Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48821
Total
3921
Critical
14470
High
14211
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-59244 | UNKNOWN | — | Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed … | Aug 12, 2026 |
| CVE-2026-59242 | MEDIUM | 5.4 | Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-read access … | Aug 12, 2026 |
| CVE-2026-58076 | UNKNOWN | — | Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from … | Aug 12, 2026 |
| CVE-2026-54183 | MEDIUM | 4.3 | Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend … | Aug 12, 2026 |
| CVE-2026-19548 | MEDIUM | 5.5 | Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that … | Aug 12, 2026 |
| CVE-2026-15803 | UNKNOWN | — | In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data or query … | Aug 12, 2026 |
| CVE-2025-35988 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | Aug 12, 2026 |
| CVE-2025-35977 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | Aug 12, 2026 |
| CVE-2025-32737 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | Aug 12, 2026 |
| CVE-2025-32087 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | Aug 12, 2026 |
| CVE-2025-32084 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | Aug 12, 2026 |
| CVE-2025-31943 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | Aug 12, 2026 |
| CVE-2025-30178 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | Aug 12, 2026 |
| CVE-2025-27570 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | Aug 12, 2026 |
| CVE-2025-27245 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | Aug 12, 2026 |
| CVE-2025-25275 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | Aug 12, 2026 |
| CVE-2025-24837 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | Aug 12, 2026 |
| CVE-2025-24488 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | Aug 12, 2026 |
| CVE-2025-20020 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | Aug 12, 2026 |
| CVE-2026-73432 | UNKNOWN | — | Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization functionality. Remote instance addresses were validated only for basic URL syntax before being … | Aug 12, 2026 |
| CVE-2026-73431 | UNKNOWN | — | Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activation and recovery links were generated using stateless signed tokens containing only the … | Aug 12, 2026 |
| CVE-2026-73405 | UNKNOWN | — | An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) streams through the /pubsub/subscribe/<topic> endpoint. The token_required decorator … | Aug 12, 2026 |
| CVE-2026-73374 | UNKNOWN | — | A stored cross-site scripting (XSS) vulnerability existed in Vulnerability-Lookup in the render_tag_badges Jinja filter used to display reference tags associated with vulnerability records. Values from … | Aug 12, 2026 |
| CVE-2026-73291 | HIGH | 7.1 | Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream … | Aug 12, 2026 |
| CVE-2026-73290 | MEDIUM | 5.3 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request in rustfs/src/storage/access.rs that lacks a direct bucket-policy grant … | Aug 12, 2026 |