Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54298
Total
4306
Critical
16144
High
15836
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-86843 | MEDIUM | 6.3 | The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the … | Sep 29, 2026 |
| CVE-2026-84739 | HIGH | 8.7 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain … | Sep 29, 2026 |
| CVE-2026-81930 | MEDIUM | 6.3 | Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built … | Sep 29, 2026 |
| CVE-2026-81914 | MEDIUM | 4.3 | Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character … | Sep 29, 2026 |
| CVE-2026-81862 | MEDIUM | 6.5 | Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` and `AzureBlobStorageToTeradataOperator` interpolate the source bucket's credentials as plain string literals into … | Sep 29, 2026 |
| CVE-2026-7395 | UNKNOWN | — | Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet … | Sep 29, 2026 |
| CVE-2026-76720 | MEDIUM | 4.3 | A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect. | Sep 29, 2026 |
| CVE-2026-76719 | HIGH | 8.2 | A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions. | Sep 29, 2026 |
| CVE-2026-76718 | HIGH | 8.2 | A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions. | Sep 29, 2026 |
| CVE-2026-4523 | LOW | 3.7 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain … | Sep 29, 2026 |
| CVE-2026-19547 | UNKNOWN | — | Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable … | Sep 29, 2026 |
| CVE-2026-15390 | UNKNOWN | — | Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can … | Sep 29, 2026 |
| CVE-2026-11796 | UNKNOWN | — | Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availability. These servlets are designed … | Sep 29, 2026 |
| CVE-2026-10518 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain … | Sep 29, 2026 |
| CVE-2026-102474 | MEDIUM | 4.0 | A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \u or \U escape, but the multi-byte token can … | Sep 29, 2026 |
| CVE-2026-102473 | MEDIUM | 5.5 | A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local … | Sep 29, 2026 |
| CVE-2026-96440 | UNKNOWN | — | Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated … | Sep 29, 2026 |
| CVE-2026-96431 | UNKNOWN | — | Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute … | Sep 29, 2026 |
| CVE-2026-96430 | UNKNOWN | — | Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL … | Sep 29, 2026 |
| CVE-2026-96429 | UNKNOWN | — | SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id … | Sep 29, 2026 |
| CVE-2026-96428 | UNKNOWN | — | SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words … | Sep 29, 2026 |
| CVE-2026-92142 | UNKNOWN | — | Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI … | Sep 29, 2026 |
| CVE-2026-91085 | UNKNOWN | — | Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg). SecuredSessionFactoryImpl.checkSecurity() resolves the roles required for an invocation and, when no ACL … | Sep 29, 2026 |
| CVE-2026-91048 | UNKNOWN | — | The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated … | Sep 29, 2026 |
| CVE-2026-91012 | UNKNOWN | — | org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell commands, derives the file it writes a configuration to from caller-supplied input without checking … | Sep 29, 2026 |