Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-9224 — Devolutions Server Unauthenticated Active Directory User Profile Update

Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attributes via a crafted API request. This is…

| Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
0.0 NA
CVE-2026-9249 — Devolutions Server Unverified Password Change Vulnerability

Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request. This issue affects : * D…

| Authentication
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
0.0 NA
CVE-2026-9245 — Devolutions Server Open Redirect Vulnerability

Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect victims to an attacker-controlled domain via a craft…

| Server-Side Request Forgery
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
0.0 NA
CVE-2026-9247 — Devolutions Server Insufficient Logging (Information Disclosure)

Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without triggering the unseal notification to admi…

| Information Disclosure
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
0.0 NA
CVE-2026-9248 — Devolutions Server Authorization Bypass Vulnerability

Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy documentation and attachments from an entry in a vault …

| Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
0.0 NA
CVE-2026-9223 — Devolutions Server Authentication Bypass

Missing authorization in the vault import feature in Devolutions Server  2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.

| Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
0.0 NA
CVE-2026-9047 — Devolutions Server MFA Bypass Vulnerability

Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-fac…

| Authentication
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
0.0 NA
CVE-2026-27136 — Invoking duplicate attributes can cause XSS in golang.org/x/net/html

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo…

| Cross-Site Scripting
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
0.0 NA
CVE-2026-25681 — Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net…

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo…

| Cross-Site Scripting
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
0.0 NA
CVE-2026-25680 — Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html

Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

| Denial of Service
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
0.0 NA
CVE-2026-42502 — Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo…

| Cross-Site Scripting
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
0.0 NA
CVE-2026-39821 — Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com…

| Authentication
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
0.0 NA
CVE-2026-42506 — Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/ne…

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML befo…

| Cross-Site Scripting
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
6.5 MEDIUM
CVE-2022-34363 — Dell Unisphere for PowerMax Authorization Bypass Vulnerability

Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the  Unisphere for VMAX application running in vApp

Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
5.9 MEDIUM
CVE-2022-31231 — Dell ECS Improper Access Control Vulnerability

Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attacker may potentially exploit this vulnerability, le…

Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
8.8 HIGH
CVE-2026-8992 — Ivanti Secure Access Client Certificate Validation Remote Code Execution

An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.

Remote | Misconfiguration
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
2.1 LOW
CVE-2026-8353 — Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik the…

Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user …

Remote | Cross-Site Scripting
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
6.7 MEDIUM
CVE-2021-21508 — Dell VxRail Plain-text Password Storage Vulnerability

Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin user may exploit this vulnerability, leading to the disclosure of certain user c…

| Information Disclosure
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
8.1 HIGH
CVE-2026-9256 — NGINX ngx_http_rewrite_module vulnerability

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Co…

Remote | Memory Corruption
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
2.3 LOW
CVE-2026-8347 — Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express…

Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog.  This can cause Cross-entity state tampering with view-only permission on one…

Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
Showing 20 of 6076 Results