This page offers a live ATOM feed of the latest CVEs and Vulnerabilities from cvefeed.io. HIGH or CRITICAL
- CVE-2026-55445 - Qinglong: Incomplete fix for CVE-2026-3965: Improper Authentication
- CVE-2026-55234 - Wekan: Broken access control: any authenticated user can move their Cards/Lists/Swimlanes into a private board they are not a member of (cross-board write via collection allow rule)
- CVE-2026-54458 - AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin
- CVE-2026-52891 - Wekan: Shell Injection via Avatar Upload
- CVE-2026-48795 - Incomplete fix for CVE-2026-25754 in @adonisjs/bodyparser
- CVE-2026-56679 - 9Router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade
- CVE-2026-52887 - NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
- CVE-2026-49352 - 9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass
- CVE-2026-46339 - 9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
- CVE-2026-33445 - Memory management vulnerability in Secure Access servers
- CVE-2026-49445 - Cilium: Sensitive information disclosure and cluster disruption via local Envoy admin socket access
- CVE-2026-46684 - DataEase: Unauthorized Command Execution Vulnerability
- CVE-2026-45419 - DataEase: Arbitrary File Write Vulnerability
- CVE-2026-45320 - DataEase Data Dashboard SqlVariable transFilter Unfiltered SQL Injection
- CVE-2026-40952 - Privilge misconfiguration in Secure Access installers
- CVE-2026-62349 - TDengine: Off-by-One Buffer Overflow