Common Vulnerabilities and Exposures (CVE)

CVE-2026-49332

Aug 18, 2026 05:52:06 UTC

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP fram...

CVE-2026-1784

Aug 18, 2026 05:48:06 UTC

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlle...

CVE-2026-46579

Aug 18, 2026 05:42:16 UTC

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plai...

CVE-2026-75091

Aug 18, 2026 05:31:20 UTC

The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. T...

CVE-2026-15748

Aug 18, 2026 05:31:20 UTC

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where...

CVE-2026-75051

Aug 18, 2026 03:55:41 UTC

In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible

CVE-2026-75045

Aug 18, 2026 03:55:40 UTC

In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature

CVE-2026-74254

Aug 18, 2026 03:55:39 UTC

Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in th...

CVE-2026-75056

Aug 18, 2026 03:55:38 UTC

In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible

CVE-2026-75059

Aug 18, 2026 03:55:37 UTC

In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible

CVE-2026-75060

Aug 18, 2026 03:55:36 UTC

In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools

CVE-2026-71947

Aug 18, 2026 03:55:35 UTC

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malici...

CVE-2025-62593

Aug 18, 2026 03:55:33 UTC

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard...

CVE-2026-75007

Aug 18, 2026 03:55:32 UTC

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.

CVE-2026-75003

Aug 18, 2026 03:55:30 UTC

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.