Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45656
Total
3653
Critical
13500
High
13451
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-70412 | LOW | 3.5 | Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readable after Memory Erase vulnerability. A low privileged … | Aug 17, 2026 |
| CVE-2026-18674 | UNKNOWN | — | On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated … | Aug 17, 2026 |
| CVE-2026-16467 | HIGH | 7.5 | Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fortilogger: before 6.1.5.9. | Aug 17, 2026 |
| CVE-2026-14564 | CRITICAL | 9.0 | Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data. This issue affects Logsign SIEM: … | Aug 17, 2026 |
| CVE-2026-74843 | CRITICAL | 10.0 | A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi of the component … | Aug 17, 2026 |
| CVE-2026-40126 | UNKNOWN | — | OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a … | Aug 17, 2026 |
| CVE-2026-74901 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext … | Aug 17, 2026 |
| CVE-2026-74900 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret … | Aug 17, 2026 |
| CVE-2026-74899 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python … | Aug 17, 2026 |
| CVE-2026-74896 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use … | Aug 17, 2026 |
| CVE-2026-74895 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted … | Aug 17, 2026 |
| CVE-2026-74894 | CRITICAL | 9.8 | openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary … | Aug 17, 2026 |
| CVE-2026-74893 | HIGH | 8.8 | openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access to source code can forge valid … | Aug 17, 2026 |
| CVE-2026-74892 | HIGH | 7.5 | openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who … | Aug 17, 2026 |
| CVE-2026-74891 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default … | Aug 17, 2026 |
| CVE-2026-74890 | MEDIUM | 5.5 | openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. … | Aug 17, 2026 |
| CVE-2026-74889 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit … | Aug 17, 2026 |
| CVE-2026-74888 | HIGH | 7.5 | openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KDF whose security properties … | Aug 17, 2026 |
| CVE-2026-74887 | NONE | — | openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to random.* were present in the … | Aug 17, 2026 |
| CVE-2026-74886 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. … | Aug 17, 2026 |
| CVE-2026-74885 | LOW | 3.6 | openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. … | Aug 17, 2026 |
| CVE-2026-74884 | HIGH | 7.5 | openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitized before constructing the plugin config … | Aug 17, 2026 |
| CVE-2026-74883 | HIGH | 8.8 | openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers … | Aug 17, 2026 |
| CVE-2026-74882 | HIGH | 7.5 | openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks … | Aug 17, 2026 |
| CVE-2026-74881 | MEDIUM | 6.5 | openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin … | Aug 17, 2026 |