Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

10557
Total
721
Critical
3059
High
3365
Medium
CVE ID Severity Score Description Published
CVE-2026-30807 UNKNOWN Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 through 800 May 12, 2026
CVE-2026-30805 UNKNOWN Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800 May 12, 2026
CVE-2023-30059 UNKNOWN An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other users via manipulation of the chamado parameter … May 12, 2026
CVE-2023-27753 UNKNOWN An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted PHP file. May 12, 2026
CVE-2026-8401 UNKNOWN Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3. May 12, 2026
CVE-2026-8368 UNKNOWN LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and … May 12, 2026
CVE-2026-8111 HIGH 8.8 SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution. May 12, 2026
CVE-2026-8110 HIGH 7.8 Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges. May 12, 2026
CVE-2026-8109 MEDIUM 6.5 An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials. May 12, 2026
CVE-2026-8051 HIGH 7.2 OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution. May 12, 2026
CVE-2026-8043 CRITICAL 9.6 External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML … May 12, 2026
CVE-2026-7432 HIGH 7.8 A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM May 12, 2026
CVE-2026-7431 MEDIUM 4.4 An incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6 allows a local authenticated user to read or modify sensitive log … May 12, 2026
CVE-2026-6866 UNKNOWN CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings … May 12, 2026
CVE-2026-5061 MEDIUM 4.7 The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. … May 12, 2026
CVE-2026-43983 UNKNOWN Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken function (oidc_service.go) validates … May 12, 2026
CVE-2026-43939 HIGH 7.3 YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post … May 12, 2026
CVE-2026-43938 HIGH 8.1 YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNET.Core/Logger/DbLogger.cs) captures the incoming request's User-Agent header into a … May 12, 2026
CVE-2026-43937 HIGH 8.8 YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttribute rewrites the response to … May 12, 2026
CVE-2026-42260 HIGH 8.2 Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to 2.1.7, isPublicHttpUrl / assertPublicHttpUrl in src/utils/urlSafety.ts … May 12, 2026
CVE-2026-32687 UNKNOWN Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex ('Elixir.Postgrex.Notifications' module) allows SQL Injection. The channel argument passed … May 12, 2026
CVE-2025-70842 MEDIUM 5.4 A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the File Management module of FluentCMS 1.2.3. The flaw allows an authenticated administrator to upload crafted … May 12, 2026
CVE-2026-8391 UNKNOWN Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3. May 12, 2026
CVE-2026-8390 UNKNOWN Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3. May 12, 2026
CVE-2026-8389 UNKNOWN JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3. May 12, 2026