Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-77519 — MaxKB: Expired application API keys remain usable on `/chat/api/mcp`

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, the /chat/api/mcp authentication path looks up an ApplicationApiKey using only its secret and active status, without en…

Remote | Authentication
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
5.0 MEDIUM
CVE-2026-77518 — MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workfl…

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows another user's active MCP tool_id in the same workspace can retrieve the hidden tool …

Remote | Authorization
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
5.4 MEDIUM
CVE-2026-77517 — MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in…

MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.10.2-lts, document and paragraph operate routes authorize only knowledge_id in the request path, then query the targe…

Remote | Authorization
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
5.4 MEDIUM
CVE-2026-77516 — MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path

MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member denied access to a tool by WorkspaceUserResourcePermission can still bind its ide…

Remote | Authorization
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.5 HIGH
CVE-2026-73553 — Envoy: RBAC Authorization Bypass via Path Parameters

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, When ignore_path_parameters_in_path_matching is enabled, Envoy's r…

envoy | Remote | Authorization
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
5.3 MEDIUM
CVE-2026-73551 — Envoy: Path normalization does not handle dot and dotdot segments with parameters

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not recognize dot and dotdot path s…

envoy | Remote | Path Traversal
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
5.3 MEDIUM
CVE-2026-73511 — Envoy: Potential path-matching/authentication bypass when using Envoy in combination with…

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw request path, while servlet backend…

envoy | Remote | Path Traversal
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
0.0 NA
CVE-2026-67827 — ZLMediaKit Remote Code Execution via Incorrect Access Control

Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpo…

| Authentication
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.1 HIGH
CVE-2026-61647 — @roomi-fields/notebooklm-mcp has path traversal in vault.batch tool that allows arbitrary…

NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories. Versions 1.6.0 through 2.0.2 contain a path travers…

Remote | Path Traversal
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
4.3 MEDIUM
CVE-2026-59816 — Joplin: Path traversal in transcribe proxy endpoint via URL-encoded slash

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, the GET /api/transcribe/:id and POST /api/transcribe/:id handlers in packages…

Remote | Server-Side Request Forgery
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
5.3 MEDIUM
CVE-2026-58272 — Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/l…

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1 contain an observable timing discrepancy in the login endpoint because authent…

server | Remote | Authentication
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
6.5 MEDIUM
CVE-2026-58270 — Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string into a `RegExp` with no…

server | Remote | Denial of Service
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
6.5 MEDIUM
CVE-2026-55179 — Joplin: Logic error in Joplin Server allows a signed-in user to read any note from its in…

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /items/:id/content route in packages/server/src/routes/in…

Remote | Authorization
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.7 HIGH
CVE-2026-55105 — Joplin: Fountain embeds allow arbitrary script execution in published notes and the note …

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, packages/renderer/MdToHtml/rules/fountain.ts passes HTML generated…

Remote | Cross-Site Scripting
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.0 HIGH
CVE-2026-49453 — Joplin: Path traversal in resource sync — silent arbitrary file write outside the resourc…

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, Joplin accepts synchronized resource metadata whose id or file_ext…

Remote | Path Traversal
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.1 HIGH
CVE-2026-49450 — Joplin desktop Windows auto-updater accepts signed installer from any publisher because a…

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Desktop for Windows omits publisherName from packages/app-desktop/pack…

| Misconfiguration
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
2.5 LOW
CVE-2026-49449 — Joplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential thef…

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 until 3.7.2, packages/renderer/MdToHtml/rules/katex.ts enables KaTeX's trust optio…

| Cross-Site Scripting
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
9.1 CRITICAL
CVE-2026-46649 — Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable …

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SS…

Remote | Authentication
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
0.0 NA
CVE-2026-46650 — Joplin: Stored XSS in public share viewer via javascript: URL bypass in isAcceptedUrl

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, isAcceptedUrl() in packages/renderer/htmlUtils.ts uses an unanchored regular …

| Cross-Site Scripting
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
5.3 MEDIUM
CVE-2026-17054 — Out-of-bounds read and permanent loss of Wi-Fi reception in the ESP-hosted SPI driver's f…

The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in esp_hosted_event_task(). For control frames it took the 16-bit TLV field …

zephyr zephyr | Memory Corruption
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
Showing 20 of 13795 Results