Common Vulnerabilities and Exposures (CVE)

CVE-2026-77549

Aug 26, 2026 10:30:06 UTC

A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices o...

CVE-2026-80206

Aug 26, 2026 10:28:15 UTC

NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles user-supplied regular expressions embedded in /regex/ pattern nodes and executes them via...

CVE-2026-80205

Aug 26, 2026 10:28:14 UTC

NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.findall() methods that accept user-supplied regular expressions without validation or timeout. Attackers can supply...

CVE-2026-80204

Aug 26, 2026 10:28:13 UTC

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not apply the API-key scope cap in the injectSecurityTab() function of BlueprintController when deciding whether a page's security/permissions blueprint section is editable. B...

CVE-2026-80203

Aug 26, 2026 10:28:12 UTC

The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() on the acting acc...

CVE-2026-77548

Aug 26, 2026 10:23:37 UTC

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.

CVE-2026-77547

Aug 26, 2026 10:20:14 UTC

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.

CVE-2026-77546

Aug 26, 2026 10:16:47 UTC

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.

CVE-2026-77545

Aug 26, 2026 10:13:43 UTC

A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or inst...

CVE-2026-80350

Aug 26, 2026 10:09:50 UTC

OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms, but has no case for the IPv4-mapped IPv6 range. The webhook delivery path calls SSRFProtection.validateWebhookTargetIs...

CVE-2026-80349

Aug 26, 2026 10:09:49 UTC

TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's proxy option to true without naming which upstream proxies may be trusted and without limiting the number of forwarded h...

CVE-2026-80348

Aug 26, 2026 10:09:48 UTC

TarsWeb enforces its per-application roles by calling AuthService from individual controller methods, and four methods in app/controller/patch/PatchController.js make no such call. uploadAndPublish accepts a package upload and then builds a...

CVE-2026-80347

Aug 26, 2026 10:09:47 UTC

mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround an IPv6 literal. isSafeUrl reads the hostname from the parsed URL, which for a literal such as http://[::1]/ yields the bracketed string, and...

CVE-2026-80346

Aug 26, 2026 10:09:47 UTC

StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every other statement type routed through AuthorizerStmtVisitor calls into Authorizer before execution, but visitDropMaterializedViewStatement ret...

CVE-2026-77543

Aug 26, 2026 10:07:54 UTC

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.