Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26401
Total
1955
Critical
7975
High
8228
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-24218 | HIGH | 8.1 | NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be … | May 20, 2026 |
| CVE-2026-24217 | HIGH | 8.8 | NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of … | May 20, 2026 |
| CVE-2026-24216 | HIGH | 7.8 | NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead … | May 20, 2026 |
| CVE-2026-24188 | HIGH | 8.2 | NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to data tampering. | May 20, 2026 |
| CVE-2026-23734 | UNKNOWN | — | XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such … | May 20, 2026 |
| CVE-2026-30691 | MEDIUM | 6.1 | Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanitize … | May 20, 2026 |
| CVE-2026-20240 | MEDIUM | 6.5 | In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged … | May 20, 2026 |
| CVE-2026-20239 | HIGH | 7.5 | In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that … | May 20, 2026 |
| CVE-2026-20238 | MEDIUM | 6.5 | In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was … | May 20, 2026 |
| CVE-2026-9101 | MEDIUM | 4.3 | Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to … | May 20, 2026 |
| CVE-2026-9100 | MEDIUM | 5.9 | The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause … | May 20, 2026 |
| CVE-2026-9087 | MEDIUM | 6.4 | A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity … | May 20, 2026 |
| CVE-2026-8342 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … | May 20, 2026 |
| CVE-2026-7613 | HIGH | 7.2 | The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parameter in versions up to, and including, … | May 20, 2026 |
| CVE-2026-44926 | HIGH | 8.8 | InfoScale CmdServer before 7.4.2 mishandles access control. | May 20, 2026 |
| CVE-2026-44925 | HIGH | 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a … | May 20, 2026 |
| CVE-2026-44924 | MEDIUM | 5.4 | InfoScale VIOM 9.1.3 allows XSS. | May 20, 2026 |
| CVE-2026-44923 | MEDIUM | 6.5 | SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges. | May 20, 2026 |
| CVE-2026-20223 | CRITICAL | 10.0 | A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the … | May 20, 2026 |
| CVE-2026-20206 | MEDIUM | 6.3 | A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on … | May 20, 2026 |
| CVE-2026-20199 | MEDIUM | 4.7 | A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating … | May 20, 2026 |
| CVE-2026-20171 | MEDIUM | 6.8 | A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could … | May 20, 2026 |
| CVE-2026-9084 | UNKNOWN | — | MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local … | May 20, 2026 |
| CVE-2026-8598 | CRITICAL | 9.1 | An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about … | May 20, 2026 |
| CVE-2026-8488 | MEDIUM | 4.3 | Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 … | May 20, 2026 |