In Drupal versions 7.x before 7.26 a medium severity vulnerability CVE-2014-1476 was detected. This vulnerability allows remote authenticated users to obtain sensitive information by viewing unpublished content via a taxonomy listing page on sites upgraded from earlier versions. To address this issue, users should upgrade Drupal to version 7.26. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2014-1476.
Read more Application DevelopmentIn FreeIPA versions 2.x and 3.x before 3.1.2 a high severity vulnerability CVE-2012-5484 was detected. This vulnerability allows attackers to perform man-in-the-middle (MITM) attacks and spoof a join procedure via a crafted certificate because the client does not properly obtain the Certification Authority (CA) certificate from the server. To address this issue, users should upgrade FreeIPA to version 3.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2012-5484.
Read more SecurityIn Prefect versions up to 3.6.21 a high severity vulnerability CVE-2026-7722 was detected. This vulnerability allows remote attackers to bypass authentication by manipulating the endswith function within the /api/health endpoint. To address this issue, users should upgrade Prefect to version 3.6.22. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-7722.
Read more Developer ToolsIn Prometheus versions prior to 3.5.3 and 3.11.3 a high severity vulnerability CVE-2026-42154 was detected. This vulnerability allows unauthenticated attackers to send a small, specially crafted snappy-compressed payload to the remote read endpoint (/api/v1/read) that causes a massive heap allocation, leading to memory exhaustion and crashing the Prometheus process (Denial of Service). To address this issue, users should upgrade Prometheus to versions 3.5.3 or 3.11.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-42154.
Read more Data AnalyticsIn Django versions 6.0 before 6.0.5 and 5.2 before 5.2.14 a medium severity vulnerability CVE-2026-6907 was detected. This vulnerability allows attackers to potentially access exposed private data because UpdateCacheMiddleware erroneously caches requests where the Vary header contains an asterisk (‘*’), leading to sensitive data being improperly stored and served. To address this issue, users should upgrade Django to versions 6.0.5 or 5.2.14. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-6907.
Read more Application DevelopmentIn Django versions 6.0 before 6.0.5 and 5.2 before 5.2.14 a medium severity vulnerability CVE-2026-5766 was detected. This vulnerability allows attackers to bypass the FILE_UPLOAD_MAX_MEMORY_SIZE limit by sending ASGI requests with a missing or understated Content-Length header, potentially loading large files into memory and causing service degradation (Denial of Service). To address this issue, users should upgrade Django to versions 6.0.5 or 5.2.14. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5766.
Read more Application DevelopmentIn Django versions 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 a medium severity vulnerability CVE-2013-6044 was detected. This vulnerability allows attackers to introduce cross-site scripting (XSS) or other vulnerabilities by exploiting the is_safe_url function, which improperly treats a URL’s scheme as safe even if it is not HTTP or HTTPS (such as the javascript: scheme). To address this issue, users should upgrade Django to versions 1.4.6, 1.5.2, or 1.6 beta 2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2013-6044.
Read more Application DevelopmentIn Appsmith versions up to 1.97 a high severity vulnerability CVE-2026-5418 was detected. This vulnerability allows remote attackers to launch server-side request forgery (SSRF) attacks by manipulating the computeDisallowedHosts function within the Dashboard component. To address this issue, users should upgrade Appsmith to version 1.99. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5418.
Read more Application DevelopmentIn Argo CD versions 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9 a high severity vulnerability CVE-2026-43824 was detected. This vulnerability allows attackers to read cleartext Kubernetes Secret data via the ServerSideDiff feature. To address this issue, users should upgrade Argo CD to versions 3.2.11 or 3.3.9. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-43824.
Read more Developer Tools