VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,557 CVE recordsPage 911 of 1238 · EPSS data 2026.08.08
ReviewHigh
CVE-2026-1529

Red Hat Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2.13, Red Hat build of Keycloak 26.4

A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized organization, leading to unauthorized access.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-1486

Red Hat Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4.9

A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lookup mechanism (lookupIdentityProviderFromIssuer) retrieves the IdP configuration but does not filter for isEnabled=false. If an administrator disables an IdP (e.g., due to a compromise or offboarding), an entity possessing that IdP's signing key can still generate valid JWT assertions that Keycloak accepts, resulting in the issuance of valid access tokens.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-24678

FreeRDP FreeRDP, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callback after a device channel close, leading to a use after free in ecam_channel_write. This vulnerability is fixed in 3.22.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-1615

jsonpath, org.webjars.npm:jsonpath, Red Hat Ansible Automation Platform 2.5

Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not designed to handle untrusted data safely. An attacker can exploit this vulnerability by supplying a malicious JSON Path expression that, when evaluated, executes arbitrary JavaScript code, leading to Remote Code Execution in Node.js environments or Cross-site Scripting (XSS) in browser contexts. This affects all methods that evaluate JSON Paths against objec...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-25859

WeKan WeKan, wekan

Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-25858

macrozheng mall

macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a victim’s telephone number. The password reset flow exposes the one-time password (OTP) directly in the API response and validates password reset requests solely by comparing the provided OTP to a value stored by telephone number, without verifying user identity or ownership of the telephone number. This enables remote account takeover of any user with a known or guessable tel...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-25568

WeKan WeKan, wekan

WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public boards due to incomplete server-side enforcement.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-25566

WeKan WeKan, wekan

WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without adequate authorization checks for the destination and without validating that destination objects belong to the destination board, potentially enabling unauthorized cross-board moves.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-25565

WeKan WeKan, wekan

WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write permission. This can allow users with read-only roles to perform card updates that should require write access.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-25564

WeKan WeKan, wekan

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID tampering by manipulating identifiers.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-25563

WeKan WeKan, wekan

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID tampering by manipulating identifiers.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-25561

WeKan WeKan, wekan

WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that provided identifiers (such as boardId, cardId, swimlaneId, and listId) are consistent and refer to a coherent card/board relationship, enabling attempts to upload attachments with mismatched object relationships.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-25560

WeKan WeKan, wekan

WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping, allowing an attacker to manipulate LDAP queries during authentication.

The CVSS severity warrants an early asset and exposure review.
CISA KEVCritical
CVE-2026-1731

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewHigh
CVE-2026-25580

pydantic pydantic-ai, Red Hat Enterprise Linux AI (RHEL AI) 3, pydantic ai

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic AI's URL download functionality. When applications accept message history from untrusted sources, attackers can include malicious URLs that cause the server to make HTTP requests to internal network resources, potentially accessing internal services or cloud credentials. This vulnerability only affects applications that accept message history from external users. This vulnerability is fixed in 1...

The CVSS severity warrants an early asset and exposure review.