Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54949
Total
4343
Critical
16375
High
16061
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84720 | MEDIUM | 6.5 | A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between workflow nodes, … | Sep 23, 2026 |
| CVE-2026-84719 | CRITICAL | 9.9 | A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and … | Sep 23, 2026 |
| CVE-2026-84718 | MEDIUM | 4.3 | A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's … | Sep 23, 2026 |
| CVE-2026-84717 | MEDIUM | 5.3 | A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after … | Sep 23, 2026 |
| CVE-2026-84716 | MEDIUM | 6.6 | A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator downloads an execution/hop node's install bundle, the controller signs an X.509 … | Sep 23, 2026 |
| CVE-2026-84714 | HIGH | 7.1 | A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two regular expressions to reject user-supplied Jinja, but the patterns stop at … | Sep 23, 2026 |
| CVE-2026-84713 | MEDIUM | 6.5 | A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notification_ configuration is protected from API filtering, its recipient value is copied in clear text … | Sep 23, 2026 |
| CVE-2026-84712 | MEDIUM | 5.3 | A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (ApiV2PingView, AllowAny) over-serializes RBAC-gated automation-mesh data into its anonymous response, exposing the … | Sep 23, 2026 |
| CVE-2026-84706 | HIGH | 7.6 | A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check … | Sep 23, 2026 |
| CVE-2026-84691 | HIGH | 8.7 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is … | Sep 23, 2026 |
| CVE-2026-84683 | HIGH | 8.7 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update … | Sep 23, 2026 |
| CVE-2026-82409 | UNKNOWN | — | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elasticsearch _bulk JSON … | Sep 23, 2026 |
| CVE-2026-82407 | UNKNOWN | — | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, core/kapp/validators/validators.go Register and the runtime validator update path accept a submitted BLSPublicKey … | Sep 23, 2026 |
| CVE-2026-82406 | UNKNOWN | — | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function core/kapp/market/market.go Buy does not check IsClaimed before accepting … | Sep 23, 2026 |
| CVE-2026-82405 | UNKNOWN | — | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the KleverUpdateAccountPermission built-in authorizes replacement of a target account's permissions by checking … | Sep 23, 2026 |
| CVE-2026-75884 | CRITICAL | 9.1 | A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, … | Sep 23, 2026 |
| CVE-2026-68492 | UNKNOWN | — | An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root … | Sep 23, 2026 |
| CVE-2026-68490 | UNKNOWN | — | Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts. | Sep 23, 2026 |
| CVE-2026-67238 | UNKNOWN | — | RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, rabbit_pid_codec:decompose_from_binary/1 parses a caller-supplied ETF-encoded binary and calls binary_to_atom(Node, utf8) on the … | Sep 23, 2026 |
| CVE-2026-66079 | UNKNOWN | — | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, parse_array_primitive/2 for constructor 0x45 (list0) returns an element with byte-width … | Sep 23, 2026 |
| CVE-2026-66076 | UNKNOWN | — | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, is_authorized/2 calls rabbit_mgmt_util:is_authorized/2, which checks only the management tag, … | Sep 23, 2026 |
| CVE-2026-66070 | UNKNOWN | — | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6, match_origin/1 returned the bare reflected Origin and allowed credentials even … | Sep 23, 2026 |
| CVE-2026-96872 | UNKNOWN | — | Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension on Linux, MacOS, and Windows allows Accessing Functionality Not … | Sep 23, 2026 |
| CVE-2026-96770 | UNKNOWN | — | All published s2s-proxy versions through 0.2.2 are affected. In versions 0.1.16 through 0.2.2, TLS server listeners use Go's RequireAnyClientCert mode when skipCAVerification is false. This … | Sep 23, 2026 |
| CVE-2026-96549 | LOW | 3.3 | A vulnerability has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This vulnerability affects unknown code of the file ssm_pro/src/main/java/cn/sfturing/service/impl/CommonUserServiceImpl.java. Such manipulation leads to cleartext … | Sep 23, 2026 |