerability that exposes the configured api_key because the router's Args struct lacks a redact attribute for it. A…

| Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.2 MEDIUM
CVE-2026-108856 — UnicomAI Wanwu through 0.6.5 Authorization Bypass via /v1/appspace/app/key AppKey Minting

UnicomAI Wanwu through 0.6.5 contains an authorization bypass vulnerability that allows authenticated users to mint AppKeys bound to other users' MCP servers via POST /v1/appspace/app/key. Attackers …

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.4 MEDIUM
CVE-2026-108855 — UnicomAI Wanwu through 0.6.5 Missing Authorization via DELETE /v1/appspace/app/publish

UnicomAI Wanwu through 0.6.5 contains a missing authorization vulnerability that allows any authenticated enabled user to revoke other users' AppKeys for arbitrary apps via the unpublish endpoint. At…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.4 MEDIUM
CVE-2026-108854 — Wanwu before 0.6.3 IDOR AppKey Deletion via DELETE /v1/appspace/app/key

Wanwu before 0.6.3 contains an insecure direct object reference vulnerability that allows any authenticated enabled user to delete other users' legacy AppKeys by supplying a numeric apiId. Attackers …

Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.1 HIGH
CVE-2026-108853 — UnicomAI Wanwu before 0.6.3 IDOR via DELETE /v1/appspace/app

UnicomAI Wanwu before 0.6.3 contains an insecure direct object reference vulnerability that allows authenticated low-privileged users to delete other tenants' agent or RAG applications by supplying t…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.7 MEDIUM
CVE-2026-108852 — Deep Chat through 2.5.1 XSS via Markdown Link Validation Bypass

Deep Chat through 2.5.1 contains a cross-site scripting vulnerability that allows attackers to inject javascript: links because RemarkableConfig.createNew disables Remarkable link validation. Attacke…

deepchat | Remote | Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.8 MEDIUM
CVE-2026-108851 — phpMyFAQ through 4.1.10 Missing Authorization via MCP Server faq_search Tool

phpMyFAQ through 4.1.10 contains a missing authorization vulnerability in the MCP server faq_search tool that allows MCP clients to read restricted FAQs because Search::searchDatabase() never applies…

phpmyfaq | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.9 MEDIUM
CVE-2026-108850 — Company Research Agent through 2.2.0 SSRF via /generate-pdf ReportLab Markup

Company Research Agent through 2.2.0 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger outbound requests by injecting unescaped ReportLab paragraph…

Remote | Server-Side Request Forgery
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.2 MEDIUM
CVE-2026-108839 — thClaws through 0.141.0 Symlink Following File Write via POST /v1/inputs

thClaws through 0.141.0 contains a link-following vulnerability in the post_inputs handler of the v1 API POST /v1/inputs endpoint that allows writes outside the workspace by following symlinks. Attac…

Remote | Path Traversal
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.3 HIGH
CVE-2026-108699 — hyper-mcp through 0.8.3 Improper Signature Verification of OCI WebAssembly Plugins

hyper-mcp through 0.8.3 contains an improper signature verification vulnerability that allows attackers to load malicious WebAssembly plugins because cosign_verify_args() accepts any signer identity …

Remote | Misconfiguration
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.3 HIGH
CVE-2026-108698 — hyper-mcp through 0.8.3 OCI Plugin Signature Verification TOCTOU Race Condition

hyper-mcp through 0.8.3 contains a signature verification bypass vulnerability in load_wasm in src/wasm/oci.rs that verifies the Cosign signature of a separately resolved tag rather than the loaded m…

Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108697 — CoreShop through 2026.2.2 Missing Authorization via ResourceController listAction

CoreShop through 2026.2.2 contains a missing authorization vulnerability that allows low-privileged backend users to list permission-restricted resources because ResourceController listAction skips t…

coreshop | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.3 MEDIUM
CVE-2026-108681 — zhayujie CowAgent Web Console web_channel.py denial of service

A security flaw has been discovered in zhayujie CowAgent up to 2.1.7. Impacted is an unknown function of the file channel/web/web_channel.py of the component Web Console. The manipulation of the argu…

cowagent | Remote | Denial of Service
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.6 HIGH
CVE-2026-108760 — LlamaFarm through 0.0.34 Unauthenticated API Exposed on All Interfaces

LlamaFarm through 0.0.34 contains an insecure default configuration that binds its unauthenticated FastAPI server to 0.0.0.0 on port 14345, while the lf CLI silently discards HOST overrides. Network-…

| Misconfiguration
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.6 HIGH
CVE-2026-108759 — mistral.rs 0.9.0 through 0.9.4 Sandbox Escape via Symlink Following in mistralrs-code-exec

mistral.rs 0.9.0 through 0.9.4 contains a link following vulnerability in mistralrs-code-exec that allows sandboxed shell code to read and overwrite files outside the sandbox via symlinks. Attackers …

mistral.rs | Remote | Path Traversal
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.8 HIGH
CVE-2026-108758 — Easy!Appointments through 1.6.0 Authorization Bypass via booking/register Endpoint

Easy!Appointments through 1.6.0 contains an authorization bypass vulnerability in Booking::register() that allows unauthenticated attackers to modify any appointment by supplying an appointment id wi…

easyappointments | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.1 HIGH
CVE-2026-108757 — Nexting pinclaw through 0.3.0 Missing Authentication via POST /pinclaw/send

Nexting pinclaw OpenClaw channel plugin through 0.3.0 contains a missing authentication vulnerability in src/core/http-router.ts that skips the authToken check on POST /pinclaw/send. Unauthenticated …

| Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.4 MEDIUM
CVE-2026-108756 — Abilityai Trinity through 0.9.5 Missing Authorization in Telegram Binding Routes

Abilityai Trinity through 0.9.5 contains a missing authorization vulnerability in the Telegram router that allows agent-scoped MCP API keys to perform human-only binding operations. Attackers control…

trinity | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.9 MEDIUM
CVE-2026-108755 — Hatchet through 0.110.5 Unauthenticated Memory Exhaustion via SNS Ingestion Endpoint

Hatchet through 0.110.5 contains an allocation of resources without limits vulnerability that allows unauthenticated attackers to exhaust memory via the SNS ingestion endpoint. Attackers can send arb…

hatchet | Remote | Denial of Service
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
Showing 20 of 13656 Results