Vulnerabilities

Summary — last 7 days

New vulnerabilities3,072▲ 552 vs. last week
Critical / high1,458▲ 273 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)383▲ 176 vs. last week
–

379 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisHigh (8.6)0.43%—Dani-garcia VaultwardenAI9/22/20269/24/2026
Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization ciphers. Attackers with revoked or pending membership can exploit missing status…
DeferredMedium (6.9)0.19%—McpvaultAIObsidianAI9/15/20269/30/2026
MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list patterns, so nested .git, .obsidian, and node_modules path segments do not match the restriction and pass both isAllowed() and…
DeferredHigh (8.4)0.20%—McpvaultAI9/15/20269/30/2026
MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, PathFilter in src/pathfilter.ts compiles restricted-directory patterns case-sensitively and compares paths without canonicalizing filesystem-equivalent segment names. On case-insensitive macOS and…
DeferredHigh (7.1)0.25%—Gallery Private Photo VaultAI9/14/20269/18/2026
Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.
DeferredMedium (5.8)0.16%—Hashicorp Vault-jsAI9/14/20269/30/2026
hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vault.js passes failed requests through parseAxiosError(), which rethrows the raw AxiosError while retaining AxiosError.config and the equivalent response configuration. These objects can contain…
AnalyzedHigh (7.7)0.58%—Commvault9/8/20269/11/2026
Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
AnalyzedHigh (8.7)0.30%—Commvault9/8/20269/9/2026
CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.
AnalyzedHigh (8.3)0.56%—Commvault9/8/20269/9/2026
CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
AnalyzedHigh (8.7)0.50%—Commvault9/8/20269/9/2026
CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
AnalyzedHigh (8.7)0.46%—Commvault9/8/20269/9/2026
CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
AnalyzedHigh (8.7)0.46%—Commvault9/8/20269/9/2026
CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
AnalyzedHigh (8.8)0.47%—Commvault9/8/20269/11/2026
Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
AnalyzedHigh (8.8)0.47%—Commvault9/8/20269/11/2026
Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
AnalyzedHigh (7.3)0.32%—Commvault9/8/20269/11/2026
Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.
AnalyzedHigh (8.5)0.18%—Commvault9/8/20269/11/2026
DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store.
AnalyzedCritical (9.3)0.61%—Commvault9/8/20269/11/2026
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
DeferredHigh (8.3)0.41%—Helicone VaultmanagerAI9/3/20269/24/2026
Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier. Attackers with admin or owner privileges in any organization can retrieve decrypted upstream provider…
DeferredHigh (7.9)0.15%—Synergis SoftwireAIStreamvault Sv-100eAIStreamvault Sv-300eAI8/28/20269/9/2026
Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows servers.
DeferredHigh (8.1)0.23%—Blogvault Backup AND StagingAIMalcare Wordpress Security PluginAITHE WP Remote WP RemoteAI8/26/20268/26/2026
The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service,…
Awaiting AnalysisMedium (6.8)0.28%—Hashicorp VaultAI8/24/20268/28/2026
A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths. An attacker who can control the referenced identity value may include slash ({{/}})…
Awaiting AnalysisCritical (9.6)0.35%—Redhat Ansible Automation PlatformAIHashicorp VaultAI8/18/20269/24/2026
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role…
DeferredLow (1.3)0.39%—Orange View Limited Dualsafe Password Manager AND Digital Vault ExtensionAI8/17/20268/20/2026
A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level…
Awaiting AnalysisCritical (9.6)0.47%—Hashicorp Vault Secrets OperatorAI8/13/20268/28/2026
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a…
AnalyzedHigh (8.8)0.39%—Commvault8/11/20269/9/2026
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.
AnalyzedCritical (9.2)0.63%—Commvault8/11/20269/11/2026
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.