Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-16137 — Path traversal via unsanitized upload filename leads to arbitrary file write in Progress …

In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to writ…

sharefile_storage_zones_controller | Remote | Path Traversal
Aug 17, 2026 Sep 02, 2026
Aug 17, 2026
Sep 02, 2026
7.9 HIGH
CVE-2026-15218 — Models-as-a-service: red hat openshift ai: maas-api and maas-controller serviceaccounts w…

A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational requirements…

openshift_ai | Remote | Authorization
Aug 17, 2026 Aug 27, 2026
Aug 17, 2026
Aug 27, 2026
6.4 MEDIUM
CVE-2026-75010 — Roundcube Webmail Password Plugin Modoboa Driver Authentication Token Information Disclos…

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. …

webmail | Remote | Information Disclosure
Aug 17, 2026 Sep 08, 2026
Aug 17, 2026
Sep 08, 2026
8.8 HIGH
CVE-2026-75007 — Roundcube Webmail LDAP Injection Vulnerability

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege …

webmail | Remote | Injection
Aug 17, 2026 Sep 08, 2026
Aug 17, 2026
Sep 08, 2026
5.8 MEDIUM
CVE-2026-75006 — Roundcube Webmail CSS Sanitization Bypass Information Disclosure

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if styleshe…

webmail | Remote | Server-Side Request Forgery
Aug 17, 2026 Sep 08, 2026
Aug 17, 2026
Sep 08, 2026
4.3 MEDIUM
CVE-2026-75004 — Roundcube Webmail Managesieve Plugin Security Restriction Bypass

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue o…

webmail | Remote | Misconfiguration
Aug 17, 2026 Sep 08, 2026
Aug 17, 2026
Sep 08, 2026
9.8 CRITICAL
CVE-2026-75003 — Roundcube Webmail SVG FuncIRI Attribute Information Disclosure Vulnerability

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or …

webmail | Remote | Cross-Site Scripting
Aug 17, 2026 Sep 10, 2026
Aug 17, 2026
Sep 10, 2026
7.1 HIGH
CVE-2026-75002 — Roundcube Webmail IMAP Command Injection Vulnerability

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injectio…

webmail | Remote | Injection
Aug 17, 2026 Sep 08, 2026
Aug 17, 2026
Sep 08, 2026
5.8 MEDIUM
CVE-2026-75000 — Roundcube Webmail SVG Sanitization Bypass Information Disclosure

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to informa…

webmail | Remote | Information Disclosure
Aug 17, 2026 Sep 08, 2026
Aug 17, 2026
Sep 08, 2026
5.4 MEDIUM
CVE-2026-74999 — Roundcube Webmail Stored Cross-Site Scripting Vulnerability

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

webmail | Remote | Cross-Site Scripting
Aug 17, 2026 Sep 08, 2026
Aug 17, 2026
Sep 08, 2026
7.2 HIGH
CVE-2026-74998 — Roundcube Webmail CSS Proxy Cross-Site Scripting and Information Disclosure

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scri…

webmail | Remote | Information Disclosure
Aug 17, 2026 Sep 08, 2026
Aug 17, 2026
Sep 08, 2026
8.8 HIGH
CVE-2026-74997 — Roundcube Webmail Markasjunk Plugin Remote Code Execution Vulnerability

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue onl…

webmail | Remote | Injection
Aug 17, 2026 Sep 08, 2026
Aug 17, 2026
Sep 08, 2026
3.5 LOW
CVE-2026-70412 — Dell iDRAC Information Disclosure Vulnerability

Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readable after Memory Erase vulnerability. A low privileged attacker with remote acce…

idrac9 idrac9 idrac10 | Remote | Information Disclosure
Aug 17, 2026 Aug 18, 2026
Aug 17, 2026
Aug 18, 2026
7.0 HIGH
CVE-2026-18674 — Kong Mesh multi-zone: the global control plane attributes KDS-synced resources by an unva…

On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated zone…

Remote | Authorization
Aug 17, 2026 Aug 31, 2026
Aug 17, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-16467 — Broken Access Control in Dolusoft Software's Fortilogger

Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fortilogger: before 6.1.5.9.

Remote | Authorization
Aug 17, 2026 Aug 26, 2026
Aug 17, 2026
Aug 26, 2026
9.0 CRITICAL
CVE-2026-14564 — Sensitive Data Exposure in Innotim Software's Logsign SIEM

Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data. This issue affects Logsi…

Remote | Authentication
Aug 17, 2026 Aug 26, 2026
Aug 17, 2026
Aug 26, 2026
Showing 20 of 14636 Results