Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.3 MEDIUM
CVE-2026-74250 — OpenStack Ironic Autodetect Deploy Interface Improper Cleaning Execution Vulnerability

In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.

ironic | Remote | Misconfiguration
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
4.2 MEDIUM
CVE-2026-74247 — Quay: ssrf via build archive_url in quay build api

A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allow…

openshift quay openshift | Remote | Server-Side Request Forgery
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.9 MEDIUM
CVE-2026-74245 — Quay: unauthenticated exported logs download in quay

A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex…

openshift quay openshift | Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.9 MEDIUM
CVE-2026-74244 — Quay: stripe webhook accepts forged events without signature verification in quay

A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/str…

openshift quay openshift | Remote | Cross-Site Request Forgery
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.5 MEDIUM
CVE-2026-74243 — Quay: unauthenticated secscan notification endpoint in quay when psk is unset

A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint.…

openshift quay openshift | Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.3 MEDIUM
CVE-2026-74242 — Quay: repository notification uuid idor in quay api

A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, inc…

openshift quay openshift | Remote | Information Disclosure
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
4.8 MEDIUM
CVE-2026-74241 — Quay: ldap referral filter injection in quay external ldap authentication

A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly…

openshift quay openshift | Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.4 MEDIUM
CVE-2026-74240 — Quay: jwt claim validation bypasses in quay federated robot and sso authentication

A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enfor…

openshift quay openshift | Remote | Authentication
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
2.0 LOW
CVE-2026-63650 — OpenVPN mbedTLS X.509 Identity Misidentification Vulnerability

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field

Remote | Authentication
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
4.1 MEDIUM
CVE-2026-63649 — OpenVPN Windows Interactive Service Arbitrary Configuration File Loading Vulnerability

The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitra…

| Misconfiguration
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.1 HIGH
CVE-2026-73683 — Laravel Socialite Facebook Provider Authentication Bypass via Nonce Replay

Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim val…

Remote | Authentication
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.8 HIGH
CVE-2026-69414 — Microsoft Defender Elevation of Privilege Vulnerability

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high qua…

Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
4.3 MEDIUM
CVE-2026-74248 — OpenStack Octavia QoS Policy Unauthorized Resource Locking

OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of t…

octavia | Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.8 HIGH
CVE-2026-73682 — Semaphore prior to version 2.18.20 OS Command Injection via git_url Repository Handling

Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows authenticated users holding the Manager or Owner …

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.1 MEDIUM
CVE-2026-71570 — Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-…

Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_icagenda` only could enumerate Joomla user profiles.

Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.3 MEDIUM
CVE-2026-67366 — Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0…

Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the frontend are callable without a CSRF token check.

Remote | Cross-Site Request Forgery
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.8 HIGH
CVE-2026-50523 — Microsoft PowerShell Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.

Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.8 HIGH
CVE-2026-73680 — Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg Filename

Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands …

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.6 HIGH
CVE-2026-71571 — Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filte…

Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permissions to access iCagenda could inject SQL.

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.2 CRITICAL
CVE-2026-67365 — Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11

Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session,…

Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
Showing 20 of 10588 Results