Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56054
Total
4437
Critical
16638
High
16408
Medium
CVE ID Severity Score Description Published
CVE-2026-82355 MEDIUM 4.2 When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the … Sep 21, 2026
CVE-2026-80110 HIGH 8.1 A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string … Sep 21, 2026
CVE-2026-75939 HIGH 7.4 A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire … Sep 21, 2026
CVE-2026-75158 MEDIUM 4.3 Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized … Sep 21, 2026
CVE-2026-71543 UNKNOWN — OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting … Sep 21, 2026
CVE-2026-68919 UNKNOWN — GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special … Sep 21, 2026
CVE-2026-61630 MEDIUM 4.2 nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can … Sep 21, 2026
CVE-2026-61629 HIGH 7.5 nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs … Sep 21, 2026
CVE-2026-61628 HIGH 8.1 nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a … Sep 21, 2026
CVE-2026-55870 UNKNOWN — GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in the userinfo portion of source control material … Sep 21, 2026
CVE-2026-55625 MEDIUM 4.9 GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test accept an arbitrary existing pipeline … Sep 21, 2026
CVE-2026-55567 HIGH 7.8 BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent … Sep 21, 2026
CVE-2026-55074 UNKNOWN — Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a … Sep 21, 2026
CVE-2026-55071 HIGH 8.4 MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp … Sep 21, 2026
CVE-2026-55060 LOW 3.7 GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can … Sep 21, 2026
CVE-2026-54584 UNKNOWN — mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An … Sep 21, 2026
CVE-2026-52743 MEDIUM 4.3 GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs … Sep 21, 2026
CVE-2026-52742 UNKNOWN — GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of … Sep 21, 2026
CVE-2026-52741 UNKNOWN — GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a project uses a lenient … Sep 21, 2026
CVE-2026-52740 UNKNOWN — GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. A … Sep 21, 2026
CVE-2026-94404 UNKNOWN — MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving the change. … Sep 21, 2026
CVE-2026-94401 UNKNOWN — MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML … Sep 21, 2026
CVE-2026-94394 UNKNOWN — When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not … Sep 21, 2026
CVE-2026-94393 UNKNOWN — When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that … Sep 21, 2026
CVE-2026-94387 MEDIUM 5.4 Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. … Sep 21, 2026