Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44895
Total
3603
Critical
13333
High
13202
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-76311 | CRITICAL | 9.4 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for … | Aug 19, 2026 |
| CVE-2026-76310 | CRITICAL | 9.4 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job … | Aug 19, 2026 |
| CVE-2026-76309 | MEDIUM | 4.3 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the "admin" or "power" Splunk roles could inject … | Aug 19, 2026 |
| CVE-2026-76263 | MEDIUM | 5.4 | In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete Splunk Processing Language … | Aug 19, 2026 |
| CVE-2026-76262 | HIGH | 7.5 | In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus service metrics from the Edge Processor SPL2 Preview sidecar, including service details … | Aug 19, 2026 |
| CVE-2026-76261 | MEDIUM | 5.3 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not … | Aug 19, 2026 |
| CVE-2026-76260 | MEDIUM | 6.5 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the rest_properties_get capability could read encrypted stored credentials … | Aug 19, 2026 |
| CVE-2026-76259 | HIGH | 8.8 | In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to the Windows host could bind to … | Aug 19, 2026 |
| CVE-2026-76258 | MEDIUM | 6.5 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who does not … | Aug 19, 2026 |
| CVE-2026-76257 | MEDIUM | 6.5 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who holds a … | Aug 19, 2026 |
| CVE-2026-76256 | MEDIUM | 4.3 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not … | Aug 19, 2026 |
| CVE-2026-76255 | MEDIUM | 6.4 | In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.8, and 9.4.13, a user who does not hold the "admin" or "power" Splunk roles could trick another … | Aug 19, 2026 |
| CVE-2026-76254 | HIGH | 7.5 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated user could cause another user to dispatch arbitrary Search Processing Language (SPL) … | Aug 19, 2026 |
| CVE-2026-76253 | HIGH | 8.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could run arbitrary Search Processing … | Aug 19, 2026 |
| CVE-2026-76252 | MEDIUM | 6.8 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.13, an unauthenticated user who tricks another user into visiting a malicious web page could run … | Aug 19, 2026 |
| CVE-2026-76251 | HIGH | 7.1 | In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin" or "power" Splunk roles could cause the Splunk … | Aug 19, 2026 |
| CVE-2026-69550 | MEDIUM | 6.5 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | Aug 19, 2026 |
| CVE-2026-63123 | MEDIUM | 6.5 | Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacms/cli/src/next/vite/cors.ts origin callback returns false for a disallowed … | Aug 19, 2026 |
| CVE-2026-59992 | MEDIUM | 5.4 | Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4, the first-party production media adapters pass attacker-controlled … | Aug 19, 2026 |
| CVE-2025-36398 | MEDIUM | 5.4 | IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command … | Aug 19, 2026 |
| CVE-2025-36255 | HIGH | 7.5 | IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user … | Aug 19, 2026 |
| CVE-2025-36254 | HIGH | 7.4 | IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security authentication due to improperly encoding … | Aug 19, 2026 |
| CVE-2026-76827 | MEDIUM | 6.8 | A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. … | Aug 19, 2026 |
| CVE-2026-76584 | CRITICAL | 9.9 | A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component … | Aug 19, 2026 |
| CVE-2026-76583 | HIGH | 7.4 | A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The … | Aug 19, 2026 |