Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.1 MEDIUM
CVE-2026-0295 — GlobalProtect App: Local Privilege Escalation via Race Condition on macOS

A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.0 MEDIUM
CVE-2026-0294 — Prisma Access Agent: Local Privilege Escalation

A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma A…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
5.6 MEDIUM
CVE-2026-0293 — Prisma Access Agent: Anti-Tamper Protection Bypass on Windows

A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to prot…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
2.1 LOW
CVE-2026-0292 — Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows

An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing t…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
1.1 LOW
CVE-2026-0291 — Prisma Access Agent: Authenticated Limited File Deletion on Linux

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files i…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.5 LOW
CVE-2026-0290 — Prisma Browser: Sensitive Information Disclosure Vulnerability

An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data.

prisma_browser prisma_browser | Information Disclosure
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.5 LOW
CVE-2026-0289 — Prisma Browser: Inappropriate Implementation in Account Protection

A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls.

prisma_browser prisma_browser | Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.3 MEDIUM
CVE-2026-50544 — NortheBridge/luminalshine has Incorrect Permission Assignment for Critical Resource and C…

NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at `src/platform/windows/misc.cpp` …

| Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
9.8 CRITICAL
CVE-2026-49819 — UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reac…

Remote | Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.8 HIGH
CVE-2026-49473 — @cedar-policy/authorization-for-expressjs has an authorization bypass via query string ma…

@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluatin…

Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
2.0 LOW
CVE-2026-48791 — Sigstore Java has a vulnerability with bundle verification of integratedTime

sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) against the Fulcio certifica…

| Cryptography
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.9 MEDIUM
CVE-2026-46688 — Meeting Room Booking System has an unauthenticated open redirect

The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, an unauthenticated request can be made to redirect the user to a query-specified …

Remote | Misconfiguration
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.7 HIGH
CVE-2026-46382 — Meeting Room Booking System has server-side request forgery in import functionality

The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local URI can be made to be fetched without checks. Versi…

Remote | Server-Side Request Forgery
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-17431 — PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() o…

PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for. to_pdf reads the generated PDF back fr…

| Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-16770 — PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via m…

PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, the constructor collects every <meta name…

| Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.8 MEDIUM
CVE-2026-71194 — OpenStack Designate mDNS Handler Denial of Service Vulnerability

In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, t…

designate | Remote | Denial of Service
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.6 CRITICAL
CVE-2026-71193 — OpenStack Designate Cross-Tenant Zone Overlap Vulnerability

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass thes…

designate | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.6 CRITICAL
CVE-2026-49481 — UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/sh…

UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command templat…

Remote | Injection
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.5 MEDIUM
CVE-2026-47718 — FUXA provides guest and invalid-token access to protected read APIs in secure mode

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and sched…

fuxa | Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.5 HIGH
CVE-2026-47717 — FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Con…

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context req…

fuxa | Remote | Information Disclosure
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
Showing 20 of 11032 Results