Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

28297
Total
2180
Critical
8507
High
8806
Medium
CVE ID Severity Score Description Published
CVE-2025-41267 UNKNOWN Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall … May 29, 2026
CVE-2025-41266 UNKNOWN Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall … May 29, 2026
CVE-2025-41265 UNKNOWN Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall … May 29, 2026
CVE-2026-9558 CRITICAL 9.9 A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated … May 29, 2026
CVE-2026-9557 MEDIUM 6.4 A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP … May 29, 2026
CVE-2026-49201 UNKNOWN The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, … May 29, 2026
CVE-2026-46579 HIGH 7.4 A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from … May 29, 2026
CVE-2026-42965 HIGH 7.7 A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an … May 29, 2026
CVE-2026-10078 LOW 2.7 A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, specifically client_id and client_secret, to be transmitted as plaintext … May 29, 2026
CVE-2025-12714 MEDIUM 5.3 The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability … May 29, 2026
CVE-2026-9189 MEDIUM 5.3 The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all … May 29, 2026
CVE-2026-6075 HIGH 8.1 The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing … May 29, 2026
CVE-2026-49200 UNKNOWN The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), … May 29, 2026
CVE-2026-49199 UNKNOWN Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device. May 29, 2026
CVE-2026-49198 UNKNOWN Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors. May 29, 2026
CVE-2026-49197 UNKNOWN Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails. May 29, 2026
CVE-2026-49196 UNKNOWN The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary shell commands. May 29, 2026
CVE-2026-49195 UNKNOWN Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands. May 29, 2026
CVE-2026-10058 MEDIUM 4.8 ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are … May 29, 2026
CVE-2026-10057 MEDIUM 4.8 ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are … May 29, 2026
CVE-2026-10056 HIGH 7.5 CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux … May 29, 2026
CVE-2026-10052 MEDIUM 4.1 A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make … May 29, 2026
CVE-2026-10039 MEDIUM 4.9 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, … May 29, 2026
CVE-2026-9243 MEDIUM 6.4 The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions … May 29, 2026
CVE-2026-4776 HIGH 7.1 An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can … May 29, 2026