s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

229688 CVEs matched. Showing 2301–2350 (page 47 of 4594).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID ↕ Title ↕ Severity ↕ Score (overview) ↕ NVD Score MSRC Score CNA ↕ Published ↕ Remediations Threat Source
CVE-2026-55210 Joplin: SAML SSO account takeover via email-based account linking (missing is_external check in ssoLogin) HIGH 7.4 7.4 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-61652 Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unb… HIGH 8.7 — — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-59814 Joplin: Stored XSS via inline-served note attachment on published shares HIGH 7.6 7.6 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-61647 @roomi-fields/notebooklm-mcp has path traversal in vault.batch tool that allows arbitrary file write outside intended va… HIGH 7.1 — — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-55105 Joplin: Fountain embeds allow arbitrary script execution in published notes and the note viewer HIGH 7.7 7.7 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-46649 Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected Endpoint CRITICAL 9.1 — — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-55179 Joplin: Logic error in Joplin Server allows a signed-in user to read any note from its internal server ID MEDIUM 6.5 6.5 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-59816 Joplin: Path traversal in transcribe proxy endpoint via URL-encoded slash MEDIUM 4.3 4.3 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-49449 Joplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft via UNC path on Windows LOW 2.5 2.5 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-49453 Joplin: Path traversal in resource sync — silent arbitrary file write outside the resource directory HIGH 7.0 7.0 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-49450 Joplin desktop Windows auto-updater accepts signed installer from any publisher because app-update.yml has no publisherN… HIGH 7.1 7.1 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-79919 MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RT… MEDIUM 6.3 6.3 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-79918 MaxKB: Sandbox escape via unhooked fexecve MEDIUM 6.3 6.3 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-94588 CVE-2026-94588 MEDIUM 4.4 4.4 — mitre 2026-09-21 10 — raw · ⬇
CVE-2026-77517 MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in another knowledge base MEDIUM 5.4 5.4 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-77521 MaxKB: Prompt-injectable agent can lead to command execution CRITICAL 10.0 10.0 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-94424 Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140001000 heap-based overflow CRITICAL 9.3 8.8 — VulDB 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-77522 MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no inter… MEDIUM 4.3 4.3 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-79917 MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation MEDIUM 6.5 6.5 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-77516 MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path MEDIUM 5.4 5.4 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-77523 MaxKB: Cross-workspace model parameter form write HIGH 7.4 7.4 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-77525 MaxKB: Management chat-record routes trust path application_id but load ChatRecord by global chat_id MEDIUM 4.2 4.2 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-77518 MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflows MEDIUM 5.0 5.0 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-79916 MaxKB AWS Bedrock model credential injection leads to remote code execution CRITICAL 9.1 9.1 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-58272 Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the pri… MEDIUM 5.3 5.3 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-58270 Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters` MEDIUM 6.5 6.5 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-77520 MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to invoke another user's applicati… MEDIUM 5.4 5.4 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-77519 MaxKB: Expired application API keys remain usable on `/chat/api/mcp` MEDIUM 5.4 5.4 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-73511 Envoy: Potential path-matching/authentication bypass when using Envoy in combination with a backend stripping per-segmen… MEDIUM 5.3 5.3 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-73553 Envoy: RBAC Authorization Bypass via Path Parameters HIGH 7.5 7.5 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-73551 Envoy: Path normalization does not handle dot and dotdot segments with parameters MEDIUM 5.3 5.3 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-94572 CVE-2026-94572 CRITICAL 9.4 — — mitre 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-93433 Libstoragemgmt: libstoragemgmt: denial of service via stack buffer overflow in scsi vpd page parsing MEDIUM 5.5 5.5 — redhat 2026-09-21 10 — raw · ⬇
CVE-2026-94571 CVE-2026-94571 CRITICAL 9.4 — — mitre 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-58269 Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token` HIGH 8.1 8.1 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-73546 Envoy: Stored XSS in Admin Stats Interface (/stats?format=html) HIGH 7.4 7.4 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-73512 Envoy: use-after-free in QUIC on internal redirects HIGH 7.5 7.5 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-58271 @sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register` MEDIUM 6.8 6.8 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-73550 Envoy: HTTP/2 Discarded Host Header 200 GB Header-Copy OOM in Envoy HIGH 7.5 7.5 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-73547 Envoy ext_authz: request `:path` pseudoheader dereferenced w/o null check HIGH 7.5 7.5 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-48521 Envoy: HTTP/3 connection pool selection null-derefs in ProdClusterManagerFactory::allocateConnPool when transport_socket… MEDIUM 5.9 5.9 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-73549 Envoy - Incomplete fix for CVE-2026-26310: copyInternetAddressAndPort crashes on scoped IPv6 addresses in ORIGINAL_DST c… MEDIUM 5.3 5.3 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-73513 Envoy: oghttp2 upstream trailers incorrect handling HIGH 7.5 7.5 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-85219 Denial-of-Service in the OpenCanary Redis service LOW 3.7 3.7 — ThinkstAppliedResearch 2026-09-21 10 — raw · ⬇
CVE-2026-49811 CVE-2026-49811 HIGH 8.4 8.4 — dell 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-73552 Envoy: HTTP RBAC safe_regex can fail open on RFC-valid obs-text header values HIGH 7.5 7.5 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-73548 Envoy: Cross-user response poisoning via a generic (non-WebSocket) HTTP upgrade on Envoy's shared backend pool HIGH 7.5 7.5 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-50572 Envoy: ext_authz - RawHttpClientImpl onSuccess 0x0 segfault MEDIUM 5.9 5.9 — GitHub_M 2026-09-21 10 — raw · ⬇
CVE-2026-55897 luci-app-advanced-reboot read ACL exposes /bin/sh through file.exec, allowing delegated users to run commands as root HIGH 8.8 8.8 — GitHub_M 2026-09-21 10 ⚠ Threat raw · ⬇
CVE-2026-81469 CVE-2026-81469 HIGH 7.8 7.8 — dell 2026-09-21 10 ⚠ Threat raw · ⬇