Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25121
Total
1793
Critical
7689
High
7893
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-55726 | MEDIUM | 5.3 | The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access any device … | Jul 03, 2026 |
| CVE-2026-54477 | MEDIUM | 5.4 | The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks. | Jul 03, 2026 |
| CVE-2026-13768 | CRITICAL | 10.0 | Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns … | Jul 03, 2026 |
| CVE-2026-13728 | UNKNOWN | — | In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability … | Jul 03, 2026 |
| CVE-2026-13722 | UNKNOWN | — | WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator can exploit this vulnerability to … | Jul 03, 2026 |
| CVE-2026-13384 | UNKNOWN | — | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests … | Jul 03, 2026 |
| CVE-2026-13383 | UNKNOWN | — | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests … | Jul 03, 2026 |
| CVE-2026-13377 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS SIP Proxy module allows Stored XSS. This vulnerability … | Jul 03, 2026 |
| CVE-2026-13376 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is … | Jul 03, 2026 |
| CVE-2026-13375 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS. This … | Jul 03, 2026 |
| CVE-2026-13374 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This … | Jul 03, 2026 |
| CVE-2026-13373 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS. This … | Jul 03, 2026 |
| CVE-2026-13371 | UNKNOWN | — | An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to the put_data endpoint, which … | Jul 03, 2026 |
| CVE-2026-13368 | UNKNOWN | — | WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated … | Jul 03, 2026 |
| CVE-2026-13084 | UNKNOWN | — | A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) condition by sending specially crafted … | Jul 03, 2026 |
| CVE-2026-13079 | UNKNOWN | — | A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT … | Jul 03, 2026 |
| CVE-2026-13054 | UNKNOWN | — | A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem. … | Jul 03, 2026 |
| CVE-2026-13053 | UNKNOWN | — | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. … | Jul 03, 2026 |
| CVE-2026-13050 | UNKNOWN | — | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests … | Jul 03, 2026 |
| CVE-2026-57100 | CRITICAL | 9.9 | Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | Jul 02, 2026 |
| CVE-2026-54998 | HIGH | 8.8 | Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | Jul 02, 2026 |
| CVE-2026-45499 | CRITICAL | 9.9 | Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. | Jul 02, 2026 |
| CVE-2026-41106 | CRITICAL | 9.3 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. | Jul 02, 2026 |
| CVE-2026-26145 | MEDIUM | 4.8 | Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. | Jul 02, 2026 |
| CVE-2026-50722 | HIGH | 8.1 | Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 … | Jul 02, 2026 |