Vulnerabilities
Summary — last 7 days
New vulnerabilities2,761▲ 5 vs. last week
Critical / high1,274▼ 254 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)245▲ 227 vs. last week
403,663 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Undergoing Analysis | Medium (4.7) | 0.09% | — | SssdAI | 10/5/2026 | 10/6/2026 | A flaw was found in SSSD. A use-after-free vulnerability exists in the Kerberos Credential Manager (KCM) responder during Kerberos ticket-granting ticket (TGT) renewal, where a deferred callback accesses memory that has already been released. An authenticated local user with a renewable Kerberos ticket can trigger… | |
| Undergoing Analysis | Medium (5.4) | 0.19% | — | SssdAI | 10/5/2026 | 10/7/2026 | A flaw was found in SSSD. When configured to enforce account expiration using LDAP (Lightweight Directory Access Protocol) shadow attributes, SSSD fails to treat an expiration value of zero as an expired account. A user with valid credentials for an expired account can exploit this flaw to bypass access controls and… | |
| Undergoing Analysis | Medium (5.5) | 0.10% | — | SssdAI | 10/5/2026 | 10/6/2026 | A flaw was found in SSSD. An unprivileged local user can repeatedly request master automount map updates through the autofs responder due to missing authorization checks. This triggers global cache invalidation and forces repeated lookups to backend directory providers, leading to a Denial of Service (DoS) from… | |
| Undergoing Analysis | Medium (5.5) | 0.10% | — | SssdAI | 10/5/2026 | 10/6/2026 | A flaw was found in SSSD. In configurations where the autofs responder service is enabled, memory allocated during successful request processing is not released until the client connection terminates. A local attacker can exploit this vulnerability by maintaining an open connection and repeatedly submitting valid… | |
| Deferred | Critical (9.8) | 0.67% | — | Viewsonic ViewboardAI | 10/5/2026 | 10/6/2026 | There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints | |
| Deferred | High (7.5) | 0.46% | — | Viewsonic ViewboardAI | 10/5/2026 | 10/6/2026 | There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation via serving a malicious APK URL through an unauthenticated download endpoint | |
| Deferred | High (8.5) | 0.29% | — | JoplinAI | 10/5/2026 | 10/6/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, packages/server/src/models/ApplicationModel.ts accepts a caller-chosen application authorization identifier, applications/:id/confirm binds that identifier to a logged-in user through a generic… | |
| Deferred | Medium (4.8) | 0.19% | — | Joplin ServerAI | 10/5/2026 | 10/8/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation, email-change, and password-reset tokens without a purpose, and packages/server/src/models/UserModel.ts… | |
| Deferred | Medium (4.6) | 0.20% | — | JoplinAI | 10/5/2026 | 10/6/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, selecting a note containing a jsoncanvas fence causes the whiteboard text and file-node components in packages/app-desktop/gui/NoteEditor/NoteBody/WhiteboardEditor/nodes/TextNode.tsx and… | |
| Deferred | High (8) | 0.14% | — | JoplinAI | 10/5/2026 | 10/6/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, when Joplin Desktop is running with the opt-in Web Clipper server enabled, the server in packages/lib/ClipperServer.ts sends Access-Control-Allow-Origin: * and allows an arbitrary website to call… | |
| Awaiting Analysis | High (7.5) | 0.38% | — | ScrapyAI | 10/5/2026 | 10/6/2026 | Scrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, RefererMiddleware in scrapy/spidermiddlewares/referer.py treated a Referrer-Policy response-header value that resembled a Python import path as a referrer policy class, imported the referenced object, and called it. A… | |
| Deferred | High (7.7) | 0.27% | — | Futo ImmichAI | 10/5/2026 | 10/6/2026 | Immich is a high-performance self-hosted photo and video management solution. Prior to 3.2.4, an authenticated non-admin user could upload SVG files that thumbnail-generation code in server/src/repositories/media.repository.ts passed to libvips. Files that bypassed libvips' native SVG loader fell through to… | |
| Deferred | Critical (9.6) | 0.28% | — | TwentyAI | 10/5/2026 | 10/8/2026 | Twenty is an open-source CRM (customer relationship management) platform. From 1.20.10 until 2.7.0, the /metadata GraphQL connectedAccounts query returned connectionParameters from ConnectedAccountDTO for every connected account in a workspace, including plaintext IMAP, SMTP, and CalDAV passwords, because the field… | |
