Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-10142 — kafka-python prior to 2.3.2 Denial of Service via Protocol Parser Frame Length

kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-in-the-middle attacker to exhaust memory or hang connections by…

Remote | Denial of Service
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
8.1 HIGH
CVE-2026-0274 — Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration

An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resource…

Remote | Authentication
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
6.1 MEDIUM
CVE-2026-0273 — PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to …

Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
6.0 MEDIUM
CVE-2026-0272 — PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)

A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with…

pan-os prisma_access pan-os prisma_access prisma_access pan-os +1 more | Remote | Authorization
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
5.9 MEDIUM
CVE-2026-0271 — Prisma Access Agent: Local Privilege Escalation by Authorized Users

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Pri…

prisma_access_agent | Authorization
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
4.8 MEDIUM
CVE-2026-0270 — Cortex XSOAR: Path Traversal Vulnerability

A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipu…

cortex_xsoar cortex_xsoar | Path Traversal
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
4.6 MEDIUM
CVE-2026-0269 — PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing

A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet…

Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
4.4 MEDIUM
CVE-2026-0268 — Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux

A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Window…

prisma_access_agent | Misconfiguration
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
4.4 MEDIUM
CVE-2026-0267 — GlobalProtect App: Information Exposure Vulnerability on macOS

An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the Glo…

Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
1.1 LOW
CVE-2026-0266 — PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue i…

pan-os prisma_access pan-os prisma_access prisma_access pan-os +1 more | Remote | Cross-Site Scripting
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
3.5 LOW
CVE-2022-48575 — macOS Login Window Bypass

A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4.

macos | Authorization
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
7.1 HIGH
CVE-2022-26758 — Apple macOS Shared Memory Corruption

A malicious application may cause unexpected changes in memory shared between processes. A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey …

macos | Memory Corruption
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
8.8 HIGH
CVE-2026-6893 — Dracut: dracut: root code execution via dhcp options command injection

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malic…

Jun 10, 2026 Jun 10, 2026
Jun 10, 2026
Jun 10, 2026
5.9 MEDIUM
CVE-2026-50127 — Weblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96)

Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, o…

weblate | Remote | Misconfiguration
Jun 10, 2026 Jun 10, 2026
Jun 10, 2026
Jun 10, 2026
6.9 MEDIUM
CVE-2026-46683 — Snappy: SSRF and local file read via the xsl-style-sheet option

Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0, there is a SSRF and local file read vulnerability via the xsl-style-sheet opt…

snappy | Remote | Server-Side Request Forgery
Jun 10, 2026 Jun 10, 2026
Jun 10, 2026
Jun 10, 2026
7.5 HIGH
CVE-2026-46643 — Snappy: Binary path is never shell-escaped due to an inverted is_executable check

Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.1, on POSIX, escapeshellarg(‘/usr/bin/wkhtmltopdf’) returns the literal string ‘…

snappy | Injection
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
8.4 HIGH
CVE-2026-46529 — PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an att…

atril | Injection
Jun 10, 2026 Jun 10, 2026
Jun 10, 2026
Jun 10, 2026
4.6 MEDIUM
CVE-2026-45106 — Weblate: Stored HTML injection in editor search preview

Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and context as HTML without escaping. Any contributor whose content reaches those …

weblate | Remote | Cross-Site Scripting
Jun 10, 2026 Jun 10, 2026
Jun 10, 2026
Jun 10, 2026
7.5 HIGH
CVE-2026-1220 — Google Chrome V8 Type Confusion

Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)

chrome chrome edge_chromium | Remote | Race Condition
Jun 10, 2026 Jun 10, 2026
Jun 10, 2026
Jun 10, 2026
6.5 MEDIUM
CVE-2026-50639 — Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against me…

Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by ne…

Remote | Injection
Jun 10, 2026 Jun 10, 2026
Jun 10, 2026
Jun 10, 2026
Showing 20 of 7149 Results