Search
442 CVEs · published 2026-08-12 to 2026-08-12
CVEs (442)
Showing 251–275 of 442
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-59244 | MEDIUM | Patched | 6.5 | 2026-08-12 | Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guar… |
| CVE-2026-59242 | MEDIUM | Patched | 5.4 | 2026-08-12 | Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_che… |
| CVE-2026-58076 | HIGH | Patched | 8.8 | 2026-08-12 | Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arg… |
| CVE-2026-54183 | MEDIUM | Patched | 4.3 | 2026-08-12 | Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into val… |
| CVE-2026-19548 | MEDIUM | 5.5 | 2026-08-12 | Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is tha… | |
| CVE-2026-15803 | NONE | Patched | — | 2026-08-12 | In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data or query results, per… |
| CVE-2025-35988 | NONE | — | 2026-08-12 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-35977 | NONE | — | 2026-08-12 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-32737 | NONE | — | 2026-08-12 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-32087 | NONE | — | 2026-08-12 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-32084 | NONE | — | 2026-08-12 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-31943 | NONE | — | 2026-08-12 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-30178 | NONE | — | 2026-08-12 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-27570 | NONE | — | 2026-08-12 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-27245 | NONE | — | 2026-08-12 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-25275 | NONE | — | 2026-08-12 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-24837 | NONE | — | 2026-08-12 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-24488 | NONE | — | 2026-08-12 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2025-20020 | NONE | — | 2026-08-12 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | |
| CVE-2026-73432 | NONE | — | 2026-08-12 | Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization functionality. Remote instance addresses were valida… | |
| CVE-2026-73431 | NONE | — | 2026-08-12 | Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activation and recovery links were generated using sta… | |
| CVE-2026-73405 | NONE | — | 2026-08-12 | An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) streams through the /pubsub/… | |
| CVE-2026-73374 | NONE | — | 2026-08-12 | A stored cross-site scripting (XSS) vulnerability existed in Vulnerability-Lookup in the render_tag_badges Jinja filter used to display reference tags associated with vulne… | |
| CVE-2026-73291 | HIGH | Patched | 7.1 | 2026-08-12 | Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the up… |
| CVE-2026-73290 | MEDIUM | Patched | 5.3 | 2026-08-12 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request in rustfs/src/storage/access.rs that lacks a di… |