Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26398
Total
1955
Critical
7975
High
8226
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-53606 | MEDIUM | 5.4 | ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Versions of sanitize-html prior to 2.17.5 … | Jun 12, 2026 |
| CVE-2026-4870 | HIGH | 7.5 | IBM Qiskit SDK 0.43.0 through 2.5.0 could allow an attacker to trigger a segmentation fault leading to a denial of service due to uncontrolled recursion … | Jun 12, 2026 |
| CVE-2026-47264 | MEDIUM | 5.3 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, DetailedTagSerializer#tag_group_names returned every tag … | Jun 12, 2026 |
| CVE-2026-47263 | MEDIUM | 4.3 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the MessageBus.publish call for … | Jun 12, 2026 |
| CVE-2026-45775 | MEDIUM | 6.8 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a path traversal vulnerability … | Jun 12, 2026 |
| CVE-2026-45085 | MEDIUM | 5.3 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, four authorization/disclosure issues in … | Jun 12, 2026 |
| CVE-2026-45014 | UNKNOWN | — | ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 are vulnerable to stored cross-site scripting via unsanitized user display name … | Jun 12, 2026 |
| CVE-2026-45013 | HIGH | 8.1 | ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password reset flow that constructs the reset URL using … | Jun 12, 2026 |
| CVE-2026-45012 | HIGH | 7.6 | ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authenticated server-side request forgery (SSRF) in the rich-text widget … | Jun 12, 2026 |
| CVE-2026-45011 | HIGH | 7.3 | ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site scripting vulnerability in the image widget functionality. A user with the … | Jun 12, 2026 |
| CVE-2026-44990 | CRITICAL | 9.3 | ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of … | Jun 12, 2026 |
| CVE-2026-44786 | HIGH | 7.5 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, chat events for public … | Jun 12, 2026 |
| CVE-2026-44785 | MEDIUM | 4.3 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the AI "explain" helper … | Jun 12, 2026 |
| CVE-2026-44784 | MEDIUM | 6.5 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, group owners who are … | Jun 12, 2026 |
| CVE-2026-44783 | MEDIUM | 5.4 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a flaw in how … | Jun 12, 2026 |
| CVE-2026-44782 | MEDIUM | 4.3 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, GroupPostSerializer declared include_user_long_name? as … | Jun 12, 2026 |
| CVE-2026-44780 | MEDIUM | 4.3 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, ReviewableQueuedPostSerializer unconditionally included payload["raw_email"] … | Jun 12, 2026 |
| CVE-2026-44779 | MEDIUM | 4.3 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, bot debug endpoints disclose … | Jun 12, 2026 |
| CVE-2026-42853 | MEDIUM | 6.5 | ApostropheCMS is an open-source Node.js content management system. Versions of the @apostrophecms/cli package up to and including 3.6.0 contain a command injection vulnerability in the … | Jun 12, 2026 |
| CVE-2026-24618 | MEDIUM | 4.3 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThemes Hash Elements allows Retrieve Embedded Sensitive Data. This issue affects Hash Elements: … | Jun 12, 2026 |
| CVE-2026-12130 | LOW | 3.5 | A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of the file /Projects/Add_Projects of the component … | Jun 12, 2026 |
| CVE-2026-12129 | LOW | 3.5 | A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/add_tod of the … | Jun 12, 2026 |
| CVE-2026-54361 | UNKNOWN | — | MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegations, and shadow attributes. Several controller actions accepted user-supplied fields that … | Jun 12, 2026 |
| CVE-2026-54360 | UNKNOWN | — | A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the controller did not remove a user-supplied id … | Jun 12, 2026 |
| CVE-2026-54359 | UNKNOWN | — | MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. When this setting is disabled, state-changing requests such as POST, PUT, or … | Jun 12, 2026 |