Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48747
Total
3915
Critical
14448
High
14180
Medium
CVE ID Severity Score Description Published
CVE-2026-13267 HIGH 8.1 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could … Aug 12, 2026
CVE-2026-12618 HIGH 7.2 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could … Aug 12, 2026
CVE-2026-12359 HIGH 8.1 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could … Aug 12, 2026
CVE-2026-12005 HIGH 7.2 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains … Aug 12, 2026
CVE-2026-12004 HIGH 8.7 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains … Aug 12, 2026
CVE-2026-11937 LOW 3.1 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and … Aug 12, 2026
CVE-2026-11923 HIGH 7.4 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse … Aug 12, 2026
CVE-2025-9486 LOW 3.3 GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain … Aug 12, 2026
CVE-2026-73301 MEDIUM 4.3 Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/src/api/routes/global/groups.ts omitted auth.builderOrAdmin, allowing an authenticated BASIC role user to enumerate … Aug 12, 2026
CVE-2026-19311 HIGH 8.1 Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index … Aug 12, 2026
CVE-2026-18952 HIGH 8.1 Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request … Aug 12, 2026
CVE-2026-18678 UNKNOWN When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over … Aug 12, 2026
CVE-2026-18677 UNKNOWN In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in … Aug 12, 2026
CVE-2026-18676 UNKNOWN The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane … Aug 12, 2026
CVE-2026-18675 UNKNOWN The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number … Aug 12, 2026
CVE-2026-18673 UNKNOWN When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 … Aug 12, 2026
CVE-2026-8667 MEDIUM 4.3 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain … Aug 12, 2026
CVE-2026-7427 MEDIUM 5.3 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain … Aug 12, 2026
CVE-2026-73327 HIGH 7.6 Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing … Aug 12, 2026
CVE-2026-73300 CRITICAL 9.6 Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL … Aug 12, 2026
CVE-2026-73299 CRITICAL 10.0 Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with … Aug 12, 2026
CVE-2026-73298 UNKNOWN The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configurations to Azure Kubernetes … Aug 12, 2026
CVE-2026-69106 HIGH 8.8 A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content. Aug 12, 2026
CVE-2026-49467 HIGH 8.8 Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0 allow an attacker to bypass password … Aug 12, 2026
CVE-2026-44741 HIGH 8.8 Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid … Aug 12, 2026