Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.6 CVE-2026-9248

CVE-2026-9248_CVE-2026-9248

Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy doc...

Devolutions Server 2026.1.6.0 CVE
LOW 2.4 CVE-2026-9247

CVE-2026-9247_CVE-2026-9247

Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entr...

Devolutions Server 2026.1.6.0 CVE
LOW 2.7 CVE-2026-8477

CVE-2026-8477_CVE-2026-8477

Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server allows an authenticated user ...

Devolutions Server 2026.1.6.0 CVE
LOW 2.1 CVE-2026-8353

Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in atomik theme_CVE-2026-8353

Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript tha...

Concrete CMS Concrete CMS 9.0 CVE
LOW 2.3 CVE-2026-8347

Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog_CVE-2026-8347

Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog.  This can cause Cross-ent...

Concrete CMS Concrete CMS 5.0 CVE
LOW 2.3 CVE-2026-8340

Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion_CVE-2026-8340

Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents permission is CSRF'd into publi...

Concrete CMS Concrete CMS 5.0 CVE
LOW 3.6 CVE-2025-46371

CVE-2025-46371_CVE-2025-46371

Dell PowerFlex Manager, version(s)

Dell PowerFlex Manager (Appliance) CVE
LOW 2.3 CVE-2026-25608

Lack of traffic encryption in STER_CVE-2026-25608

STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middle attack and obtain sensiti...

Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy STER CVE
LOW 2.3 CVE-2026-8435

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion()_CVE-2026-8435

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion(). The Concrete ...

Concrete CMS Concrete CMS 9.0 CVE
LOW 2.3 CVE-2026-8434

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple()_CVE-2026-8434

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete ...

Concrete CMS Concrete CMS 9.0 CVE