| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-27880 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-27528 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-27511 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-27393 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-27381 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-27302 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-27299 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-26594 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-25778 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-25079 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-24596 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-24543 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-24541 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-24462 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-24017 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-24013 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-23905 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-22658 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2023-22431 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | ||
| CVE-2022-51007 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2022-51006 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2022-51005 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2022-51004 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2022-51003 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2022-51002 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2022-51001 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2021-48005 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2021-48004 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2021-48003 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2021-48002 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2021-48001 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2021-48000 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2021-47999 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2021-47998 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2021-47997 | — | 0.00 | — | — | Aug 27, 2026 | Rejected reason: This CVE ID has been rejected. | ||
| CVE-2026-81814 | Med | 0.26 | — | 0.00 | Aug 27, 2026 | Affected versions of Flowintel render calendar event titles using innerHTML. Because those titles are derived from case titles, a user able to create or modify a case title could store HTML or script-capable content that is later interpreted by the browser when another user… | ||
| CVE-2026-81753 | Med | 0.26 | — | 0.01 | Aug 27, 2026 | Affected versions of Flowintel render Mermaid blocks contained in stored case notes without sufficiently neutralizing attacker-controlled markup. Because Mermaid note content is persisted and later rendered for other users, an attacker with permission to create or edit a note… | ||
| CVE-2026-81743 | Hig | 0.42 | — | 0.00 | Aug 27, 2026 | Affected versions of Flowintel allow the LOG_FILE configuration value to be modified through system settings without restricting it to a filename inside the intended log directory. Because the application constructs the log destination from this configurable value, an… | ||
| CVE-2026-81677 | — | Hig | 0.57 | — | 0.00 | Aug 27, 2026 | The ‘/ws/apiprensa/getVideo’ endpoint is vulnerable to SQL injection due to improper validation of the GET parameter `id_ambito`. An attacker can inject SQL syntax that breaks the underlying structure of the MariaDB query, resulting in syntax errors and the exposure of… | |
| CVE-2026-81676 | — | Hig | 0.57 | — | 0.00 | Aug 27, 2026 | A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the `limit_videos` parameter is directly concatenated into a MariaDB SQL query without proper sanitization or parameterization. By injecting SQL syntax into this parameter, a remote attacker can cause SQL… | |
| CVE-2026-81675 | — | Cri | 0.60 | — | 0.00 | Aug 27, 2026 | The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter. The parameter is directly embedded in a complex SQL query that includes grouping and sorting operations. By injecting SQL syntax, an attacker can disrupt… | |
| CVE-2026-81674 | — | Cri | 0.60 | — | 0.00 | Aug 27, 2026 | The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized input is directly incorporated into a MariaDB query, allowing attackers to inject SQL syntax that interrupts the query's execution. The vulnerability results… | |
| CVE-2026-81673 | — | Cri | 0.60 | — | 0.01 | Aug 27, 2026 | The ‘/ws/apitribuna/setVisita’ endpoint is vulnerable to SQL injection through the id_video and id_ambito parameters. The application does not validate or sanitize these inputs before including them in SQL queries. This allows a remote attacker to inject SQL syntax and… | |
| CVE-2026-81672 | — | Cri | 0.60 | — | 0.00 | Aug 27, 2026 | SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video parameter. The application does not sanitize input before constructing SQL queries, which results in execution errors when malicious input is provided. The… | |
| CVE-2026-81668 | Med | 0.35 | 5.4 | 0.00 | Aug 27, 2026 | A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An authenticated, low-privileged user with Content View permissions in one organization may be able to access and modify filter rules… | ||
| CVE-2026-81662 | Hig | 0.49 | — | 0.01 | Aug 27, 2026 | Affected versions of Flowintel improperly trust configuration keys supplied to the alerts settings update endpoint. While configuration values were normalized to Python literals, the corresponding keys were used directly when constructing and replacing lines in… | ||
| CVE-2026-81659 | Hig | 0.39 | — | 0.00 | Aug 27, 2026 | Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export. | ||
| CVE-2026-81658 | Med | 0.42 | 6.5 | 0.00 | Aug 27, 2026 | A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged user with a template-related permission, such as view_ptables, can obtain historical template… | ||
| CVE-2026-81562 | — | Med | 0.27 | 5.3 | 0.01 | Aug 27, 2026 | A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the file src/adb/client.ts. Performing a manipulation results in os command injection. The attack requires a local approach. The exploit has been released to the… | |
| CVE-2026-81560 | Med | 0.34 | 5.3 | 0.01 | Aug 27, 2026 | A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of the file src/web/server.ts of the component Static File Handler. Such manipulation of the argument req.url leads to path traversal. The attack can be executed… |
- CVE-2023-27880Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-27528Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-27511Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-27393Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-27381Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-27302Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-27299Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-26594Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-25778Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-25079Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-24596Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-24543Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-24541Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-24462Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-24017Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-24013Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-23905Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-22658Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2023-22431Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
- CVE-2022-51007Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2022-51006Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2022-51005Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2022-51004Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2022-51003Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2022-51002Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2022-51001Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2021-48005Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2021-48004Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2021-48003Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2021-48002Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2021-48001Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2021-48000Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2021-47999Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2021-47998Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- CVE-2021-47997Aug 27, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected.
