Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08

Vendors · pega

pega

· 7 Critical

Total CVEs

48

Critical

7

Products

4

Search All CVEs →

48

Recent Vulnerabilities

View all 48
CVE-2026-1711MEDIUM 4.8

Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.

CVE-2026-1564MEDIUM 4.8

Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.

CVE-2025-62184LOW 3.4

Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component. Requires an administrative user and given extensive access rights, impact to Confidentiality is low and Integrity is none.

CVE-2025-9559MEDIUM 6.5

Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data.

CVE-2025-8681MEDIUM 5.5

Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component.  Requires a high privileged user with a developer role.

CVE-2025-2161HIGH 7.1

Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup

CVE-2025-2160HIGH 8.1

Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup

CVE-2024-12211MEDIUM 5.4

Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.

CVE-2024-10716MEDIUM 5.9

Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.

CVE-2024-10094CRITICAL 9.1

Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code

CVE-2024-6702MEDIUM 5.2

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.

CVE-2024-6701MEDIUM 5.5

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.

CVE-2024-6700MEDIUM 5.5

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.

CVE-2023-50168HIGH 7.7

Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.

CVE-2023-50167MEDIUM 5.4

Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.

CVE-2023-50166MEDIUM 6.1

Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.

CVE-2023-50165HIGH 8.5

Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.

CVE-2023-32089MEDIUM 4.6

Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description

CVE-2023-32088MEDIUM 4.6

Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation

CVE-2023-32087MEDIUM 4.6

Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation

CVE-2023-4843MEDIUM 4.3

Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.

CVE-2023-32090CRITICAL 9.8

Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials

CVE-2023-28094HIGH 8.1

Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.

CVE-2023-26465MEDIUM 6.1

Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.

CVE-2023-26467MEDIUM 5.4

A man in the middle can redirect traffic to a malicious server in a compromised configuration.