Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26567
Total
1967
Critical
8010
High
8270
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-20257 | MEDIUM | 5.7 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that … | Jun 10, 2026 |
| CVE-2026-20256 | MEDIUM | 5.7 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that … | Jun 10, 2026 |
| CVE-2026-20255 | MEDIUM | 5.7 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that … | Jun 10, 2026 |
| CVE-2026-20254 | MEDIUM | 5.7 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that … | Jun 10, 2026 |
| CVE-2026-20253 | CRITICAL | 9.8 | In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary … | Jun 10, 2026 |
| CVE-2026-20252 | HIGH | 7.6 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.2604.3, 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, a low-privileged user … | Jun 10, 2026 |
| CVE-2026-20251 | HIGH | 8.8 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions … | Jun 10, 2026 |
| CVE-2026-11596 | MEDIUM | 4.7 | In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the … | Jun 10, 2026 |
| CVE-2026-11417 | HIGH | 7.3 | OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who controls the value of … | Jun 10, 2026 |
| CVE-2026-46616 | MEDIUM | 5.4 | Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to support member related operations … | Jun 10, 2026 |
| CVE-2026-46609 | MEDIUM | 4.6 | Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML into an input field, which is … | Jun 10, 2026 |
| CVE-2026-53698 | MEDIUM | 6.5 | Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set. | Jun 10, 2026 |
| CVE-2026-53694 | UNKNOWN | — | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Argument Injection.This issue affects Nomachine: before 9.5.7, before 8.23.2. | Jun 10, 2026 |
| CVE-2026-53693 | UNKNOWN | — | A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering paths interpolated tag names, collection names, entity identifiers, cluster names, … | Jun 10, 2026 |
| CVE-2026-49760 | UNKNOWN | — | Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulnerability is associated with program file lib/erl_interface/src/misc/ei_printterm.c and program routine ei_s_print_term. The … | Jun 10, 2026 |
| CVE-2026-49759 | UNKNOWN | — | Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR … | Jun 10, 2026 |
| CVE-2026-48860 | UNKNOWN | — | Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-over-TLS LAN allowlist. The inet_tls_dist:check_ip/1 function, which enforces … | Jun 10, 2026 |
| CVE-2026-48859 | UNKNOWN | — | Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication. When the SSH daemon … | Jun 10, 2026 |
| CVE-2026-48858 | UNKNOWN | — | Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV response IP address. The ftp_internal:handle_ctrl_result/2 … | Jun 10, 2026 |
| CVE-2026-48856 | UNKNOWN | — | Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data. The httpc client forwards the Authorization and Proxy-Authorization request headers … | Jun 10, 2026 |
| CVE-2026-48855 | UNKNOWN | — | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_READLINK handler in ssh_sftpd sends the … | Jun 10, 2026 |
| CVE-2026-48096 | MEDIUM | 5.0 | OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same … | Jun 10, 2026 |
| CVE-2026-46558 | HIGH | 8.3 | Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, … | Jun 10, 2026 |
| CVE-2026-46497 | UNKNOWN | — | Crawlee is a web scraping and browser automation library. From version 1.0.0 to before version 1.7.0, Crawlee is vulnerable to SSRF via sitemap-derived URLs. This … | Jun 10, 2026 |
| CVE-2026-45569 | HIGH | 8.1 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. … | Jun 10, 2026 |