Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

46113
Total
3679
Critical
13638
High
13568
Medium
CVE ID Severity Score Description Published
CVE-2026-16049 MEDIUM 4.3 Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions when processing API requests with a caller-supplied_ {{post_id}}_, and fails … Aug 17, 2026
CVE-2026-16048 MEDIUM 6.3 Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel … Aug 17, 2026
CVE-2026-16047 MEDIUM 4.3 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate that users have read access to a channel before linking a … Aug 17, 2026
CVE-2026-16046 MEDIUM 4.3 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on write operations for finished playbook runs which allows a run participant … Aug 17, 2026
CVE-2026-16045 MEDIUM 4.3 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauthorization and personal access token management endpoints to direct user sessions, which … Aug 17, 2026
CVE-2026-16044 MEDIUM 5.4 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive import which allows a … Aug 17, 2026
CVE-2026-15754 MEDIUM 4.2 Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint fails to re-validate that each target channel still belongs to the … Aug 17, 2026
CVE-2026-13202 UNKNOWN A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue affects Opentext Directory Services: through 22.2. Aug 17, 2026
CVE-2026-10527 MEDIUM 6.3 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which allows a user … Aug 17, 2026
CVE-2026-59911 MEDIUM 5.5 Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low privileged attacker with local … Aug 17, 2026
CVE-2026-59910 HIGH 7.8 Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged … Aug 17, 2026
CVE-2026-59909 HIGH 7.1 Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to … Aug 17, 2026
CVE-2026-56686 HIGH 7.8 Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged … Aug 17, 2026
CVE-2026-56685 HIGH 7.3 Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged … Aug 17, 2026
CVE-2026-56090 HIGH 7.3 Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, … Aug 17, 2026
CVE-2026-56089 LOW 3.3 Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to … Aug 17, 2026
CVE-2026-19693 HIGH 8.1 extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two … Aug 17, 2026
CVE-2026-16471 HIGH 7.5 Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sonlogger: from v6.6.6 before 6.7.4.8. Aug 17, 2026
CVE-2026-16139 HIGH 7.2 In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, … Aug 17, 2026
CVE-2026-16138 HIGH 8.0 In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a … Aug 17, 2026
CVE-2026-16137 HIGH 7.2 In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing … Aug 17, 2026
CVE-2026-15218 HIGH 7.9 A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational … Aug 17, 2026
CVE-2026-75010 MEDIUM 6.4 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a … Aug 17, 2026
CVE-2026-75007 MEDIUM 5.4 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to … Aug 17, 2026
CVE-2026-75006 MEDIUM 5.8 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information … Aug 17, 2026