Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

28475
Total
2191
Critical
8537
High
8862
Medium
CVE ID Severity Score Description Published
CVE-2026-48968 MEDIUM 6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slider allows DOM-Based XSS. This issue affects Master Slider: from n/a … May 27, 2026
CVE-2026-48877 MEDIUM 6.5 Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive Data. This issue affects GenerateBlocks: from n/a through 2.1.0. May 27, 2026
CVE-2026-40852 HIGH 7.2 A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly checking this configuration value … May 27, 2026
CVE-2026-40851 HIGH 8.4 A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an USB stick leading to code execution. This … May 27, 2026
CVE-2026-40850 HIGH 7.5 An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountData function due to improper neutralization of special elements in a SQL … May 27, 2026
CVE-2026-40849 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the user_alarmprofile view due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40848 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the tag view due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40847 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system_tag view due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40846 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system view due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40845 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the devices_configuration view due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40844 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dashboard view due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40843 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the alarming view due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40842 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getWidgetTags function due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40841 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectTags function due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40840 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the VerifyCreateLicences function due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40839 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getComponentScalings function due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40838 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDeviceScalings function due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40837 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectScalings function due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40836 HIGH 7.1 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the inmessage model due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40835 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the saveObjectFromData function due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40834 HIGH 7.1 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash_layout.php files saveDashboardLayout function due to improper neutralization of special elements … May 27, 2026
CVE-2026-40833 HIGH 7.1 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash.php files saveDashboardLayout function due to improper neutralization of special elements … May 27, 2026
CVE-2026-40832 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDevicegroups function due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40831 MEDIUM 6.5 An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the Easy View due to improper neutralization of special elements in a … May 27, 2026
CVE-2026-40830 MEDIUM 5.5 A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the admin.mbnetj.php files UpdateParam function due to improper neutralization of special elements … May 27, 2026