Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49645
Total
4014
Critical
14740
High
14481
Medium
CVE ID Severity Score Description Published
CVE-2026-70598 LOW 3.9 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data … Aug 05, 2026
CVE-2026-70597 MEDIUM 6.3 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the check Electron uses … Aug 05, 2026
CVE-2026-70596 MEDIUM 4.3 Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content … Aug 05, 2026
CVE-2026-70595 MEDIUM 4.0 Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an … Aug 05, 2026
CVE-2026-60053 UNKNOWN Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained usable after the owning administrator was demoted … Aug 05, 2026
CVE-2026-60023 UNKNOWN Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted or pending answers could be … Aug 05, 2026
CVE-2026-53992 MEDIUM 6.1 ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remote attackers to inject arbitrary HTML and JavaScript by supplying unsanitized values in … Aug 05, 2026
CVE-2026-50749 UNKNOWN Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due … Aug 05, 2026
CVE-2026-49331 MEDIUM 6.5 A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream … Aug 05, 2026
CVE-2026-48912 UNKNOWN Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar-cleanup logic allows any authenticated … Aug 05, 2026
CVE-2026-48911 UNKNOWN Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing authorization check in the external-login email binding … Aug 05, 2026
CVE-2026-48834 UNKNOWN Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service … Aug 05, 2026
CVE-2026-39924 MEDIUM 6.8 Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a … Aug 05, 2026
CVE-2026-39923 HIGH 8.1 Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly … Aug 05, 2026
CVE-2026-32835 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 05, 2026
CVE-2026-18531 MEDIUM 5.3 IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak … Aug 05, 2026
CVE-2026-16442 HIGH 7.4 A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because … Aug 05, 2026
CVE-2026-15656 MEDIUM 4.3 IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to … Aug 05, 2026
CVE-2026-15587 UNKNOWN Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level … Aug 05, 2026
CVE-2026-15572 HIGH 8.8 A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data … Aug 05, 2026
CVE-2026-13477 MEDIUM 4.7 IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with … Aug 05, 2026
CVE-2026-12762 MEDIUM 5.3 IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files. Aug 05, 2026
CVE-2026-12730 LOW 3.8 IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim … Aug 05, 2026
CVE-2026-10025 HIGH 8.2 IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides … Aug 05, 2026
CVE-2026-54876 HIGH 7.5 Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP … Aug 05, 2026