Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
1.7 LOW
CVE-2026-0301 — PAN-OS: Information Disclosure Vulnerability in URL Filtering

An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panor…

pan-os prisma_access pan-os prisma_access prisma_access pan-os +2 more | Remote | Information Disclosure
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
5.9 MEDIUM
CVE-2026-0299 — GlobalProtect App: Local Privilege Escalation Vulnerabilities

Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
5.2 MEDIUM
CVE-2026-0298 — GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLA…

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
5.2 MEDIUM
CVE-2026-0297 — GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially exe…

globalprotect_app globalprotect_app | Memory Corruption
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
4.5 MEDIUM
CVE-2026-0296 — GlobalProtect App: Improper Certificate Validation Bypass Vulnerability

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application co…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
4.1 MEDIUM
CVE-2026-0295 — GlobalProtect App: Local Privilege Escalation via Race Condition on macOS

A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.0 MEDIUM
CVE-2026-0294 — Prisma Access Agent: Local Privilege Escalation

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma A…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
5.6 MEDIUM
CVE-2026-0293 — Prisma Access Agent: Anti-Tamper Protection Bypass on Windows

A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to prot…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
2.1 LOW
CVE-2026-0292 — Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows

An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing t…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
1.1 LOW
CVE-2026-0291 — Prisma Access Agent: Authenticated Limited File Deletion on Linux

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files i…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.5 LOW
CVE-2026-0290 — Prisma Browser: Sensitive Information Disclosure Vulnerability

An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data.

prisma_browser prisma_browser | Information Disclosure
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.5 LOW
CVE-2026-0289 — Prisma Browser: Inappropriate Implementation in Account Protection

A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls.

prisma_browser prisma_browser | Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-18728 — Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing

A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker o…

enterprise_linux enterprise_linux | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.3 MEDIUM
CVE-2026-50544 — NortheBridge/luminalshine has Incorrect Permission Assignment for Critical Resource and C…

NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at `src/platform/windows/misc.cpp` …

| Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
9.8 CRITICAL
CVE-2026-49819 — UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reac…

Remote | Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.8 HIGH
CVE-2026-49473 — @cedar-policy/authorization-for-expressjs has an authorization bypass via query string ma…

@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluatin…

Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
2.0 LOW
CVE-2026-48791 — Sigstore Java has a vulnerability with bundle verification of integratedTime

sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) against the Fulcio certifica…

| Cryptography
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.9 MEDIUM
CVE-2026-46688 — Meeting Room Booking System has an unauthenticated open redirect

The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, an unauthenticated request can be made to redirect the user to a query-specified …

Remote | Misconfiguration
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.7 HIGH
CVE-2026-46382 — Meeting Room Booking System has server-side request forgery in import functionality

The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local URI can be made to be fetched without checks. Versi…

Remote | Server-Side Request Forgery
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-17431 — PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() o…

PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for. to_pdf reads the generated PDF back fr…

| Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
Showing 20 of 11040 Results