Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28475
Total
2191
Critical
8537
High
8862
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-48968 | MEDIUM | 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slider allows DOM-Based XSS. This issue affects Master Slider: from n/a … | May 27, 2026 |
| CVE-2026-48877 | MEDIUM | 6.5 | Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive Data. This issue affects GenerateBlocks: from n/a through 2.1.0. | May 27, 2026 |
| CVE-2026-40852 | HIGH | 7.2 | A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly checking this configuration value … | May 27, 2026 |
| CVE-2026-40851 | HIGH | 8.4 | A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an USB stick leading to code execution. This … | May 27, 2026 |
| CVE-2026-40850 | HIGH | 7.5 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountData function due to improper neutralization of special elements in a SQL … | May 27, 2026 |
| CVE-2026-40849 | MEDIUM | 6.5 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the user_alarmprofile view due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40848 | MEDIUM | 6.5 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the tag view due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40847 | MEDIUM | 6.5 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system_tag view due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40846 | MEDIUM | 6.5 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system view due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40845 | MEDIUM | 6.5 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the devices_configuration view due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40844 | MEDIUM | 6.5 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dashboard view due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40843 | MEDIUM | 6.5 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the alarming view due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40842 | MEDIUM | 6.5 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getWidgetTags function due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40841 | MEDIUM | 6.5 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectTags function due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40840 | MEDIUM | 6.5 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the VerifyCreateLicences function due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40839 | MEDIUM | 6.5 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getComponentScalings function due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40838 | MEDIUM | 6.5 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDeviceScalings function due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40837 | MEDIUM | 6.5 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectScalings function due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40836 | HIGH | 7.1 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the inmessage model due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40835 | MEDIUM | 6.5 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the saveObjectFromData function due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40834 | HIGH | 7.1 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash_layout.php files saveDashboardLayout function due to improper neutralization of special elements … | May 27, 2026 |
| CVE-2026-40833 | HIGH | 7.1 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash.php files saveDashboardLayout function due to improper neutralization of special elements … | May 27, 2026 |
| CVE-2026-40832 | MEDIUM | 6.5 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDevicegroups function due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40831 | MEDIUM | 6.5 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the Easy View due to improper neutralization of special elements in a … | May 27, 2026 |
| CVE-2026-40830 | MEDIUM | 5.5 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the admin.mbnetj.php files UpdateParam function due to improper neutralization of special elements … | May 27, 2026 |