Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

894
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 361 - 380 of 27,228 CVEs
CVE-2026-20240 MEDIUM - 6.5

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not hold the โ€˜adminโ€™ or โ€˜powerโ€™ Splunk roles could cause a Denial of ...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: May 20, 2026
Source: NVD
CVE-2026-20239 HIGH - 7.5

In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data.

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: May 20, 2026
Source: NVD
CVE-2026-20238 MEDIUM - 6.5

In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app contains an `authorize.conf` configu...

Vendor: Splunk
Product: Splunk AI Toolkit
Published: May 20, 2026
Source: NVD
CVE-2026-9101 MEDIUM - 4.3

Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution.

Published: May 20, 2026
Source: NVD
CVE-2026-9100 MEDIUM - 5.9

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API to either crash (via a division-by-zero) or silently leak process ...

Published: May 20, 2026
Source: NVD
CVE-2026-9087 MEDIUM - 6.4

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.

Published: May 20, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Published: May 20, 2026
Source: NVD
CVE-2026-7613 HIGH - 7.2

The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parameter in versions up to, and including, 1.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthent...

Published: May 20, 2026
Source: NVD
CVE-2026-44926 HIGH - 8.8

InfoScale CmdServer before 7.4.2 mishandles access control.

Published: May 20, 2026
Source: NVD
CVE-2026-44925 HIGH - 8.8

Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge.

Vendor: veritas
Product: infoscale_operations_manager
Published: May 20, 2026
Source: NVD
CVE-2026-44924 MEDIUM - 5.4

InfoScale VIOM 9.1.3 allows XSS.

Vendor: veritas
Product: infoscale_operations_manager
Published: May 20, 2026
Source: NVD
CVE-2026-44923 MEDIUM - 6.5

SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.

Vendor: veritas
Product: infoscale_operations_manager
Published: May 20, 2026
Source: NVD
CVE-2026-20223 CRITICAL - 10.0

A vulnerability in the&nbsp;access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the&nbsp;Site Admin role. This vulnerability is due to insufficient validation and authentication wh...

Vendor: Cisco
Product: Cisco Secure Workload
Published: May 20, 2026
Source: NVD
CVE-2026-20206 MEDIUM - 6.3

A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process. Cisco has addressed this vulnerability in the Cisco ThousandEy...

Vendor: Cisco
Product: Cisco ThousandEyes Enterprise Agent
Published: May 20, 2026
Source: NVD
CVE-2026-20199 MEDIUM - 4.7

A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due to insufficient validation of user-supplied input. An authentica...

Vendor: Cisco
Product: Cisco ThousandEyes Enterprise Agent
Published: May 20, 2026
Source: NVD
CVE-2026-20171 MEDIUM - 6.8

A vulnerability in the Border Gateway Protocol (BGP)&nbsp;enforce-first-as feature of&nbsp;Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of servic...

Vendor: Cisco
Product: Cisco NX-OS Software
Published: May 20, 2026
Source: NVD

MISPโ€™s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local account had no stored sub value. Under insecure or untrusted IdP configurations where email ownership is not enforced, an attacker with a valid OI...

Published: May 20, 2026
Source: NVD
CVE-2026-8598 CRITICAL - 9.1

An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials.

Published: May 20, 2026
Source: NVD
CVE-2026-8488 MEDIUM - 4.3

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Vendor: progress
Product: moveit_automation
Published: May 20, 2026
Source: NVD
CVE-2026-8487 MEDIUM - 6.5

Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Vendor: progress
Product: moveit_automation
Published: May 20, 2026
Source: NVD