Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26398
Total
1955
Critical
7975
High
8226
Medium
CVE ID Severity Score Description Published
CVE-2026-53606 MEDIUM 5.4 ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Versions of sanitize-html prior to 2.17.5 … Jun 12, 2026
CVE-2026-4870 HIGH 7.5 IBM Qiskit SDK 0.43.0 through 2.5.0 could allow an attacker to trigger a segmentation fault leading to a denial of service due to uncontrolled recursion … Jun 12, 2026
CVE-2026-47264 MEDIUM 5.3 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, DetailedTagSerializer#tag_group_names returned every tag … Jun 12, 2026
CVE-2026-47263 MEDIUM 4.3 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the MessageBus.publish call for … Jun 12, 2026
CVE-2026-45775 MEDIUM 6.8 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a path traversal vulnerability … Jun 12, 2026
CVE-2026-45085 MEDIUM 5.3 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, four authorization/disclosure issues in … Jun 12, 2026
CVE-2026-45014 UNKNOWN ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 are vulnerable to stored cross-site scripting via unsanitized user display name … Jun 12, 2026
CVE-2026-45013 HIGH 8.1 ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password reset flow that constructs the reset URL using … Jun 12, 2026
CVE-2026-45012 HIGH 7.6 ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authenticated server-side request forgery (SSRF) in the rich-text widget … Jun 12, 2026
CVE-2026-45011 HIGH 7.3 ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site scripting vulnerability in the image widget functionality. A user with the … Jun 12, 2026
CVE-2026-44990 CRITICAL 9.3 ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of … Jun 12, 2026
CVE-2026-44786 HIGH 7.5 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, chat events for public … Jun 12, 2026
CVE-2026-44785 MEDIUM 4.3 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the AI "explain" helper … Jun 12, 2026
CVE-2026-44784 MEDIUM 6.5 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, group owners who are … Jun 12, 2026
CVE-2026-44783 MEDIUM 5.4 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a flaw in how … Jun 12, 2026
CVE-2026-44782 MEDIUM 4.3 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, GroupPostSerializer declared include_user_long_name? as … Jun 12, 2026
CVE-2026-44780 MEDIUM 4.3 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, ReviewableQueuedPostSerializer unconditionally included payload["raw_email"] … Jun 12, 2026
CVE-2026-44779 MEDIUM 4.3 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, bot debug endpoints disclose … Jun 12, 2026
CVE-2026-42853 MEDIUM 6.5 ApostropheCMS is an open-source Node.js content management system. Versions of the @apostrophecms/cli package up to and including 3.6.0 contain a command injection vulnerability in the … Jun 12, 2026
CVE-2026-24618 MEDIUM 4.3 Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThemes Hash Elements allows Retrieve Embedded Sensitive Data. This issue affects Hash Elements: … Jun 12, 2026
CVE-2026-12130 LOW 3.5 A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of the file /Projects/Add_Projects of the component … Jun 12, 2026
CVE-2026-12129 LOW 3.5 A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/add_tod of the … Jun 12, 2026
CVE-2026-54361 UNKNOWN MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegations, and shadow attributes. Several controller actions accepted user-supplied fields that … Jun 12, 2026
CVE-2026-54360 UNKNOWN A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the controller did not remove a user-supplied id … Jun 12, 2026
CVE-2026-54359 UNKNOWN MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. When this setting is disabled, state-changing requests such as POST, PUT, or … Jun 12, 2026