7.1

CVSS4.0

CVE-2026-23984 - Apache Superset: SQLLab Read-Only Bypass on PostgreSQL

An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only verification check when using a PostgreSQL database connection. While the system effectively blocks standard Data Manipulation Language (DML) statements …

📅 Published: Feb. 24, 2026, 12:51 p.m. 🔄 Last Modified: Feb. 26, 2026, 4:25 p.m.

6.5

CVSS3.1

CVE-2026-3121 - Keycloak: org.keycloak/keycloak-services: keycloak: privilege escalation via manage-clients permiss…

A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over roles, users, or other administrative functions with…

📅 Published: Feb. 24, 2026, 11:11 a.m. 🔄 Last Modified: April 15, 2026, 10:45 p.m.

6.5

CVSS3.1

CVE-2025-27555 - Apache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow cli

Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection parameters were set via airflow CLI, values of those variables appeared in the audit log and were stor…

📅 Published: Feb. 24, 2026, 10:09 a.m. 🔄 Last Modified: March 11, 2026, 4:16 p.m.

6.8

CVSS4.0

CVE-2026-2664 - Out of bounds read vulnerability in grpcfuse kernel module

An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows, Linux and macOS up to version 4.61.0 could allow a local attacker to cause an unspecified impact by writing to /proc/docker entries. The issue has been fixed in Docker Desktop 4.…

📅 Published: Feb. 24, 2026, 10:09 a.m. 🔄 Last Modified: Feb. 27, 2026, 5:56 p.m.

8.4

CVSS3.1

CVE-2024-56373 - Apache Airflow: SSTI to Code Execution in Airflow through Shared DB Information

DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server context, which they should normally not be able to do, leading to potentially remote code execution in the context of web-server (server-side) as a r…

📅 Published: Feb. 24, 2026, 10:06 a.m. 🔄 Last Modified: Feb. 26, 2026, 2:44 p.m.

7.7

CVSS3.1

CVE-2024-1524 - A local user can be impersonated when using federated authentication with Silent JIT Provisioning.

When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk that a local user store user's information may be replaced during the account provisioning process in cases where federated users share the same username as local users. There …

📅 Published: Feb. 24, 2026, 8:51 a.m. 🔄 Last Modified: March 3, 2026, 12:32 a.m.

9.4

CVSS4.0

CVE-2025-11165 -

A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileges to bypass class and package restrictions enforced by SecureUberspectorImpl. By dynamically modifying the Velocity engine’s runtime configuration and reinit…

📅 Published: Feb. 24, 2026, 8:27 a.m. 🔄 Last Modified: March 3, 2026, 12:34 a.m.

2.9

CVSS4.0

CVE-2026-1229 - Incorrect calculation in CIRCL secp384r1 CombinedMult

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in v1.6.3 https://github.com/cloudfla…

📅 Published: Feb. 24, 2026, 7:58 a.m. 🔄 Last Modified: March 3, 2026, 12:29 a.m.

9.1

CVSS3.1

CVE-2025-40541 - SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Remote Code Execution Vulnerability

An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium becaus…

📅 Published: Feb. 24, 2026, 7:41 a.m. 🔄 Last Modified: Feb. 26, 2026, 2:44 p.m.

9.1

CVSS3.1

CVE-2025-40540 - SolarWinds Serv-U Type Confusion Remote Code Execution Vulnerability

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequent…

📅 Published: Feb. 24, 2026, 7:41 a.m. 🔄 Last Modified: Feb. 26, 2026, 2:44 p.m.
Total resulsts: 344960
Page 1049 of 34,496
« previous page » next page
Filters