Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52341
Total
4150
Critical
15505
High
15208
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-7494 | UNKNOWN | — | Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the … | Jul 14, 2026 |
| CVE-2026-62644 | MEDIUM | 6.4 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which … | Jul 14, 2026 |
| CVE-2026-62643 | HIGH | 7.2 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information … | Jul 14, 2026 |
| CVE-2026-62642 | MEDIUM | 4.3 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service … | Jul 14, 2026 |
| CVE-2026-62641 | MEDIUM | 4.3 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size. | Jul 14, 2026 |
| CVE-2026-60119 | MEDIUM | 5.4 | Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event creation or edit permissions to inject arbitrary HTML and JavaScript by … | Jul 14, 2026 |
| CVE-2026-60118 | MEDIUM | 5.3 | Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden tickets by referencing hidden product and price IDs … | Jul 14, 2026 |
| CVE-2026-60082 | UNKNOWN | — | DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source … | Jul 14, 2026 |
| CVE-2026-60081 | UNKNOWN | — | DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an … | Jul 14, 2026 |
| CVE-2026-59841 | HIGH | 7.5 | A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert … | Jul 14, 2026 |
| CVE-2026-59840 | MEDIUM | 4.3 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through … | Jul 14, 2026 |
| CVE-2026-59839 | MEDIUM | 5.5 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 … | Jul 14, 2026 |
| CVE-2026-59837 | MEDIUM | 6.6 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 … | Jul 14, 2026 |
| CVE-2026-59836 | HIGH | 7.5 | A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure … | Jul 14, 2026 |
| CVE-2026-59835 | HIGH | 8.6 | A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access … | Jul 14, 2026 |
| CVE-2026-59205 | HIGH | 7.5 | Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output … | Jul 14, 2026 |
| CVE-2026-59204 | HIGH | 7.5 | Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per … | Jul 14, 2026 |
| CVE-2026-59203 | MEDIUM | 5.3 | Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing … | Jul 14, 2026 |
| CVE-2026-59199 | HIGH | 7.5 | Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near … | Jul 14, 2026 |
| CVE-2026-59198 | MEDIUM | 6.5 | Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 … | Jul 14, 2026 |
| CVE-2026-58461 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jul 14, 2026 |
| CVE-2026-55954 | UNKNOWN | — | Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims. The Ueberauth.Strategy.Apple.Token.payload/2 function verifies the JWT signature of the … | Jul 14, 2026 |
| CVE-2026-55651 | HIGH | 7.1 | Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to … | Jul 14, 2026 |
| CVE-2026-52841 | LOW | 3.1 | Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session, and `oauth_callback` saves … | Jul 14, 2026 |
| CVE-2026-52840 | LOW | 2.7 | Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `application/controllers/Caldav.php:60` hands the request's `caldav_url` to a Guzzle `REPORT` call without … | Jul 14, 2026 |