Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45395
Total
3650
Critical
13467
High
13391
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-30250 | MEDIUM | 6.1 | Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to execute arbitrary code | Aug 18, 2026 |
| CVE-2026-19869 | UNKNOWN | — | @neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-resolver fields when a type-level @authentication rule is also present … | Aug 18, 2026 |
| CVE-2026-18963 | CRITICAL | 9.1 | A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat … | Aug 18, 2026 |
| CVE-2026-75926 | HIGH | 8.6 | Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not reach the … | Aug 18, 2026 |
| CVE-2026-75915 | HIGH | 7.5 | CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js. … | Aug 18, 2026 |
| CVE-2026-75914 | HIGH | 7.5 | CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace … | Aug 18, 2026 |
| CVE-2026-75913 | CRITICAL | 9.3 | CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed … | Aug 18, 2026 |
| CVE-2026-75912 | HIGH | 7.4 | CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into … | Aug 18, 2026 |
| CVE-2026-75911 | HIGH | 7.8 | CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by … | Aug 18, 2026 |
| CVE-2026-75904 | LOW | 3.3 | libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and … | Aug 18, 2026 |
| CVE-2026-75859 | HIGH | 7.5 | CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. … | Aug 18, 2026 |
| CVE-2026-75858 | HIGH | 7.8 | CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns … | Aug 18, 2026 |
| CVE-2026-75857 | HIGH | 7.0 | CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto. This overrides the default Required … | Aug 18, 2026 |
| CVE-2026-75856 | HIGH | 8.6 | CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses … | Aug 18, 2026 |
| CVE-2026-75485 | MEDIUM | 5.5 | A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, … | Aug 18, 2026 |
| CVE-2026-73834 | MEDIUM | 5.5 | A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data … | Aug 18, 2026 |
| CVE-2026-73373 | UNKNOWN | — | Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML … | Aug 18, 2026 |
| CVE-2026-73371 | UNKNOWN | — | Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to … | Aug 18, 2026 |
| CVE-2026-73337 | UNKNOWN | — | Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass … | Aug 18, 2026 |
| CVE-2026-73073 | UNKNOWN | — | Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped … | Aug 18, 2026 |
| CVE-2026-72532 | UNKNOWN | — | Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to … | Aug 18, 2026 |
| CVE-2026-71574 | UNKNOWN | — | Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to … | Aug 18, 2026 |
| CVE-2026-71477 | MEDIUM | 6.7 | mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/mise with user and group ID 1001 and … | Aug 18, 2026 |
| CVE-2026-71365 | HIGH | 7.7 | A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks, AWX extracts the status callback … | Aug 18, 2026 |
| CVE-2026-63328 | UNKNOWN | — | Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins without confining plugin names to … | Aug 18, 2026 |