In Gravity Forms component for WordPress versions 2.10.4 and earlier a high severity vulnerability CVE-2026-12997 was detected. This vulnerability allows unauthenticated attackers to read the contents of arbitrary files on the server. To address this issue, users should upgrade Gravity Forms to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-12997.
Read more CMSIn Argo CD versions before 3.2.12, 3.3.10, and 3.4.2 a medium severity vulnerability CVE-2026-45737 was detected. This vulnerability allows attackers to view sensitive Kubernetes Secret values in UI or CLI diffs. To address this issue, users should upgrade Argo CD to version 3.2.12 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-45737.
Read more Developer ToolsIn Argo CD versions prior to 3.2.12, 3.3.10, and 3.4.2 a high severity vulnerability CVE-2026-45738 was detected. This vulnerability allows attackers to execute arbitrary javascript in a victim’s browser session. To address this issue, users should upgrade Argo CD to version 3.2.12 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-45738.
Read more Developer ToolsIn the MCP Python SDK component for Python versions prior to 1.27.2 a high severity vulnerability CVE-2026-52869 was detected. This vulnerability allows an authenticated attacker to inject JSON-RPC messages into another user’s session. To address this issue, users should upgrade the MCP Python SDK to version 1.27.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-52869.
Read more Application DevelopmentIn mcp component for Python versions from 1.23.0 until 1.27.2 a high severity vulnerability CVE-2026-52870 was detected. This vulnerability allows any connected client to enumerate, read results from, or cancel other clients’ tasks. To address this issue, users should upgrade mcp to version 1.27.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-52870.
Read more Application DevelopmentIn Redash versions from 5.0.2 to 26.3.0 a medium severity vulnerability CVE-2026-33213 was detected. This vulnerability allows attackers to redirect users to malicious external websites. To address this issue, users should upgrade Redash to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-33213.
Read more Data AnalyticsIn NGINX a high severity vulnerability CVE-2026-42533 was detected. This vulnerability allows an attacker to cause a denial of service. To address this issue, users should upgrade NGINX to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-42533.
Read more Application DevelopmentIn ngx_http_ssi_module component for NGINX certain versions a medium severity vulnerability CVE-2026-56434 was detected. This vulnerability allows an attacker to potentially access sensitive information. To address this issue, users should upgrade NGINX to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-56434.
Read more Application DevelopmentIn NGINX in versions prior to the patched release a medium severity vulnerability CVE-2026-52865 was detected. This vulnerability allows an authenticated attacker to cause the Ingress Controller process to terminate. To address this issue, users should upgrade NGINX to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-52865.
Read more Application Development