Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28297
Total
2180
Critical
8507
High
8806
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-41267 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41266 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall … | May 29, 2026 |
| CVE-2025-41265 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall … | May 29, 2026 |
| CVE-2026-9558 | CRITICAL | 9.9 | A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated … | May 29, 2026 |
| CVE-2026-9557 | MEDIUM | 6.4 | A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP … | May 29, 2026 |
| CVE-2026-49201 | UNKNOWN | — | The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, … | May 29, 2026 |
| CVE-2026-46579 | HIGH | 7.4 | A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from … | May 29, 2026 |
| CVE-2026-42965 | HIGH | 7.7 | A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an … | May 29, 2026 |
| CVE-2026-10078 | LOW | 2.7 | A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, specifically client_id and client_secret, to be transmitted as plaintext … | May 29, 2026 |
| CVE-2025-12714 | MEDIUM | 5.3 | The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability … | May 29, 2026 |
| CVE-2026-9189 | MEDIUM | 5.3 | The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all … | May 29, 2026 |
| CVE-2026-6075 | HIGH | 8.1 | The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing … | May 29, 2026 |
| CVE-2026-49200 | UNKNOWN | — | The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), … | May 29, 2026 |
| CVE-2026-49199 | UNKNOWN | — | Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device. | May 29, 2026 |
| CVE-2026-49198 | UNKNOWN | — | Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors. | May 29, 2026 |
| CVE-2026-49197 | UNKNOWN | — | Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails. | May 29, 2026 |
| CVE-2026-49196 | UNKNOWN | — | The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary shell commands. | May 29, 2026 |
| CVE-2026-49195 | UNKNOWN | — | Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands. | May 29, 2026 |
| CVE-2026-10058 | MEDIUM | 4.8 | ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are … | May 29, 2026 |
| CVE-2026-10057 | MEDIUM | 4.8 | ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are … | May 29, 2026 |
| CVE-2026-10056 | HIGH | 7.5 | CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux … | May 29, 2026 |
| CVE-2026-10052 | MEDIUM | 4.1 | A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make … | May 29, 2026 |
| CVE-2026-10039 | MEDIUM | 4.9 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, … | May 29, 2026 |
| CVE-2026-9243 | MEDIUM | 6.4 | The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions … | May 29, 2026 |
| CVE-2026-4776 | HIGH | 7.1 | An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can … | May 29, 2026 |