-Infinity
0

nanocoai NanoClawnanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization

Risk 46
Severity
6.3
First published (updated )

Zephyr Project Zephyr OSSMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot

Risk 54
Severity
6.5
First published (updated )

ImageMagick ImageMagickImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options

Risk 22
Severity
4.8
First published (updated )

Yoast Yoast SEO – Advanced SEO with real-time guidance and built-in AIYoast SEO <= 28.0 - Authenticated (Author+) Stored Cross-Site Scripting via Post Slug (post_name)

Risk 39
Severity
6.4
First published (updated )

WooCommerce Checkout Field Editor for WooCommerce (Pro)Checkout Field Editor for WooCommerce (Pro) <= 3.7.7 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read via 'thwcfe_legacy_file' Parameter

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/@frontmcp/adaptersSSRF

Risk 35
Severity
5.9
First published (updated )

go/github.com/getkin/kin-openapiNull Pointer Dereference

Risk 27
Severity
5.3
First published (updated )

npm/quasar### Summary `quasar@2.20.1`, the latest published version at the time of testing, appears to be vul…

Risk 42
Severity
5.6
First published (updated )

go/github.com/jandedobbeleer/oh-my-posh### Summary Oh My Posh renders dynamic, potentially attacker-controlled strings (the current directo…

Risk 43
Severity
6.1
First published (updated )

go/github.com/OpenListTeam/OpenList/v4### Summary An authorization bypass vulnerability exists in the file sharing mechanism of `Openlist`…

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/OpenListTeam/OpenList/v4Infoleak

Risk 22
Severity
4.3
First published (updated )

Gnome libsoupLibsoup: libsoup: proxy credentials leak to destination server via proxy-authorization header in connect tunnels

Risk 37
Severity
6.5
First published (updated )

Gnome libsoupLibsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream_read_until()

Risk 40
Severity
6.5
First published (updated )

libsoupLibsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked()

Risk 35
Severity
5.4
First published (updated )

Gnome libsoupAfter a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-…

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Gnome libsoupAn unsigned integer underflow in soup_filter_input_stream_read_until() in libsoup/soup-filter-input-…

Risk 19
Severity
4
First published (updated )

swift/swift-nio-http2## Summary SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, S…

Risk 27
Severity
5.3
First published (updated )

go/github.com/cloudreve/Cloudreve/v3SSRF

Risk 34
Severity
5.4
First published (updated )

go/github.com/zxh326/kitePath Traversal

Risk 38
Severity
6.5
First published (updated )

npm/@budibase/server## Summary The login lockout mechanism in Budibase creates an observable response discrepancy that …

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Tycon Systems TPDIN-Monitor-WEB2Tycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Sensitive Information

Risk 26
Severity
5.3
First published (updated )

npm/@budibase/serverInfoleak

Risk 33
Severity
5.7
First published (updated )

go/github.com/cloudreve/Cloudreve/v3## Summary Cloudreve WOPI access tokens are generated as `<session-id>.<random-secret>`, but the WO…

Risk 43
Severity
6.3
First published (updated )

go/github.com/cloudreve/Cloudreve/v3## Summary Cloudreve WOPI access tokens are generated as `<session-id>.<random-secret>`, but the WO…

Risk 43
Severity
6.3
First published (updated )

npm/@budibase/serverInfoleak

Risk 30
Severity
4.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/@budibase/server## Summary The `GET /api/global/groups` endpoint on the worker service has no role-based authorizat…

Risk 22
Severity
4.3
First published (updated )

maven/org.openidentityplatform.openam:openam-oauth2XSS, CSRF

Risk 38
Severity
6.1
First published (updated )

maven/org.openidentityplatform.openam:openam-oauth2XSS, CSRF

Risk 38
Severity
6.1
First published (updated )

pip/open-webui## Summary An authenticated non-admin user with read access to an arena wrapper model can reach a r…

Risk 34
Severity
5.4
First published (updated )

pip/open-webui## Summary Current `main` and `v0.9.6` still allow an authenticated user to turn read-only access t…

Risk 34
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203