Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26401
Total
1955
Critical
7975
High
8228
Medium
CVE ID Severity Score Description Published
CVE-2026-11848 MEDIUM 5.3 The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain … Jun 12, 2026
CVE-2026-50645 HIGH 7.5 There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to … Jun 12, 2026
CVE-2026-50634 MEDIUM 6.5 A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can … Jun 12, 2026
CVE-2026-50633 HIGH 8.1 A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to … Jun 12, 2026
CVE-2026-50632 HIGH 8.1 A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow … Jun 12, 2026
CVE-2026-50631 HIGH 7.4 A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' … Jun 12, 2026
CVE-2026-50630 MEDIUM 6.5 A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return … Jun 12, 2026
CVE-2026-50629 MEDIUM 5.3 The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to … Jun 12, 2026
CVE-2026-50628 UNKNOWN A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this … Jun 12, 2026
CVE-2026-50627 UNKNOWN The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one … Jun 12, 2026
CVE-2026-50623 MEDIUM 6.5 An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection … Jun 12, 2026
CVE-2026-49875 UNKNOWN Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to … Jun 12, 2026
CVE-2026-48914 MEDIUM 6.7 A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing … Jun 12, 2026
CVE-2026-11847 MEDIUM 4.3 The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Path Traversal vulnerability, allowing authenticated remote attackers to exploit this vulnerability to create … Jun 12, 2026
CVE-2026-11846 HIGH 8.1 The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerability, allowing authenticated remote attackers to exploit this vulnerability to … Jun 12, 2026
CVE-2026-11845 HIGH 7.2 The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, allowing privileged remote attackers to inject arbitrary OS commands … Jun 12, 2026
CVE-2026-11844 MEDIUM 4.9 The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, allowing privileged remote attackers to access files outside the … Jun 12, 2026
CVE-2026-12058 UNKNOWN The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed. Jun 12, 2026
CVE-2026-11535 UNKNOWN An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’s device. Jun 12, 2026
CVE-2026-9271 MEDIUM 5.9 Vulnerability Title Jun 12, 2026
CVE-2026-9269 LOW 3.5 The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high … Jun 12, 2026
CVE-2026-12060 MEDIUM 6.5 Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering techniques to trick a … Jun 12, 2026
CVE-2026-12059 HIGH 8.8 The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated remote attackers to bypass the enforced command restrictions and … Jun 12, 2026
CVE-2026-45169 UNKNOWN Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, … Jun 12, 2026
CVE-2026-44892 HIGH 7.5 Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, the default configuration of the `Http3ConnectionHandler` in the … Jun 12, 2026