| | CVE-2026-19682 | Tenable | critical | 9.9 | 1.9%
| | A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker… | Aug 14, 2026 | Aug 19, 2026 |
| | CVE-2026-19681 | Tenable | critical | 9.9 | 2.2%
| | An authenticated command injection vulnerability exists in Security Center related to file upload pr… | Aug 14, 2026 | Aug 19, 2026 |
| | CVE-2026-19680 | Tenable | high | 7.1 | 0.3%
| | A SQL injection vulnerability exists in Security Center that could allow an attacker to access unaut… | Aug 14, 2026 | Aug 19, 2026 |
| | CVE-2026-19679 | Tenable | high | 8.8 | 1.6%
| | An input validation vulnerability exists in Security Center's file upload handling, where insufficie… | Aug 14, 2026 | Aug 19, 2026 |
| | CVE-2026-19639 | Tenable | medium | 4.3 | 0.3%
| | An improper access control vulnerability exists where an authenticated non-administrative applicatio… | Aug 14, 2026 | Aug 19, 2026 |
| | CVE-2026-19636 | Tenable | medium | 5.3 | 0.3%
| | An issue was identified in which CSRF tokens were generated using a predictable method, potentially … | Aug 14, 2026 | Aug 19, 2026 |
| | CVE-2026-19635 | Tenable | high | 8.8 | 0.2%
| | A local privilege escalation vulnerability exists in Security Center. An attacker with write access … | Aug 14, 2026 | Aug 19, 2026 |
| | CVE-2026-19631 | Tenable | medium | 4.9 | 0.4%
| | A SQL injection vulnerability exists in Security Center that could allow an authenticated administra… | Aug 14, 2026 | Aug 19, 2026 |
| | CVE-2026-19629 | Tenable | high | 8.1 | 0.4%
| | A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Secu… | Aug 14, 2026 | Aug 19, 2026 |
| | CVE-2026-19628 | Tenable | high | 7.2 | 2.0%
| | A command injection vulnerability exists in Tenable Security Center. An authenticated administrator … | Aug 14, 2026 | Aug 19, 2026 |
| | CVE-2026-19626 | Tenable | critical | 9.9 | 0.8%
| | A remote code execution vulnerability exists in Tenable Security Center's report generation function… | Aug 14, 2026 | Aug 19, 2026 |
| | CVE-2026-19879 | Red Hat | medium | 5.3 | 0.2%
| | A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `wri… | Aug 14, 2026 | Aug 14, 2026 |
| | CVE-2026-73633 | Apache | high | 7.5 | 0.3%
| | Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an applica… | Aug 14, 2026 | Aug 18, 2026 |
| | CVE-2026-74240 | Red Hat | medium | 5.4 | 0.2%
| | A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and … | Aug 14, 2026 | Aug 14, 2026 |
| | CVE-2026-74242 | Red Hat | medium | 5.3 | 0.3%
| | A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a targe… | Aug 14, 2026 | Aug 14, 2026 |
| | CVE-2026-74241 | Red Hat | medium | 4.8 | 0.2%
| | A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authenticat… | Aug 14, 2026 | Aug 14, 2026 |
| | CVE-2026-74243 | Red Hat | medium | 6.5 | 0.3%
| | A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a re… | Aug 14, 2026 | Aug 14, 2026 |
| | CVE-2026-74244 | Red Hat | medium | 5.9 | 0.1%
| | A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unau… | Aug 14, 2026 | Aug 14, 2026 |
| | CVE-2026-74247 | Red Hat | medium | 4.2 | 0.1%
| | A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write acc… | Aug 14, 2026 | Aug 14, 2026 |
| | CVE-2026-74245 | Red Hat | medium | 5.9 | 0.3%
| | A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid f… | Aug 14, 2026 | Aug 14, 2026 |
| | CVE-2026-56657 | Red Hat | medium | 6.5 | — | | A flaw was found in Gitea. The SSH Key Parser component is vulnerable to a denial of service. A remo… | Aug 13, 2026 | Aug 13, 2026 |
| | CVE-2026-66804 | Red Hat | high | 7.7 | 3.0%
| | Improper access control in Windows Cross Device Service allows an authorized attacker to elevate pri… | Aug 13, 2026 | Aug 13, 2026 |
| | CVE-2026-73585 | Red Hat | medium | 6.3 | — | | A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration s… | Aug 13, 2026 | Aug 13, 2026 |
| | CVE-2026-73584 | Red Hat | medium | 6.3 | — | | A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during… | Aug 13, 2026 | Aug 13, 2026 |
