Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42739
Total
3465
Critical
12744
High
12574
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-78495 | UNKNOWN | — | A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Remote Backup Connection Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent … | Aug 28, 2026 |
| CVE-2026-78195 | UNKNOWN | — | A Cross-Site Scripting (XSS) vulnerability in the WatchGuard Dimension Backup Historical Data feature allows an authenticated administrator user to execute arbitrary JavaScript in another user's … | Aug 28, 2026 |
| CVE-2026-78174 | UNKNOWN | — | WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract … | Aug 28, 2026 |
| CVE-2026-78103 | UNKNOWN | — | WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not enforce this lock/unlock workflow state, allowing an authenticated … | Aug 28, 2026 |
| CVE-2026-78047 | UNKNOWN | — | A stored cross-site scripting (XSS) vulnerability in WatchGuard Dimension's task scheduling feature allows a low-privileged authenticated administrator to inject arbitrary HTML/JavaScript into these fields, which … | Aug 28, 2026 |
| CVE-2026-78011 | UNKNOWN | — | An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in … | Aug 28, 2026 |
| CVE-2026-78010 | UNKNOWN | — | A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated attacker to create a Denial of Service (DoS) condition … | Aug 28, 2026 |
| CVE-2026-78009 | UNKNOWN | — | An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in … | Aug 28, 2026 |
| CVE-2026-78008 | UNKNOWN | — | A buffer overflow vulnerability in the WatchGuard Fireware OS Management Web UI allows an authenticated administrator with network access to cause a denial of service … | Aug 28, 2026 |
| CVE-2026-61802 | MEDIUM | 6.5 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, a low-privilege API … | Aug 28, 2026 |
| CVE-2026-61800 | CRITICAL | 9.1 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding … | Aug 28, 2026 |
| CVE-2026-38822 | HIGH | 7.6 | In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection … | Aug 28, 2026 |
| CVE-2026-38821 | HIGH | 7.1 | A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon … | Aug 28, 2026 |
| CVE-2026-38820 | HIGH | 8.3 | openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of … | Aug 28, 2026 |
| CVE-2026-38819 | MEDIUM | 5.3 | Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within … | Aug 28, 2026 |
| CVE-2026-19318 | UNKNOWN | — | A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted … | Aug 28, 2026 |
| CVE-2026-19317 | UNKNOWN | — | An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in … | Aug 28, 2026 |
| CVE-2026-19316 | UNKNOWN | — | A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN … | Aug 28, 2026 |
| CVE-2026-19315 | UNKNOWN | — | A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted … | Aug 28, 2026 |
| CVE-2026-19314 | UNKNOWN | — | An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in … | Aug 28, 2026 |
| CVE-2026-19313 | UNKNOWN | — | An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network … | Aug 28, 2026 |
| CVE-2026-13108 | UNKNOWN | — | WatchGuard Dimension is susceptible to a denial-of-service condition when an attacker sends a high volume of TCP SYN packets to the log listening service. | Aug 28, 2026 |
| CVE-2026-13086 | UNKNOWN | — | A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated … | Aug 28, 2026 |
| CVE-2026-82072 | HIGH | 8.8 | Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a … | Aug 28, 2026 |
| CVE-2026-81851 | UNKNOWN | — | A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash the IKE daemon (iked), resulting in a denial of … | Aug 28, 2026 |