Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25592
Total
1903
Critical
7807
High
8024
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-49201 | UNKNOWN | — | The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, … | May 29, 2026 |
| CVE-2026-46579 | HIGH | 7.4 | A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from … | May 29, 2026 |
| CVE-2026-42965 | HIGH | 7.7 | A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an … | May 29, 2026 |
| CVE-2026-10078 | LOW | 2.7 | A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, specifically client_id and client_secret, to be transmitted as plaintext … | May 29, 2026 |
| CVE-2025-12714 | MEDIUM | 5.3 | The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability … | May 29, 2026 |
| CVE-2026-9189 | MEDIUM | 5.3 | The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all … | May 29, 2026 |
| CVE-2026-6075 | HIGH | 8.1 | The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing … | May 29, 2026 |
| CVE-2026-49200 | UNKNOWN | — | The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), … | May 29, 2026 |
| CVE-2026-49199 | UNKNOWN | — | Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device. | May 29, 2026 |
| CVE-2026-49198 | UNKNOWN | — | Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors. | May 29, 2026 |
| CVE-2026-49197 | UNKNOWN | — | Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails. | May 29, 2026 |
| CVE-2026-49196 | UNKNOWN | — | The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary shell commands. | May 29, 2026 |
| CVE-2026-49195 | UNKNOWN | — | Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands. | May 29, 2026 |
| CVE-2026-10058 | MEDIUM | 4.8 | ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are … | May 29, 2026 |
| CVE-2026-10057 | MEDIUM | 4.8 | ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are … | May 29, 2026 |
| CVE-2026-10056 | HIGH | 7.5 | CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux … | May 29, 2026 |
| CVE-2026-10052 | MEDIUM | 4.1 | A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make … | May 29, 2026 |
| CVE-2026-10039 | MEDIUM | 4.9 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, … | May 29, 2026 |
| CVE-2026-9243 | MEDIUM | 6.4 | The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions … | May 29, 2026 |
| CVE-2026-4776 | HIGH | 7.1 | An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can … | May 29, 2026 |
| CVE-2026-49322 | MEDIUM | 4.3 | Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read … | May 29, 2026 |
| CVE-2026-3655 | CRITICAL | 9.8 | The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to … | May 29, 2026 |
| CVE-2025-11262 | HIGH | 7.2 | The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 0.9.0 … | May 29, 2026 |
| CVE-2026-9714 | MEDIUM | 6.4 | The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in versions up to, … | May 29, 2026 |
| CVE-2026-9493 | MEDIUM | 6.5 | Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify the parameter of a specific … | May 29, 2026 |