Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45339
Total
3649
Critical
13458
High
13386
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-63336 | UNKNOWN | — | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) configure … | Aug 18, 2026 |
| CVE-2026-63335 | UNKNOWN | — | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly … | Aug 18, 2026 |
| CVE-2026-61634 | UNKNOWN | — | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning … | Aug 18, 2026 |
| CVE-2026-61574 | HIGH | 8.8 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user … | Aug 18, 2026 |
| CVE-2026-57580 | UNKNOWN | — | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets … | Aug 18, 2026 |
| CVE-2026-55106 | MEDIUM | 5.3 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object-level read-authorization … | Aug 18, 2026 |
| CVE-2026-54730 | UNKNOWN | — | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band … | Aug 18, 2026 |
| CVE-2026-52723 | CRITICAL | 9.1 | ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration performs VAU … | Aug 18, 2026 |
| CVE-2026-52606 | MEDIUM | 6.1 | A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by … | Aug 18, 2026 |
| CVE-2026-50578 | HIGH | 7.5 | ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration disables TLS … | Aug 18, 2026 |
| CVE-2026-50577 | HIGH | 7.4 | ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration leaves request_counter … | Aug 18, 2026 |
| CVE-2026-50576 | MEDIUM | 6.8 | ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration does not … | Aug 18, 2026 |
| CVE-2026-50126 | MEDIUM | 4.0 | Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteorological, climatological and remote sensing data via OGC standards. Versions … | Aug 18, 2026 |
| CVE-2026-49228 | HIGH | 8.8 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product … | Aug 18, 2026 |
| CVE-2026-49225 | HIGH | 8.3 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product … | Aug 18, 2026 |
| CVE-2026-49224 | HIGH | 8.3 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post … | Aug 18, 2026 |
| CVE-2026-49223 | HIGH | 7.6 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product … | Aug 18, 2026 |
| CVE-2026-49222 | HIGH | 7.6 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product … | Aug 18, 2026 |
| CVE-2026-48744 | MEDIUM | 6.5 | Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleor/permission/utils.py can incorrectly authorize unauthenticated GraphQL requests. The … | Aug 18, 2026 |
| CVE-2026-30250 | MEDIUM | 6.1 | Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to execute arbitrary code | Aug 18, 2026 |
| CVE-2026-19869 | UNKNOWN | — | @neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-resolver fields when a type-level @authentication rule is also present … | Aug 18, 2026 |
| CVE-2026-18963 | CRITICAL | 9.1 | A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat … | Aug 18, 2026 |
| CVE-2026-75926 | HIGH | 8.6 | Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not reach the … | Aug 18, 2026 |
| CVE-2026-75915 | HIGH | 7.5 | CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js. … | Aug 18, 2026 |
| CVE-2026-75914 | HIGH | 7.5 | CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace … | Aug 18, 2026 |