Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41921
Total
3420
Critical
12394
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-74237 | MEDIUM | 6.5 | GFI Exinda AI and ClearView before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Client functionality. The web_tools_cmd() function constructs an iperf command … | Sep 04, 2026 |
| CVE-2026-74236 | MEDIUM | 6.5 | GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with … | Sep 04, 2026 |
| CVE-2026-74235 | MEDIUM | 4.9 | GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed … | Sep 04, 2026 |
| CVE-2026-18198 | HIGH | 8.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows … | Sep 04, 2026 |
| CVE-2026-85617 | HIGH | 8.8 | snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside their authorized scope. … | Sep 04, 2026 |
| CVE-2026-85616 | HIGH | 8.5 | Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission … | Sep 04, 2026 |
| CVE-2026-85615 | MEDIUM | 6.4 | Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboardId to the authorized … | Sep 04, 2026 |
| CVE-2026-85614 | HIGH | 8.6 | OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled URL parameter with no private … | Sep 04, 2026 |
| CVE-2026-85613 | HIGH | 8.2 | OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying … | Sep 04, 2026 |
| CVE-2026-85612 | HIGH | 7.5 | OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. … | Sep 04, 2026 |
| CVE-2026-85611 | MEDIUM | 6.4 | OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to … | Sep 04, 2026 |
| CVE-2026-85610 | HIGH | 8.8 | OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering the native … | Sep 04, 2026 |
| CVE-2026-85609 | HIGH | 7.5 | Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET /tools/site-checker endpoint (apps/api/src/controllers/tools.controller.ts). The endpoint passes a user-supplied url query … | Sep 04, 2026 |
| CVE-2026-85604 | HIGH | 8.8 | Grav before 2.0.19 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's … | Sep 04, 2026 |
| CVE-2026-85603 | MEDIUM | 6.5 | Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An … | Sep 04, 2026 |
| CVE-2026-85602 | MEDIUM | 5.3 | The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in … | Sep 04, 2026 |
| CVE-2026-85601 | MEDIUM | 5.4 | Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} directive in MarkdownEditor and MarkdownModal components. … | Sep 04, 2026 |
| CVE-2026-85600 | MEDIUM | 5.4 | Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into … | Sep 04, 2026 |
| CVE-2026-85599 | HIGH | 7.2 | Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages … | Sep 04, 2026 |
| CVE-2026-85598 | MEDIUM | 6.4 | Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with … | Sep 04, 2026 |
| CVE-2026-85597 | UNKNOWN | — | Traefik before v2.11.55 contains a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host … | Sep 04, 2026 |
| CVE-2026-85596 | UNKNOWN | — | Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying … | Sep 04, 2026 |
| CVE-2026-85595 | UNKNOWN | — | Traefik versions before v2.11.55 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can … | Sep 04, 2026 |
| CVE-2026-85594 | UNKNOWN | — | Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the … | Sep 04, 2026 |
| CVE-2026-85593 | MEDIUM | 5.4 | phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ content, reversing entity-encoding protection. Authenticated users with … | Sep 04, 2026 |