Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54298
Total
4306
Critical
16144
High
15836
Medium
CVE ID Severity Score Description Published
CVE-2026-70413 MEDIUM 5.6 Dell Live Optics Collector, versions prior to 27.2.13.310, contain(s) a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit … Sep 28, 2026
CVE-2026-4556 HIGH 7.8 Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privileged helper, which communicates with the application via XPC. The [ConsoleLogHelper copyConsoleIntoFileFromStartDate:] method … Sep 28, 2026
CVE-2026-101333 LOW 3.7 A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the … Sep 28, 2026
CVE-2026-101075 CRITICAL 10.0 A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location … Sep 28, 2026
CVE-2026-101074 CRITICAL 9.8 A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing … Sep 28, 2026
CVE-2026-101073 HIGH 8.3 A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing … Sep 28, 2026
CVE-2026-97335 HIGH 7.7 Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows … Sep 28, 2026
CVE-2026-93537 MEDIUM 6.5 A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to … Sep 28, 2026
CVE-2026-90926 HIGH 8.8 Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue … Sep 28, 2026
CVE-2026-90925 HIGH 7.1 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Path … Sep 28, 2026
CVE-2026-90924 CRITICAL 9.8 Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Try Common or Default Usernames and Passwords. This … Sep 28, 2026
CVE-2026-87799 CRITICAL 9.9 Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows … Sep 28, 2026
CVE-2026-87798 MEDIUM 5.8 Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, … Sep 28, 2026
CVE-2026-86595 HIGH 8.8 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue … Sep 28, 2026
CVE-2026-86335 MEDIUM 6.3 Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects … Sep 28, 2026
CVE-2026-86334 MEDIUM 4.2 Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms … Sep 28, 2026
CVE-2026-85526 CRITICAL 9.9 Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace … Sep 28, 2026
CVE-2026-85185 CRITICAL 9.6 Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an … Sep 28, 2026
CVE-2026-73642 UNKNOWN — Dayforce Payroll is vulnerable to Path Traversal in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any … Sep 28, 2026
CVE-2026-73641 UNKNOWN — Dayforce Payroll is vulnerable to Reflected XSS in multiple endpoints. An attacker can prepare a specially crafted URL that, when opened, results in arbitrary JavaScript … Sep 28, 2026
CVE-2026-73640 UNKNOWN — Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters … Sep 28, 2026
CVE-2026-15953 MEDIUM 5.0 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and … Sep 28, 2026
CVE-2026-15952 MEDIUM 6.4 Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through … Sep 28, 2026
CVE-2026-101072 CRITICAL 10.0 A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation … Sep 28, 2026
CVE-2026-101071 MEDIUM 6.3 A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component … Sep 28, 2026