CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2026-84942

    Last Modified: 9 Sept 2026

    Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation.

    Published: 8 Sept 2026
    6.1
    Medium

    CVE-2026-76002

    Last Modified: 11 Sept 2026

    ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.

    Published: 8 Sept 2026
    9.1
    Critical

    CVE-2026-75746

    Last Modified: 11 Sept 2026

    ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-76000

    Last Modified: 11 Sept 2026

    ColdFusion is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-75998

    Last Modified: 11 Sept 2026

    ColdFusion is affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.

    Published: 8 Sept 2026
    9.9
    Critical

    CVE-2026-48273

    Last Modified: 9 Sept 2026

    ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 8 Sept 2026
    8.6
    High

    CVE-2026-76190

    Last Modified: 10 Sept 2026

    ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 8 Sept 2026
    8.4
    High

    CVE-2026-75999

    Last Modified: 9 Sept 2026

    ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 8 Sept 2026
    8.5
    High

    CVE-2026-75993

    Last Modified: 10 Sept 2026

    ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-75771

    Last Modified: 9 Sept 2026

    Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-75631

    Last Modified: 9 Sept 2026

    Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-75862

    Last Modified: 9 Sept 2026

    Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2026
    8.6
    High

    CVE-2026-76199

    Last Modified: 9 Sept 2026

    Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-82005

    Last Modified: 9 Sept 2026

    Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-82007

    Last Modified: 9 Sept 2026

    Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-82006

    Last Modified: 9 Sept 2026

    Photoshop Desktop is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-75863

    Last Modified: 9 Sept 2026

    Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-86808

    Last Modified: 8 Sept 2026

    A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 20260819.01 is sufficient to fix this issue. The name of the patch is 3b92dd64d5648f829968cf48bf67dc3113852fef. Upgrading the affected component is advised.

    Published: 8 Sept 2026
    8.6
    High

    CVE-2026-75991

    Last Modified: 11 Sept 2026

    Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 8 Sept 2026
    8.6
    High

    CVE-2026-75990

    Last Modified: 11 Sept 2026

    Illustrator is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-75992

    Last Modified: 9 Sept 2026

    Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2026
    9.9
    Critical

    CVE-2026-84869

    Last Modified: 11 Sept 2026

    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

    Published: 8 Sept 2026
    10
    Critical

    CVE-2026-28659

    Last Modified: 10 Sept 2026

    In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    6.9
    Medium

    CVE-2026-86806

    Last Modified: 8 Sept 2026

    A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. This manipulation causes server-side request forgery. The attack can be initiated remotely. Upgrading to version 2.4.0 is recommended to address this issue. Patch name: b745f62e29fa37364686525a21eee5e5c0f8a369. It is recommended to upgrade the affected component.

    Published: 8 Sept 2026
    10
    Critical

    CVE-2026-49883

    Last Modified: 10 Sept 2026

    In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    6.9
    Medium

    CVE-2026-86804

    Last Modified: 8 Sept 2026

    A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the function CPAResource of the file apps/manager-server/internal/http/controller/proxy/handler.go of the component HTTP Handler. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. Upgrading to version 1.11.11 is able to resolve this issue. The identifier of the patch is 842eec791377ddcbea5cd639bc065eaa4801d656. It is suggested to upgrade the affected component.

    Published: 8 Sept 2026
    4.2
    Medium

    CVE-2026-87053

    Last Modified: 8 Sept 2026

    A flaw was found in operator-sdk-builder. Due to an oversight in the Containerfile configuration, the final built container image runs with root privileges by default. This increases the attack surface of the container, as any process executed within it will have elevated permissions. If a malicious actor compromises the container, they could leverage these root privileges to perform unauthorized actions, potentially leading to a broader system compromise.

