Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48919
Total
3931
Critical
14503
High
14257
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-48160 | UNKNOWN | — | react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the default branch contained malicious commits 6978272a7d6ca02225cb747ea69f427512e33699 through 949f1a3d6bb1ff7d1a0dec892afd773e742627e8 that executed remote … | Aug 10, 2026 |
| CVE-2026-19411 | LOW | 3.9 | A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a … | Aug 10, 2026 |
| CVE-2026-18982 | HIGH | 8.8 | A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate … | Aug 10, 2026 |
| CVE-2026-18951 | HIGH | 8.8 | A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into … | Aug 10, 2026 |
| CVE-2026-18950 | HIGH | 8.8 | A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does … | Aug 10, 2026 |
| CVE-2026-18949 | HIGH | 8.8 | A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions … | Aug 10, 2026 |
| CVE-2026-18948 | CRITICAL | 9.9 | A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This … | Aug 10, 2026 |
| CVE-2026-18947 | HIGH | 8.5 | A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits … | Aug 10, 2026 |
| CVE-2026-18942 | MEDIUM | 5.5 | A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by … | Aug 10, 2026 |
| CVE-2026-18941 | HIGH | 7.7 | A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no security manager … | Aug 10, 2026 |
| CVE-2026-18621 | HIGH | 7.6 | A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow … | Aug 10, 2026 |
| CVE-2026-18620 | HIGH | 7.1 | A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying … | Aug 10, 2026 |
| CVE-2026-18618 | HIGH | 7.5 | A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. … | Aug 10, 2026 |
| CVE-2026-18617 | HIGH | 8.8 | A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for … | Aug 10, 2026 |
| CVE-2026-18611 | HIGH | 7.5 | A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords … | Aug 10, 2026 |
| CVE-2026-18608 | HIGH | 8.7 | A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary … | Aug 10, 2026 |
| CVE-2026-16456 | MEDIUM | 6.5 | A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the `loadSecret` function. This … | Aug 10, 2026 |
| CVE-2026-15581 | HIGH | 8.0 | A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access … | Aug 10, 2026 |
| CVE-2026-15467 | HIGH | 8.1 | A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to … | Aug 10, 2026 |
| CVE-2026-14450 | CRITICAL | 9.9 | A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP … | Aug 10, 2026 |
| CVE-2026-13717 | HIGH | 8.8 | A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard … | Aug 10, 2026 |
| CVE-2026-11810 | HIGH | 7.5 | The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) parses the JSON metadata returned by the update server into a fixed two-level nested-array struct. After … | Aug 10, 2026 |
| CVE-2026-11809 | LOW | 3.7 | The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z_impl_updatehub_probe(). The probe response from the UpdateHub server is copied into a … | Aug 10, 2026 |
| CVE-2026-72902 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands on a local … | Aug 10, 2026 |
| CVE-2026-72901 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the … | Aug 10, 2026 |