- CVE-2026-54617 CRITICAL CVSS 9.8 -
NVD: GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. NVD: Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274. NVD: FileServerHandler.channelRead0 in components/launchserver/src/main/java/pro/gravit/launchserver/socket/handlers/fileserver/FileServerHandler.java strips the first request-target character and resolves the remaining path against updatesDir without...
An attacker may be able to reach files outside the intended application path; CVSS 9.8 (CRITICAL); EPSS percentile 64; sources: NVD, OSV.
- CVE-2026-47252 CRITICAL CVSS 9.0 -
NVD: Anyquery is an SQL query engine built on top of SQLite. NVD: Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-system commands because the Chrome plugin and equivalent Brave, Edge, and Safari variants interpolate a SQL-controlled URL into AppleScript... NVD: In plugins/chrome/tabs.go, tabsTable.Insert() passes the URL through fmt.Sprintf(newTabScript, url), and tabsTable.Update() uses fmt.Sprintf(setURLScript, pk, url).
An attacker may be able to run code or commands on affected systems; CVSS 9.0 (CRITICAL); EPSS percentile 51; sources: NVD, OSV.
- CVE-2026-54504 HIGH CVSS 8.8 -
NVD: MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. NVD: From 1.13.0 until 1.13.1, the automatically started Web UI in src/server.ts calls startWebServer in src/web-server.ts with START_WEB_UI enabled by default and WEB_PORT set to 3080. NVD: startWebServer uses app.listen(PORT) without a host, which binds the unauthenticated document-management API to all interfaces rather than localhost.
An attacker may be able to run code or commands on affected systems; CVSS 8.8 (HIGH); EPSS percentile 45; sources: NVD, OSV.
- CVE-2026-54239 HIGH CVSS 8.8 -
NVD: Faust.js is a headless WordPress toolkit. NVD: Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and excludes the 16-byte initialization vector from the HMAC in WPE\FaustWP\Auth\encrypt() and WPE\FaustWP\Auth\decrypt() in... NVD: A logged-in non-administrator who obtains an authorization code from GET /generate can modify the unauthenticated initialization vector so that CBC decryption changes the token type and user identifier while the HMAC remains valid.
An attacker may be able to run code or commands on affected systems; CVSS 8.8 (HIGH); EPSS percentile 23; sources: NVD, OSV.
- CVE-2026-54571 HIGH CVSS 8.7 -
NVD: ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. NVD: Prior to 3.11.1, the multipart/form-data parser in src/WebRequest.cpp stores _boundaryPosition as an 8-bit value while _parseMultipartPostByte processes the boundary. NVD: A remote request containing an exactly 256-byte multipart boundary wraps _boundaryPosition from 255 to zero, prevents the boundary parsing loop from terminating, consumes excessive CPU, and triggers a FreeRTOS watchdog reset on affected ESP32 or ESP8266...
The affected service may become unavailable or unreliable; CVSS 8.7 (HIGH); EPSS percentile 42; sources: NVD, OSV.
- CVE-2026-19477 HIGH CVSS 8.6 -
NVD: There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq). NVD: This may result in information disclosure or arbitrary code execution. NVD: This vulnerability affects MCC Universal Library for Linux (uldaq) v1.2.1 and prior versions.
An attacker may be able to access information that should not be exposed; CVSS 8.6 (HIGH); EPSS percentile 2; sources: NVD.
- CVE-2026-55062 HIGH CVSS 8.4 -
NVD: uniget is a universal installer and updater for (container) tools. NVD: Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory components to escape that directory. NVD: The resulting path is passed to the configured editor, which can access or modify files outside the hooks directory with the privileges of the uniget process account.
An attacker may be able to reach files outside the intended application path; CVSS 8.4 (HIGH); EPSS percentile 8; sources: NVD, OSV.
- CVE-2026-54451 HIGH CVSS 8.2 -
NVD: Elixir protobuf is a pure Elixir implementation of Google Protobuf. NVD: From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains a self-referential or cyclic message type. NVD: In lib/protobuf/decoder.ex, Protobuf.Decoder.value_for_field/3 handles an embedded?: true field by recursively entering the decode / build_message / handle_value / value_for_field call chain without enforcing a nesting-depth limit.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.2 (HIGH); EPSS percentile 42; sources: NVD, OSV.
- CVE-2026-54253 HIGH CVSS 8.2 -
NVD: TS3 Manager is modern web interface for maintaining Teamspeak3 servers. NVD: Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled port query parameter to socket.connect(port, host) and returns the resulting error.message through res.status(400).send(error.message) as text/html... NVD: When a logged-in operator follows a crafted top-level link, the reflected value executes in the manager origin.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · user interaction required; CVSS 8.2 (HIGH); EPSS percentile 18; sources: NVD, OSV.
- CVE-2026-92230 HIGH CVSS 7.5 -
NVD: Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. NVD: Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or feature install, update, or refresh operations can leave successive bundle ClassLoader's pinned in memory and unreachable for garbage collection, leading to unbounded...
