Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

47870
Total
3850
Critical
14243
High
13921
Medium
CVE ID Severity Score Description Published
CVE-2026-74247 MEDIUM 4.2 A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability … Aug 14, 2026
CVE-2026-74245 MEDIUM 5.9 A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without … Aug 14, 2026
CVE-2026-74244 MEDIUM 5.9 A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted … Aug 14, 2026
CVE-2026-74243 MEDIUM 6.5 A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to … Aug 14, 2026
CVE-2026-74242 MEDIUM 5.3 A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can … Aug 14, 2026
CVE-2026-74241 MEDIUM 4.8 A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the … Aug 14, 2026
CVE-2026-74240 MEDIUM 5.4 A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related … Aug 14, 2026
CVE-2026-63650 UNKNOWN OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field Aug 14, 2026
CVE-2026-63649 UNKNOWN The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and … Aug 14, 2026
CVE-2026-18932 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 14, 2026
CVE-2026-73683 HIGH 8.1 Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation … Aug 14, 2026
CVE-2026-69414 HIGH 7.8 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are … Aug 14, 2026
CVE-2026-74248 MEDIUM 4.3 OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent … Aug 14, 2026
CVE-2026-73682 HIGH 8.8 Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows authenticated users holding the Manager … Aug 14, 2026
CVE-2026-71570 UNKNOWN Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_icagenda` only could enumerate … Aug 14, 2026
CVE-2026-67366 UNKNOWN Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the frontend are callable without … Aug 14, 2026
CVE-2026-50523 HIGH 7.8 Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally. Aug 14, 2026
CVE-2026-73680 HIGH 8.8 Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute … Aug 14, 2026
CVE-2026-71571 UNKNOWN Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permissions to access iCagenda could … Aug 14, 2026
CVE-2026-67365 UNKNOWN Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, … Aug 14, 2026
CVE-2026-64887 UNKNOWN Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack. This issue affects Airwall: before 4.1. Aug 14, 2026
CVE-2026-39925 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 14, 2026
CVE-2026-34492 UNKNOWN External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipulation. This issue affects Airwall: before 4.1. Aug 14, 2026
CVE-2026-27871 UNKNOWN Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 allows Cryptanalytic Attack. This issue affects TL280: before 5.63. Aug 14, 2026
CVE-2026-19910 HIGH 7.5 PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of … Aug 14, 2026