Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47944
Total
3850
Critical
14243
High
13921
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-27771 | UNKNOWN | — | UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/add_prompts` endpoint is vulnerable to remote code … | Aug 17, 2026 |
| CVE-2025-27770 | UNKNOWN | — | UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/create_project` endpoint is vulnerable to remote code … | Aug 17, 2026 |
| CVE-2025-27621 | UNKNOWN | — | UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the UpTrain backend creates a new default user … | Aug 17, 2026 |
| CVE-2026-73851 | UNKNOWN | — | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed … | Aug 17, 2026 |
| CVE-2026-71567 | HIGH | 7.7 | In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected without quoting them either into command lines or … | Aug 17, 2026 |
| CVE-2026-71566 | CRITICAL | 9.3 | FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end it's up to the BMC to … | Aug 17, 2026 |
| CVE-2026-16049 | MEDIUM | 4.3 | Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions when processing API requests with a caller-supplied_ {{post_id}}_, and fails … | Aug 17, 2026 |
| CVE-2026-16048 | MEDIUM | 6.3 | Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel … | Aug 17, 2026 |
| CVE-2026-16047 | MEDIUM | 4.3 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate that users have read access to a channel before linking a … | Aug 17, 2026 |
| CVE-2026-16046 | MEDIUM | 4.3 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on write operations for finished playbook runs which allows a run participant … | Aug 17, 2026 |
| CVE-2026-16045 | MEDIUM | 4.3 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauthorization and personal access token management endpoints to direct user sessions, which … | Aug 17, 2026 |
| CVE-2026-16044 | MEDIUM | 5.4 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive import which allows a … | Aug 17, 2026 |
| CVE-2026-15754 | MEDIUM | 4.2 | Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint fails to re-validate that each target channel still belongs to the … | Aug 17, 2026 |
| CVE-2026-13202 | UNKNOWN | — | A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue affects Opentext Directory Services: through 22.2. | Aug 17, 2026 |
| CVE-2026-10527 | MEDIUM | 6.3 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which allows a user … | Aug 17, 2026 |
| CVE-2026-59911 | MEDIUM | 5.5 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low privileged attacker with local … | Aug 17, 2026 |
| CVE-2026-59910 | HIGH | 7.8 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged … | Aug 17, 2026 |
| CVE-2026-59909 | HIGH | 7.1 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to … | Aug 17, 2026 |
| CVE-2026-56686 | HIGH | 7.8 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged … | Aug 17, 2026 |
| CVE-2026-56685 | HIGH | 7.3 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged … | Aug 17, 2026 |
| CVE-2026-56090 | HIGH | 7.3 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, … | Aug 17, 2026 |
| CVE-2026-56089 | LOW | 3.3 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to … | Aug 17, 2026 |
| CVE-2026-19693 | HIGH | 8.1 | extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two … | Aug 17, 2026 |
| CVE-2026-16471 | HIGH | 7.5 | Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sonlogger: from v6.6.6 before 6.7.4.8. | Aug 17, 2026 |
| CVE-2026-16139 | HIGH | 7.2 | In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, … | Aug 17, 2026 |