Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44793
Total
3597
Critical
13314
High
13164
Medium
CVE ID Severity Score Description Published
CVE-2026-68745 UNKNOWN Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a SAML response to … Aug 21, 2026
CVE-2026-66797 MEDIUM 5.4 Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure. The addAnnotation and listAnnotation APIs perform an ownership check when an entity's … Aug 21, 2026
CVE-2026-66722 UNKNOWN Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack. A Domain Admin can create, update, delete, and … Aug 21, 2026
CVE-2026-66721 UNKNOWN Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by default, have permission to call the listHostTags API, but the … Aug 21, 2026
CVE-2026-65613 UNKNOWN Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while listing and deleting deliveries. This issue affects Apache CloudStack: from … Aug 21, 2026
CVE-2026-63046 HIGH 8.8 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell commands via ExcuteLinux.exeCmd() with no … Aug 21, 2026
CVE-2026-62440 UNKNOWN Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes. This issue … Aug 21, 2026
CVE-2026-61422 UNKNOWN Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. When registering a template or ISO, CloudStack makes a live HTTP HEAD/GET call … Aug 21, 2026
CVE-2026-61400 HIGH 8.8 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics functionality for the system VMs and … Aug 21, 2026
CVE-2026-61399 UNKNOWN Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 … Aug 21, 2026
CVE-2026-61398 UNKNOWN Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality. This issue affects Apache CloudStack: from 4.15.1.0 through … Aug 21, 2026
CVE-2026-61397 UNKNOWN Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration. This issue affects Apache CloudStack: from … Aug 21, 2026
CVE-2026-59799 UNKNOWN Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the two-factor authentication disable flow. This issue affects Apache CloudStack: from 4.18.0.0 … Aug 21, 2026
CVE-2026-59780 UNKNOWN Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP providers. LDAP configurations can be listed by … Aug 21, 2026
CVE-2026-59657 UNKNOWN Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. This issue affects Apache CloudStack: from 4.0.0 through 4.20.3.0 and … Aug 21, 2026
CVE-2026-59655 UNKNOWN Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth providers. This issue affects Apache CloudStack: from … Aug 21, 2026
CVE-2026-59085 UNKNOWN Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and … Aug 21, 2026
CVE-2026-50222 UNKNOWN Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs. Several userdata-related APIs in Apache CloudStack, including deleteUserData, … Aug 21, 2026
CVE-2026-50112 HIGH 8.8 SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage … Aug 21, 2026
CVE-2026-47359 UNKNOWN Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache CloudStack's NAS backup provider plugin. The addBackupRepository API (available … Aug 21, 2026
CVE-2026-77264 CRITICAL 9.8 The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, … Aug 21, 2026
CVE-2026-73537 MEDIUM 4.7 Cross-site scripting vulnerability exists in Miraikan Assist App. If this vulnerability is exploited, an arbitrary script may be executed in the browser component (WebView) running … Aug 21, 2026
CVE-2026-19441 MEDIUM 5.3 Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data. This issue affects Rush: through 21082026. Aug 21, 2026
CVE-2026-16323 HIGH 7.5 Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass. This issue affects ArchitectPanel Web Admin Panel: … Aug 21, 2026
CVE-2026-75796 HIGH 7.2 The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged … Aug 21, 2026