Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28297
Total
2180
Critical
8507
High
8806
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-49323 | MEDIUM | 4.3 | Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year … | May 29, 2026 |
| CVE-2026-48527 | HIGH | 8.7 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scripting (XSS) … | May 29, 2026 |
| CVE-2026-45611 | UNKNOWN | — | Rejected reason: Further research determined the issue is not a vulnerability. | May 29, 2026 |
| CVE-2026-45551 | UNKNOWN | — | Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.165, GroupOffice allows authenticated users to persist arbitrary legacy settings … | May 29, 2026 |
| CVE-2026-45312 | CRITICAL | 9.9 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated user … | May 29, 2026 |
| CVE-2026-45043 | UNKNOWN | — | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoint allows a user with ImportIAMAction … | May 29, 2026 |
| CVE-2026-10071 | CRITICAL | 9.8 | DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code … | May 29, 2026 |
| CVE-2026-9811 | MEDIUM | 5.4 | A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, … | May 29, 2026 |
| CVE-2026-9809 | HIGH | 7.6 | A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such … | May 29, 2026 |
| CVE-2026-9808 | HIGH | 7.1 | An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as … | May 29, 2026 |
| CVE-2026-9559 | CRITICAL | 9.9 | A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the … | May 29, 2026 |
| CVE-2025-41281 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in … | May 29, 2026 |
| CVE-2025-41280 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access … | May 29, 2026 |
| CVE-2025-41279 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41278 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attackers with access to the TX … | May 29, 2026 |
| CVE-2025-41277 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41276 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41275 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41274 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41273 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts … | May 29, 2026 |
| CVE-2025-41272 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41271 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that … | May 29, 2026 |
| CVE-2025-41270 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41269 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41268 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that … | May 29, 2026 |