Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

34313
Total
2675
Critical
10128
High
10348
Medium
CVE ID Severity Score Description Published
CVE-2026-20089 MEDIUM 4.8 A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack … Apr 01, 2026
CVE-2026-20088 MEDIUM 4.8 A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack … Apr 01, 2026
CVE-2026-20087 MEDIUM 4.8 A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack … Apr 01, 2026
CVE-2026-20085 MEDIUM 6.1 A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user … Apr 01, 2026
CVE-2026-20042 MEDIUM 6.5 A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or … Apr 01, 2026
CVE-2026-20041 MEDIUM 6.1 A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack … Apr 01, 2026
CVE-2024-43028 CRITICAL 9.8 A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a crafted HTTP request. Apr 01, 2026
CVE-2024-40489 CRITICAL 9.8 There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on … Apr 01, 2026
CVE-2026-5175 MEDIUM 5.0 Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to delete their own configured MFA factors and … Apr 01, 2026
CVE-2026-4989 MEDIUM 4.3 Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticated user to perform server-side request forgery (SSRF), potentially leading … Apr 01, 2026
CVE-2026-4927 MEDIUM 6.5 Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via … Apr 01, 2026
CVE-2026-4925 MEDIUM 5.0 Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and remove their own multi-factor authentication … Apr 01, 2026
CVE-2026-4924 HIGH 8.2 Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multifactor authentication … Apr 01, 2026
CVE-2026-4829 MEDIUM 5.4 Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, … Apr 01, 2026
CVE-2026-4828 HIGH 8.2 Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multi-factor authentication via … Apr 01, 2026
CVE-2026-35099 HIGH 7.4 Lakeside SysTrack Agent 11 before 11.5.0.15 has a race condition with resultant local privilege escalation to SYSTEM. The fixed versions are 11.2.1.28, 11.3.0.38, 11.4.0.24, and … Apr 01, 2026
CVE-2026-34510 MEDIUM 5.3 OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file URLs and UNC-style paths before local-path validation. Attackers can … Apr 01, 2026
CVE-2026-31027 CRITICAL 9.8 TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste_modules/app.so. The vulnerability occurs because the rootSsid parameter is not properly validated … Apr 01, 2026
CVE-2025-67807 MEDIUM 4.7 The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise … Apr 01, 2026
CVE-2025-67806 LOW 3.7 The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise … Apr 01, 2026
CVE-2025-67805 MEDIUM 5.9 A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Database Monitor feature, exposing sensitive information such as hashes and … Apr 01, 2026
CVE-2026-30573 HIGH 7.5 A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is located in the add-sales.php file. The application fails to validate … Apr 01, 2026
CVE-2026-30526 MEDIUM 6.1 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Zoo Management System v1.0. The vulnerability is located in the login page, specifically within the msg … Apr 01, 2026
CVE-2026-30523 MEDIUM 6.5 A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input validation. The application allows administrators to define … Apr 01, 2026
CVE-2026-30292 HIGH 8.4 An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite critical internal files via the file import process, … Apr 01, 2026