Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.3 HIGH
CVE-2026-56685 — Dell ObjectScale OS Command Injection Vulnerability

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with loc…

objectscale | Injection
Aug 17, 2026 Aug 19, 2026
Aug 17, 2026
Aug 19, 2026
7.3 HIGH
CVE-2026-56090 — Dell ObjectScale Uncontrolled Search Path Element Vulnerability

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, le…

objectscale | Path Traversal
Aug 17, 2026 Aug 19, 2026
Aug 17, 2026
Aug 19, 2026
3.3 LOW
CVE-2026-56089 — Dell ObjectScale Path Traversal Vulnerability

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Informatio…

objectscale | Path Traversal
Aug 17, 2026 Aug 19, 2026
Aug 17, 2026
Aug 19, 2026
8.1 HIGH
CVE-2026-19693 — extract-zip arbitrary file write outside the destination directory via a symlink at the f…

extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names …

extract-zip | Remote | Path Traversal
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
7.5 HIGH
CVE-2026-16471 — Broken Access Control in Dolusoft Software's Sonlogger

Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sonlogger: from v6.6.6 before 6.7.…

Remote | Authorization
Aug 17, 2026 Aug 26, 2026
Aug 17, 2026
Aug 26, 2026
7.2 HIGH
CVE-2026-16139 — Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller po…

In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker…

sharefile_storage_zones_controller | Remote | Path Traversal
Aug 17, 2026 Sep 02, 2026
Aug 17, 2026
Sep 02, 2026
8.0 HIGH
CVE-2026-16138 — Remote code execution via unsafe deserialization in Progress ShareFile Storage Zones Cont…

In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary…

Aug 17, 2026 Sep 02, 2026
Aug 17, 2026
Sep 02, 2026
7.2 HIGH
CVE-2026-16137 — Path traversal via unsanitized upload filename leads to arbitrary file write in Progress …

In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to writ…

sharefile_storage_zones_controller | Remote | Path Traversal
Aug 17, 2026 Sep 02, 2026
Aug 17, 2026
Sep 02, 2026
7.9 HIGH
CVE-2026-15218 — Models-as-a-service: red hat openshift ai: maas-api and maas-controller serviceaccounts w…

A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational requirements…

openshift_ai | Remote | Authorization
Aug 17, 2026 Aug 27, 2026
Aug 17, 2026
Aug 27, 2026
Showing 20 of 14649 Results