Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44839
Total
3598
Critical
13323
High
13186
Medium
CVE ID Severity Score Description Published
CVE-2026-66787 HIGH 8.7 A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP … Aug 20, 2026
CVE-2026-66785 CRITICAL 9.9 A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing … Aug 20, 2026
CVE-2026-66002 UNKNOWN Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request.py return distinguishable response … Aug 20, 2026
CVE-2026-66001 UNKNOWN Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in frappe/integrations/oauth2.py allow the OAuth2 consent flow to … Aug 20, 2026
CVE-2026-64777 MEDIUM 4.3 A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name … Aug 20, 2026
CVE-2026-63654 UNKNOWN Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.bulk_workflow_approval endpoint in frappe/model/workflow.py accepts safe HTTP methods for state-changing workflow … Aug 20, 2026
CVE-2026-63003 MEDIUM 6.5 django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, page duplication lacks an object-level authorization check on … Aug 20, 2026
CVE-2026-62315 UNKNOWN Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/client.py checks a dictionary supplied through the fieldname parameter against forbidden … Aug 20, 2026
CVE-2026-61663 MEDIUM 4.3 django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, render_object_structure fails to authorize non-PageContent objects that use … Aug 20, 2026
CVE-2026-54624 MEDIUM 6.5 django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, render_object_structure in cms/views.py renders cms/toolbar/structure.html for a PageContent … Aug 20, 2026
CVE-2026-54622 MEDIUM 6.5 django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the copy_plugins endpoint in cms/admin/placeholderadmin.py authorizes only the … Aug 20, 2026
CVE-2026-53993 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 20, 2026
CVE-2026-53587 HIGH 7.5 libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality … Aug 20, 2026
CVE-2026-53586 MEDIUM 6.5 libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality … Aug 20, 2026
CVE-2026-53585 MEDIUM 5.3 libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality … Aug 20, 2026
CVE-2026-53584 MEDIUM 4.3 libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality … Aug 20, 2026
CVE-2026-53583 MEDIUM 6.5 libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality … Aug 20, 2026
CVE-2026-53569 UNKNOWN Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_as_seen endpoints in frappe/desk/like.py and frappe/desk/doctype/note/note.py do not enforce … Aug 20, 2026
CVE-2026-50190 UNKNOWN Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in `application/front/controller/visitor/BookmarkListController.php`. The `permalink` handler concatenates the raw `$bookmark->getTitle()` into … Aug 20, 2026
CVE-2026-49996 LOW 3.7 SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a … Aug 20, 2026
CVE-2026-46537 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 20, 2026
CVE-2026-46536 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 20, 2026
CVE-2026-46535 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 20, 2026
CVE-2026-46534 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 20, 2026
CVE-2026-46533 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 20, 2026