Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48747
Total
3915
Critical
14448
High
14180
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-13267 | HIGH | 8.1 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could … | Aug 12, 2026 |
| CVE-2026-12618 | HIGH | 7.2 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could … | Aug 12, 2026 |
| CVE-2026-12359 | HIGH | 8.1 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could … | Aug 12, 2026 |
| CVE-2026-12005 | HIGH | 7.2 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains … | Aug 12, 2026 |
| CVE-2026-12004 | HIGH | 8.7 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains … | Aug 12, 2026 |
| CVE-2026-11937 | LOW | 3.1 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and … | Aug 12, 2026 |
| CVE-2026-11923 | HIGH | 7.4 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse … | Aug 12, 2026 |
| CVE-2025-9486 | LOW | 3.3 | GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain … | Aug 12, 2026 |
| CVE-2026-73301 | MEDIUM | 4.3 | Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/src/api/routes/global/groups.ts omitted auth.builderOrAdmin, allowing an authenticated BASIC role user to enumerate … | Aug 12, 2026 |
| CVE-2026-19311 | HIGH | 8.1 | Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index … | Aug 12, 2026 |
| CVE-2026-18952 | HIGH | 8.1 | Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request … | Aug 12, 2026 |
| CVE-2026-18678 | UNKNOWN | — | When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over … | Aug 12, 2026 |
| CVE-2026-18677 | UNKNOWN | — | In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in … | Aug 12, 2026 |
| CVE-2026-18676 | UNKNOWN | — | The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane … | Aug 12, 2026 |
| CVE-2026-18675 | UNKNOWN | — | The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number … | Aug 12, 2026 |
| CVE-2026-18673 | UNKNOWN | — | When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 … | Aug 12, 2026 |
| CVE-2026-8667 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain … | Aug 12, 2026 |
| CVE-2026-7427 | MEDIUM | 5.3 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain … | Aug 12, 2026 |
| CVE-2026-73327 | HIGH | 7.6 | Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing … | Aug 12, 2026 |
| CVE-2026-73300 | CRITICAL | 9.6 | Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL … | Aug 12, 2026 |
| CVE-2026-73299 | CRITICAL | 10.0 | Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with … | Aug 12, 2026 |
| CVE-2026-73298 | UNKNOWN | — | The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configurations to Azure Kubernetes … | Aug 12, 2026 |
| CVE-2026-69106 | HIGH | 8.8 | A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content. | Aug 12, 2026 |
| CVE-2026-49467 | HIGH | 8.8 | Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0 allow an attacker to bypass password … | Aug 12, 2026 |
| CVE-2026-44741 | HIGH | 8.8 | Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid … | Aug 12, 2026 |