NIST

CVE intelligence

Cached from NVD. 2026-09-19 PT. Recent.

CVETitleVendorPublishedCVSSKEV listed
CVE-2026-86188AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary J2026-09-05
CVE-2026-86187WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integer2026-09-05
CVE-2026-86186AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operatio2026-09-05
CVE-2026-86185Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration wit2026-09-05
CVE-2026-86184Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attack2026-09-05
CVE-2026-86178Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated user2026-09-05
CVE-2026-86177Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedu2026-09-05
CVE-2026-86176NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bo2026-09-05
CVE-2026-86175NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with o2026-09-05
CVE-2026-86174Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attacke2026-09-05
CVE-2026-86173MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers2026-09-05
CVE-2026-86169Axolotl before 0.19.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None in2026-09-05
CVE-2026-86150A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Su2026-09-05
CVE-2026-86149A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This m2026-09-05
CVE-2026-86148A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of2026-09-05
CVE-2026-86145PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching works2026-09-05
CVE-2026-86144In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevanceXmlsoft2026-09-05
CVE-2026-86143In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacksXmlsoft2026-09-05
CVE-2026-86142In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.Xmlsoft2026-09-05
CVE-2026-86141xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculateXmlsoft2026-09-05
CVE-2026-86140In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.Xmlsoft2026-09-05
CVE-2026-86139In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.Xmlsoft2026-09-05
CVE-2026-86138In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.Xmlsoft2026-09-05
CVE-2026-86137In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.Xmlsoft2026-09-05
CVE-2026-86124AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attack2026-09-05
CVE-2026-86123SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL qu2026-09-05
CVE-2026-86122Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations2026-09-05
CVE-2026-86121Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfa2026-09-05
CVE-2026-86120APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level acc2026-09-05
CVE-2026-86119Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asse2026-09-05
CVE-2026-86118gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger2026-09-05
CVE-2026-86117Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts2026-09-05
CVE-2026-86116Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to2026-09-05
CVE-2026-86115Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation a2026-09-05
CVE-2026-86114Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delet2026-09-05
CVE-2026-86113BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to mo2026-09-05
CVE-2026-86112BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers 2026-09-05
CVE-2026-86111BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read f2026-09-05
CVE-2026-86100Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature.2026-09-05
CVE-2026-86060MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command VulnerabilityMikrotik2026-09-052026-09-10

Previous81–120 of 210Next