12 entries matching vault — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-54053 | Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import impl | CRITICAL | 9.6 | 52%ile | NVD | 2026-09-17 |
| CVE-2026-54618 | Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authoriza | CRITICAL | 9.4 | 34%ile | NVD | 2026-09-17 |
| CVE-2026-54597 | ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi | HIGH | 8.3 | 24%ile | NVD | 2026-09-17 |
| CVE-2026-86465 | Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled | MEDIUM | 6.5 | 55%ile | NVD | 2026-09-16 |
| CVE-2026-57441 | MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, | HIGH | 8.4 | 7%ile | NVD | 2026-09-15 |
| CVE-2026-57442 | MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, | MEDIUM | 6.9 | 6%ile | NVD | 2026-09-15 |
| CVE-2026-55775 | OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities o | LOW | 2.3 | 30%ile | NVD | 2026-09-15 |
| CVE-2026-55774 | OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/l | LOW | 2.1 | 38%ile | NVD | 2026-09-15 |
| CVE-2026-90969 | Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authent | UNKNOWN | — | 4%ile | NVD | 2026-09-15 |
| CVE-2026-77884 | Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The | HIGH | 7.1 | 25%ile | NVD | 2026-09-14 |
| CVE-2026-55102 | hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src | MEDIUM | 5.8 | 2%ile | NVD | 2026-09-14 |
| CVE-2026-62825 | Azure Key Vault Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 52%ile | Microsoft | 2026-07-14 |