Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44793
Total
3597
Critical
13314
High
13164
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-68745 | UNKNOWN | — | Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a SAML response to … | Aug 21, 2026 |
| CVE-2026-66797 | MEDIUM | 5.4 | Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure. The addAnnotation and listAnnotation APIs perform an ownership check when an entity's … | Aug 21, 2026 |
| CVE-2026-66722 | UNKNOWN | — | Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack. A Domain Admin can create, update, delete, and … | Aug 21, 2026 |
| CVE-2026-66721 | UNKNOWN | — | Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by default, have permission to call the listHostTags API, but the … | Aug 21, 2026 |
| CVE-2026-65613 | UNKNOWN | — | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while listing and deleting deliveries. This issue affects Apache CloudStack: from … | Aug 21, 2026 |
| CVE-2026-63046 | HIGH | 8.8 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell commands via ExcuteLinux.exeCmd() with no … | Aug 21, 2026 |
| CVE-2026-62440 | UNKNOWN | — | Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes. This issue … | Aug 21, 2026 |
| CVE-2026-61422 | UNKNOWN | — | Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. When registering a template or ISO, CloudStack makes a live HTTP HEAD/GET call … | Aug 21, 2026 |
| CVE-2026-61400 | HIGH | 8.8 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics functionality for the system VMs and … | Aug 21, 2026 |
| CVE-2026-61399 | UNKNOWN | — | Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 … | Aug 21, 2026 |
| CVE-2026-61398 | UNKNOWN | — | Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality. This issue affects Apache CloudStack: from 4.15.1.0 through … | Aug 21, 2026 |
| CVE-2026-61397 | UNKNOWN | — | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration. This issue affects Apache CloudStack: from … | Aug 21, 2026 |
| CVE-2026-59799 | UNKNOWN | — | Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the two-factor authentication disable flow. This issue affects Apache CloudStack: from 4.18.0.0 … | Aug 21, 2026 |
| CVE-2026-59780 | UNKNOWN | — | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP providers. LDAP configurations can be listed by … | Aug 21, 2026 |
| CVE-2026-59657 | UNKNOWN | — | Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. This issue affects Apache CloudStack: from 4.0.0 through 4.20.3.0 and … | Aug 21, 2026 |
| CVE-2026-59655 | UNKNOWN | — | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth providers. This issue affects Apache CloudStack: from … | Aug 21, 2026 |
| CVE-2026-59085 | UNKNOWN | — | Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and … | Aug 21, 2026 |
| CVE-2026-50222 | UNKNOWN | — | Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs. Several userdata-related APIs in Apache CloudStack, including deleteUserData, … | Aug 21, 2026 |
| CVE-2026-50112 | HIGH | 8.8 | SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage … | Aug 21, 2026 |
| CVE-2026-47359 | UNKNOWN | — | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache CloudStack's NAS backup provider plugin. The addBackupRepository API (available … | Aug 21, 2026 |
| CVE-2026-77264 | CRITICAL | 9.8 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, … | Aug 21, 2026 |
| CVE-2026-73537 | MEDIUM | 4.7 | Cross-site scripting vulnerability exists in Miraikan Assist App. If this vulnerability is exploited, an arbitrary script may be executed in the browser component (WebView) running … | Aug 21, 2026 |
| CVE-2026-19441 | MEDIUM | 5.3 | Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data. This issue affects Rush: through 21082026. | Aug 21, 2026 |
| CVE-2026-16323 | HIGH | 7.5 | Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass. This issue affects ArchitectPanel Web Admin Panel: … | Aug 21, 2026 |
| CVE-2026-75796 | HIGH | 7.2 | The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged … | Aug 21, 2026 |