Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45502
Total
3651
Critical
13471
High
13397
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-59781 | UNKNOWN | — | When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secure access permissions. … | Aug 18, 2026 |
| CVE-2026-45532 | UNKNOWN | — | DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on … | Aug 18, 2026 |
| CVE-2026-23938 | UNKNOWN | — | An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service. | Aug 18, 2026 |
| CVE-2026-23937 | UNKNOWN | — | The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity. | Aug 18, 2026 |
| CVE-2026-23935 | UNKNOWN | — | A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality … | Aug 18, 2026 |
| CVE-2026-23934 | UNKNOWN | — | An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading … | Aug 18, 2026 |
| CVE-2026-23933 | UNKNOWN | — | In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario … | Aug 18, 2026 |
| CVE-2026-23931 | UNKNOWN | — | The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality. | Aug 18, 2026 |
| CVE-2026-23930 | UNKNOWN | — | An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading … | Aug 18, 2026 |
| CVE-2026-23929 | UNKNOWN | — | Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with … | Aug 18, 2026 |
| CVE-2026-23922 | UNKNOWN | — | The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. … | Aug 18, 2026 |
| CVE-2026-1199 | UNKNOWN | — | Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent … | Aug 18, 2026 |
| CVE-2026-18751 | UNKNOWN | — | External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607. | Aug 18, 2026 |
| CVE-2026-16309 | MEDIUM | 5.3 | Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EdoWEB: before 780-g7. | Aug 18, 2026 |
| CVE-2026-75855 | HIGH | 8.7 | ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, allowing authenticated root users to … | Aug 18, 2026 |
| CVE-2026-75854 | CRITICAL | 9.8 | ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers to read, write, and delete data. Attackers … | Aug 18, 2026 |
| CVE-2026-75853 | HIGH | 8.8 | ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but performs no authorization: it never checks database access permissions (canAccessToDatabase) and … | Aug 18, 2026 |
| CVE-2026-75852 | CRITICAL | 9.8 | ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, … | Aug 18, 2026 |
| CVE-2026-75851 | CRITICAL | 9.9 | ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted … | Aug 18, 2026 |
| CVE-2026-75850 | MEDIUM | 4.2 | ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and time-series HTTP handlers. Because no principal is bound on the worker … | Aug 18, 2026 |
| CVE-2026-75846 | HIGH | 7.1 | ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. DeleteFunctionStatement.executeSimple unregisters and persists deletion of a … | Aug 18, 2026 |
| CVE-2026-75845 | MEDIUM | 6.3 | ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool. SetServerSettingTool.execute() gates only on the global allowAdmin flag and … | Aug 18, 2026 |
| CVE-2026-75844 | HIGH | 7.1 | ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where the security validator resolves and checks hostnames but the … | Aug 18, 2026 |
| CVE-2026-75843 | CRITICAL | 9.9 | ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without … | Aug 18, 2026 |
| CVE-2026-75842 | HIGH | 7.7 | ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users to read local files. … | Aug 18, 2026 |