Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51713
Total
4098
Critical
15342
High
14990
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-28317 | CRITICAL | 9.1 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The … | Jul 21, 2026 |
| CVE-2026-28316 | CRITICAL | 9.1 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability … | Jul 21, 2026 |
| CVE-2026-28315 | MEDIUM | 6.2 | SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator … | Jul 21, 2026 |
| CVE-2026-28314 | CRITICAL | 9.1 | SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower … | Jul 21, 2026 |
| CVE-2026-28313 | CRITICAL | 9.1 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact … | Jul 21, 2026 |
| CVE-2026-28312 | CRITICAL | 9.1 | SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The … | Jul 21, 2026 |
| CVE-2026-28310 | CRITICAL | 9.1 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. … | Jul 21, 2026 |
| CVE-2026-28309 | CRITICAL | 9.1 | SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in … | Jul 21, 2026 |
| CVE-2026-28308 | CRITICAL | 9.1 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The … | Jul 21, 2026 |
| CVE-2026-28307 | CRITICAL | 9.1 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is … | Jul 21, 2026 |
| CVE-2026-28306 | CRITICAL | 9.1 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is … | Jul 21, 2026 |
| CVE-2026-28305 | CRITICAL | 9.1 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with … | Jul 21, 2026 |
| CVE-2026-28304 | CRITICAL | 9.1 | SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact … | Jul 21, 2026 |
| CVE-2026-28302 | CRITICAL | 9.1 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This … | Jul 21, 2026 |
| CVE-2026-16450 | MEDIUM | 4.3 | A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. … | Jul 21, 2026 |
| CVE-2026-16449 | MEDIUM | 6.3 | A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted element is the function OrderItem.asc/OrderItem.desc of the file /api/system/sys/dept/page of the component com.zs.sys.dept.controller.SysDeptController. … | Jul 21, 2026 |
| CVE-2026-8933 | HIGH | 7.8 | A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap … | Jul 21, 2026 |
| CVE-2026-65052 | HIGH | 7.5 | Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form … | Jul 21, 2026 |
| CVE-2026-65051 | MEDIUM | 6.5 | Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging … | Jul 21, 2026 |
| CVE-2026-65050 | MEDIUM | 6.5 | Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated … | Jul 21, 2026 |
| CVE-2026-65049 | CRITICAL | 9.3 | Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of … | Jul 21, 2026 |
| CVE-2026-65048 | CRITICAL | 9.3 | Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary … | Jul 21, 2026 |
| CVE-2026-59851 | HIGH | 8.8 | A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for … | Jul 21, 2026 |
| CVE-2026-59850 | MEDIUM | 4.3 | A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated … | Jul 21, 2026 |
| CVE-2026-59849 | LOW | 3.1 | A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are … | Jul 21, 2026 |