Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25592
Total
1903
Critical
7807
High
8024
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-45043 | UNKNOWN | — | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoint allows a user with ImportIAMAction … | May 29, 2026 |
| CVE-2026-10071 | CRITICAL | 9.8 | DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code … | May 29, 2026 |
| CVE-2026-9811 | MEDIUM | 5.4 | A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, … | May 29, 2026 |
| CVE-2026-9809 | HIGH | 7.6 | A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such … | May 29, 2026 |
| CVE-2026-9808 | HIGH | 7.1 | An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as … | May 29, 2026 |
| CVE-2026-9559 | CRITICAL | 9.9 | A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the … | May 29, 2026 |
| CVE-2025-41281 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in … | May 29, 2026 |
| CVE-2025-41280 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access … | May 29, 2026 |
| CVE-2025-41279 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41278 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attackers with access to the TX … | May 29, 2026 |
| CVE-2025-41277 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41276 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41275 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41274 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41273 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts … | May 29, 2026 |
| CVE-2025-41272 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41271 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that … | May 29, 2026 |
| CVE-2025-41270 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41269 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41268 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that … | May 29, 2026 |
| CVE-2025-41267 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41266 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41265 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall … | May 29, 2026 |
| CVE-2026-9558 | CRITICAL | 9.9 | A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated … | May 29, 2026 |
| CVE-2026-9557 | MEDIUM | 6.4 | A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP … | May 29, 2026 |