Export limit exceeded: 404426 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 404426 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404426 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-108734 | 1 Frappe | 1 Crm | 2026-10-11 | 4.3 Medium |
| Frappe CRM 1.49.0 through 1.87.0 contains a missing authorization vulnerability in crm.api.doc.get_linked_docs_of_document that allows authenticated users to read linked documents without permission checks. Attackers can name a lead, deal, comment or user they cannot read to obtain linked call log phone numbers, deal organizations and mention notification text. | ||||
| CVE-2026-108725 | 1 Cheshire-cat-ai | 1 Core | 2026-10-11 | 5.4 Medium |
| Cheshire Cat AI core through 2.0.23 contains a stored cross-site scripting vulnerability in the uploads plugin that allows authenticated users to upload HTML files via POST /uploads without type restrictions. Attackers can send the public GET /uploads/{path} URL to a signed-in victim, executing script in the application origin with the victim's access_token cookie, including administrators. | ||||
| CVE-2026-108729 | 1 Cortezaproject | 1 Corteza | 2026-10-11 | 5.9 Medium |
| Corteza through 2024.9.10 contains an incorrect authorization vulnerability in compose attachment endpoints that allows unauthenticated attackers to download private attachments by setting the URL kind segment to page, icon, or namespace. Attackers who know a private record or module attachment id can request the original or preview route without a token or signature to retrieve files across namespace and record permission boundaries. | ||||
| CVE-2026-108739 | 1 Openagents-org | 1 Openagents | 2026-10-11 | 7.5 High |
| OpenAgents Workspace backend through launcher-v1.0.17 contains an information disclosure vulnerability that allows unauthenticated attackers to list all workspaces via GET /v1/workspaces. Attackers can read the unmasked browserfabric_api_key in each workspace's settings map, along with workspace ids, slugs, creator emails and member lists. | ||||
| CVE-2026-108710 | 1 Orneryd | 1 Nornicdb | 2026-10-11 | 6.5 Medium |
| NornicDB through 1.4.1 contains a missing authorization vulnerability that allows authenticated users to bypass per-database read restrictions on the /nornicdb/search and /nornicdb/similar endpoints. Viewer-role users allowlisted for a database but denied read can submit search queries or node IDs to retrieve node IDs, labels and full property maps. | ||||
| CVE-2026-108865 | 2026-10-11 | 8.2 High | ||
| AmoyLab Unla through 0.10.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid access tokens because the OAuth2 server never authenticates a resource owner. Attackers can register a client, request a code from /authorize, and exchange it at /token to access OAuth2-protected MCP prefixes, proxied upstream APIs and injected credentials. | ||||
| CVE-2026-108863 | 2026-10-11 | 7.5 High | ||
| Katanemo Plano through 0.4.37 contains a missing authentication vulnerability that allows unauthenticated network attackers to access the Envoy admin interface, which is bound to all host interfaces on port 9901. Attackers can request the /config_dump endpoint to read configured LLM provider API keys in plaintext from the WASM filter configuration. | ||||
| CVE-2026-108862 | 2026-10-11 | 5.3 Medium | ||
| APIPark through 1.9.7-beta contains an insecure direct object reference vulnerability that allows authenticated users to read other applications' credentials by supplying a foreign authorization UUID. Attackers with authorization-view permission on one application can query /api/v1/app/authorization or its details route to retrieve plaintext API keys regardless of HideCredential. | ||||
| CVE-2026-108861 | 2026-10-11 | 4.3 Medium | ||
| Odoo MCP 1.0.0 through 1.3.2 contains an information disclosure vulnerability that allows MCP clients to bypass the field-level ACL by invoking the execute_method tool. Attackers or prompt-injected agents can call read or search_read through execute_method naming denied fields to receive their values unredacted. | ||||
| CVE-2026-108860 | 2026-10-11 | 9.1 Critical | ||
| BotSharp through 5.2.0 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to forge bearer tokens using the hard-coded Jwt:Key in WebStarter appsettings.json. Attackers can sign tokens with the committed HMAC secret and fixed botsharp issuer and audience to impersonate any known user, including administrators, on Authorize-protected API routes. | ||||
