U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-39359 - Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a logic flaw affects the Wazuh Manager's enrollment daemon (authd) and synchronization daemon... read CVE-2026-39359
    Published: July 16, 2026; 8:16:25 PM -0400

  • CVE-2026-54132 - Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
    Published: July 14, 2026; 1:17:05 PM -0400

  • CVE-2026-49181 - Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.
    Published: July 14, 2026; 1:16:53 PM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2026-54982 - Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
    Published: July 14, 2026; 1:17:05 PM -0400

  • CVE-2026-34150 - Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and above, prior to 4.14.5, a heap buffer overflow in wazuh-analysisd allows an unauthenticated remote attacker to crash the Wazuh mana... read CVE-2026-34150
    Published: July 16, 2026; 8:16:25 PM -0400

  • CVE-2026-49183 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
    Published: July 14, 2026; 1:16:53 PM -0400

  • CVE-2026-49172 - Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
    Published: July 14, 2026; 1:16:52 PM -0400

  • CVE-2026-49173 - Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
    Published: July 14, 2026; 1:16:52 PM -0400

  • CVE-2026-33754 - Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and above, prior to 4.14.5, a remote attacker can trigger memory exhaustion in the cluster protocol parser by sending a crafted message... read CVE-2026-33754
    Published: July 16, 2026; 8:16:25 PM -0400

  • CVE-2026-49184 - Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
    Published: July 14, 2026; 1:16:53 PM -0400

    V3.1: 7.8 HIGH

  • CVE-2026-49787 - Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
    Published: July 14, 2026; 1:16:54 PM -0400

  • CVE-2026-49174 - Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
    Published: July 14, 2026; 1:16:52 PM -0400

  • CVE-2026-49180 - Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
    Published: July 14, 2026; 1:16:53 PM -0400

    V3.1: 5.5 MEDIUM

  • CVE-2025-30007 - HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary commands as root by injecting a single-quote character into unvalidated DNS record types. Attacke... read CVE-2025-30007
    Published: July 10, 2026; 3:17:18 PM -0400

  • CVE-2025-30008 - HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a double-quote followed by a script payload in the value field. The app... read CVE-2025-30008
    Published: July 10, 2026; 3:17:19 PM -0400

    V3.1: 5.4 MEDIUM

  • CVE-2026-62641 - In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.
    Published: July 14, 2026; 12:17:04 PM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2026-62642 - In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.
    Published: July 14, 2026; 12:17:04 PM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2026-62643 - In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: thi... read CVE-2026-62643
    Published: July 14, 2026; 12:17:04 PM -0400

  • CVE-2026-49788 - Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.
    Published: July 14, 2026; 1:16:54 PM -0400

  • CVE-2026-49783 - Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
    Published: July 14, 2026; 1:16:53 PM -0400

Created September 20, 2022 , Updated August 27, 2024