Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-77555 — UniFi Gateway Out-of-bounds Write Vulnerability

A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

unifi_connect | Remote | Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.5 HIGH
CVE-2026-77544 — UniFi Gateway Out-of-bounds Write Denial of Service Vulnerability

A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

unifi_connect | Remote | Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
6.5 MEDIUM
CVE-2026-77399 — icalendar: Denial of service via unbounded VALARM REPEAT expansion

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.from_ical accepts an attacker-controlled VALARM REPEAT value and applications that…

Remote | Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.4 MEDIUM
CVE-2026-77272 — MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth error query parameter is passed to CallbackHandler._send_response in oa…

mcp_atlassian | Remote | Cross-Site Scripting
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
6.5 MEDIUM
CVE-2026-77269 — MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete…

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the remediation for CVE-2026-27825 protects download destinations but does not co…

mcp_atlassian | Remote | Path Traversal
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.5 MEDIUM
CVE-2026-77268 — MCP Atlassian: Insecure File Permissions on OAuth Token Storage

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth fallback token directory and JSON file are created without explicit own…

mcp_atlassian | Misconfiguration
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
6.5 MEDIUM
CVE-2026-77266 — MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltr…

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment accepts absolute paths and traversal sequences without constrai…

mcp_atlassian | Remote | Path Traversal
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.6 HIGH
CVE-2026-77262 — MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP t…

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment accepts an attacker-controlled file_path and does no…

mcp_atlassian | Remote | Path Traversal
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.7 HIGH
CVE-2026-77259 — MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration o…

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment opens a caller-selected server-local file without ch…

mcp_atlassian | Remote | Path Traversal
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.3 HIGH
CVE-2026-77257 — MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, HTTP-exposed Jira and Confluence upload tools pass a caller-provided file_path to…

mcp_atlassian | Remote | Path Traversal
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.3 HIGH
CVE-2026-77256 — MCP Atlassian: OAuth refresh-token backup file is world-readable under default Unix umask

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the plaintext OAuth fallback file containing refresh and access tokens is written…

mcp_atlassian | Remote | Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.6 HIGH
CVE-2026-77255 — MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira update_issue attachments argument is converted into local paths and rout…

mcp_atlassian | Remote | Path Traversal
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.1 CRITICAL
CVE-2026-77254 — MCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Con…

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, requests to the HTTP MCP endpoint without a per-user identity are allowed to reac…

mcp_atlassian | Remote | Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.1 HIGH
CVE-2026-77253 — MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-loca…

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence attachment upload tools accept arbitrary local filesystem pat…

mcp_atlassian | Remote | Path Traversal
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.3 MEDIUM
CVE-2026-77249 — MCP Atlassian: Incomplete fix for CVE-2026-27826: redirect-based SSRF via unhooked reques…

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, JiraUserMixin._lookup_user_by_permissions uses the module-level requests.get func…

mcp_atlassian | Remote | Server-Side Request Forgery
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.6 HIGH
CVE-2026-77248 — MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path,…

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the streamable HTTP transport accepts requests without a user identity and falls …

mcp_atlassian | Remote | Path Traversal
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.3 HIGH
CVE-2026-77247 — MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unre…

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence upload tools interpret caller-controlled path arguments on th…

mcp_atlassian | Remote | Path Traversal
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.4 HIGH
CVE-2026-77246 — MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment …

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, an HTTP transport deployment with READ_ONLY_MODE=false accepts a request without …

mcp_atlassian | Server-Side Request Forgery
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
4.3 MEDIUM
CVE-2026-76194 — CAI Content Credentials | Improper Input Validation (CWE-20)

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security meas…

Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.5 MEDIUM
CVE-2026-76192 — InDesign Desktop | NULL Pointer Dereference (CWE-476)

InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, …

indesign | Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
Showing 20 of 14162 Results