Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.1 CRITICAL
CVE-2026-73311 — XenForo < 2.3.13 OAuth2 Authorization Code Reuse

XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers …

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.2 HIGH
CVE-2026-73310 — XenForo < 2.3.13 OAuth2 Authorization Code Token Theft via redirect_uri Bypass

XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a differe…

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.1 CRITICAL
CVE-2026-73309 — XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint

XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for cli…

Remote | Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.1 MEDIUM
CVE-2026-33920 — Cross-site request forgery in the Guardian/CMC login before 26.3.0

A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker with a valid account can tr…

cmc guardian cmc guardian | Remote | Cross-Site Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.4 MEDIUM
CVE-2026-33391 — Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0

An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges can re…

cmc guardian cmc guardian | Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.5 HIGH
CVE-2026-33389 — Disabled and non-configurable certificate/host key validation in Smart Polling in Guardia…

An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote ho…

cmc guardian cmc guardian arc arc | Remote | Misconfiguration
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.4 HIGH
CVE-2026-33388 — Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0

An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges can view…

cmc guardian cmc guardian | Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.1 MEDIUM
CVE-2026-33387 — Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0

A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a das…

cmc guardian cmc guardian | Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.8 HIGH
CVE-2026-18851 — Ivanti Endpoint Manager Mobile Privilege Escalation Vulnerability

Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.

endpoint_manager_mobile | Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-33197 — BDS Module Bypass Secure Boot Advisory

AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vulnerability may lead to arb…

| Misconfiguration
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
0.0 NA
CVE-2026-86135 — Dimension CSRF Vulnerability in Database Snapshot Creation Allows Denial of Service

A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authen…

dimension | Cross-Site Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
4.3 MEDIUM
CVE-2026-79603 — Unconditionally do TLB flushing ahead of page scrubbing

x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page …

Remote | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
0.0 NA
CVE-2026-79602 — x86: improper handling of HVM emulation return codes

A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.

| Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.7 HIGH
CVE-2026-77106 — Cvlaunchd Code Execution

Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including …

| Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-77105 — CommServe Privilege Escalation

CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.

| Cryptography
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.3 HIGH
CVE-2026-77104 — CommServe Path Traversal

CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.

| Path Traversal
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-77103 — CommServe Information Disclosure

CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.

| Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-77102 — CommServe Denial of Service

CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.

| Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-77101 — CommServe Stack-based Buffer Overflow

CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.

| Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.8 HIGH
CVE-2026-77098 — Private Metrics Server SQL Injection

Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.

| Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
Showing 20 of 12601 Results