Common Vulnerabilities and Exposures (CVE)

CVE-2026-44924

May 20, 2026 18:36:36 UTC

InfoScale VIOM 9.1.3 allows XSS.

CVE-2026-20171

May 20, 2026 18:31:44 UTC

A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to tri...

CVE-2026-44925

May 20, 2026 18:12:23 UTC

Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM ...

CVE-2026-9101

May 20, 2026 18:05:45 UTC

Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution.

CVE-2025-56009

May 20, 2026 17:58:40 UTC

Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.

CVE-2025-56008

May 20, 2026 17:57:11 UTC

Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near to the router to takeover the device via adding additional users with full permissions.

CVE-2025-56007

May 20, 2026 17:55:15 UTC

CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.

CVE-2026-44923

May 20, 2026 17:51:40 UTC

SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.

CVE-2026-30691

May 20, 2026 17:50:41 UTC

Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanitize file content and explicitly casts raw...

CVE-2026-44926

May 20, 2026 17:49:42 UTC

InfoScale CmdServer before 7.4.2 mishandles access control.

CVE-2026-20238

May 20, 2026 17:48:46 UTC

In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app contains...

CVE-2026-20240

May 20, 2026 17:47:46 UTC

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not hold ...

CVE-2026-7385

May 20, 2026 17:34:58 UTC

The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API endpoint, allowing unauthenticated attackers to enumerate registered user email ad...

CVE-2026-7613

May 20, 2026 17:33:43 UTC

The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parameter in versions up to, and including, 1.2.12 due to insufficient input sanitization and out...

CVE-2026-45232

May 20, 2026 17:31:52 UTC

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy respo...