Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45002
Total
3609
Critical
13358
High
13243
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-71470 | CRITICAL | 9.1 | A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate Search CR fields such … | Aug 19, 2026 |
| CVE-2026-50173 | UNKNOWN | — | Flow-Like is a platform for building end-to-end use cases. Prior to version 1.0.4, `GET /api/v1/apps/{app_id}/invoke/presign` grants Azure Blob Storage SAS credentials with write and delete … | Aug 19, 2026 |
| CVE-2026-49441 | CRITICAL | 9.1 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 and 5.0.0-beta3, the non-merged branch of … | Aug 19, 2026 |
| CVE-2026-49392 | MEDIUM | 5.3 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in … | Aug 19, 2026 |
| CVE-2026-48162 | CRITICAL | 9.1 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, DistributedAPI.send_tmp_file() in framework/wazuh/core/cluster/dapi/dapi.py joins … | Aug 19, 2026 |
| CVE-2026-48024 | CRITICAL | 9.1 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, cluster.unmerge_info() in framework/wazuh/core/cluster/cluster.py constructs … | Aug 19, 2026 |
| CVE-2026-45798 | HIGH | 7.5 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies … | Aug 19, 2026 |
| CVE-2026-44901 | HIGH | 8.4 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts … | Aug 19, 2026 |
| CVE-2026-44256 | MEDIUM | 5.3 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.4.0 until 4.14.6 and 5.0.0-beta2, api/api/middlewares.py decodes the Basic … | Aug 19, 2026 |
| CVE-2026-44255 | MEDIUM | 5.3 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AuthenticationManager.check_user() in framework/wazuh/rbac/orm.py performs … | Aug 19, 2026 |
| CVE-2026-41424 | HIGH | 8.2 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.9.0 until 4.10.4 and 4.14.6, PUT /security/users/{user_id} in api/api/controllers/security_controller.py … | Aug 19, 2026 |
| CVE-2026-20359 | CRITICAL | 9.9 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This … | Aug 19, 2026 |
| CVE-2026-20358 | CRITICAL | 10.0 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This … | Aug 19, 2026 |
| CVE-2026-20357 | CRITICAL | 10.0 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This … | Aug 19, 2026 |
| CVE-2026-20327 | MEDIUM | 6.5 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack … | Aug 19, 2026 |
| CVE-2026-20320 | HIGH | 7.5 | A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on … | Aug 19, 2026 |
| CVE-2026-20319 | HIGH | 7.5 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. … | Aug 19, 2026 |
| CVE-2026-20318 | CRITICAL | 9.6 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. … | Aug 19, 2026 |
| CVE-2026-20317 | CRITICAL | 10.0 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. … | Aug 19, 2026 |
| CVE-2026-20315 | CRITICAL | 10.0 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. … | Aug 19, 2026 |
| CVE-2026-20314 | MEDIUM | 5.0 | A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to … | Aug 19, 2026 |
| CVE-2026-20302 | MEDIUM | 6.1 | A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected … | Aug 19, 2026 |
| CVE-2026-20232 | MEDIUM | 5.4 | A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored … | Aug 19, 2026 |
| CVE-2026-20231 | CRITICAL | 9.9 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. … | Aug 19, 2026 |
| CVE-2026-20177 | MEDIUM | 5.3 | A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the … | Aug 19, 2026 |