Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49645
Total
4014
Critical
14740
High
14481
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-70598 | LOW | 3.9 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data … | Aug 05, 2026 |
| CVE-2026-70597 | MEDIUM | 6.3 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the check Electron uses … | Aug 05, 2026 |
| CVE-2026-70596 | MEDIUM | 4.3 | Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content … | Aug 05, 2026 |
| CVE-2026-70595 | MEDIUM | 4.0 | Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an … | Aug 05, 2026 |
| CVE-2026-60053 | UNKNOWN | — | Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained usable after the owning administrator was demoted … | Aug 05, 2026 |
| CVE-2026-60023 | UNKNOWN | — | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted or pending answers could be … | Aug 05, 2026 |
| CVE-2026-53992 | MEDIUM | 6.1 | ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remote attackers to inject arbitrary HTML and JavaScript by supplying unsanitized values in … | Aug 05, 2026 |
| CVE-2026-50749 | UNKNOWN | — | Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due … | Aug 05, 2026 |
| CVE-2026-49331 | MEDIUM | 6.5 | A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream … | Aug 05, 2026 |
| CVE-2026-48912 | UNKNOWN | — | Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar-cleanup logic allows any authenticated … | Aug 05, 2026 |
| CVE-2026-48911 | UNKNOWN | — | Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing authorization check in the external-login email binding … | Aug 05, 2026 |
| CVE-2026-48834 | UNKNOWN | — | Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service … | Aug 05, 2026 |
| CVE-2026-39924 | MEDIUM | 6.8 | Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a … | Aug 05, 2026 |
| CVE-2026-39923 | HIGH | 8.1 | Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly … | Aug 05, 2026 |
| CVE-2026-32835 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 05, 2026 |
| CVE-2026-18531 | MEDIUM | 5.3 | IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak … | Aug 05, 2026 |
| CVE-2026-16442 | HIGH | 7.4 | A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because … | Aug 05, 2026 |
| CVE-2026-15656 | MEDIUM | 4.3 | IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to … | Aug 05, 2026 |
| CVE-2026-15587 | UNKNOWN | — | Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level … | Aug 05, 2026 |
| CVE-2026-15572 | HIGH | 8.8 | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data … | Aug 05, 2026 |
| CVE-2026-13477 | MEDIUM | 4.7 | IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with … | Aug 05, 2026 |
| CVE-2026-12762 | MEDIUM | 5.3 | IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files. | Aug 05, 2026 |
| CVE-2026-12730 | LOW | 3.8 | IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim … | Aug 05, 2026 |
| CVE-2026-10025 | HIGH | 8.2 | IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides … | Aug 05, 2026 |
| CVE-2026-54876 | HIGH | 7.5 | Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP … | Aug 05, 2026 |