Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-72538 — PrefectHQ Prefect - Argument Injection

An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code execution via the git_clone pull step branch field. The branch parameter is pa…

| Injection
Aug 11, 2026 Sep 03, 2026
Aug 11, 2026
Sep 03, 2026
8.8 HIGH
CVE-2026-72537 — Authentik Security authentik - Privilege Escalation

A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account including superuser…

| Authorization
Aug 11, 2026 Sep 03, 2026
Aug 11, 2026
Sep 03, 2026
8.6 HIGH
CVE-2026-72536 — Chaskiq Chaskiq - Missing Authentication

A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subscription via the stripeCreateIntent GraphQL mutati…

chaskiq | Remote | Authentication
Aug 11, 2026 Sep 03, 2026
Aug 11, 2026
Sep 03, 2026
8.6 HIGH
CVE-2026-72535 — Chaskiq Chaskiq - Missing Authentication

A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint Stripe Billing Portal sessions for any tenant via the stripeCustomerPortal Gra…

chaskiq | Remote | Authentication
Aug 11, 2026 Sep 03, 2026
Aug 11, 2026
Sep 03, 2026
8.8 HIGH
CVE-2026-72534 — Authentik Security authentik - Privilege Escalation

A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to gain superuser privileges by provisioning a SC…

| Authorization
Aug 11, 2026 Sep 03, 2026
Aug 11, 2026
Sep 03, 2026
8.8 HIGH
CVE-2026-72533 — Portainer Portainer CE - Authentication Bypass

An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeat…

| Authorization
Aug 11, 2026 Sep 03, 2026
Aug 11, 2026
Sep 03, 2026
7.4 HIGH
CVE-2026-50237 — Openshift/console: namespace tenant ssrf with egress bypass, catalog poisoning, and admin…

A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the con…

openshift_container_platform grub2 libssh | Remote | Server-Side Request Forgery
Aug 11, 2026 Sep 08, 2026
Aug 11, 2026
Sep 08, 2026
7.4 HIGH
CVE-2026-50236 — Openshift/console: authenticated ssrf with full response reflection and path neutralizati…

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbi…

openshift_container_platform grub2 libssh | Remote | Server-Side Request Forgery
Aug 11, 2026 Sep 08, 2026
Aug 11, 2026
Sep 08, 2026
8.8 HIGH
CVE-2026-13739 — Server-Side Request Forgery (SSRF)

A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to reso…

| Server-Side Request Forgery
Aug 11, 2026 Sep 02, 2026
Aug 11, 2026
Sep 02, 2026
9.2 CRITICAL
CVE-2026-13738 — Improper Authorization Validation

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault i…

| Authorization
Aug 11, 2026 Sep 02, 2026
Aug 11, 2026
Sep 02, 2026
9.2 CRITICAL
CVE-2026-13737 — Command Restriction Bypass

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, inclu…

| Authorization
Aug 11, 2026 Sep 02, 2026
Aug 11, 2026
Sep 02, 2026
10.0 CRITICAL
CVE-2026-58231 — Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploi…

commerce_cloud | Remote | Authentication
Aug 11, 2026 Aug 17, 2026
Aug 11, 2026
Aug 17, 2026
5.3 MEDIUM
CVE-2026-73162 — cti-transmute CSRF Allows Unauthorized Follow and Notification State Changes

Affected versions of MISP cti-transmute expose several state-changing account operations as GET requests: * /account/follow * /account/delete_notification * /account/mark_notificat…

Remote | Cross-Site Request Forgery
Aug 11, 2026 Aug 26, 2026
Aug 11, 2026
Aug 26, 2026
6.8 MEDIUM
CVE-2026-33922 — Path traversal in the Offline archives functionality of the local web interface in Arc be…

A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter. A local user with administrative c…

arc arc | Path Traversal
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
5.2 MEDIUM
CVE-2026-33921 — Npcap driver installed without administrator-only access restriction on Windows in Arc be…

The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to a…

arc arc | Misconfiguration
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
5.1 MEDIUM
CVE-2026-73161 — cti-transmute Conversion Table Allows XSS via Unescaped Cell Content During Search Highli…

Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feature. The highlight() function previously returned the underlying text directly …

Remote | Cross-Site Scripting
Aug 11, 2026 Aug 26, 2026
Aug 11, 2026
Aug 26, 2026
8.7 HIGH
CVE-2026-73160 — cti-transmute Unauthenticated SSRF via Hostnames Resolving to Internal IP Addresses

Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. The URL validation routine checked whether a supplied hostname was itsel…

Remote | Server-Side Request Forgery
Aug 11, 2026 Aug 26, 2026
Aug 11, 2026
Aug 26, 2026
5.1 MEDIUM
CVE-2026-73159 — cti-transmute Stored XSS via Crafted Tag Icon on Admin Triage Interface

Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's v-html. The helper mapIcon() previously constructed an HTML string directly fro…

Remote | Cross-Site Scripting
Aug 11, 2026 Aug 26, 2026
Aug 11, 2026
Aug 26, 2026
5.1 MEDIUM
CVE-2026-73158 — cti-transmute Saved Graph Configuration Allows Stored Cross-Site Scripting via svgIcon

Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can contain style properties that are later consumed by Pivotick, and Pivotick interpre…

Remote | Cross-Site Scripting
Aug 11, 2026 Aug 26, 2026
Aug 11, 2026
Aug 26, 2026
2.3 LOW
CVE-2026-73157 — cti-transmute Remote MISP Event Browser Allows Cross-Site Scripting via Malicious Event M…

Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface using HTML interpolation. Because fields such as event IDs, event information, org…

Remote | Cross-Site Scripting
Aug 11, 2026 Aug 26, 2026
Aug 11, 2026
Aug 26, 2026
Showing 20 of 13972 Results