Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-72743 — SQLBot 1.10.0 SQText Dashboard Component Stored XSS via v-html

SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders TinyMCE output via v-html without sanitization. Att…

sqlbot | Remote | Cross-Site Scripting
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
7.8 HIGH
CVE-2026-63622 — Libvirt: swtpm privilege escalation via symlink following

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By p…

Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
9.3 CRITICAL
CVE-2026-48160 — react-tracked was vulnerable to malicious code execution via compromised commits

react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the default branch contained malicious commits 6978272a7d6ca02225cb747ea69f427512e33699 …

Remote | Supply Chain
Aug 10, 2026 Aug 11, 2026
Aug 10, 2026
Aug 11, 2026
3.9 LOW
CVE-2026-19411 — Shim/dp.c library: null-pointer dereference in is_removable_media_path() when devicepatht…

A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack on a system that uses shim …

enterprise_linux enterprise_linux | Memory Corruption
Aug 10, 2026 Aug 14, 2026
Aug 10, 2026
Aug 14, 2026
8.8 HIGH
CVE-2026-18982 — Odh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit/a…

A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of t…

openshift_ai | Remote | Authorization
Aug 10, 2026 Aug 27, 2026
Aug 10, 2026
Aug 27, 2026
8.8 HIGH
CVE-2026-18951 — Odh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggregates train…

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit Cl…

openshift_ai | Remote | Authorization
Aug 10, 2026 Aug 27, 2026
Aug 10, 2026
Aug 27, 2026
8.8 HIGH
CVE-2026-18950 — Odh-dashboard: odh-dashboard: confused-deputy privilege escalation via unchecked roleref …

A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` fiel…

openshift_ai | Remote | Authorization
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
8.8 HIGH
CVE-2026-18949 — Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac ma…

A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This e…

openshift_ai | Remote | Authorization
Aug 10, 2026 Aug 14, 2026
Aug 10, 2026
Aug 14, 2026
9.9 CRITICAL
CVE-2026-18948 — Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server…

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to sto…

openshift_ai | Remote | Authentication
Aug 10, 2026 Aug 27, 2026
Aug 10, 2026
Aug 27, 2026
8.5 HIGH
CVE-2026-18947 — Feast: feast: authorization bypass in /materialize endpoints enables dos via unauthorized…

A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views…

openshift_ai | Remote | Authorization
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
5.5 MEDIUM
CVE-2026-18942 — Feast-operator: feast: feast apply cronjob runs user python with feature-server sa — tena…

A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, all…

openshift_ai | Remote | Injection
Aug 10, 2026 Aug 19, 2026
Aug 10, 2026
Aug 19, 2026
7.7 HIGH
CVE-2026-18941 — Feast: feast-operator: feast: default authentication mode is no_auth — shared multi-tenan…

A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no security manager is installed. This default allows unaut…

openshift_ai | Remote | Authentication
Aug 10, 2026 Aug 14, 2026
Aug 10, 2026
Aug 14, 2026
7.6 HIGH
CVE-2026-18621 — Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypas…

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allo…

openshift_ai ai_inference_server | Remote | Authorization
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-18620 — Data-sciences-pipeline: user-controlled serviceaccount for workflow pods without authoriz…

A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged…

openshift_ai | Remote | Authorization
Aug 10, 2026 Aug 27, 2026
Aug 10, 2026
Aug 27, 2026
7.5 HIGH
CVE-2026-18618 — Ml-metdata: bundled grpc 1.46.3 (2022) with published http/2 dos cves — directly reachabl…

A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network…

openshift_ai | Remote | Denial of Service
Aug 10, 2026 Aug 14, 2026
Aug 10, 2026
Aug 14, 2026
8.8 HIGH
CVE-2026-18617 — Data-science-pipelines-operator: dspo: mysql dsn parameter injection via customextraparam…

A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerou…

openshift_ai | Remote | Injection
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
7.5 HIGH
CVE-2026-18611 — Data-science-pipelines-operator: dspo: cryptographically weak secret generation (math/ran…

A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/se…

openshift_ai | Remote | Cryptography
Aug 10, 2026 Aug 27, 2026
Aug 10, 2026
Aug 27, 2026
8.7 HIGH
CVE-2026-18608 — Data-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:*, kubeflow.…

A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. Th…

openshift_ai | Remote | Authorization
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-16456 — Odh-model-controller: odh-model-controller: cross-namespace secret read via nim account c…

A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the `loadSecret` function. This function improperly re…

openshift_ai | Remote | Information Disclosure
Aug 10, 2026 Aug 14, 2026
Aug 10, 2026
Aug 14, 2026
8.0 HIGH
CVE-2026-15581 — Trustyai-service-operator: trustyai-service-operator: tas internal service bypasses kube-…

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can e…

openshift_ai | Authentication
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
Showing 20 of 13969 Results