Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-9223 — Devolutions Server Authentication Bypass

Missing authorization in the vault import feature in Devolutions Server  2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.

devolutions_server | Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
7.6 HIGH
CVE-2026-9047 — Devolutions Server MFA Bypass Vulnerability

Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-fac…

devolutions_server | Remote | Authentication
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
2.7 LOW
CVE-2026-8477 — Devolutions Server Sensitive Data Retrieval Information Disclosure

Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server allows an authenticated user with access to a sealed entry to retrieve its sensit…

devolutions_server | Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
7.1 HIGH
CVE-2026-7325 — Devolutions Server Active Directory Browsing Authorization Bypass

Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication material associated with a stored PAM provide…

devolutions_server | Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
4.3 MEDIUM
CVE-2026-5171 — Devolutions Server Unauthenticated Access Control Bypass

Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activ…

devolutions_server | Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
6.1 MEDIUM
CVE-2026-42506 — Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/ne…

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo…

net html | Remote | Cross-Site Scripting
May 22, 2026 May 29, 2026
May 22, 2026
May 29, 2026
6.1 MEDIUM
CVE-2026-42502 — Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo…

net html | Remote | Cross-Site Scripting
May 22, 2026 May 29, 2026
May 22, 2026
May 29, 2026
10.0 CRITICAL
CVE-2026-39821 — Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com…

net | Remote | Authentication
May 22, 2026 May 29, 2026
May 22, 2026
May 29, 2026
6.1 MEDIUM
CVE-2026-27136 — Invoking duplicate attributes can cause XSS in golang.org/x/net/html

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo…

net html | Remote | Cross-Site Scripting
May 22, 2026 May 29, 2026
May 22, 2026
May 29, 2026
6.1 MEDIUM
CVE-2026-25681 — Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net…

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo…

net html | Remote | Cross-Site Scripting
May 22, 2026 May 29, 2026
May 22, 2026
May 29, 2026
6.5 MEDIUM
CVE-2026-25680 — Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html

Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

net html | Remote | Denial of Service
May 22, 2026 May 29, 2026
May 22, 2026
May 29, 2026
7.5 HIGH
CVE-2022-34363 — Dell Unisphere for PowerMax Authorization Bypass Vulnerability

Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the  Unisphere for VMAX application running in vApp

May 22, 2026 May 29, 2026
May 22, 2026
May 29, 2026
7.5 HIGH
CVE-2022-31231 — Dell ECS Improper Access Control Vulnerability

Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attacker may potentially exploit this vulnerability, le…

elastic_cloud_storage | Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
9.2 CRITICAL
CVE-2026-9256 — NGINX ngx_http_rewrite_module vulnerability

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Co…

nginx_plus nginx_open_source | Remote | Memory Corruption
May 22, 2026 May 23, 2026
May 22, 2026
May 23, 2026
8.8 HIGH
CVE-2026-8992 — Ivanti Secure Access Client Certificate Validation Remote Code Execution

An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.

windows secure_access_client | Remote | Misconfiguration
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
4.8 MEDIUM
CVE-2026-8353 — Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik the…

Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user …

concrete_cms | Remote | Cross-Site Scripting
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
4.3 MEDIUM
CVE-2026-8347 — Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express…

Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog.  This can cause Cross-entity state tampering with view-only permission on one…

concrete_cms | Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
4.3 MEDIUM
CVE-2026-8340 — Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion

Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents permission is CSRF'd into publishing an attacker-chosen previously-uploaded version…

concrete_cms | Remote | Cross-Site Request Forgery
May 22, 2026 May 26, 2026
May 22, 2026
May 26, 2026
5.5 MEDIUM
CVE-2025-46371 — Dell PowerFlex Manager SSH Cryptographic Algorithm Vulnerability

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially explo…

May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
7.5 HIGH
CVE-2025-45145 — Follett Software Destiny Library Manager Directory Traversal Vulnerability

Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows remote attackers to read arbitrary system and application files via the image parameter

Remote | Path Traversal
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
Showing 20 of 7016 Results