Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54298
Total
4306
Critical
16144
High
15836
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-70413 | MEDIUM | 5.6 | Dell Live Optics Collector, versions prior to 27.2.13.310, contain(s) a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit … | Sep 28, 2026 |
| CVE-2026-4556 | HIGH | 7.8 | Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privileged helper, which communicates with the application via XPC. The [ConsoleLogHelper copyConsoleIntoFileFromStartDate:] method … | Sep 28, 2026 |
| CVE-2026-101333 | LOW | 3.7 | A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the … | Sep 28, 2026 |
| CVE-2026-101075 | CRITICAL | 10.0 | A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location … | Sep 28, 2026 |
| CVE-2026-101074 | CRITICAL | 9.8 | A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing … | Sep 28, 2026 |
| CVE-2026-101073 | HIGH | 8.3 | A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing … | Sep 28, 2026 |
| CVE-2026-97335 | HIGH | 7.7 | Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows … | Sep 28, 2026 |
| CVE-2026-93537 | MEDIUM | 6.5 | A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to … | Sep 28, 2026 |
| CVE-2026-90926 | HIGH | 8.8 | Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue … | Sep 28, 2026 |
| CVE-2026-90925 | HIGH | 7.1 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Path … | Sep 28, 2026 |
| CVE-2026-90924 | CRITICAL | 9.8 | Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Try Common or Default Usernames and Passwords. This … | Sep 28, 2026 |
| CVE-2026-87799 | CRITICAL | 9.9 | Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows … | Sep 28, 2026 |
| CVE-2026-87798 | MEDIUM | 5.8 | Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, … | Sep 28, 2026 |
| CVE-2026-86595 | HIGH | 8.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue … | Sep 28, 2026 |
| CVE-2026-86335 | MEDIUM | 6.3 | Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects … | Sep 28, 2026 |
| CVE-2026-86334 | MEDIUM | 4.2 | Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms … | Sep 28, 2026 |
| CVE-2026-85526 | CRITICAL | 9.9 | Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace … | Sep 28, 2026 |
| CVE-2026-85185 | CRITICAL | 9.6 | Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an … | Sep 28, 2026 |
| CVE-2026-73642 | UNKNOWN | — | Dayforce Payroll is vulnerable to Path Traversal in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any … | Sep 28, 2026 |
| CVE-2026-73641 | UNKNOWN | — | Dayforce Payroll is vulnerable to Reflected XSS in multiple endpoints. An attacker can prepare a specially crafted URL that, when opened, results in arbitrary JavaScript … | Sep 28, 2026 |
| CVE-2026-73640 | UNKNOWN | — | Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters … | Sep 28, 2026 |
| CVE-2026-15953 | MEDIUM | 5.0 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and … | Sep 28, 2026 |
| CVE-2026-15952 | MEDIUM | 6.4 | Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through … | Sep 28, 2026 |
| CVE-2026-101072 | CRITICAL | 10.0 | A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation … | Sep 28, 2026 |
| CVE-2026-101071 | MEDIUM | 6.3 | A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component … | Sep 28, 2026 |