Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28561
Total
2193
Critical
8548
High
8866
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44925 | HIGH | 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a … | May 20, 2026 |
| CVE-2026-44924 | MEDIUM | 5.4 | InfoScale VIOM 9.1.3 allows XSS. | May 20, 2026 |
| CVE-2026-44923 | MEDIUM | 6.5 | SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges. | May 20, 2026 |
| CVE-2026-20223 | CRITICAL | 10.0 | A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the … | May 20, 2026 |
| CVE-2026-20206 | MEDIUM | 6.3 | A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on … | May 20, 2026 |
| CVE-2026-20199 | MEDIUM | 4.7 | A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating … | May 20, 2026 |
| CVE-2026-20171 | MEDIUM | 6.8 | A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could … | May 20, 2026 |
| CVE-2026-9084 | UNKNOWN | — | MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local … | May 20, 2026 |
| CVE-2026-8598 | CRITICAL | 9.1 | An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about … | May 20, 2026 |
| CVE-2026-8488 | MEDIUM | 4.3 | Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 … | May 20, 2026 |
| CVE-2026-8487 | MEDIUM | 6.5 | Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. | May 20, 2026 |
| CVE-2026-8486 | MEDIUM | 5.3 | Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before … | May 20, 2026 |
| CVE-2026-5783 | HIGH | 7.6 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Beyaz Computer Software Design Industry and Trade Ltd. Co. CityPLus allows Reflected XSS. … | May 20, 2026 |
| CVE-2026-4293 | MEDIUM | 5.3 | The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be executed by the victim's browser, which allows the … | May 20, 2026 |
| CVE-2026-39047 | HIGH | 7.5 | Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Printing Service (JetDirect) on TCP port 9100 | May 20, 2026 |
| CVE-2025-32750 | HIGH | 7.5 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, … | May 20, 2026 |
| CVE-2023-7346 | MEDIUM | 4.0 | Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause incorrect Bitcoin addresses to be displayed by exploiting … | May 20, 2026 |
| CVE-2026-8485 | MEDIUM | 5.9 | Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. | May 20, 2026 |
| CVE-2026-8469 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in phenixdigital phoenix_storybook allows unauthenticated denial-of-service via BEAM atom table exhaustion. Multiple LiveView event handlers convert user-supplied … | May 20, 2026 |
| CVE-2026-8467 | UNKNOWN | — | Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanitized attribute value interpolation in HEEx template generation. The psb-assign WebSocket event handler … | May 20, 2026 |
| CVE-2026-47068 | UNKNOWN | — | Authorization Bypass Through User-Controlled Key vulnerability in phenixdigital phoenix_storybook allows cross-session PubSub topic injection via a URL query parameter. 'Elixir.PhoenixStorybook.Story.ComponentIframeLive':handle_params/3 in lib/phoenix_storybook/live/story/component_iframe_live.ex reads a PubSub … | May 20, 2026 |
| CVE-2026-24425 | HIGH | 8.8 | Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass … | May 20, 2026 |
| CVE-2026-22554 | HIGH | 7.8 | MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability | May 20, 2026 |
| CVE-2026-21836 | MEDIUM | 6.5 | The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability. Under certain circumstances, document level access restrictions will be ignored when determining … | May 20, 2026 |
| CVE-2026-5950 | MEDIUM | 5.3 | An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource … | May 20, 2026 |