Threat Intelligence Feed

Aggregating 7850 articles from trusted cybersecurity sources

LATEST CVEs
MED · CVE-2026-77522 MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the knowledge web-document impor CRIT · CVE-2026-77521 MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skil MED · CVE-2026-77520 MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal user in the same workspace can MED · CVE-2026-77519 MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, the /chat/api/mcp authentication path lo MED · CVE-2026-77518 MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows anothe MED · CVE-2026-77517 MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.10.2-lts, document and paragraph opera MED · CVE-2026-77516 MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member de HIGH · CVE-2026-73553 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, MED · CVE-2026-73551 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, MED · CVE-2026-73511 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, CRIT · CVE-2026-67827 Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote C CVE-2026-61647 NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content MED · CVE-2026-59816 Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7 MED · CVE-2026-58272 Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1 MED · CVE-2026-58270 Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, MED · CVE-2026-55179 Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2 HIGH · CVE-2026-55105 Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.1 HIGH · CVE-2026-49453 Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.1 HIGH · CVE-2026-49450 Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2 CVE-2026-49449 Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 unt CVE-2026-46649 Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2 CVE-2026-85219 Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause u HIGH · CVE-2026-81469 Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A l MED · CVE-2026-79320 Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime. When a downs CVE-2026-79319 Stencil core 4.43.5 is vulnerable to Incorrect Access Control. MED · CVE-2026-79318 web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file( HIGH · CVE-2026-73552 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, HIGH · CVE-2026-73550 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, MED · CVE-2026-73549 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, HIGH · CVE-2026-73548 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, HIGH · CVE-2026-73547 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, HIGH · CVE-2026-73546 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, HIGH · CVE-2026-73513 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, HIGH · CVE-2026-73512 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, MED · CVE-2026-62247 Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authoriz MED · CVE-2026-58271 Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, HIGH · CVE-2026-58269 Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, HIGH · CVE-2026-55897 luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router in HIGH · CVE-2026-55159 luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, MED · CVE-2026-54915 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /aut
5293 general 1010 advisories 724 research 546 vendor 277 enterprise

Trending Vendors

Latest News

Data Breaches

No articles found.