Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45339
Total
3649
Critical
13458
High
13386
Medium
CVE ID Severity Score Description Published
CVE-2026-63336 UNKNOWN The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) configure … Aug 18, 2026
CVE-2026-63335 UNKNOWN The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly … Aug 18, 2026
CVE-2026-61634 UNKNOWN The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning … Aug 18, 2026
CVE-2026-61574 HIGH 8.8 authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user … Aug 18, 2026
CVE-2026-57580 UNKNOWN authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets … Aug 18, 2026
CVE-2026-55106 MEDIUM 5.3 authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object-level read-authorization … Aug 18, 2026
CVE-2026-54730 UNKNOWN authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band … Aug 18, 2026
CVE-2026-52723 CRITICAL 9.1 ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration performs VAU … Aug 18, 2026
CVE-2026-52606 MEDIUM 6.1 A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by … Aug 18, 2026
CVE-2026-50578 HIGH 7.5 ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration disables TLS … Aug 18, 2026
CVE-2026-50577 HIGH 7.4 ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration leaves request_counter … Aug 18, 2026
CVE-2026-50576 MEDIUM 6.8 ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration does not … Aug 18, 2026
CVE-2026-50126 MEDIUM 4.0 Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteorological, climatological and remote sensing data via OGC standards. Versions … Aug 18, 2026
CVE-2026-49228 HIGH 8.8 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product … Aug 18, 2026
CVE-2026-49225 HIGH 8.3 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product … Aug 18, 2026
CVE-2026-49224 HIGH 8.3 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post … Aug 18, 2026
CVE-2026-49223 HIGH 7.6 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product … Aug 18, 2026
CVE-2026-49222 HIGH 7.6 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product … Aug 18, 2026
CVE-2026-48744 MEDIUM 6.5 Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleor/permission/utils.py can incorrectly authorize unauthenticated GraphQL requests. The … Aug 18, 2026
CVE-2026-30250 MEDIUM 6.1 Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to execute arbitrary code Aug 18, 2026
CVE-2026-19869 UNKNOWN @neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-resolver fields when a type-level @authentication rule is also present … Aug 18, 2026
CVE-2026-18963 CRITICAL 9.1 A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat … Aug 18, 2026
CVE-2026-75926 HIGH 8.6 Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not reach the … Aug 18, 2026
CVE-2026-75915 HIGH 7.5 CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js. … Aug 18, 2026
CVE-2026-75914 HIGH 7.5 CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace … Aug 18, 2026