VulnSea

Server vulnerabilities

CVEs whose affected-version data names the Server package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

14 CVEsRSS

CVE-2026-77165Medium· 6.5
today

File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.

File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.

SunlitNextcloud · Servervia NVD
CVE-2026-68493Low· 3.1
3d ago

After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.

After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.

SunlitNextcloud · ServerEPSS 0.14%via NVD
CVE-2026-82985Medium· 6.5
3d ago

The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration

The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration. When an album owner shares a smart alb…

SunlitNextcloud · ServerEPSS 0.20%via NVD
CVE-2026-77164Medium· 6.2
3d ago

Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF p…

Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF p…

SunlitNextcloud · ServerEPSS 0.13%via NVD
CVE-2026-13327High· 8.3
6d ago

Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controll…

Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controll…

TwilightDevolutions · ServerEPSS 0.13%via NVD
CVE-2026-90971Medium· 6.5
6d ago

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata netwo…

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata netwo…

SunlitDevolutions · ServerEPSS 0.21%via NVD
CVE-2026-90969Medium· 6.5
6d ago

Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing end…

Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing end…

SunlitDevolutions · ServerEPSS 0.21%via NVD
CVE-2026-84850Medium· 4.8
6d ago

Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connect…

Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connect…

SunlitDevolutions · ServerEPSS 0.10%via NVD
CVE-2026-54047Critical· 9.2
1w ago

Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud

Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies …

MidnightLaciSynchroni · serverEPSS 0.23%via NVD
CVE-2026-89099High· 7.5
1w ago

A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption

A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-…

TwilightMongoDB · MongoDB ServerEPSS 0.18%via NVD
CVE-2026-87032Medium· 4.3
1w ago

Tanium addressed an information disclosure vulnerability in Tanium Server.

Tanium addressed an information disclosure vulnerability in Tanium Server.

SunlitTanium · Tanium ServerEPSS 0.18%via NVD
CVE-2026-14892Medium· 4.3
1w ago

Tanium addressed an improper access controls vulnerability in Tanium Server.

Tanium addressed an improper access controls vulnerability in Tanium Server.

SunlitTanium · Tanium ServerEPSS 0.19%via NVD
CVE-2026-13062Medium· 6.5
2mo ago

MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the m…

SunlitMongoDB · MongoDB ServerEPSS 0.19%via CVEORG
CVE-2026-13060Medium· 6.5
2mo ago

$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection Access

An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization and …

SunlitMongoDB · MongoDB ServerEPSS 0.40%via CVEORG
Server vulnerabilities (CVEs) · VulnSea