    Published: 8 Sept 2026
    4.2
    Medium

    CVE-2026-87054

    Last Modified: 8 Sept 2026

    A flaw was found in operator-sdk-builder. The containers-policy.json configuration file defaults to insecureAcceptAnything for container image registries that are not explicitly listed. This default setting causes signature verification to be entirely skipped for images pulled from these unlisted registries, which could allow for the use of untrusted or malicious container images.

    Published: 8 Sept 2026
    2.6
    Low

    CVE-2026-87055

    Last Modified: 8 Sept 2026

    A flaw was found in operator-sdk-builder. The software uses a flexible label, called a mutable tag, to identify its base container image instead of a unique, fixed identifier. This practice allows the underlying base image to change unexpectedly between builds. Such a change could introduce vulnerabilities or malicious code into the build process, posing a supply chain integrity risk.

    Published: 8 Sept 2026
    2.6
    Low

    CVE-2026-87056

    Last Modified: 8 Sept 2026

    A flaw was found in operator-sdk-builder. The repository lacks automated dependency-update configurations for its git submodules, Containerfile base image, and Tekton bundle references. This absence prevents the automatic flagging of stale or vulnerable dependencies. Consequently, this could lead to the inclusion of known vulnerable components in the build process, increasing the risk of security exposures.

    Published: 8 Sept 2026
    4.2
    Medium

    CVE-2026-87057

    Last Modified: 8 Sept 2026

    A flaw was found in olm-operator-konflux-sample. The build pipelines use mutable floating tags to reference runtime base images instead of immutable SHA256 digests. This configuration allows for the content of the base images to be altered without detection, potentially leading to the introduction of malicious code or unexpected changes in the build process. An attacker could exploit this to compromise the integrity of the software supply chain.

    Published: 8 Sept 2026
    2.6
    Low

    CVE-2026-87058

    Last Modified: 8 Sept 2026

    A flaw was found in olm-operator-konflux-sample. The hermetic build mode is disabled by default, allowing bundle builds to perform live network fetches. This means that external, unverified resources can be pulled during the build process, potentially compromising the integrity and trustworthiness of the resulting software artifacts. This introduces a supply chain risk where the final product might contain unintended or malicious code.

    Published: 8 Sept 2026
    2.6
    Low

    CVE-2026-87059

    Last Modified: 8 Sept 2026

    A flaw was found in olm-operator-konflux-sample. The bundle builder stage installs and upgrades Python packages using pip, a package installer, without verifying their versions or using hash verification. This allows a malicious or compromised package to be introduced into the build process undetected, potentially leading to a supply chain compromise where untrusted code is incorporated into software builds.

    Published: 8 Sept 2026
    2.6
    Low

    CVE-2026-87060

    Last Modified: 8 Sept 2026

    A flaw was found in olm-operator-konflux-sample. The system's automated merging of updates, known as Renovate automerge, is configured too broadly, allowing a wide range of updates without sufficient scrutiny. Additionally, the critical base image for the catalog, ose-operator-registry, is entirely excluded from this update tracking. This combination creates an inconsistent and potentially insecure update process, increasing the risk of unpatched vulnerabilities being introduced into the system.

    Published: 8 Sept 2026
    2.6
    Low

    CVE-2026-87061

    Last Modified: 8 Sept 2026

    A flaw was found in olm-operator-konflux-sample. The `bundle-hack/update_bundle.sh` script lacks mechanisms to stop execution immediately upon encountering an error. This oversight allows critical data processing steps, such as those involving `skopeo` or `jq` commands, to fail silently and proceed with outdated or incomplete information. Consequently, this could lead to data integrity issues within the system.

    Published: 8 Sept 2026
    4.2
    Medium

    CVE-2026-87062

    Last Modified: 8 Sept 2026

    A flaw was found in konflux-operator-tasks. GitHub Actions within this component are configured to use mutable tags or branches instead of specific, immutable commit SHAs. This vulnerability could allow a remote attacker to introduce malicious code into the build process if they compromise the referenced mutable tag or branch. Such a compromise could lead to unauthorized code execution or integrity issues within the affected system.