| CVE-2026-108858 | 2026-10-11 | 5.5 Medium | ||
| Predibase LoRAX through 0.12.1 contains a sensitive information exposure vulnerability that writes the caller-supplied api_token from POST /generate request bodies into router logs. Attackers with access to router logs or OTLP trace backends can recover other users' private-adapter tokens recorded through the instrumented GenerateParameters span field. | ||||
| CVE-2026-108857 | 2026-10-11 | 3.3 Low | ||
| Hugging Face Text Embeddings Inference through 1.9.4 contains a cleartext logging vulnerability that exposes the configured api_key because the router's Args struct lacks a redact attribute for it. Attackers with access to router logs, container output, or OTLP telemetry can recover the Bearer token and call the protected embedding and rerank endpoints. | ||||
| CVE-2026-108856 | 2026-10-11 | 4.2 Medium | ||
| UnicomAI Wanwu through 0.6.5 contains an authorization bypass vulnerability that allows authenticated users to mint AppKeys bound to other users' MCP servers via POST /v1/appspace/app/key. Attackers supplying a victim's MCP server UUID with appType mcpserver can open MCP sessions and invoke the server's tools using the victim's upstream authentication. | ||||
| CVE-2026-108855 | 2026-10-11 | 5.4 Medium | ||
| UnicomAI Wanwu through 0.6.5 contains a missing authorization vulnerability that allows any authenticated enabled user to revoke other users' AppKeys for arbitrary apps via the unpublish endpoint. Attackers can supply a target appId and appType from the exploration marketplace to delete other users' api_key rows across organizations, cutting off MCP and OpenAPI client access. | ||||
| CVE-2026-108854 | 2026-10-11 | 5.4 Medium | ||
| Wanwu before 0.6.3 contains an insecure direct object reference vulnerability that allows any authenticated enabled user to delete other users' legacy AppKeys by supplying a numeric apiId. Attackers can iterate sequential key IDs against DELETE /v1/appspace/app/key to revoke AppKeys across organizations, breaking MCP and OpenAPI clients until owners issue new keys. | ||||
| CVE-2026-108853 | 2026-10-11 | 8.1 High | ||
| UnicomAI Wanwu before 0.6.3 contains an insecure direct object reference vulnerability that allows authenticated low-privileged users to delete other tenants' agent or RAG applications by supplying their appId. Attackers can send requests to DELETE /v1/appspace/app with guessed sequential assistant IDs to permanently delete victims' applications, workflows, conversations, and associated data. | ||||
| CVE-2026-108852 | 1 Thinkinai | 1 Deepchat | 2026-10-11 | 4.7 Medium |
| Deep Chat through 2.5.1 contains a cross-site scripting vulnerability that allows attackers to inject javascript: links because RemarkableConfig.createNew disables Remarkable link validation. Attackers can place crafted Markdown links in AI responses, addMessage content, or loaded history to execute script in the embedding page when victims click them. | ||||
| CVE-2026-108851 | 1 Phpmyfaq | 1 Phpmyfaq | 2026-10-11 | 3.3 Low |
| phpMyFAQ through 4.1.10 contains a missing authorization vulnerability in the MCP server faq_search tool that allows MCP clients to read restricted FAQs because Search::searchDatabase() never applies user or group permission checks. Attackers connected to the phpmyfaq:mcp:server can issue search queries to retrieve the full question and answer text of active FAQs restricted to specific users or groups. | ||||
| CVE-2026-108850 | 2026-10-11 | 5.3 Medium | ||
| Company Research Agent through 2.2.0 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger outbound requests by injecting unescaped ReportLab paragraph markup into the /generate-pdf endpoint. Attackers can embed inline img elements in report_content to make the server fetch internal or external hosts, leaking image responses in returned PDFs and probing reachability. | ||||
| CVE-2026-108839 | 2026-10-11 | 4.2 Medium | ||
| thClaws through 0.141.0 contains a link-following vulnerability in the post_inputs handler of the v1 API POST /v1/inputs endpoint that allows writes outside the workspace by following symlinks. Attackers who plant a symlink under the allowed inputs/ prefix can cause later authenticated uploads to write or truncate files outside the workspace with daemon privileges. | ||||