In Discourse versions prior to 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1 a medium severity vulnerability CVE-2026-33514 was detected. This vulnerability allows an authenticated user to read the name and structured content of form templates intended exclusively for categories they are not authorized to access. This occurs due to missing authorization checks when the form templates feature is enabled, leading to the disclosure of site configuration metadata. To address this issue, users should upgrade Discourse to versions 2026.1.4, 2026.3.1, 2026.4.1, or 2026.5.0-latest.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-33514.
Read more CommunicationIn Dolibarr ERP/CRM version 6.0.0 a medium severity vulnerability CVE-2017-14240 was detected. This vulnerability allows attackers to access sensitive information due to a flaw in the document.php file via the file parameter. To address this issue, users should upgrade Dolibarr ERP/CRM to version 6.0.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2017-14240.
Read more ERPIn GitLab CE/EE versions 8.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 a medium severity vulnerability CVE-2026-8280 was detected. This vulnerability allows an authenticated user to cause a denial of service (DoS) through excessive memory consumption due to improper input validation. To address this issue, users should upgrade GitLab CE/EE to versions 18.9.7, 18.10.6, or 18.11.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-8280.
Read more Developer ToolsIn Argo Workflows versions 4.0.0 to before 4.0.5 a high severity vulnerability CVE-2026-42297 was detected. This vulnerability allows any authenticated user, including those using fake Bearer tokens, to create, read, update, and delete Kubernetes ConfigMaps containing synchronization limits. This occurs due to a complete lack of authorization checks on CRUD operations in the Sync Service’s ConfigMap-backed provider. To address this issue, users should upgrade Argo Workflows to version 4.0.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-42297.
Read more Application DevelopmentIn Ansible versions before 1.6.6 a medium severity vulnerability CVE-2014-3498 was detected. This vulnerability allows remote authenticated users to execute arbitrary commands due to a flaw in the user module. To address this issue, users should upgrade Ansible to version 1.6.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2014-3498.
Read more IT Business ManagementIn CKAN versions prior to 2.10.10 and 2.11.5 a critical severity vulnerability CVE-2026-42032 was detected. This vulnerability allows unauthenticated attackers to bypass authorization and gain unauthorized access to private resources and PostgreSQL system information due to a flaw in the datastore_search_sql function. To address this issue, users should upgrade CKAN to versions 2.10.10 or 2.11.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-42032.
Read more Data AnalyticsIn Django versions 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 a medium severity vulnerability CVE-2017-7233 was detected. This vulnerability allows an attacker to conduct open redirect and Cross-Site Scripting (XSS) attacks. This occurs because the django.utils.http.is_safe_url() function incorrectly considers some numeric URLs as safe, potentially leading to unsafe redirects or XSS if developers place these URLs into links. To address this issue, users should upgrade Django to versions 1.10.7, 1.9.13, or 1.8.18. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2017-7233.
Read more Application DevelopmentIn Drupal versions 8.x before 8.2.8 and 8.3.x before 8.3.1 a medium severity vulnerability CVE-2017-6919 was detected. This vulnerability allows authenticated users to bypass critical access restrictions if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests. To address this issue, users should upgrade Drupal to versions 8.2.8 or 8.3.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2017-6919.
Read more Application DevelopmentIn Jenkins versions through 2.93 a low severity vulnerability CVE-2017-17383 was detected. This vulnerability allows remote authenticated administrators to conduct Cross-Site Scripting (XSS) attacks by injecting a specially crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin. To address this issue, users should upgrade Jenkins to version 2.94. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2017-17383.
Read more Developer Tools