Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52613
Total
4187
Critical
15589
High
15276
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-61692 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61454. Reason: This candidate is a duplicate of CVE-2026-61454. Notes: All CVE users … | Jul 13, 2026 |
| CVE-2026-59245 | HIGH | 8.1 | In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so … | Jul 13, 2026 |
| CVE-2026-58065 | HIGH | 8.1 | The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path … | Jul 13, 2026 |
| CVE-2026-6847 | UNKNOWN | — | Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application exposes an endpoint that allows unauthenticated … | Jul 13, 2026 |
| CVE-2026-61498 | CRITICAL | 9.8 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying … | Jul 13, 2026 |
| CVE-2026-60121 | CRITICAL | 9.8 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a … | Jul 13, 2026 |
| CVE-2026-40553 | HIGH | 7.5 | Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially … | Jul 13, 2026 |
| CVE-2026-40469 | CRITICAL | 9.1 | Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and … | Jul 13, 2026 |
| CVE-2026-40468 | CRITICAL | 9.1 | Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and … | Jul 13, 2026 |
| CVE-2026-40467 | HIGH | 7.5 | Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk … | Jul 13, 2026 |
| CVE-2026-15584 | HIGH | 7.5 | A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. The tool creates privileged debug pods with host filesystem access in the shared … | Jul 13, 2026 |
| CVE-2026-15559 | MEDIUM | 6.3 | A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the file /SimpleOnlineLeave/admin/accept.php of the component POST … | Jul 13, 2026 |
| CVE-2026-62147 | MEDIUM | 6.5 | The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated … | Jul 13, 2026 |
| CVE-2026-15558 | MEDIUM | 6.3 | A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file … | Jul 13, 2026 |
| CVE-2026-12257 | UNKNOWN | — | Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located in the endpoint “/index.cfm/_api/json/v1/default”, where the … | Jul 13, 2026 |
| CVE-2026-9824 | MEDIUM | 4.3 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an … | Jul 13, 2026 |
| CVE-2026-9820 | LOW | 3.8 | Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the … | Jul 13, 2026 |
| CVE-2026-6541 | MEDIUM | 4.3 | Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an … | Jul 13, 2026 |
| CVE-2026-4765 | UNKNOWN | — | Stored Cross-Site Scripting (XSS) vulnerability in the RD Station Conversas chat. The vulnerability resides in the ‘name’ parameter of the initialization process due to improper … | Jul 13, 2026 |
| CVE-2026-14934 | UNKNOWN | — | A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May … | Jul 13, 2026 |
| CVE-2026-61985 | MEDIUM | 5.3 | Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through … | Jul 13, 2026 |
| CVE-2026-61983 | MEDIUM | 5.3 | Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through <= 5.0.30. | Jul 13, 2026 |
| CVE-2026-61977 | MEDIUM | 5.3 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a … | Jul 13, 2026 |
| CVE-2026-61976 | MEDIUM | 5.3 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks … | Jul 13, 2026 |
| CVE-2026-61975 | MEDIUM | 5.3 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a … | Jul 13, 2026 |