Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-76261 — Insecure Default Access Control List through the REST API in Splunk Secure Gateway

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk rol…

Remote | Information Disclosure
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
6.5 MEDIUM
CVE-2026-76260 — Incorrect Permission Assignment for Critical Resource through the REST API in Splunk Ente…

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the rest_properties_get capability could read encrypted stored credentials through the Representa…

Remote | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.8 HIGH
CVE-2026-76259 — Improper Privilege Management on the Management Port in Splunk Enterprise for Windows

In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to the Windows host could bind to the management port before Splunk Enterprise sta…

| Authentication
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
6.5 MEDIUM
CVE-2026-76258 — Use of Hard-coded Cryptographic Key through Companion App Registration in Splunk Secure G…

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who does not hold the "admin" or "power" Splunk ro…

Remote | Authentication
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
6.5 MEDIUM
CVE-2026-76257 — Missing Authorization through REST API Endpoints in Splunk Secure Gateway

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who holds a Splunk role with permissions to list s…

Remote | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
4.3 MEDIUM
CVE-2026-76256 — Information Exposure through REST API Endpoints in Splunk Secure Gateway

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk rol…

Remote | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
6.4 MEDIUM
CVE-2026-76255 — Risky Command Safeguards Bypass through Splunk Web in Splunk Enterprise

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.8, and 9.4.13, a user who does not hold the "admin" or "power" Splunk roles could trick another user into running arbitrary Search Processing …

Remote | Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.5 HIGH
CVE-2026-76254 — SPL Command Safeguards Bypass through Splunk Web in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated user could cause another user to dispatch arbitrary Search Processing Language (SPL) pipelines from …

Remote | Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.8 HIGH
CVE-2026-76253 — Privilege Escalation through Scheduled Search Alert Action Configuration in Splunk Enterp…

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could run arbitrary Search Processing Language (SPL) commands with…

Remote | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
6.8 MEDIUM
CVE-2026-76252 — Cross-Site Scripting (XSS) through Splunk Web Message Validation in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.13, an unauthenticated user who tricks another user into visiting a malicious web page could run unauthorized JavaScript in that us…

Remote | Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.1 HIGH
CVE-2026-76251 — Missing Authorization through REST API Endpoints in the Splunk App for Splunk Observabili…

In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin" or "power" Splunk roles could cause the Splunk App for Splunk Observability Cloud to forward reque…

Remote | Information Disclosure
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
6.5 MEDIUM
CVE-2026-69550 — Windows App for Mac Information Disclosure Vulnerability

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
6.5 MEDIUM
CVE-2026-63123 — Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tin…

Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacms/cli/src/next/vite/cors.ts origin callback returns false for a disallowed orig…

Remote | Misconfiguration
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
5.4 MEDIUM
CVE-2026-59992 — Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and …

Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4, the first-party production media…

Remote | Misconfiguration
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
5.4 MEDIUM
CVE-2025-36398 — DS8900F and DS8A00 Information Disclosure

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an extern…

ds8900f ds8a00 | Remote | Path Traversal
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.5 HIGH
CVE-2025-36255 — DS8900F and DS8A00 Privilege Escalation

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user roles due to improper privi…

ds8900f ds8a00 | Remote | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.4 HIGH
CVE-2025-36254 — DS8900F and DS8A00 Authentication Bypass

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security authentication due to improperly encoding of DSCLI comma…

ds8900f ds8a00 | Remote | Authentication
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
6.8 MEDIUM
CVE-2026-76827 — Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (…

A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because t…

Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
9.9 CRITICAL
CVE-2026-76584 — TRENDnet TV-IP751WIC alphapd set_time.cgi stack-based overflow

A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipu…

tv-ip751wic | Remote | Memory Corruption
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.4 HIGH
CVE-2026-76583 — TRENDnet TV-IP751WIC alphapd set_time.cgi command injection

A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manip…

tv-ip751wic | Remote | Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Showing 20 of 12686 Results