Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.1 MEDIUM
CVE-2026-33920 — Cross-site request forgery in the Guardian/CMC login before 26.3.0

A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker with a valid account can tr…

cmc guardian cmc guardian | Remote | Cross-Site Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.4 MEDIUM
CVE-2026-33391 — Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0

An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can re…

cmc guardian cmc guardian | Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.5 HIGH
CVE-2026-33389 — Disabled and non-configurable certificate/host key validation in Smart Polling in Guardia…

An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote ho…

cmc guardian cmc guardian arc arc | Remote | Misconfiguration
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.4 HIGH
CVE-2026-33388 — Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0

An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges can view…

cmc guardian cmc guardian | Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.1 MEDIUM
CVE-2026-33387 — Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0

A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a das…

cmc guardian cmc guardian | Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
0.0 NA
CVE-2026-86644 — star7th showdoc API Page Save Endpoint editormd.js cross site scripting

A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API Page Save Endpoint. Execut…

| Cross-Site Scripting
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.6 HIGH
CVE-2026-74239 — XenForo < 2.3.13 Path Traversal via Style Archive Importer on Windows

XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windows deployments that allows authenticated non-super administrators with style permissions to write a…

Remote | Path Traversal
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-73321 — XenForo < 2.3.13 Uncontrolled Recursion DoS via BBCode Parser

XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated attackers to cause persistent denial of service by submitting a post with deeply …

Remote | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.1 MEDIUM
CVE-2026-73320 — XenForo < 2.3.13 Unauthenticated Information Disclosure via Unfurl Endpoint

XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private unfurl records by supplying predictable auto-increment…

Remote | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.1 MEDIUM
CVE-2026-73319 — XenForo < 2.3.13 XSS via Dynamic Redirect Handler

XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers to execute arbitrary JavaScript in the board origin by crafti…

Remote | Cross-Site Scripting
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.1 MEDIUM
CVE-2026-73318 — XenForo < 2.3.13 Missing Authorization via force-agreement Controller

XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreement forms regardless of their…

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.1 MEDIUM
CVE-2026-73317 — XenForo < 2.3.13 Missing Authorization via ACP Cache-Rebuild Dispatcher

XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited administrators with only the rebuildCache permission to perform unauthoriz…

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-73316 — XenForo < 2.3.13 Payment Replay via PayPal REST Payment Provider

XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing dupl…

Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.6 HIGH
CVE-2026-73315 — XenForo < 2.3.13 SSRF via PayPal REST Webhook Handler

XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests …

Remote | Server-Side Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-73314 — XenForo < 2.3.13 Signature Verification Bypass via PayPal REST Webhook

XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a web…

Remote | Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.6 HIGH
CVE-2026-73313 — XenForo < 2.3.13 MFA Bypass via Passkey TFA Provider

XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated attacker to complete login as another user by submitting the…

Remote | Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
0.0 NA
CVE-2026-79603 — Unconditionally do TLB flushing ahead of page scrubbing

x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page …

| Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
0.0 NA
CVE-2026-79602 — x86: improper handling of HVM emulation return codes

A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.

| Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.7 HIGH
CVE-2026-77106 — Cvlaunchd Code Execution

Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including …

| Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-77105 — CommServe Privilege Escalation

CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.

| Cryptography
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
Showing 20 of 12574 Results