Recent vulnerabilities


ID CVSS Description Vendor Product Published Updated
cve-2026-15217 8.7 (v3.1) Improper Neutralization of Input During Web Page Gener… GitLab
GitLab
2026-08-12T19:04:51.420Z 2026-08-13T14:40:06.098Z
cve-2026-15216 8.7 (v3.1) Improper Neutralization of Input During Web Page Gener… GitLab
GitLab
2026-08-12T19:04:46.419Z 2026-08-13T14:40:53.789Z
cve-2026-16494 7.1 (v3.1) Missing Authorization in GitLab GitLab
GitLab
2026-08-12T19:04:36.421Z 2026-08-13T14:41:39.675Z
cve-2026-18433 4.3 (v3.1) Incorrect Authorization in GitLab GitLab
GitLab
2026-08-12T19:04:26.420Z 2026-08-13T14:42:24.418Z
cve-2026-19228 8.5 (v3.1) Authorization Bypass Through User-Controlled Key in GitLab GitLab
GitLab
2026-08-12T19:04:16.530Z 2026-08-13T14:43:02.808Z
cve-2026-73406 Budibase: Unauthenticated user information disclosure … Budibase
budibase
2026-08-12T19:03:51.766Z 2026-08-13T14:07:05.692Z
cve-2026-73308 Budibase: OAuth2 Token Disclosure via Automation Test … Budibase
budibase
2026-08-12T19:01:15.182Z 2026-08-14T21:55:19.960Z
cve-2026-73330 7.5 (v4.0) 6.6 (v3.1) CamaleonCMS 2.9.1 Server-Side Template Injection via t… owen2345
CamaleonCMS
2026-08-12T19:00:36.609Z 2026-08-14T16:52:27.408Z
cve-2026-73307 Budibase: SSRF via bare fetch() in uploadUrl during AI… Budibase
budibase
2026-08-12T18:59:52.011Z 2026-08-12T19:46:08.763Z
cve-2026-73306 Budibase: Account Enumeration via Login Lockout Respon… Budibase
budibase
2026-08-12T18:56:08.322Z 2026-08-13T12:18:51.707Z
cve-2026-73329 9.2 (v4.0) 8.7 (v3.1) CamaleonCMS Stored XSS via Draft Post Title Creation E… owen2345
CamaleonCMS
2026-08-12T18:54:07.352Z 2026-08-14T16:52:26.722Z
cve-2026-18679 5.8 (v4.0) Kong Mesh: kuma-dp connects to the control plane witho… Kong Inc.
Kong Mesh
2026-08-12T18:52:31.146Z 2026-08-13T14:45:35.957Z
cve-2026-73303 Budibase: Email Change IDOR via POST /api/v2/email all… Budibase
budibase
2026-08-12T18:51:38.748Z 2026-08-12T22:11:41.829Z
cve-2026-18678 5.5 (v4.0) Kong Mesh: kumactl connects to the control plane witho… Kong Inc.
Kong Mesh
2026-08-12T18:49:45.530Z 2026-08-13T14:47:36.551Z
cve-2026-18677 6 (v4.0) Kong Mesh: a dataplane token without a workload bindin… Kong Inc.
Kong Mesh
2026-08-12T18:47:06.710Z 2026-08-13T14:49:27.614Z
cve-2026-18676 5.1 (v4.0) Kong Mesh: default control plane config leaks the admi… Kong Inc.
Kong Mesh
2026-08-12T18:42:38.843Z 2026-08-13T14:50:43.069Z
cve-2026-18952 8.6 (v4.0) 8.1 (v3.1) Missing Input Validation in Threat Intel Feed Parser i… AWS
Opensearch
2026-08-12T18:42:38.633Z 2026-08-21T18:22:28.717Z
cve-2026-18675 5.3 (v4.0) Kong Mesh: control plane denial of service via a malfo… Kong Inc.
Kong Mesh
2026-08-12T18:36:17.377Z 2026-08-13T15:28:44.341Z
cve-2026-19311 8.6 (v4.0) 8.1 (v3.1) Missing Authorization in Execute Monitor API in OpenSe… AWS
OpenSearch
2026-08-12T18:34:02.669Z 2026-08-13T14:53:00.212Z
cve-2026-18673 5.3 (v4.0) Kong Mesh: the kuma-dp readiness service exposes the E… Kong Inc.
Kong Mesh
2026-08-12T18:20:33.205Z 2026-08-13T14:54:00.482Z
cve-2026-73301 Budibase: Missing RBAC on GET /api/global/groups allow… Budibase
budibase
2026-08-12T18:08:07.998Z 2026-08-14T21:53:29.056Z
cve-2026-7427 5.3 (v3.1) Allocation of Resources Without Limits or Throttling i… GitLab
GitLab
2026-08-12T18:06:10.271Z 2026-08-13T14:55:04.449Z
cve-2026-8667 4.3 (v3.1) Incorrect Authorization in GitLab GitLab
GitLab
2026-08-12T18:06:00.271Z 2026-08-13T14:56:08.625Z
cve-2026-73300 Budibase: SQL Injection via `multipleStatements: true` Budibase
budibase
2026-08-12T18:05:51.428Z 2026-08-12T18:55:16.387Z
cve-2026-15423 8.5 (v3.1) Incorrect Authorization in GitLab GitLab
GitLab
2026-08-12T18:05:50.271Z 2026-08-13T14:57:10.045Z
cve-2026-16627 7.7 (v3.1) Improper Neutralization of Input During Web Page Gener… GitLab
GitLab
2026-08-12T18:05:40.268Z 2026-08-13T03:55:50.759Z
cve-2026-18244 4.3 (v3.1) Missing Authorization in GitLab GitLab
GitLab
2026-08-12T18:05:30.375Z 2026-08-13T15:03:21.129Z
cve-2026-73327 N/A {'providerMetadata': {'orgId': '83251b91-4cc7-4094-a5c7-464a1b83ea10', 'shortName': 'VulnCheck', 'dateUpdated': '2026-08-17T19:15:06.958Z'}, 'rejectedReasons': [{'lang': 'en', 'value': 'This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported behavior is intentional. The update process is designed to write files to disk and is restricted to the highest-privilege users working with cryptographically verified Joomla archives.', 'supportingMedia': [{'type': 'text/html', 'base64': False, 'value': 'This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported behavior is intentional. The update process is designed to write files to disk and is restricted to the highest-privilege users working with cryptographically verified Joomla archives.'}]}], 'x_generator': {'engine': 'Vulnogram 1.0.4'}} N/A N/A 2026-08-12T18:05:19.383Z 2026-08-17T19:15:06.958Z
cve-2026-69106 8.8 (v3.1) Potential cache poisoning in JFrog Artifactory jfrog
artifactory
2026-08-12T17:48:29.429Z 2026-08-13T15:04:49.658Z
cve-2026-42018 7.5 (v3.1) Anonymous user token generation exposure in JFrog Arti… jfrog
artifactory
2026-08-12T17:43:21.289Z 2026-09-12T03:55:21.730Z
ID CVSS Description Vendor Product Published Updated
ID Description Package Published Updated
ID Description Type
ID Description Updated
ID Description Updated
ID Description Updated
ID Description