Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

34617
Total
2726
Critical
10244
High
10450
Medium
CVE ID Severity Score Description Published
CVE-2026-23922 UNKNOWN The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. … Aug 18, 2026
CVE-2026-1199 UNKNOWN Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent … Aug 18, 2026
CVE-2026-18751 UNKNOWN External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607. Aug 18, 2026
CVE-2026-16309 MEDIUM 5.3 Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EdoWEB: before 780-g7. Aug 18, 2026
CVE-2026-75855 HIGH 8.7 ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, allowing authenticated root users to … Aug 18, 2026
CVE-2026-75854 CRITICAL 9.8 ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers to read, write, and delete data. Attackers … Aug 18, 2026
CVE-2026-75853 HIGH 8.8 ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but performs no authorization: it never checks database access permissions (canAccessToDatabase) and … Aug 18, 2026
CVE-2026-75852 CRITICAL 9.8 ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, … Aug 18, 2026
CVE-2026-75851 CRITICAL 9.9 ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted … Aug 18, 2026
CVE-2026-75850 MEDIUM 4.2 ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and time-series HTTP handlers. Because no principal is bound on the worker … Aug 18, 2026
CVE-2026-75846 HIGH 7.1 ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. DeleteFunctionStatement.executeSimple unregisters and persists deletion of a … Aug 18, 2026
CVE-2026-75845 MEDIUM 6.3 ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool. SetServerSettingTool.execute() gates only on the global allowAdmin flag and … Aug 18, 2026
CVE-2026-75844 HIGH 7.1 ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where the security validator resolves and checks hostnames but the … Aug 18, 2026
CVE-2026-75843 CRITICAL 9.9 ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without … Aug 18, 2026
CVE-2026-75842 HIGH 7.7 ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users to read local files. … Aug 18, 2026
CVE-2026-75841 MEDIUM 4.3 ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticated users to exhaust server heap memory. Attackers can … Aug 18, 2026
CVE-2026-75840 HIGH 7.5 ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped regular expressions to validate package names. … Aug 18, 2026
CVE-2026-75839 MEDIUM 4.3 ArcadeDB (com.arcadedb:arcadedb-server) versions <= 26.7.3 contain an insecure direct object reference (IDOR) vulnerability in the Raft cluster-info endpoints (GetClusterHandler and PostBootstrapStateHandler), which authenticate but do … Aug 18, 2026
CVE-2026-75838 UNKNOWN DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event … Aug 18, 2026
CVE-2026-75837 CRITICAL 9.1 Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can … Aug 18, 2026
CVE-2026-75836 HIGH 8.8 The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in MenubarController::executeAction(). While the GET /menubar/items listing … Aug 18, 2026
CVE-2026-75835 MEDIUM 4.3 Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuthorize() (AbstractApiController.php). The function fails to consult the calling request's API key scopes, … Aug 18, 2026
CVE-2026-75834 MEDIUM 5.4 Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). All XSS detection patterns use the PCRE /u (UTF-8) modifier, so … Aug 18, 2026
CVE-2026-75833 MEDIUM 4.2 The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0.14 contains an open redirect weakness in SsoController::sanitizeReturnTo(). The function rejects a … Aug 18, 2026
CVE-2026-75832 MEDIUM 4.3 The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorization vulnerability in BlueprintPathResolver::resolveUserScope(). The method gates … Aug 18, 2026