Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49732
Total
4014
Critical
14766
High
14490
Medium
CVE ID Severity Score Description Published
CVE-2026-39923 HIGH 8.1 Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly … Aug 05, 2026
CVE-2026-32835 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 05, 2026
CVE-2026-18531 MEDIUM 5.3 IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak … Aug 05, 2026
CVE-2026-16442 HIGH 7.4 A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because … Aug 05, 2026
CVE-2026-15656 MEDIUM 4.3 IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to … Aug 05, 2026
CVE-2026-15587 UNKNOWN Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level … Aug 05, 2026
CVE-2026-15572 HIGH 8.8 A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data … Aug 05, 2026
CVE-2026-13477 MEDIUM 4.7 IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with … Aug 05, 2026
CVE-2026-12762 MEDIUM 5.3 IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files. Aug 05, 2026
CVE-2026-12730 LOW 3.8 IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim … Aug 05, 2026
CVE-2026-10025 HIGH 8.2 IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides … Aug 05, 2026
CVE-2026-54876 HIGH 7.5 Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP … Aug 05, 2026
CVE-2026-17613 HIGH 7.5 Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe … Aug 05, 2026
CVE-2026-16102 HIGH 8.1 A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to … Aug 05, 2026
CVE-2026-16100 MEDIUM 6.5 A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations … Aug 05, 2026
CVE-2026-16071 MEDIUM 5.4 A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when … Aug 05, 2026
CVE-2026-15573 HIGH 8.1 A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before … Aug 05, 2026
CVE-2026-12410 HIGH 7.8 Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via … Aug 05, 2026
CVE-2026-7529 HIGH 7.5 The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its … Aug 05, 2026
CVE-2026-7456 MEDIUM 6.5 The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_disconnect()` function in all … Aug 05, 2026
CVE-2026-67623 HIGH 8.8 Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a … Aug 05, 2026
CVE-2026-17506 HIGH 7.2 The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tracking parameter in versions up to, and including, 2.15.0. … Aug 05, 2026
CVE-2026-16443 HIGH 7.4 A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat … Aug 05, 2026
CVE-2026-15979 HIGH 8.1 The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in versions up … Aug 05, 2026
CVE-2025-70962 HIGH 7.5 Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can … Aug 05, 2026