| | CVE-2026-73583 | Red Hat | medium | 6.6 | — | | A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe des… | Aug 13, 2026 | Aug 13, 2026 |
| | CVE-2026-11970 | Forcepoint | medium | — | 0.1%
| | This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExt… | Aug 13, 2026 | Sep 3, 2026 |
| | CVE-2026-67986 | Red Hat | high | 7.8 | — | | A flaw was found in amazing_print. This vulnerability allows an attacker to inject and execute arbit… | Aug 13, 2026 | Aug 13, 2026 |
| | CVE-2026-68454 | Red Hat | medium | 5.5 | — | | A flaw was found in the KVM (Kernel-based Virtual Machine) subsystem of the Linux kernel, affecting … | Aug 13, 2026 | Aug 13, 2026 |
| | CVE-2026-68453 | Red Hat | medium | 7.0 | — | | A flaw was found in the Linux kernel's s390/zcrypt component. This vulnerability arises from insuffi… | Aug 13, 2026 | Aug 13, 2026 |
| | CVE-2026-68452 | Red Hat | medium | 7.0 | — | | A flaw was found in the Linux kernel's s390/zcrypt component. This vulnerability arises from insuffi… | Aug 13, 2026 | Aug 13, 2026 |
| | CVE-2026-68451 | Red Hat | medium | 7.0 | — | | A flaw was found in the Linux kernel's s390 zcrypt module. The `cca_ecc2protkey()` function, respons… | Aug 13, 2026 | Aug 13, 2026 |
| | CVE-2026-73240 | Apache | critical | 9.8 | 0.4%
| | Specifically crafted inputs may lead to git argument injection in Apache Allura.
This issue affects… | Aug 12, 2026 | Aug 17, 2026 |
| | CVE-2026-73239 | Apache | medium | 6.5 | 0.2%
| | Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types… | Aug 12, 2026 | Aug 17, 2026 |
| | CVE-2026-73238 | Apache | medium | 6.1 | 0.2%
| | XSS vulnerability in code display in Apache Allura.
This issue affects Apache Allura: before 1.19.1… | Aug 12, 2026 | Aug 17, 2026 |
| | CVE-2026-73237 | Apache | medium | 6.1 | 0.2%
| | XSS vulnerability in Markdown handling in Apache Allura.
This issue affects Apache Allura: from 1.1… | Aug 12, 2026 | Aug 17, 2026 |
| | CVE-2026-68971 | Apache | medium | 6.5 | 0.1%
| | Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and t… | Aug 12, 2026 | Aug 13, 2026 |
| | CVE-2026-68970 | Apache | medium | 6.5 | 0.2%
| | Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so sec… | Aug 12, 2026 | Aug 14, 2026 |
| | CVE-2026-68969 | Apache | medium | 6.5 | 0.2%
| | Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext w… | Aug 12, 2026 | Aug 13, 2026 |
| | CVE-2026-68968 | Apache | high | 7.5 | 0.2%
| | Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever … | Aug 12, 2026 | Aug 13, 2026 |
| | CVE-2026-68076 | Apache | medium | 5.4 | 0.3%
| | Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable … | Aug 12, 2026 | Aug 14, 2026 |
| | CVE-2026-67587 | Apache | high | 8.8 | 0.4%
| | Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constru… | Aug 12, 2026 | Aug 17, 2026 |
| | CVE-2026-67260 | Apache | high | 7.3 | 0.3%
| | Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task… | Aug 12, 2026 | Aug 17, 2026 |
| | CVE-2026-65017 | Apache | medium | 6.5 | 0.4%
| | Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team de… | Aug 12, 2026 | Aug 14, 2026 |
| | CVE-2026-59244 | Apache | medium | 6.5 | 0.2%
| | Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the… | Aug 12, 2026 | Aug 18, 2026 |
| | CVE-2026-59242 | Apache | medium | 5.4 | 0.6%
| | Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a strin… | Aug 12, 2026 | Aug 14, 2026 |
| | CVE-2026-58076 | Apache | high | 8.8 | 0.5%
| | Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a… | Aug 12, 2026 | Aug 18, 2026 |
| | CVE-2026-54183 | Apache | medium | 4.3 | 0.5%
| | Apache Airflow's secrets masker hides values stored under sensitive key names when they are displaye… | Aug 12, 2026 | Aug 14, 2026 |
| | CVE-2026-70468 | Fortinet | high | 7.3 | — | | A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.… | Aug 12, 2026 | Aug 13, 2026 |
| | CVE-2026-26035 | Fortinet | high | 8.8 | — | | An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through … | Aug 12, 2026 | Aug 13, 2026 |
| | CVE-2026-70466 | Fortinet | medium | 4.8 | — | | A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, Forti… | Aug 12, 2026 | Aug 13, 2026 |