Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-8110 — Ivanti Endpoint Manager Privilege Escalation Vulnerability

Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges.

endpoint_manager | Authorization
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
6.5 MEDIUM
CVE-2026-8109 — Ivanti Endpoint Manager Credentials Disclosure

An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.

endpoint_manager | Remote | Information Disclosure
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
7.2 HIGH
CVE-2026-8051 — Ivanti Virtual Traffic Manager OS Command Injection Vulnerability

OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Remote | Injection
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
9.6 CRITICAL
CVE-2026-8043 — Ivanti Xtraction File Name Manipulation Vulnerability

External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to …

xtraction | Remote | Path Traversal
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
7.8 HIGH
CVE-2026-7432 — Ivanti Secure Access Client Privilege Escalation Vulnerability

A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM

windows secure_access_client | Race Condition
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
4.4 MEDIUM
CVE-2026-7431 — Ivanti Secure Access Client Privilege Escalation

An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a sh…

windows secure_access_client | Misconfiguration
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
8.2 HIGH
CVE-2026-6866 — Initialization of a Resource with an Insecure Default vulnerability on EcoStruxure™ Panel…

CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in ra…

Remote | Authentication
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
4.7 MEDIUM
CVE-2026-5061 — Consul-template vulnerable to sandbox path bypass in file helper via a symlink attack

The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) …

terraform_provider | Path Traversal
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.5 HIGH
CVE-2026-43983 — Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, …

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken function (oidc_service.go) validates the refresh …

pocket_id | Remote | Authentication
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
7.3 HIGH
CVE-2026-43939 — YAF.NET: Stored XSS in Forum Thread Posts/Replies Allowing Arbitrary JavaScript Execution…

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and…

yaf.net | Remote | Cross-Site Scripting
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.1 HIGH
CVE-2026-43938 — YAF.NET: Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-A…

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNET.Core/Logger/DbLogger.cs) captures the incoming request's User-Agent header in…

yaf.net | Remote | Cross-Site Scripting
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.8 HIGH
CVE-2026-43937 — YAF.NET: Pre-Handler Authorization Bypass on Admin Pages Enabling Blind SQL Execution via…

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttribute rewrites the response to a 302 to /Info/4. Th…

yaf.net | Remote | Injection
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.2 HIGH
CVE-2026-42260 — Open-WebSearch: SSRF in `fetchWebContent` MCP tool: bracketed IPv6 literals and non-resol…

Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to 2.1.7, isPublicHttpUrl / assertPublicHttpUrl in src/utils/urlSafety.ts do not r…

Remote | Server-Side Request Forgery
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
7.5 HIGH
CVE-2026-32687 — SQL injection via channel name in Postgrex.Notifications.listen/3 and unlisten/3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex ('Elixir.Postgrex.Notifications' module) allows SQL Injection. The channel …

postgrex | Injection
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
5.4 MEDIUM
CVE-2025-70842 — FluentCMS Stored Cross-Site Scripting (XSS)

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the File Management module of FluentCMS 1.2.3. The flaw allows an authenticated administrator to upload crafted SVG files containin…

Remote | Cross-Site Scripting
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
5.3 MEDIUM
CVE-2026-8391 — Other issue in the JavaScript Engine component

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3.

firefox | Remote
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
7.3 HIGH
CVE-2026-8390 — Use-after-free in the JavaScript: WebAssembly component

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.

firefox | Remote | Memory Corruption
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
7.3 HIGH
CVE-2026-8389 — JIT miscompilation in the JavaScript Engine: JIT component

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.

firefox | Remote | Memory Corruption
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
6.5 MEDIUM
CVE-2026-8388 — Incorrect boundary conditions in the JavaScript Engine: JIT component

Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.

firefox | Remote | Memory Corruption
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
7.1 HIGH
CVE-2026-6865 — Improper Limitation of a Pathname to a Restricted Directory Vulnerability on Multiple Pro…

CWE-22: Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) vulnerability that could cause unauthorized access to sensitive files when user-supplied input is improperly han…

Remote | Path Traversal
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
Showing 20 of 6418 Results