Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
46113
Total
3679
Critical
13638
High
13568
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-75004 | MEDIUM | 4.3 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in … | Aug 17, 2026 |
| CVE-2026-75003 | MEDIUM | 5.8 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image … | Aug 17, 2026 |
| CVE-2026-75002 | HIGH | 7.1 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP … | Aug 17, 2026 |
| CVE-2026-75000 | MEDIUM | 5.8 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, … | Aug 17, 2026 |
| CVE-2026-74999 | MEDIUM | 5.4 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS. | Aug 17, 2026 |
| CVE-2026-74998 | HIGH | 7.2 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information … | Aug 17, 2026 |
| CVE-2026-74997 | HIGH | 8.8 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder … | Aug 17, 2026 |
| CVE-2026-70412 | LOW | 3.5 | Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readable after Memory Erase vulnerability. A low privileged … | Aug 17, 2026 |
| CVE-2026-18674 | UNKNOWN | — | On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated … | Aug 17, 2026 |
| CVE-2026-16467 | HIGH | 7.5 | Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fortilogger: before 6.1.5.9. | Aug 17, 2026 |
| CVE-2026-14564 | CRITICAL | 9.0 | Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data. This issue affects Logsign SIEM: … | Aug 17, 2026 |
| CVE-2026-74843 | CRITICAL | 10.0 | A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi of the component … | Aug 17, 2026 |
| CVE-2026-40126 | UNKNOWN | — | OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a … | Aug 17, 2026 |
| CVE-2026-74901 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext … | Aug 17, 2026 |
| CVE-2026-74900 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret … | Aug 17, 2026 |
| CVE-2026-74899 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python … | Aug 17, 2026 |
| CVE-2026-74896 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use … | Aug 17, 2026 |
| CVE-2026-74895 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted … | Aug 17, 2026 |
| CVE-2026-74894 | CRITICAL | 9.8 | openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary … | Aug 17, 2026 |
| CVE-2026-74893 | HIGH | 8.8 | openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access to source code can forge valid … | Aug 17, 2026 |
| CVE-2026-74892 | HIGH | 7.5 | openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who … | Aug 17, 2026 |
| CVE-2026-74891 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default … | Aug 17, 2026 |
| CVE-2026-74890 | MEDIUM | 5.5 | openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. … | Aug 17, 2026 |
| CVE-2026-74889 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit … | Aug 17, 2026 |
| CVE-2026-74888 | HIGH | 7.5 | openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KDF whose security properties … | Aug 17, 2026 |