| Deferred | High (8.3) | 0.34% | — | DifyAI | 10/5/2026 | 10/6/2026 | Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remote_files.py accepted an attacker-controlled URL without authentication and caused the Dify server to retrieve it. A remote attacker could use the endpoint to send requests to… | |
| Deferred | Medium (5.5) | 0.26% | — | Anisha Online Appointment Booking SystemAI | 10/5/2026 | 10/6/2026 | A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. Impacted is an unknown function of the file signup.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. The attack can be executed… | |
| Deferred | High (7.1) | 0.25% | — | DifyAI | 10/5/2026 | 10/6/2026 | Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT /console/api/apps/<app_id>/server endpoint in api/controllers/console/app/mcp_server.py used AppMCPServerController.put() to retrieve an AppMCPServer by the client-supplied server ID without verifying that the server belonged to the… | |
| Undergoing Analysis | Medium (5.3) | 0.30% | — | VllmAI | 10/5/2026 | 10/6/2026 | vLLM is an inference and serving engine for large language models. Prior to 0.30.0, a caller can use the request-level media_io_kwargs field to select the GLMGA video backend and supply large values for the fps and max_frames options without a strict work ceiling. GLMGA constructs and deduplicates an attacker-sized… | |
| Undergoing Analysis | Medium (5.9) | 0.33% | — | VllmAI | 10/5/2026 | 10/6/2026 | vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the Rust frontend's track_http_metrics middleware records the raw HTTP method token as a Prometheus label for requests reaching registered routes. An unauthenticated attacker can send unique arbitrary method tokens to unguarded routes… | |
| Analyzed | Medium (5.3) | 0.30% | — | Vllm | 10/5/2026 | 10/8/2026 | vLLM is an inference and serving engine for large language models. From 0.24.0 until 0.30.0, the Qwen2VLVideoBackend and Qwen3VLVideoBackend classes accept request-level values for the media_io_kwargs.video.max_frames and media_io_kwargs.video.fps fields without enforcing server-side ceilings. An unauthenticated… | |
| Analyzed | Medium (6.5) | 0.31% | — | Vllm | 10/5/2026 | 10/7/2026 | vLLM is an inference and serving engine for large language models. Prior to 0.30.0, structured-output request failures can escape request-scoped validation and reach the EngineCore fatal-error path. A per-request backend mismatch can re-raise a grammar compilation exception, padding produced by the ngram_gpu… | |
| Analyzed | Medium (6.5) | 0.31% | — | Vllm | 10/5/2026 | 10/7/2026 | vLLM is an inference and serving engine for large language models. Prior to 0.30.0, OpenAI-compatible request models accept a non-empty cache_salt value without enforcing the character and length restrictions required by the IPCCacheServerKey consumer in LMCache-MP. On deployments using the LMCache-MP connector, a… | |
| Analyzed | Medium (4.2) | 0.20% | — | Vllm | 10/5/2026 | 10/7/2026 | vLLM is an inference and serving engine for large language models. Prior to 0.30.0, flash late-interaction scoring at the /score and /rerank endpoints derives each worker's query_key value from the caller-controlled X-Request-Id header. A concurrent request that reuses a victim's identifier can overwrite the cached… | |
| Analyzed | Medium (6.5) | 0.27% | — | Vllm | 10/5/2026 | 10/8/2026 | vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the /inference/v1/generate endpoint in the disaggregated scale-out path accepts caller-supplied tensors in the features.kwargs_data field, cache identifiers in the features.mm_hashes field, ranges in the features.mm_placeholders field,… | |
| Analyzed | Medium (6.5) | 0.43% | — | Vllm | 10/5/2026 | 10/7/2026 | vLLM is an inference and serving engine for large language models. Prior to 0.28.0, the default mirrored multimodal LRU cache can commit a media hash in the frontend sender cache during multimodal rendering and before engine admission, while the engine receiver cache never receives the payload if that request is… | |
| Analyzed | Low (3.1) | 0.22% | — | Vllm | 10/5/2026 | 10/7/2026 | vLLM is an inference and serving engine for large language models. Prior to 0.30.0, Harmony tool continuations submitted through "POST /v1/responses" requests rebuild the next-turn engine input without preserving the cache_salt value, placing the continuation prefix in the global unsalted cache namespace even when the… |