Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26401
Total
1955
Critical
7975
High
8228
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-11848 | MEDIUM | 5.3 | The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain … | Jun 12, 2026 |
| CVE-2026-50645 | HIGH | 7.5 | There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to … | Jun 12, 2026 |
| CVE-2026-50634 | MEDIUM | 6.5 | A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can … | Jun 12, 2026 |
| CVE-2026-50633 | HIGH | 8.1 | A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to … | Jun 12, 2026 |
| CVE-2026-50632 | HIGH | 8.1 | A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow … | Jun 12, 2026 |
| CVE-2026-50631 | HIGH | 7.4 | A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' … | Jun 12, 2026 |
| CVE-2026-50630 | MEDIUM | 6.5 | A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return … | Jun 12, 2026 |
| CVE-2026-50629 | MEDIUM | 5.3 | The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to … | Jun 12, 2026 |
| CVE-2026-50628 | UNKNOWN | — | A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this … | Jun 12, 2026 |
| CVE-2026-50627 | UNKNOWN | — | The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one … | Jun 12, 2026 |
| CVE-2026-50623 | MEDIUM | 6.5 | An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection … | Jun 12, 2026 |
| CVE-2026-49875 | UNKNOWN | — | Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to … | Jun 12, 2026 |
| CVE-2026-48914 | MEDIUM | 6.7 | A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing … | Jun 12, 2026 |
| CVE-2026-11847 | MEDIUM | 4.3 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Path Traversal vulnerability, allowing authenticated remote attackers to exploit this vulnerability to create … | Jun 12, 2026 |
| CVE-2026-11846 | HIGH | 8.1 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerability, allowing authenticated remote attackers to exploit this vulnerability to … | Jun 12, 2026 |
| CVE-2026-11845 | HIGH | 7.2 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, allowing privileged remote attackers to inject arbitrary OS commands … | Jun 12, 2026 |
| CVE-2026-11844 | MEDIUM | 4.9 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, allowing privileged remote attackers to access files outside the … | Jun 12, 2026 |
| CVE-2026-12058 | UNKNOWN | — | The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed. | Jun 12, 2026 |
| CVE-2026-11535 | UNKNOWN | — | An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’s device. | Jun 12, 2026 |
| CVE-2026-9271 | MEDIUM | 5.9 | Vulnerability Title | Jun 12, 2026 |
| CVE-2026-9269 | LOW | 3.5 | The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high … | Jun 12, 2026 |
| CVE-2026-12060 | MEDIUM | 6.5 | Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering techniques to trick a … | Jun 12, 2026 |
| CVE-2026-12059 | HIGH | 8.8 | The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated remote attackers to bypass the enforced command restrictions and … | Jun 12, 2026 |
| CVE-2026-45169 | UNKNOWN | — | Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, … | Jun 12, 2026 |
| CVE-2026-44892 | HIGH | 7.5 | Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, the default configuration of the `Http3ConnectionHandler` in the … | Jun 12, 2026 |