Real-time CVE monitoring

CVE alerts for
Edge

CVEye scans every new CVE and notifies your team the moment Edge is affected — before attackers can exploit it.

Monitor Edge free →No credit card · 7-day trial

Recent Edge CVEs

  • CVE-2026-85671HIGHCVSS 7.5

    QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc endpoints that allows unauthenticated attackers to access any uploaded file or document. Attackers can enumerate file identifiers through unauthenticated endpoints and retrieve base64-encoded files or parsed document chunks without ownership verification to disclose cross-tenant knowledge base content.

  • CVE-2026-70403CRITICALCVSS 9.8

    XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.

  • CVE-2026-69657CRITICALCVSS 9.8

    XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.

  • CVE-2026-85446HIGHCVSS 7.5

    MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a ledger entry and triggers all-pairs distribution work. Attackers can supply unbounded distinct node names in reports to drive the shoreside broker into quadratic processing, delaying or preventing distribution of legitimate node reports.

  • CVE-2026-83711CRITICALCVSS 10.0

    Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-70178HIGHCVSS 8.5

    Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-62916CRITICALCVSS 9.1

    Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-62906HIGHCVSS 7.4

    Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-80254MEDIUMCVSS 6.5

    Authorization bypass through user-controlled key issue exists in ShizenBox2 (edge-app). If exploited, an attacker who can log in to the product may change the other user's password.

  • CVE-2026-84672HIGHCVSS 8.8

    Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group.

  • CVE-2026-19475MEDIUMCVSS 6.5

    An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected.

Never miss a Edge vulnerability

CVEye monitors Edge and your entire stack 24/7, sending instant alerts via email, Slack, Discord, or webhook the moment a new CVE is published.

7-day free trial · No credit card required

Also monitor