9.1
CVE-2026-21671 -
A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.
7.7
CVE-2026-21670 -
A vulnerability allowing a low-privileged user to extract saved SSH credentials.
10
CVE-2026-21666 -
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
10
CVE-2026-21667 -
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
8.7
CVE-2026-4042 - Tenda i12 WifiMacFilterGet formWifiMacFilterGet stack-based overflow
A weakness has been identified in Tenda i12 1.0.0.6(2204). The affected element is the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet. This manipulation of the argument index causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made avai…
8.7
CVE-2026-4041 - Tenda i12 exeCommand vos_strcpy stack-based overflow
A security flaw has been discovered in Tenda i12 1.0.0.6(2204). Impacted is the function vos_strcpy of the file /goform/exeCommand. The manipulation of the argument cmdinput results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and …
9.4
CVE-2026-28384 - Authenticated RCE via unsanitized compression_algorithm
An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This issue affected LXD from 4.12 through 6.6 and was fixed in the sna…
6.3
CVE-2026-0809 - Weak KSeF token encoding in Streamsoft Prestiż
Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-Faktur) token to be guessed after analyzing how tokens with know values are encoded. This issue was fixed in version 20.0.380.92.
8.6
CVE-2026-2514 - Possibility of unintended actions when viewing maliciously crafted network data in Progress Flowmon…
In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authenticated user, could result in unintended actions being execute…
8.6
CVE-2026-2513 - Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flo…
A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session.