Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45395
Total
3650
Critical
13467
High
13391
Medium
CVE ID Severity Score Description Published
CVE-2026-69219 UNKNOWN The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to … Aug 18, 2026
CVE-2026-67271 CRITICAL 9.8 Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial … Aug 18, 2026
CVE-2026-66783 HIGH 8.2 A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user … Aug 18, 2026
CVE-2026-66782 HIGH 7.8 A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker service account (SA) bearer token within the … Aug 18, 2026
CVE-2026-66781 MEDIUM 6.5 A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in … Aug 18, 2026
CVE-2026-63337 UNKNOWN The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType … Aug 18, 2026
CVE-2026-63336 UNKNOWN The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) configure … Aug 18, 2026
CVE-2026-63335 UNKNOWN The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly … Aug 18, 2026
CVE-2026-61634 UNKNOWN The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning … Aug 18, 2026
CVE-2026-61574 HIGH 8.8 authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user … Aug 18, 2026
CVE-2026-57580 UNKNOWN authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets … Aug 18, 2026
CVE-2026-55106 MEDIUM 5.3 authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object-level read-authorization … Aug 18, 2026
CVE-2026-54730 UNKNOWN authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band … Aug 18, 2026
CVE-2026-52723 CRITICAL 9.1 ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration performs VAU … Aug 18, 2026
CVE-2026-52606 MEDIUM 6.1 A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by … Aug 18, 2026
CVE-2026-50578 HIGH 7.5 ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration disables TLS … Aug 18, 2026
CVE-2026-50577 HIGH 7.4 ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration leaves request_counter … Aug 18, 2026
CVE-2026-50576 MEDIUM 6.8 ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration does not … Aug 18, 2026
CVE-2026-50126 MEDIUM 4.0 Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteorological, climatological and remote sensing data via OGC standards. Versions … Aug 18, 2026
CVE-2026-49228 HIGH 8.8 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product … Aug 18, 2026
CVE-2026-49225 HIGH 8.3 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product … Aug 18, 2026
CVE-2026-49224 HIGH 8.3 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post … Aug 18, 2026
CVE-2026-49223 HIGH 7.6 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product … Aug 18, 2026
CVE-2026-49222 HIGH 7.6 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product … Aug 18, 2026
CVE-2026-48744 MEDIUM 6.5 Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleor/permission/utils.py can incorrectly authorize unauthenticated GraphQL requests. The … Aug 18, 2026