| CVE ID | Product | Description | Score | Severity | Link |
|---|---|---|---|---|---|
| CVE-2025-29471 | Nagios Log Server | Authenticated Stored XSS + Privilege Escalation in Nagios Log Server 2024R1.3.1 | 8.3 | High | π₯ |
| CVE-2025-53392 | pfSense Community Edition | Authenticated Arbitrary File Read in pfSense 2.8.0 via Diagnostics Web Interface | 6.5 | Medium | π₯ |
| CVE-2025-54138 | LibreNMS | Authenticated Remote File Inclusion in LibreNMS 25.6.0 via ajax_form.php |
7.5 | High | π₯ |
| CVE-2025-44824 | Nagios Log Server | Incorrect Authorization in Nagios Log Server 2024R1.3.1 | 8.5 | High | π₯ |
| CVE-2025-44823 | Nagios Log Server | Authenticated API Key Exposure in Nagios Log Server 2024R1.3.1 (CC: Alex Tisdale) | 9.9 | Critical | π₯ |
| CVE-2026-26936 | Kibana | Inefficient Regular Expression Complexity in Kibana Leading to Denial of Service | 4.9 | Medium | π₯ |
| CVE-2026-25769 | Wazuh | Authenticated Remote Code Execution via Insecure Deserialization in Wazuh Cluster (CC: Gabriel Rodrigues) | 9.1 | Critical | π₯ |
| CVE-2026-25770 | Wazuh | Privilege Escalation in Wazuh 4.14.3 via Cluster Protocol File Write | 9.1 | Critical | π₯ |
| CVE-2026-25771 | Wazuh | Unauthenticated Denial of Service in Wazuh 4.14.3 via API | 7.5 | High | π₯ |
| CVE-2026-25772 | Wazuh | Stack-based Buffer Overflow in Wazuh 4.14.3 via snprintf Integer Underflow | 4.9 | Medium | π₯ |
| CVE-2026-25790 | Wazuh | Stack-based Buffer Overflow in Wazuh 4.14.3 via Security Configuration Assessment JSON Parser | 4.9 | Medium | π₯ |
| CVE-2026-9136 | MISP | Authenticated IDOR via Shadow Attribute Batch Import in MISP 2.5.37 | 8.3 | High | π₯ |
| CVE-2026-9137 | MISP | Unauthenticated Denial of Service via CSP Report Validation in MISP 2.5.37 | 7.5 | High | π₯ |
| CVE-2026-56148 | Elasticsearch | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service | 6.5 | Medium | π₯ |
| CVE-2026-63143 | Kibana | Improper Access Control in Kibana Workflows via Unscoped Execution Outputs | 4.3 | Medium | π₯ |
| CVE-2026-56149 | Elasticsearch | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service | 4.9 | Medium | π₯ |
| CVE-2026-63263 | Elasticsearch | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service | 6.5 | Medium | π₯ |
| CVE-2026-63144 | Elasticsearch | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service | 6.5 | Medium | π₯ |
| CVE-2026-72679 | Elasticsearch | Uncontrolled Recursion in Elasticsearch Intervals Query Leading to Denial of Service | 6.5 | Medium | π₯ |
Total: 19 CVEs (3 Critical, 6 High, 10 Medium)