Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-30810 — Server-Side Request Forgery in API Checker leads to Privilege Escalation

Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800

pandora_fms | Remote | Server-Side Request Forgery
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.1 HIGH
CVE-2026-30808 — Session Fixation in Authentication leads to Session Hijacking

Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777 through 800

pandora_fms | Remote | Authentication
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.8 HIGH
CVE-2026-30807 — Cross-Site Request Forgery on Extension Pages

Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 through 800

pandora_fms | Remote | Cross-Site Request Forgery
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
9.1 CRITICAL
CVE-2026-30805 — Insecure Default Initialization in API Authentication leads to Authentication Bypass

Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800

pandora_fms | Remote | Authentication
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
5.4 MEDIUM
CVE-2023-30059 — MK-Auth Insecure Direct Object Reference

An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other users via manipulation of the chamado parameter through a crafted GET request.

Remote | Authorization
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.0 HIGH
CVE-2023-27753 — MK-Auth PHP File Upload Remote Code Execution Vulnerability

An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Remote | Misconfiguration
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
0.0 NA
CVE-2026-8401 — Sandbox escape in the Profile Backup component

Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3.

firefox | Misconfiguration
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
0.0 NA
CVE-2026-8368 — LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization h…

LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before …

| Information Disclosure
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
8.8 HIGH
CVE-2026-8111 — Ivanti Endpoint Manager SQL Injection Remote Code Execution

SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.

endpoint_manager | Remote | Injection
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
7.8 HIGH
CVE-2026-8110 — Ivanti Endpoint Manager Privilege Escalation Vulnerability

Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges.

endpoint_manager | Authorization
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
6.5 MEDIUM
CVE-2026-8109 — Ivanti Endpoint Manager Credentials Disclosure

An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.

endpoint_manager | Remote | Information Disclosure
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
7.2 HIGH
CVE-2026-8051 — Ivanti Virtual Traffic Manager OS Command Injection Vulnerability

OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Remote | Injection
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
9.6 CRITICAL
CVE-2026-8043 — Ivanti Xtraction File Name Manipulation Vulnerability

External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to …

xtraction | Remote | Path Traversal
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
7.8 HIGH
CVE-2026-7432 — Ivanti Secure Access Client Privilege Escalation Vulnerability

A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM

windows secure_access_client | Race Condition
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
4.4 MEDIUM
CVE-2026-7431 — Ivanti Secure Access Client Privilege Escalation

An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a sh…

windows secure_access_client | Misconfiguration
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
8.2 HIGH
CVE-2026-6866 — Initialization of a Resource with an Insecure Default vulnerability on EcoStruxure™ Panel…

CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in ra…

Remote | Authentication
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
4.7 MEDIUM
CVE-2026-5061 — Consul-template vulnerable to sandbox path bypass in file helper via a symlink attack

The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) …

terraform_provider | Path Traversal
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.5 HIGH
CVE-2026-43983 — Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, …

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken function (oidc_service.go) validates the refresh …

pocket_id | Remote | Authentication
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
7.3 HIGH
CVE-2026-43939 — YAF.NET: Stored XSS in Forum Thread Posts/Replies Allowing Arbitrary JavaScript Execution…

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and…

yaf.net | Remote | Cross-Site Scripting
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.1 HIGH
CVE-2026-43938 — YAF.NET: Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-A…

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNET.Core/Logger/DbLogger.cs) captures the incoming request's User-Agent header in…

yaf.net | Remote | Cross-Site Scripting
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
Showing 20 of 6425 Results