Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48821
Total
3921
Critical
14470
High
14211
Medium
CVE ID Severity Score Description Published
CVE-2026-59244 UNKNOWN Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed … Aug 12, 2026
CVE-2026-59242 MEDIUM 5.4 Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-read access … Aug 12, 2026
CVE-2026-58076 UNKNOWN Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from … Aug 12, 2026
CVE-2026-54183 MEDIUM 4.3 Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend … Aug 12, 2026
CVE-2026-19548 MEDIUM 5.5 Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that … Aug 12, 2026
CVE-2026-15803 UNKNOWN In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data or query … Aug 12, 2026
CVE-2025-35988 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused Aug 12, 2026
CVE-2025-35977 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused Aug 12, 2026
CVE-2025-32737 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused Aug 12, 2026
CVE-2025-32087 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused Aug 12, 2026
CVE-2025-32084 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused Aug 12, 2026
CVE-2025-31943 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused Aug 12, 2026
CVE-2025-30178 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused Aug 12, 2026
CVE-2025-27570 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused Aug 12, 2026
CVE-2025-27245 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused Aug 12, 2026
CVE-2025-25275 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused Aug 12, 2026
CVE-2025-24837 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused Aug 12, 2026
CVE-2025-24488 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused Aug 12, 2026
CVE-2025-20020 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused Aug 12, 2026
CVE-2026-73432 UNKNOWN Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization functionality. Remote instance addresses were validated only for basic URL syntax before being … Aug 12, 2026
CVE-2026-73431 UNKNOWN Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activation and recovery links were generated using stateless signed tokens containing only the … Aug 12, 2026
CVE-2026-73405 UNKNOWN An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) streams through the /pubsub/subscribe/<topic> endpoint. The token_required decorator … Aug 12, 2026
CVE-2026-73374 UNKNOWN A stored cross-site scripting (XSS) vulnerability existed in Vulnerability-Lookup in the render_tag_badges Jinja filter used to display reference tags associated with vulnerability records. Values from … Aug 12, 2026
CVE-2026-73291 HIGH 7.1 Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream … Aug 12, 2026
CVE-2026-73290 MEDIUM 5.3 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request in rustfs/src/storage/access.rs that lacks a direct bucket-policy grant … Aug 12, 2026