Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-40016 — Exim ManageSieve CPU Time Limit Bypass Vulnerability

Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to deg…

dovecot dovecot | Remote | Denial of Service
May 12, 2026 May 18, 2026
May 12, 2026
May 18, 2026
8.2 HIGH
CVE-2026-35071 — Dell PowerScale InsightIQ OS Command Injection

Dell PowerScale InsightIQ, versions 6.0.0 through 6.2.0, contains an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability. A high privileged attack…

insightiq | Injection
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
6.8 MEDIUM
CVE-2026-33603 — Dovecot SCRAM TLS Channel Binding Man-in-the-Middle Vulnerability

Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the c…

dovecot dovecot | Cryptography
May 12, 2026 May 18, 2026
May 12, 2026
May 18, 2026
9.1 CRITICAL
CVE-2026-27851 — Apache Struts Unvalidated User Input Injection

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP …

dovecot dovecot | Remote | Injection
May 12, 2026 May 18, 2026
May 12, 2026
May 18, 2026
7.8 HIGH
CVE-2025-12659 — Heap-based buffer overflow in Siemens Simcenter Femap

Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute code in the context of the current process.

simcenter_femap | Memory Corruption
May 12, 2026 Jun 09, 2026
May 12, 2026
Jun 09, 2026
Showing 20 of 7365 Results