Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-31217 — Optimate Python Code Execution Vulnerability

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) allows arbitrary code execution. When a user …

optimate | Remote | Injection
May 12, 2026 May 26, 2026
May 12, 2026
May 26, 2026
9.1 CRITICAL
CVE-2026-31216 — Nexenta MinIO Unauthorized File Deletion Vulnerability

The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file management API. The DELETE /storage/{object_name:path} endpoint lacks authentica…

nexent | Remote | Authorization
May 12, 2026 May 26, 2026
May 12, 2026
May 26, 2026
9.1 CRITICAL
CVE-2026-31215 — "Nexent ElasticSearch Unauthenticated Arbitrary File Deletion Vulnerability"

The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch service interface. The DELETE /{index_name}/documents endpoint lacks proper aut…

nexent | Remote | Authorization
May 12, 2026 May 26, 2026
May 12, 2026
May 26, 2026
9.8 CRITICAL
CVE-2026-31214 — TensorFlow PyTorch Insecure Deserialization Vulnerability

The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insecure deserialization vulnerability (CWE-502). The s…

Remote | Injection
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.8 HIGH
CVE-2026-30810 — Server-Side Request Forgery in API Checker leads to Privilege Escalation

Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800

pandora_fms | Remote | Server-Side Request Forgery
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.1 HIGH
CVE-2026-30808 — Session Fixation in Authentication leads to Session Hijacking

Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777 through 800

pandora_fms | Remote | Authentication
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.8 HIGH
CVE-2026-30807 — Cross-Site Request Forgery on Extension Pages

Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 through 800

pandora_fms | Remote | Cross-Site Request Forgery
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
9.1 CRITICAL
CVE-2026-30805 — Insecure Default Initialization in API Authentication leads to Authentication Bypass

Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800

pandora_fms | Remote | Authentication
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
5.4 MEDIUM
CVE-2023-30059 — MK-Auth Insecure Direct Object Reference

An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other users via manipulation of the chamado parameter through a crafted GET request.

Remote | Authorization
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.0 HIGH
CVE-2023-27753 — MK-Auth PHP File Upload Remote Code Execution Vulnerability

An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Remote | Misconfiguration
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
9.8 CRITICAL
CVE-2026-8401 — Sandbox escape in the Profile Backup component

Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.

firefox thunderbird | Remote | Misconfiguration
May 12, 2026 May 19, 2026
May 12, 2026
May 19, 2026
6.5 MEDIUM
CVE-2026-8368 — LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization h…

LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before …

Remote | Information Disclosure
May 12, 2026 May 19, 2026
May 12, 2026
May 19, 2026
8.8 HIGH
CVE-2026-8111 — Ivanti Endpoint Manager SQL Injection Remote Code Execution

SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.

endpoint_manager | Remote | Injection
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
7.8 HIGH
CVE-2026-8110 — Ivanti Endpoint Manager Privilege Escalation Vulnerability

Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges.

endpoint_manager | Authorization
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
6.5 MEDIUM
CVE-2026-8109 — Ivanti Endpoint Manager Credentials Disclosure

An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.

endpoint_manager | Remote | Information Disclosure
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
7.2 HIGH
CVE-2026-8051 — Ivanti Virtual Traffic Manager OS Command Injection Vulnerability

OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

virtual_traffic_manager | Remote | Injection
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
9.6 CRITICAL
CVE-2026-8043 — Ivanti Xtraction File Name Manipulation Vulnerability

External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to …

xtraction | Remote | Path Traversal
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
7.8 HIGH
CVE-2026-7432 — Ivanti Secure Access Client Privilege Escalation Vulnerability

A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM

windows secure_access_client | Race Condition
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
4.4 MEDIUM
CVE-2026-7431 — Ivanti Secure Access Client Privilege Escalation

An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a sh…

windows secure_access_client | Misconfiguration
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
8.2 HIGH
CVE-2026-6866 — Initialization of a Resource with an Insecure Default vulnerability on EcoStruxure™ Panel…

CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in ra…

Remote | Authentication
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
Showing 20 of 7368 Results