Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26401
Total
1955
Critical
7975
High
8228
Medium
CVE ID Severity Score Description Published
CVE-2026-8487 MEDIUM 6.5 Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. May 20, 2026
CVE-2026-8486 MEDIUM 5.3 Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before … May 20, 2026
CVE-2026-5783 HIGH 7.6 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Beyaz Computer Software Design Industry and Trade Ltd. Co. CityPLus allows Reflected XSS. … May 20, 2026
CVE-2026-4293 MEDIUM 5.3 The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the … May 20, 2026
CVE-2026-39047 HIGH 7.5 Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Printing Service (JetDirect) on TCP port 9100 May 20, 2026
CVE-2025-32750 HIGH 7.5 Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, … May 20, 2026
CVE-2023-7346 MEDIUM 4.0 Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause incorrect Bitcoin addresses to be displayed by exploiting … May 20, 2026
CVE-2026-8485 MEDIUM 5.9 Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. May 20, 2026
CVE-2026-8469 UNKNOWN Allocation of Resources Without Limits or Throttling vulnerability in phenixdigital phoenix_storybook allows unauthenticated denial-of-service via BEAM atom table exhaustion. Multiple LiveView event handlers convert user-supplied … May 20, 2026
CVE-2026-8467 UNKNOWN Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanitized attribute value interpolation in HEEx template generation. The psb-assign WebSocket event handler … May 20, 2026
CVE-2026-47068 UNKNOWN Authorization Bypass Through User-Controlled Key vulnerability in phenixdigital phoenix_storybook allows cross-session PubSub topic injection via a URL query parameter. 'Elixir.PhoenixStorybook.Story.ComponentIframeLive':handle_params/3 in lib/phoenix_storybook/live/story/component_iframe_live.ex reads a PubSub … May 20, 2026
CVE-2026-24425 HIGH 8.8 Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass … May 20, 2026
CVE-2026-22554 HIGH 7.8 MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability May 20, 2026
CVE-2026-21836 MEDIUM 6.5 The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability. Under certain circumstances, document level access restrictions will be ignored when determining … May 20, 2026
CVE-2026-5950 MEDIUM 5.3 An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource … May 20, 2026
CVE-2026-5947 HIGH 7.5 Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it … May 20, 2026
CVE-2026-5946 HIGH 7.5 Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or … May 20, 2026
CVE-2026-45584 HIGH 8.1 Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. May 20, 2026
CVE-2026-45498 MEDIUM 4.0 Microsoft Defender Denial of Service Vulnerability May 20, 2026
CVE-2026-45443 MEDIUM 5.0 Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue … May 20, 2026
CVE-2026-42834 HIGH 7.8 Improper link resolution before file access ('link following') in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally. May 20, 2026
CVE-2026-42383 HIGH 7.6 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Blind SQL Injection. This issue … May 20, 2026
CVE-2026-41091 HIGH 7.8 Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. May 20, 2026
CVE-2026-3593 HIGH 7.4 A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BIND … May 20, 2026
CVE-2026-3592 MEDIUM 5.3 BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will … May 20, 2026