    Published: 8 Sept 2026
    2.6
    Low

    CVE-2026-87063

    Last Modified: 8 Sept 2026

    A flaw was found in konflux-operator-tasks. The Continuous Integration (CI) process installs the `tkn` command-line interface (CLI) from a network download without verifying its integrity through checksums or digital signatures. This vulnerability could allow a compromised distribution channel to substitute a malicious binary, potentially leading to the execution of unauthorized code within the CI environment.

    Published: 8 Sept 2026
    2.6
    Low

    CVE-2026-87064

    Last Modified: 8 Sept 2026

    A flaw was found in konflux-operator-tasks. The GitHub workflows used by this component do not explicitly define their required permissions. This oversight means the workflows may inherit default access tokens that grant broader privileges than intended. Such excessive permissions could potentially allow an attacker to gain unauthorized access or perform actions beyond the intended scope, leading to information disclosure or unauthorized modifications.

    Published: 8 Sept 2026
    2.6
    Low

    CVE-2026-87065

    Last Modified: 8 Sept 2026

    A flaw was found in konflux-operator-tasks. Tekton task steps within this component run with root privileges without sufficient security hardening. This lack of defense-in-depth controls, such as restricted capabilities or disabled privilege escalation, could potentially allow an attacker to escalate privileges or perform unauthorized actions if another vulnerability is exploited within the root-run process.

    Published: 8 Sept 2026
    2.6
    Low

    CVE-2026-87052

    Last Modified: 8 Sept 2026

    A flaw was found in operator-foundry. The absence of automated dependency-update and vulnerability-scanning configurations in the repository increases the risk of undetected security vulnerabilities. This lack of automated security checks could potentially lead to the inclusion of known vulnerable components, which might then be exploited by an attacker if those underlying vulnerabilities are present and exploitable.

    Published: 8 Sept 2026
    8.7
    High

    CVE-2026-87049

    Last Modified: 8 Sept 2026

    A flaw was found in operator-foundry. Untrusted external actors can exploit over-permissive GitHub access tokens and Google Cloud Platform (GCP) Workload Identity Federation credentials granted to a third-party reusable workflow. By invoking this workflow on untrusted-triggerable events without sufficient authorization checks, an attacker could gain highly privileged access to GitHub and cloud resources, potentially leading to unauthorized control.

    Published: 8 Sept 2026
    4.2
    Medium

    CVE-2026-87050

    Last Modified: 8 Sept 2026

    A flaw was found in operator-foundry. GitHub Actions and reusable workflows within the component are referenced using mutable tags (e.g., `@v0`, `@v4`) instead of fixed commit SHAs. This allows an attacker to potentially alter the code executed in the Continuous Integration (CI) pipeline through an upstream compromise or by re-pointing a tag, leading to unauthorized code execution or manipulation.

    Published: 8 Sept 2026
    2.6
    Low

    CVE-2026-87051

    Last Modified: 8 Sept 2026

    A flaw was found in operator-foundry. The path-containment check, designed to restrict file access within a build context, only performs string-based validation. It fails to resolve symbolic links (symlinks), allowing an attacker to create a symlink within the build context that points to files or directories outside of it. This could enable unauthorized access to files beyond the intended confinement.

    Published: 8 Sept 2026
    10
    Critical

    CVE-2026-82004

    Last Modified: 9 Sept 2026

    Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-86716

    Last Modified: 8 Sept 2026

    A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 8 Sept 2026
    8.5
    High

    CVE-2026-85384

    Last Modified: 10 Sept 2026

    A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution. Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-66307

    Last Modified: 8 Sept 2026

    Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-66303

    Last Modified: 8 Sept 2026

    Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.

    Published: 8 Sept 2026
    8.3
    High

    CVE-2026-69646

    Last Modified: 9 Sept 2026

    Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-69642

    Last Modified: 9 Sept 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.

    Published: 8 Sept 2026
    Items Per Page