Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42400
Total
3455
Critical
12534
High
12466
Medium
CVE ID Severity Score Description Published
CVE-2026-73209 MEDIUM 6.5 An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process … Aug 28, 2026
CVE-2026-73208 HIGH 7.4 An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, … Aug 28, 2026
CVE-2026-6128 MEDIUM 6.4 The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ai1wm_backups_path' parameter in all versions up to, and … Aug 28, 2026
CVE-2026-5510 MEDIUM 6.4 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'give_form' shortcode in all versions up … Aug 28, 2026
CVE-2026-52687 MEDIUM 6.5 An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and … Aug 28, 2026
CVE-2026-52681 LOW 3.1 Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the … Aug 28, 2026
CVE-2026-42395 MEDIUM 4.3 A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. … Aug 28, 2026
CVE-2026-42393 LOW 3.1 The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An … Aug 28, 2026
CVE-2026-42392 MEDIUM 4.3 An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned … Aug 28, 2026
CVE-2026-42391 HIGH 7.5 An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage … Aug 28, 2026
CVE-2026-42008 MEDIUM 4.3 Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a value sent by … Aug 28, 2026
CVE-2026-42007 CRITICAL 9.1 An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and … Aug 28, 2026
CVE-2026-40205 MEDIUM 5.9 An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in … Aug 28, 2026
CVE-2026-40204 LOW 3.1 None None None No publicly available exploits are known. Aug 28, 2026
CVE-2026-40203 LOW 3.7 When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and … Aug 28, 2026
CVE-2026-40019 MEDIUM 5.9 An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU. This … Aug 28, 2026
CVE-2026-40018 HIGH 7.4 None None None No publicly available exploits are known. Aug 28, 2026
CVE-2026-40017 MEDIUM 6.5 An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, … Aug 28, 2026
CVE-2026-40015 MEDIUM 4.3 An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read … Aug 28, 2026
CVE-2026-40014 MEDIUM 6.5 An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the … Aug 28, 2026
CVE-2026-40013 MEDIUM 4.3 An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when the ManageSieve service … Aug 28, 2026
CVE-2026-33607 MEDIUM 4.3 An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of service for IMAP. Monitor … Aug 28, 2026
CVE-2026-33606 MEDIUM 4.8 Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with … Aug 28, 2026
CVE-2026-33605 HIGH 7.5 An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community … Aug 28, 2026
CVE-2026-33604 MEDIUM 5.9 An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission relay, can use a crafted line ending in … Aug 28, 2026