Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51943
Total
4127
Critical
15407
High
15098
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-21760 | MEDIUM | 4.6 | HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted … | Jul 17, 2026 |
| CVE-2026-16108 | MEDIUM | 4.3 | A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned … | Jul 17, 2026 |
| CVE-2026-16106 | MEDIUM | 4.9 | A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator … | Jul 17, 2026 |
| CVE-2026-16104 | MEDIUM | 4.3 | A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity … | Jul 17, 2026 |
| CVE-2026-16103 | MEDIUM | 4.3 | A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to … | Jul 17, 2026 |
| CVE-2026-16093 | MEDIUM | 5.4 | Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw … | Jul 17, 2026 |
| CVE-2026-12694 | CRITICAL | 9.1 | Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 … | Jul 17, 2026 |
| CVE-2026-12693 | CRITICAL | 9.4 | Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video … | Jul 17, 2026 |
| CVE-2026-12692 | CRITICAL | 9.8 | Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. | Jul 17, 2026 |
| CVE-2026-12691 | HIGH | 7.5 | Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. | Jul 17, 2026 |
| CVE-2026-11763 | MEDIUM | 6.5 | Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows Exploitation of Trusted … | Jul 17, 2026 |
| CVE-2026-9537 | UNKNOWN | — | Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recomputed HMAC … | Jul 17, 2026 |
| CVE-2026-63100 | MEDIUM | 6.5 | Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role users to access and modify global hosting settings by exploiting unprotected show … | Jul 17, 2026 |
| CVE-2026-63099 | MEDIUM | 6.5 | TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachments belonging to other … | Jul 17, 2026 |
| CVE-2026-63098 | MEDIUM | 5.3 | TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the … | Jul 17, 2026 |
| CVE-2026-63097 | MEDIUM | 4.3 | Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/routing/context.go) that allows authenticated local users to access post-leave room state … | Jul 17, 2026 |
| CVE-2026-63096 | MEDIUM | 5.8 | Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts … | Jul 17, 2026 |
| CVE-2026-63095 | MEDIUM | 6.5 | Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging … | Jul 17, 2026 |
| CVE-2026-60025 | UNKNOWN | — | The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection. | Jul 17, 2026 |
| CVE-2026-60024 | UNKNOWN | — | The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets. | Jul 17, 2026 |
| CVE-2026-58149 | UNKNOWN | — | The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses. | Jul 17, 2026 |
| CVE-2026-58148 | UNKNOWN | — | The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability. | Jul 17, 2026 |
| CVE-2026-15783 | UNKNOWN | — | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from … | Jul 17, 2026 |
| CVE-2026-15343 | UNKNOWN | — | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write … | Jul 17, 2026 |
| CVE-2026-15007 | UNKNOWN | — | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release … | Jul 17, 2026 |