Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45502
Total
3651
Critical
13471
High
13397
Medium
CVE ID Severity Score Description Published
CVE-2026-59781 UNKNOWN When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secure access permissions. … Aug 18, 2026
CVE-2026-45532 UNKNOWN DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on … Aug 18, 2026
CVE-2026-23938 UNKNOWN An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service. Aug 18, 2026
CVE-2026-23937 UNKNOWN The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity. Aug 18, 2026
CVE-2026-23935 UNKNOWN A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality … Aug 18, 2026
CVE-2026-23934 UNKNOWN An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading … Aug 18, 2026
CVE-2026-23933 UNKNOWN In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario … Aug 18, 2026
CVE-2026-23931 UNKNOWN The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality. Aug 18, 2026
CVE-2026-23930 UNKNOWN An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading … Aug 18, 2026
CVE-2026-23929 UNKNOWN Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with … Aug 18, 2026
CVE-2026-23922 UNKNOWN The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. … Aug 18, 2026
CVE-2026-1199 UNKNOWN Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent … Aug 18, 2026
CVE-2026-18751 UNKNOWN External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607. Aug 18, 2026
CVE-2026-16309 MEDIUM 5.3 Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EdoWEB: before 780-g7. Aug 18, 2026
CVE-2026-75855 HIGH 8.7 ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, allowing authenticated root users to … Aug 18, 2026
CVE-2026-75854 CRITICAL 9.8 ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers to read, write, and delete data. Attackers … Aug 18, 2026
CVE-2026-75853 HIGH 8.8 ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but performs no authorization: it never checks database access permissions (canAccessToDatabase) and … Aug 18, 2026
CVE-2026-75852 CRITICAL 9.8 ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, … Aug 18, 2026
CVE-2026-75851 CRITICAL 9.9 ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted … Aug 18, 2026
CVE-2026-75850 MEDIUM 4.2 ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and time-series HTTP handlers. Because no principal is bound on the worker … Aug 18, 2026
CVE-2026-75846 HIGH 7.1 ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. DeleteFunctionStatement.executeSimple unregisters and persists deletion of a … Aug 18, 2026
CVE-2026-75845 MEDIUM 6.3 ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool. SetServerSettingTool.execute() gates only on the global allowAdmin flag and … Aug 18, 2026
CVE-2026-75844 HIGH 7.1 ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where the security validator resolves and checks hostnames but the … Aug 18, 2026
CVE-2026-75843 CRITICAL 9.9 ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without … Aug 18, 2026
CVE-2026-75842 HIGH 7.7 ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users to read local files. … Aug 18, 2026