Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45502
Total
3651
Critical
13471
High
13397
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-59909 | HIGH | 7.1 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to … | Aug 17, 2026 |
| CVE-2026-56686 | HIGH | 7.8 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged … | Aug 17, 2026 |
| CVE-2026-56685 | HIGH | 7.3 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged … | Aug 17, 2026 |
| CVE-2026-56090 | HIGH | 7.3 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, … | Aug 17, 2026 |
| CVE-2026-56089 | LOW | 3.3 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to … | Aug 17, 2026 |
| CVE-2026-19693 | HIGH | 8.1 | extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two … | Aug 17, 2026 |
| CVE-2026-16471 | HIGH | 7.5 | Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sonlogger: from v6.6.6 before 6.7.4.8. | Aug 17, 2026 |
| CVE-2026-16139 | HIGH | 7.2 | In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, … | Aug 17, 2026 |
| CVE-2026-16138 | HIGH | 8.0 | In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a … | Aug 17, 2026 |
| CVE-2026-16137 | HIGH | 7.2 | In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing … | Aug 17, 2026 |
| CVE-2026-15218 | HIGH | 7.9 | A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational … | Aug 17, 2026 |
| CVE-2026-75010 | MEDIUM | 6.4 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a … | Aug 17, 2026 |
| CVE-2026-75007 | MEDIUM | 5.4 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to … | Aug 17, 2026 |
| CVE-2026-75006 | MEDIUM | 5.8 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information … | Aug 17, 2026 |
| CVE-2026-75004 | MEDIUM | 4.3 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in … | Aug 17, 2026 |
| CVE-2026-75003 | MEDIUM | 5.8 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image … | Aug 17, 2026 |
| CVE-2026-75002 | HIGH | 7.1 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP … | Aug 17, 2026 |
| CVE-2026-75000 | MEDIUM | 5.8 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, … | Aug 17, 2026 |
| CVE-2026-74999 | MEDIUM | 5.4 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS. | Aug 17, 2026 |
| CVE-2026-74998 | HIGH | 7.2 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information … | Aug 17, 2026 |
| CVE-2026-74997 | HIGH | 8.8 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder … | Aug 17, 2026 |
| CVE-2026-70412 | LOW | 3.5 | Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readable after Memory Erase vulnerability. A low privileged … | Aug 17, 2026 |
| CVE-2026-18674 | UNKNOWN | — | On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated … | Aug 17, 2026 |
| CVE-2026-16467 | HIGH | 7.5 | Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fortilogger: before 6.1.5.9. | Aug 17, 2026 |
| CVE-2026-14564 | CRITICAL | 9.0 | Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data. This issue affects Logsign SIEM: … | Aug 17, 2026 |