The affected service may become unavailable or unreliable; CVSS 7.5 (HIGH); EPSS percentile 39; sources: NVD.
- CVE-2026-90997 HIGH CVSS 7.4 -
NVD: A flaw was found in Keycloak. NVD: When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. NVD: This vulnerability enables an attacker who intercepts single-use security artifacts, such as JWT client assertions, DPoP proofs, or one-time password (TOTP) codes, to replay them.
An attacker may access resources that should require stronger authorization; CVSS 7.4 (HIGH); EPSS percentile 31; sources: NVD.
- CVE-2026-52727 HIGH CVSS 7.2 -
NVD: lxc-ci contains continuous integration and image-build scripts for LXC. NVD: Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman local-signing private key in /etc/pacman.d/gnupg and redistribute it to every container or virtual machine created from that image. NVD: An attacker who controls an HTTP package mirror or can intercept mirror traffic can use the shared pacman signing private key to sign modified packages that affected clients accept as trusted.
An attacker may gain root or administrative-level privileges on affected systems; CVSS 7.2 (HIGH); EPSS percentile 46; sources: NVD, OSV.
- CVE-2026-54524 HIGH CVSS 7.1 -
NVD: Frappe HR is an open-source human resources management solution (HRMS). NVD: Prior to 16.7.0, an authenticated user with the HR User role can inject SQL through filters in the Salary Payments Based on Payment Mode report. NVD: In hrms/payroll/report/salary_payments_based_on_payment_mode/salary_payments_based_on_payment_mode.py, get_conditions constructs filter clauses from user-controlled values and get_data incorporates those clauses into a string-formatted SQL query, allowing...
An attacker may be able to read or change database-backed application data; CVSS 7.1 (HIGH); EPSS percentile 39; sources: NVD, OSV.
- CVE-2026-52851 HIGH CVSS 7.1 -
NVD: Traccar is an open source GPS tracking system. NVD: Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair can submit DELETE /api/permissions with an extra attacker-controlled JSON key. NVD: Permission(LinkedHashMap<String, Long>) in src/main/java/org/traccar/model/Permission.java validates only the first two keys, but DatabaseStorage.removePermission() in src/main/java/org/traccar/storage/DatabaseStorage.java concatenates every map key into the...
An attacker may be able to read or change database-backed application data; CVSS 7.1 (HIGH); EPSS percentile 30; sources: NVD, OSV.
- CVE-2026-45720 HIGH CVSS 7.0 -
NVD: Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. NVD: Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks SAMLAssertion.Used and marks it used in separate state operations. NVD: Concurrent requests carrying the same captured saml-session token can each observe the assertion as unused and obtain authentication as the victim before either update is visible.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.0 (HIGH); EPSS percentile 3; sources: NVD, OSV.
- CVE-2026-52852 MEDIUM CVSS 6.5 -
NVD: Traccar is an open source GPS tracking system. NVD: Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create a cyclic group-parent hierarchy and request a trips or stops report for a device in that hierarchy. NVD: org.traccar.api.resource.GroupResource permits the parent cycle, while org.traccar.helper.model.AttributeUtil.lookup follows group parents without cycle detection, a visited set, or a depth limit.
The affected service may become unavailable or unreliable; CVSS 6.5 (MEDIUM); EPSS percentile 42; sources: NVD, OSV.
- CVE-2026-54649 LOW CVSS 2.1 -
NVD: punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. NVD: Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops the added Reply-To header intended to route responses through the relay. NVD: When a correspondent sends mail to an alias and the operator replies, the mail client can send directly to the correspondent from the private FORWARD_TO inbox address, exposing that address.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review; CVSS 2.1 (LOW); EPSS percentile 56; sources: NVD, OSV.
- CVE-2026-92992 LOW CVSS 2.1 -
NVD: A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. NVD: The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. NVD: The manipulation leads to missing authorization.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.1 (LOW); EPSS percentile 31; sources: NVD, OSV.
- CVE-2026-55061 LOW CVSS 1.0 -
NVD: uniget is a universal installer and updater for (container) tools. NVD: Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go parses UNIGET_EDITOR or EDITOR with strings.Split(editor, " ") and passes every space-delimited suffix as an argument to the selected editor executable. NVD: An attacker who can influence the editor environment and cause hook editing can supply unexpected editor arguments, potentially causing unintended actions with the privileges of the uniget process account.
An attacker may be able to run unintended system commands through the affected component; CVSS 1.0 (LOW); EPSS percentile 4; sources: NVD, OSV.
- CVE-2026-49292 NONE CVSS 0.0 -
NVD: Kiwi TCMS is an open source test management system. NVD: Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migrate. NVD: The migration command is reentrant, so repeated access reports that no migrations are available and does not cause data loss, alter application state, reveal confidential information, or produce a documented availability impact.
This none severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 0.0 (NONE); EPSS percentile 35; sources: NVD, OSV.