Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26091
Total
1954
Critical
7964
High
8211
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-7569 | HIGH | 8.8 | Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User … | Jun 25, 2026 |
| CVE-2026-40079 | CRITICAL | 9.8 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in … | Jun 25, 2026 |
| CVE-2026-39951 | HIGH | 7.6 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injection vulnerability through graph_name_regexp in the Reports … | Jun 25, 2026 |
| CVE-2025-60473 | MEDIUM | 5.5 | A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying … | Jun 25, 2026 |
| CVE-2025-60466 | MEDIUM | 5.0 | A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted … | Jun 25, 2026 |
| CVE-2026-39955 | CRITICAL | 9.8 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php. This issue … | Jun 24, 2026 |
| CVE-2026-39948 | CRITICAL | 9.8 | Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request parameter is retrieved via the raw accessor … | Jun 24, 2026 |
| CVE-2026-39938 | CRITICAL | 9.8 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtool IPC serialization hardening. This … | Jun 24, 2026 |
| CVE-2026-39900 | MEDIUM | 6.1 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflected XSS via tab parameter in the auth_profile.php … | Jun 24, 2026 |
| CVE-2026-39899 | MEDIUM | 5.3 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal via filename parameter in package_import.php. This … | Jun 24, 2026 |
| CVE-2025-8106 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jun 24, 2026 |
| CVE-2025-60474 | HIGH | 7.5 | A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a … | Jun 24, 2026 |
| CVE-2025-60467 | HIGH | 7.5 | A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted … | Jun 24, 2026 |
| CVE-2026-9779 | HIGH | 7.2 | ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of … | Jun 24, 2026 |
| CVE-2026-9778 | HIGH | 7.2 | ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Authentication … | Jun 24, 2026 |
| CVE-2026-9777 | HIGH | 7.2 | ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Authentication … | Jun 24, 2026 |
| CVE-2026-9776 | HIGH | 7.5 | ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ATEN Unizon. Authentication is … | Jun 24, 2026 |
| CVE-2026-9775 | MEDIUM | 5.5 | ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of ATEN Unizon. Authentication … | Jun 24, 2026 |
| CVE-2026-9774 | MEDIUM | 5.5 | ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of ATEN Unizon. Authentication … | Jun 24, 2026 |
| CVE-2026-9773 | HIGH | 8.8 | Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication … | Jun 24, 2026 |
| CVE-2026-9772 | HIGH | 8.8 | Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication … | Jun 24, 2026 |
| CVE-2026-55762 | HIGH | 8.1 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, the POST /api/v1/fingerprint REST endpoint enforces … | Jun 24, 2026 |
| CVE-2026-55759 | HIGH | 7.4 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, Rocket.Chat's Apple Sign-In handler verifies JWT … | Jun 24, 2026 |
| CVE-2026-55666 | UNKNOWN | — | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, in apps/meteor/app/apple/server/loginHandler.ts, handleIdentityToken parses a JWT … | Jun 24, 2026 |
| CVE-2026-55570 | CRITICAL | 9.0 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, description) when they are … | Jun 24, 2026 |