Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41921
Total
3420
Critical
12394
High
12304
Medium
CVE ID Severity Score Description Published
CVE-2026-74237 MEDIUM 6.5 GFI Exinda AI and ClearView before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Client functionality. The web_tools_cmd() function constructs an iperf command … Sep 04, 2026
CVE-2026-74236 MEDIUM 6.5 GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with … Sep 04, 2026
CVE-2026-74235 MEDIUM 4.9 GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed … Sep 04, 2026
CVE-2026-18198 HIGH 8.8 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows … Sep 04, 2026
CVE-2026-85617 HIGH 8.8 snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside their authorized scope. … Sep 04, 2026
CVE-2026-85616 HIGH 8.5 Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission … Sep 04, 2026
CVE-2026-85615 MEDIUM 6.4 Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboardId to the authorized … Sep 04, 2026
CVE-2026-85614 HIGH 8.6 OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled URL parameter with no private … Sep 04, 2026
CVE-2026-85613 HIGH 8.2 OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying … Sep 04, 2026
CVE-2026-85612 HIGH 7.5 OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. … Sep 04, 2026
CVE-2026-85611 MEDIUM 6.4 OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to … Sep 04, 2026
CVE-2026-85610 HIGH 8.8 OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering the native … Sep 04, 2026
CVE-2026-85609 HIGH 7.5 Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET /tools/site-checker endpoint (apps/api/src/controllers/tools.controller.ts). The endpoint passes a user-supplied url query … Sep 04, 2026
CVE-2026-85604 HIGH 8.8 Grav before 2.0.19 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's … Sep 04, 2026
CVE-2026-85603 MEDIUM 6.5 Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An … Sep 04, 2026
CVE-2026-85602 MEDIUM 5.3 The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in … Sep 04, 2026
CVE-2026-85601 MEDIUM 5.4 Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} directive in MarkdownEditor and MarkdownModal components. … Sep 04, 2026
CVE-2026-85600 MEDIUM 5.4 Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into … Sep 04, 2026
CVE-2026-85599 HIGH 7.2 Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages … Sep 04, 2026
CVE-2026-85598 MEDIUM 6.4 Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with … Sep 04, 2026
CVE-2026-85597 UNKNOWN Traefik before v2.11.55 contains a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host … Sep 04, 2026
CVE-2026-85596 UNKNOWN Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying … Sep 04, 2026
CVE-2026-85595 UNKNOWN Traefik versions before v2.11.55 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can … Sep 04, 2026
CVE-2026-85594 UNKNOWN Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the … Sep 04, 2026
CVE-2026-85593 MEDIUM 5.4 phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ content, reversing entity-encoding protection. Authenticated users with … Sep 04, 2026