Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57306
Total
4581
Critical
17028
High
16895
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-52819 | UNKNOWN | — | Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user and users[] target identifiers from a caller with … | Sep 15, 2026 |
| CVE-2026-1759 | MEDIUM | 6.5 | Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escalation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or … | Sep 15, 2026 |
| CVE-2026-1758 | HIGH | 8.3 | Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above | Sep 15, 2026 |
| CVE-2026-91859 | UNKNOWN | — | Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, exception rendering runs the application … | Sep 15, 2026 |
| CVE-2026-91857 | UNKNOWN | — | Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affected actions are: - EventReportsController::purgeUnusedPictures() - NoticelistsController::enableNoticelist() - ServersController::removeOrphanedCorrelations() - … | Sep 15, 2026 |
| CVE-2026-62379 | CRITICAL | 9.8 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value … | Sep 15, 2026 |
| CVE-2026-62280 | MEDIUM | 6.1 | Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource … | Sep 15, 2026 |
| CVE-2026-62263 | UNKNOWN | — | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than … | Sep 15, 2026 |
| CVE-2026-59341 | MEDIUM | 4.2 | A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modified payload containing custom Go template logic in spec.template.data, an … | Sep 15, 2026 |
| CVE-2026-53660 | UNKNOWN | — | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without … | Sep 15, 2026 |
| CVE-2026-48717 | UNKNOWN | — | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a code_verifier only when the realm-wide codeVerifierEnforced setting is enabled, even … | Sep 15, 2026 |
| CVE-2026-47426 | UNKNOWN | — | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses ClientJwksResolverCache without reliably binding a cached jwks_uri … | Sep 15, 2026 |
| CVE-2026-47424 | UNKNOWN | — | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite … | Sep 15, 2026 |
| CVE-2026-46623 | UNKNOWN | — | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that … | Sep 15, 2026 |
| CVE-2026-46619 | UNKNOWN | — | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an … | Sep 15, 2026 |
| CVE-2026-46498 | UNKNOWN | — | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without … | Sep 15, 2026 |
| CVE-2026-45794 | UNKNOWN | — | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS callback handled by SnsMessageResource falls back to a … | Sep 15, 2026 |
| CVE-2026-45052 | UNKNOWN | — | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent … | Sep 15, 2026 |
| CVE-2026-45051 | UNKNOWN | — | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators … | Sep 15, 2026 |
| CVE-2026-45048 | HIGH | 8.5 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks … | Sep 15, 2026 |
| CVE-2026-44793 | UNKNOWN | — | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered … | Sep 15, 2026 |
| CVE-2026-44203 | UNKNOWN | — | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint does not sufficiently encode user-supplied … | Sep 15, 2026 |
| CVE-2026-44202 | UNKNOWN | — | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification … | Sep 15, 2026 |
| CVE-2026-41573 | UNKNOWN | — | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled, bypassing … | Sep 15, 2026 |
| CVE-2026-19515 | HIGH | 7.0 | The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources. This … | Sep 15, 2026 |