Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2025-59786 — Cookies are not Invalidated upon Logout and Password Change

2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application.

access_commander | Remote | Authentication
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
7.2 HIGH
CVE-2025-59785 — API - Insufficient Input Validation

Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encryption. This vulnerability can only be exploited afte…

access_commander | Remote | Authentication
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
7.2 HIGH
CVE-2025-59784 — Log Pollution - Control Characters Not Escaped

2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be included in the logs without prior validation or sanitisation. This vulnerability c…

access_commander | Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
8.8 HIGH
CVE-2025-59783 — OS Command Injection over API

API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injection. This vulnerability can only be exploited afte…

access_commander | Remote | Injection
Mar 04, 2026 Mar 05, 2026
Mar 04, 2026
Mar 05, 2026
6.5 MEDIUM
CVE-2025-12801 — Nfs-utils: rpc.mountd in the nfs-utils privilege escalation

A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at m…

Mar 04, 2026 Apr 02, 2026
Mar 04, 2026
Apr 02, 2026
Showing 20 of 6345 Results