Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49732
Total
4014
Critical
14766
High
14490
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-39923 | HIGH | 8.1 | Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly … | Aug 05, 2026 |
| CVE-2026-32835 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 05, 2026 |
| CVE-2026-18531 | MEDIUM | 5.3 | IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak … | Aug 05, 2026 |
| CVE-2026-16442 | HIGH | 7.4 | A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because … | Aug 05, 2026 |
| CVE-2026-15656 | MEDIUM | 4.3 | IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to … | Aug 05, 2026 |
| CVE-2026-15587 | UNKNOWN | — | Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level … | Aug 05, 2026 |
| CVE-2026-15572 | HIGH | 8.8 | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data … | Aug 05, 2026 |
| CVE-2026-13477 | MEDIUM | 4.7 | IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with … | Aug 05, 2026 |
| CVE-2026-12762 | MEDIUM | 5.3 | IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files. | Aug 05, 2026 |
| CVE-2026-12730 | LOW | 3.8 | IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim … | Aug 05, 2026 |
| CVE-2026-10025 | HIGH | 8.2 | IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides … | Aug 05, 2026 |
| CVE-2026-54876 | HIGH | 7.5 | Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP … | Aug 05, 2026 |
| CVE-2026-17613 | HIGH | 7.5 | Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe … | Aug 05, 2026 |
| CVE-2026-16102 | HIGH | 8.1 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to … | Aug 05, 2026 |
| CVE-2026-16100 | MEDIUM | 6.5 | A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations … | Aug 05, 2026 |
| CVE-2026-16071 | MEDIUM | 5.4 | A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when … | Aug 05, 2026 |
| CVE-2026-15573 | HIGH | 8.1 | A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before … | Aug 05, 2026 |
| CVE-2026-12410 | HIGH | 7.8 | Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via … | Aug 05, 2026 |
| CVE-2026-7529 | HIGH | 7.5 | The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its … | Aug 05, 2026 |
| CVE-2026-7456 | MEDIUM | 6.5 | The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_disconnect()` function in all … | Aug 05, 2026 |
| CVE-2026-67623 | HIGH | 8.8 | Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a … | Aug 05, 2026 |
| CVE-2026-17506 | HIGH | 7.2 | The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tracking parameter in versions up to, and including, 2.15.0. … | Aug 05, 2026 |
| CVE-2026-16443 | HIGH | 7.4 | A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat … | Aug 05, 2026 |
| CVE-2026-15979 | HIGH | 8.1 | The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in versions up … | Aug 05, 2026 |
| CVE-2025-70962 | HIGH | 7.5 | Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can … | Aug 05, 2026 |