Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42275
Total
3446
Critical
12492
High
12441
Medium
CVE ID Severity Score Description Published
CVE-2026-82474 HIGH 7.8 Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can … Aug 29, 2026
CVE-2026-82473 HIGH 8.2 KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark … Aug 29, 2026
CVE-2026-82472 HIGH 7.5 Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF … Aug 29, 2026
CVE-2026-82470 MEDIUM 5.4 Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who … Aug 29, 2026
CVE-2026-82469 MEDIUM 5.4 Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can … Aug 29, 2026
CVE-2026-82468 MEDIUM 4.7 Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with … Aug 29, 2026
CVE-2026-82467 MEDIUM 4.7 Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading double slashes that browsers … Aug 29, 2026
CVE-2026-82466 HIGH 8.7 Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit … Aug 29, 2026
CVE-2026-82465 MEDIUM 5.3 pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.validateLogoutRequest(). When an IdP sends no SessionIndex, a session can be destroyed … Aug 29, 2026
CVE-2026-82464 MEDIUM 6.1 pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-prefixed logout redirect targets matching logoutUrlPattern. Attackers can craft logout links with backslash-prefixed … Aug 29, 2026
CVE-2026-82463 HIGH 8.1 pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and … Aug 29, 2026
CVE-2026-82462 MEDIUM 6.5 pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for … Aug 29, 2026
CVE-2026-82461 HIGH 8.1 pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens … Aug 29, 2026
CVE-2026-82460 CRITICAL 9.8 Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use … Aug 29, 2026
CVE-2026-82481 UNKNOWN The cohttp package before 6.3.0 for OCaml allows directory traversal. Aug 29, 2026
CVE-2026-82477 MEDIUM 5.8 In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. … Aug 29, 2026
CVE-2026-82457 HIGH 7.8 su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values … Aug 29, 2026
CVE-2026-82456 CRITICAL 10.0 argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can … Aug 29, 2026
CVE-2026-82455 HIGH 7.1 RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction … Aug 29, 2026
CVE-2026-82454 CRITICAL 9.1 The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' … Aug 29, 2026
CVE-2026-82453 HIGH 7.5 rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing … Aug 29, 2026
CVE-2026-82452 CRITICAL 9.8 rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, … Aug 29, 2026
CVE-2026-82451 MEDIUM 6.1 Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer … Aug 29, 2026
CVE-2026-82450 HIGH 8.8 BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions … Aug 29, 2026
CVE-2026-82449 MEDIUM 5.3 Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification. Attackers can measure response … Aug 29, 2026