U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-47427 - GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, so a completion/complete request with a missing or empty ref f... read CVE-2026-47427
    Published: July 28, 2026; 12:18:14 PM -0400

  • CVE-2026-41186 - When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listener can ret... read CVE-2026-41186
    Published: July 30, 2026; 11:16:31 AM -0400

    V3.1: 7.5 HIGH

  • CVE-2026-41187 - Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A us... read CVE-2026-41187
    Published: July 30, 2026; 11:16:31 AM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2026-6540 - Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not co... read CVE-2026-6540
    Published: July 30, 2026; 11:16:37 AM -0400

    V3.1: 7.5 HIGH

  • CVE-2026-71559 - Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue aff... read CVE-2026-71559
    Published: August 07, 2026; 6:16:59 AM -0400

  • CVE-2026-71558 - Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserializat... read CVE-2026-71558
    Published: August 07, 2026; 6:16:59 AM -0400

  • CVE-2026-71560 - Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-b... read CVE-2026-71560
    Published: August 07, 2026; 6:16:59 AM -0400

  • CVE-2026-56793 - Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
    Published: August 07, 2026; 9:16:52 AM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2026-56794 - Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
    Published: August 07, 2026; 9:16:52 AM -0400

  • CVE-2026-10050 - In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-... read CVE-2026-10050
    Published: August 04, 2026; 7:22:43 AM -0400

    V3.1: 9.1 CRITICAL

  • CVE-2026-14537 - Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests... read CVE-2026-14537
    Published: July 30, 2026; 10:16:27 PM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2026-14538 - An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The t... read CVE-2026-14538
    Published: July 30, 2026; 10:16:28 PM -0400

    V3.1: 7.7 HIGH

  • CVE-2026-14539 - An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads i... read CVE-2026-14539
    Published: July 30, 2026; 10:16:28 PM -0400

    V3.1: 7.5 HIGH

  • CVE-2026-14540 - A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, t... read CVE-2026-14540
    Published: July 30, 2026; 10:16:29 PM -0400

    V3.1: 6.1 MEDIUM

  • CVE-2026-14541 - An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audienc... read CVE-2026-14541
    Published: July 30, 2026; 11:16:24 PM -0400

    V3.1: 7.5 HIGH

  • CVE-2026-60773 - Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network acc... read CVE-2026-60773
    Published: July 21, 2026; 6:18:16 PM -0400

  • CVE-2026-60671 - Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unaut... read CVE-2026-60671
    Published: July 21, 2026; 6:18:08 PM -0400

  • CVE-2026-60674 - Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unaut... read CVE-2026-60674
    Published: July 21, 2026; 6:18:08 PM -0400

  • CVE-2026-60678 - Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network ... read CVE-2026-60678
    Published: July 21, 2026; 6:18:08 PM -0400

  • CVE-2026-60772 - Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with... read CVE-2026-60772
    Published: July 21, 2026; 6:18:16 PM -0400

Created September 20, 2022 , Updated August 27, 2024