CVEs

Browse and track CVEs by technology, product and vulnerability type. Find the latest vulnerabilities for WordPress, NGINX, APIs and more.

Latest

  1. CVE-2026-18635 Published Aug 11, 2026

    Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velociraptor versions prior to 0.77.2 evaluate this permission against the caller's org instead of against the target org. This allows an administrator in one org to impersonate another user in another org, in which they may not have the IMPERSONATE permission.

  2. CVE-2026-18129 Published Aug 11, 2026

    Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.

  3. CVE-2026-18127 Published Aug 11, 2026

    External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.

  4. CVE-2026-18125 Published Aug 11, 2026

    An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.

  5. CVE-2026-17535 Published Aug 11, 2026

    Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the filesystem. However, in some applications (e.g.  dead disk forensics https://docs.velociraptor.app/docs/forensic/deaddisk/ ) Velociraptor may be used on untrusted NTFS image files.  If an attacker is able to inject maliciously corrupted NTFS Volumes they can cause a crash and a Denial of Service.

  6. CVE-2026-17061 Published Aug 11, 2026

    A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.

  7. CVE-2023-54374 Published Aug 11, 2026

    Rejected reason: This CVE ID has been rejected.

  8. CVE-2023-54373 Published Aug 11, 2026

    Rejected reason: This CVE ID has been rejected.

  9. CVE-2023-54372 Published Aug 11, 2026

    Rejected reason: This CVE ID has been rejected.

  10. CVE-2023-54371 Published Aug 11, 2026

    Rejected reason: This CVE ID has been rejected.

Categories