Known Vulnerabilities for Application Server by Redhat
Listed below are 10 of the newest known vulnerabilities associated with "Application Server" by "Redhat".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-41459 json | Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthenticated a... | Not Provided | 2026-04-22 | 2026-04-22 |
| CVE-2026-41318 json | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. P... | Not Provided | 2026-04-24 | 2026-04-24 |
| CVE-2026-41270 json | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Reques... | Not Provided | 2026-04-23 | 2026-04-23 |
| CVE-2026-41269 json | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configu... | Not Provided | 2026-04-23 | 2026-04-23 |
| CVE-2026-41177 json | Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Squidex... | Not Provided | 2026-04-22 | 2026-04-23 |
| CVE-2026-41130 json | Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.1... | Not Provided | 2026-04-22 | 2026-04-22 |
| CVE-2026-40905 json | LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, a password reset poisoning vulnerability was ident... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-40608 json | Next AI Draw.io is a next.js web application that integrates AI capabilities with draw.io diagrams. Prior to 0.4.15, the embe... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-40487 json | Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticat... | Not Provided | 2026-04-18 | 2026-04-20 |
| CVE-2026-40478 json | Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain... | Not Provided | 2026-04-17 | 2026-04-22 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Application Server | - |