Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49732
Total
4014
Critical
14766
High
14490
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-7557 | CRITICAL | 9.1 | An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker … | Aug 05, 2026 |
| CVE-2026-7329 | CRITICAL | 9.9 | An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated … | Aug 05, 2026 |
| CVE-2026-7327 | HIGH | 8.1 | An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with … | Aug 05, 2026 |
| CVE-2026-7326 | HIGH | 7.5 | A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated … | Aug 05, 2026 |
| CVE-2026-70606 | MEDIUM | 5.9 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6, 41.9.1, 42.5.1, and 43.0.0, when a custom protocol … | Aug 05, 2026 |
| CVE-2026-70605 | MEDIUM | 5.9 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, … | Aug 05, 2026 |
| CVE-2026-70604 | HIGH | 7.4 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0, a custom scheme registered … | Aug 05, 2026 |
| CVE-2026-70603 | MEDIUM | 6.0 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1, shell.openPath() did not reject … | Aug 05, 2026 |
| CVE-2026-70602 | MEDIUM | 6.6 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting … | Aug 05, 2026 |
| CVE-2026-70601 | HIGH | 7.5 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning … | Aug 05, 2026 |
| CVE-2026-70600 | LOW | 3.1 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup … | Aug 05, 2026 |
| CVE-2026-70599 | MEDIUM | 5.9 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission … | Aug 05, 2026 |
| CVE-2026-70598 | LOW | 3.9 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data … | Aug 05, 2026 |
| CVE-2026-70597 | MEDIUM | 6.3 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the check Electron uses … | Aug 05, 2026 |
| CVE-2026-70596 | MEDIUM | 4.3 | Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content … | Aug 05, 2026 |
| CVE-2026-70595 | MEDIUM | 4.0 | Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an … | Aug 05, 2026 |
| CVE-2026-60053 | UNKNOWN | — | Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained usable after the owning administrator was demoted … | Aug 05, 2026 |
| CVE-2026-60023 | UNKNOWN | — | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted or pending answers could be … | Aug 05, 2026 |
| CVE-2026-53992 | MEDIUM | 6.1 | ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remote attackers to inject arbitrary HTML and JavaScript by supplying unsanitized values in … | Aug 05, 2026 |
| CVE-2026-50749 | UNKNOWN | — | Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due … | Aug 05, 2026 |
| CVE-2026-49331 | MEDIUM | 6.5 | A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream … | Aug 05, 2026 |
| CVE-2026-48912 | UNKNOWN | — | Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar-cleanup logic allows any authenticated … | Aug 05, 2026 |
| CVE-2026-48911 | UNKNOWN | — | Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing authorization check in the external-login email binding … | Aug 05, 2026 |
| CVE-2026-48834 | UNKNOWN | — | Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service … | Aug 05, 2026 |
| CVE-2026-39924 | MEDIUM | 6.8 | Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a … | Aug 05, 2026 |