- risk 0.26cvss —epss 0.00
Affected versions of Flowintel render calendar event titles using innerHTML. Because those titles are derived from case titles, a user able to create or modify a case title could store HTML or script-capable content that is later interpreted by the browser when another user…
- risk 0.26cvss —epss 0.01
Affected versions of Flowintel render Mermaid blocks contained in stored case notes without sufficiently neutralizing attacker-controlled markup. Because Mermaid note content is persisted and later rendered for other users, an attacker with permission to create or edit a note…
- risk 0.42cvss —epss 0.00
Affected versions of Flowintel allow the LOG_FILE configuration value to be modified through system settings without restricting it to a filename inside the intended log directory. Because the application constructs the log destination from this configurable value, an…
- risk 0.57cvss —epss 0.00
The ‘/ws/apiprensa/getVideo’ endpoint is vulnerable to SQL injection due to improper validation of the GET parameter `id_ambito`. An attacker can inject SQL syntax that breaks the underlying structure of the MariaDB query, resulting in syntax errors and the exposure of…
- risk 0.57cvss —epss 0.00
A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the `limit_videos` parameter is directly concatenated into a MariaDB SQL query without proper sanitization or parameterization. By injecting SQL syntax into this parameter, a remote attacker can cause SQL…
- risk 0.60cvss —epss 0.00
The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter. The parameter is directly embedded in a complex SQL query that includes grouping and sorting operations. By injecting SQL syntax, an attacker can disrupt…
- risk 0.60cvss —epss 0.00
The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized input is directly incorporated into a MariaDB query, allowing attackers to inject SQL syntax that interrupts the query's execution. The vulnerability results…
- risk 0.60cvss —epss 0.01
The ‘/ws/apitribuna/setVisita’ endpoint is vulnerable to SQL injection through the id_video and id_ambito parameters. The application does not validate or sanitize these inputs before including them in SQL queries. This allows a remote attacker to inject SQL syntax and…
- risk 0.60cvss —epss 0.00
SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video parameter. The application does not sanitize input before constructing SQL queries, which results in execution errors when malicious input is provided. The…
- risk 0.35cvss 5.4epss 0.00
A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An authenticated, low-privileged user with Content View permissions in one organization may be able to access and modify filter rules…
- risk 0.49cvss —epss 0.01
Affected versions of Flowintel improperly trust configuration keys supplied to the alerts settings update endpoint. While configuration values were normalized to Python literals, the corresponding keys were used directly when constructing and replacing lines in…
- risk 0.39cvss —epss 0.00
Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export.
- risk 0.42cvss 6.5epss 0.00
A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged user with a template-related permission, such as view_ptables, can obtain historical template…
- risk 0.27cvss 5.3epss 0.01
A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the file src/adb/client.ts. Performing a manipulation results in os command injection. The attack requires a local approach. The exploit has been released to the…
- risk 0.34cvss 5.3epss 0.01
A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of the file src/web/server.ts of the component Static File Handler. Such manipulation of the argument req.url leads to path traversal. The attack can be executed…