Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54298
Total
4306
Critical
16144
High
15836
Medium
CVE ID Severity Score Description Published
CVE-2026-86843 MEDIUM 6.3 The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the … Sep 29, 2026
CVE-2026-84739 HIGH 8.7 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain … Sep 29, 2026
CVE-2026-81930 MEDIUM 6.3 Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built … Sep 29, 2026
CVE-2026-81914 MEDIUM 4.3 Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character … Sep 29, 2026
CVE-2026-81862 MEDIUM 6.5 Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` and `AzureBlobStorageToTeradataOperator` interpolate the source bucket's credentials as plain string literals into … Sep 29, 2026
CVE-2026-7395 UNKNOWN — Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet … Sep 29, 2026
CVE-2026-76720 MEDIUM 4.3 A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect. Sep 29, 2026
CVE-2026-76719 HIGH 8.2 A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions. Sep 29, 2026
CVE-2026-76718 HIGH 8.2 A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions. Sep 29, 2026
CVE-2026-4523 LOW 3.7 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain … Sep 29, 2026
CVE-2026-19547 UNKNOWN — Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable … Sep 29, 2026
CVE-2026-15390 UNKNOWN — Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can … Sep 29, 2026
CVE-2026-11796 UNKNOWN — Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availability. These servlets are designed … Sep 29, 2026
CVE-2026-10518 MEDIUM 4.3 GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain … Sep 29, 2026
CVE-2026-102474 MEDIUM 4.0 A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \u or \U escape, but the multi-byte token can … Sep 29, 2026
CVE-2026-102473 MEDIUM 5.5 A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local … Sep 29, 2026
CVE-2026-96440 UNKNOWN — Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated … Sep 29, 2026
CVE-2026-96431 UNKNOWN — Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute … Sep 29, 2026
CVE-2026-96430 UNKNOWN — Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL … Sep 29, 2026
CVE-2026-96429 UNKNOWN — SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id … Sep 29, 2026
CVE-2026-96428 UNKNOWN — SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words … Sep 29, 2026
CVE-2026-92142 UNKNOWN — Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI … Sep 29, 2026
CVE-2026-91085 UNKNOWN — Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg). SecuredSessionFactoryImpl.checkSecurity() resolves the roles required for an invocation and, when no ACL … Sep 29, 2026
CVE-2026-91048 UNKNOWN — The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated … Sep 29, 2026
CVE-2026-91012 UNKNOWN — org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell commands, derives the file it writes a configuration to from caller-supplied input without checking … Sep 29, 2026