Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44839
Total
3598
Critical
13323
High
13186
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-66787 | HIGH | 8.7 | A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP … | Aug 20, 2026 |
| CVE-2026-66785 | CRITICAL | 9.9 | A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing … | Aug 20, 2026 |
| CVE-2026-66002 | UNKNOWN | — | Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request.py return distinguishable response … | Aug 20, 2026 |
| CVE-2026-66001 | UNKNOWN | — | Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in frappe/integrations/oauth2.py allow the OAuth2 consent flow to … | Aug 20, 2026 |
| CVE-2026-64777 | MEDIUM | 4.3 | A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name … | Aug 20, 2026 |
| CVE-2026-63654 | UNKNOWN | — | Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.bulk_workflow_approval endpoint in frappe/model/workflow.py accepts safe HTTP methods for state-changing workflow … | Aug 20, 2026 |
| CVE-2026-63003 | MEDIUM | 6.5 | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, page duplication lacks an object-level authorization check on … | Aug 20, 2026 |
| CVE-2026-62315 | UNKNOWN | — | Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/client.py checks a dictionary supplied through the fieldname parameter against forbidden … | Aug 20, 2026 |
| CVE-2026-61663 | MEDIUM | 4.3 | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, render_object_structure fails to authorize non-PageContent objects that use … | Aug 20, 2026 |
| CVE-2026-54624 | MEDIUM | 6.5 | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, render_object_structure in cms/views.py renders cms/toolbar/structure.html for a PageContent … | Aug 20, 2026 |
| CVE-2026-54622 | MEDIUM | 6.5 | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the copy_plugins endpoint in cms/admin/placeholderadmin.py authorizes only the … | Aug 20, 2026 |
| CVE-2026-53993 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 20, 2026 |
| CVE-2026-53587 | HIGH | 7.5 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality … | Aug 20, 2026 |
| CVE-2026-53586 | MEDIUM | 6.5 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality … | Aug 20, 2026 |
| CVE-2026-53585 | MEDIUM | 5.3 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality … | Aug 20, 2026 |
| CVE-2026-53584 | MEDIUM | 4.3 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality … | Aug 20, 2026 |
| CVE-2026-53583 | MEDIUM | 6.5 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality … | Aug 20, 2026 |
| CVE-2026-53569 | UNKNOWN | — | Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_as_seen endpoints in frappe/desk/like.py and frappe/desk/doctype/note/note.py do not enforce … | Aug 20, 2026 |
| CVE-2026-50190 | UNKNOWN | — | Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in `application/front/controller/visitor/BookmarkListController.php`. The `permalink` handler concatenates the raw `$bookmark->getTitle()` into … | Aug 20, 2026 |
| CVE-2026-49996 | LOW | 3.7 | SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a … | Aug 20, 2026 |
| CVE-2026-46537 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 20, 2026 |
| CVE-2026-46536 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 20, 2026 |
| CVE-2026-46535 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 20, 2026 |
| CVE-2026-46534 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 20, 2026 |
| CVE-2026-46533 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 20, 2026 |