Fri, May 22 · 04:16 AM CDTCVE-2026-46595
10.0/10 · Must read/watchNVDvuln
Summary
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
CVECVE-2026-46595
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Sep 11 · 01:18 PM CDT
Tue, Aug 04 · 08:16 PM CDTCVE-2026-70478
10.0/10 · Must read/watchNVDvuln
Summary
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The endpoint decrypts the stored credential, sends a refresh request to the configured
CVECVE-2026-70478
SeverityCRITICAL
TypeUPDATED
PublishedTue, Aug 04 · 08:16 PM CDT
ModifiedFri, Sep 11 · 09:14 PM CDT
Thu, Jul 23 · 09:17 PM CDTCVE-2026-15630
9.9/10 · Must read/watchNVDvuln
Summary
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
CVECVE-2026-15630
SeverityCRITICAL
TypeUPDATED
PublishedThu, Jul 23 · 09:17 PM CDT
ModifiedFri, Sep 11 · 07:17 PM CDT
Thu, Mar 12 · 03:16 PM CDTCVE-2026-28384
9.9/10 · Must read/watchNVDvuln
Summary
An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This issue affected LXD from 4.12 through 6.6 and was fixed in the snap versions 5.0.6-e49d
CVECVE-2026-28384
SeverityCRITICAL
TypeUPDATED
PublishedThu, Mar 12 · 03:16 PM CDT
ModifiedFri, Sep 11 · 03:33 PM CDT
Wed, Aug 12 · 08:17 PM CDTCVE-2026-62420
9.9/10 · Must read/watchNVDvuln
Summary
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: , and target: , the des
CVECVE-2026-62420
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 12 · 08:17 PM CDT
ModifiedFri, Sep 11 · 02:32 PM CDT
Wed, Aug 12 · 08:17 PM CDTCVE-2026-63294
9.9/10 · Must read/watchNVDvuln
Summary
A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by provi
CVECVE-2026-63294
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 12 · 08:17 PM CDT
ModifiedFri, Sep 11 · 03:11 PM CDT
Wed, Aug 12 · 08:17 PM CDTCVE-2026-63296
9.9/10 · Must read/watchNVDvuln
Summary
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions.
CVECVE-2026-63296
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 12 · 08:17 PM CDT
ModifiedFri, Sep 11 · 03:15 PM CDT
Wed, Aug 12 · 08:17 PM CDTCVE-2026-63297
9.9/10 · Must read/watchNVDvuln
Summary
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is comple
CVECVE-2026-63297
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 12 · 08:17 PM CDT
ModifiedFri, Sep 11 · 03:18 PM CDT
Wed, Aug 12 · 08:17 PM CDTCVE-2026-63298
9.9/10 · Must read/watchNVDvuln
Summary
An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can
CVECVE-2026-63298
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 12 · 08:17 PM CDT
ModifiedFri, Sep 11 · 03:20 PM CDT
Wed, Aug 12 · 08:17 PM CDTCVE-2026-63299
9.9/10 · Must read/watchNVDvuln
Summary
An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreation check before moving a volume across pr
CVECVE-2026-63299
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 12 · 08:17 PM CDT
ModifiedFri, Sep 11 · 03:26 PM CDT
Wed, Aug 12 · 08:17 PM CDTCVE-2026-63300
9.9/10 · Must read/watchNVDvuln
Summary
An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance between projects, LXD fails to validate the i
CVECVE-2026-63300
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 12 · 08:17 PM CDT
ModifiedFri, Sep 11 · 03:21 PM CDT
Wed, Aug 12 · 09:17 PM CDTCVE-2026-66898
9.9/10 · Must read/watchNVDvuln
Summary
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplyin
CVECVE-2026-66898
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 12 · 09:17 PM CDT
ModifiedFri, Sep 11 · 03:30 PM CDT
Tue, Aug 11 · 12:17 PM CDTCVE-2026-13738
9.8/10 · Must read/watchNVDvuln
Summary
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
CVECVE-2026-13738
SeverityCRITICAL
TypeUPDATED
PublishedTue, Aug 11 · 12:17 PM CDT
ModifiedFri, Sep 11 · 02:25 PM CDT
Wed, Aug 12 · 09:17 PM CDTCVE-2026-19001
9.8/10 · Must read/watchNVDvuln
Summary
The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, un
CVECVE-2026-19001
SeverityCRITICAL
TypeUPDATED
PublishedWed, Aug 12 · 09:17 PM CDT
ModifiedFri, Sep 11 · 06:53 PM CDT
Fri, Jul 31 · 04:17 AM CDTCVE-2026-43830
9.8/10 · Must read/watchNVDvuln
Summary
Full details and mitigation steps are currently restricted and will be published at a later date.
CVECVE-2026-43830
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jul 31 · 04:17 AM CDT
ModifiedFri, Sep 11 · 01:18 PM CDT
Tue, Aug 04 · 08:16 PM CDTCVE-2026-70477
9.8/10 · Must read/watchNVDvuln
Summary
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Pyodide environment. The
CVECVE-2026-70477
SeverityCRITICAL
TypeUPDATED
PublishedTue, Aug 04 · 08:16 PM CDT
ModifiedFri, Sep 11 · 09:09 PM CDT
Fri, May 22 · 04:16 PM CDTCVE-2026-39821
9.6/10 · Must read/watchNVDvuln
Summary
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a
CVECVE-2026-39821
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 PM CDT
ModifiedFri, Sep 11 · 01:17 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedFri, Sep 11 · 01:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39830
9.1/10 · Must read/watchNVDvuln
Summary
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVECVE-2026-39830
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Sep 11 · 01:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39832
9.1/10 · Must read/watchNVDvuln
Summary
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. A
CVECVE-2026-39832
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Sep 11 · 01:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-42508
9.1/10 · Must read/watchNVDvuln
Summary
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVECVE-2026-42508
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Sep 11 · 01:18 PM CDT
Tue, Jun 09 · 05:17 PM CDTCVE-2026-45447
8.8/10 · Worth your timeNVDvuln
Summary
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed message, if the SignedD
CVECVE-2026-45447
SeverityHIGH
TypeUPDATED
PublishedTue, Jun 09 · 05:17 PM CDT
ModifiedFri, Sep 11 · 01:18 PM CDT
Wed, Aug 12 · 06:18 PM CDTCVE-2026-69106
8.8/10 · Worth your timeNVDvuln
Summary
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
CVECVE-2026-69106
SeverityHIGH
TypeUPDATED
PublishedWed, Aug 12 · 06:18 PM CDT
ModifiedFri, Sep 11 · 03:36 PM CDT
Tue, Aug 18 · 09:17 PM CDTCVE-2026-70737
8.8/10 · Worth your timeNVDvuln
Summary
Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Storage Server Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle
CVECVE-2026-70737
SeverityHIGH
TypeUPDATED
PublishedTue, Aug 18 · 09:17 PM CDT
ModifiedFri, Sep 11 · 08:14 PM CDT
Thu, Jun 11 · 05:16 PM CDTCVE-2026-44494
8.7/10 · Worth your timeNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack — intercepti
CVECVE-2026-44494
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 11 · 05:16 PM CDT
ModifiedFri, Sep 11 · 01:18 PM CDT