Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,260
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,701 - 6,720 of 35,861 CVEs
CVE-2026-9808 HIGH - 7.1

An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as `viewown` or `editown`) are not properly enforced. This allows low-privilege authenticated API users to bypass own...

Published: May 29, 2026
Source: NVD
CVE-2026-9559 CRITICAL - 9.9

A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. An authenticated user with campaign import privileges (campaign...

Published: May 29, 2026
Source: NVD
CVE-2025-41281 HIGH - 7.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL conne...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41280 HIGH - 7.8

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured and file compression is enabled.

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41279 HIGH - 7.2

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operat...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41278 HIGH - 7.8

Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attackers with access to the TX Host to execute code on the RX Host.

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41277 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41276 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41275 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41274 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41273 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to bypass authentication of the Console web application and perform...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41272 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41271 HIGH - 7.5

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to read arbitrary files from the device.

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41270 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41269 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41268 CRITICAL - 9.1

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete arbitrary files on the Host machines.

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41267 HIGH - 7.2

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operat...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41266 HIGH - 7.2

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operat...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41265 HIGH - 7.2

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operat...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2026-9558 CRITICAL - 9.9

A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the ...

Published: May 29, 2026
Source: NVD