Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43590
Total
3522
Critical
13030
High
12889
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2022-51003 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 27, 2026 |
| CVE-2022-51002 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 27, 2026 |
| CVE-2022-51001 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 27, 2026 |
| CVE-2021-48005 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 27, 2026 |
| CVE-2021-48004 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 27, 2026 |
| CVE-2021-48003 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 27, 2026 |
| CVE-2021-48002 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 27, 2026 |
| CVE-2021-48001 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 27, 2026 |
| CVE-2021-48000 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 27, 2026 |
| CVE-2021-47999 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 27, 2026 |
| CVE-2021-47998 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 27, 2026 |
| CVE-2021-47997 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 27, 2026 |
| CVE-2026-81814 | UNKNOWN | — | Affected versions of Flowintel render calendar event titles using innerHTML. Because those titles are derived from case titles, a user able to create or modify … | Aug 27, 2026 |
| CVE-2026-81753 | UNKNOWN | — | Affected versions of Flowintel render Mermaid blocks contained in stored case notes without sufficiently neutralizing attacker-controlled markup. Because Mermaid note content is persisted and later … | Aug 27, 2026 |
| CVE-2026-81743 | UNKNOWN | — | Affected versions of Flowintel allow the LOG_FILE configuration value to be modified through system settings without restricting it to a filename inside the intended log … | Aug 27, 2026 |
| CVE-2026-81677 | UNKNOWN | — | The ‘/ws/apiprensa/getVideo’ endpoint is vulnerable to SQL injection due to improper validation of the GET parameter `id_ambito`. An attacker can inject SQL syntax that breaks … | Aug 27, 2026 |
| CVE-2026-81676 | UNKNOWN | — | A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the `limit_videos` parameter is directly concatenated into a MariaDB SQL query without proper sanitization or parameterization. By injecting … | Aug 27, 2026 |
| CVE-2026-81675 | UNKNOWN | — | The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter. The parameter is directly embedded in a complex SQL query that includes grouping … | Aug 27, 2026 |
| CVE-2026-81674 | UNKNOWN | — | The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized input is directly incorporated into a MariaDB query, allowing attackers to inject … | Aug 27, 2026 |
| CVE-2026-81673 | UNKNOWN | — | The ‘/ws/apitribuna/setVisita’ endpoint is vulnerable to SQL injection through the id_video and id_ambito parameters. The application does not validate or sanitize these inputs before including … | Aug 27, 2026 |
| CVE-2026-81672 | UNKNOWN | — | SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video parameter. The application does not sanitize input before constructing SQL queries, … | Aug 27, 2026 |
| CVE-2026-81668 | MEDIUM | 5.4 | A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An … | Aug 27, 2026 |
| CVE-2026-81662 | UNKNOWN | — | Affected versions of Flowintel improperly trust configuration keys supplied to the alerts settings update endpoint. While configuration values were normalized to Python literals, the corresponding … | Aug 27, 2026 |
| CVE-2026-81659 | UNKNOWN | — | Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local … | Aug 27, 2026 |
| CVE-2026-81658 | MEDIUM | 6.5 | A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged … | Aug 27, 2026 |