U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-14681 - Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may ex... read CVE-2026-14681
    Published: August 13, 2026; 9:17:45 AM -0400

  • CVE-2026-14680 - Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutua... read CVE-2026-14680
    Published: August 13, 2026; 9:17:45 AM -0400

  • CVE-2026-14679 - Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 ... read CVE-2026-14679
    Published: August 13, 2026; 9:17:45 AM -0400

  • CVE-2026-14678 - Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.5, 17... read CVE-2026-14678
    Published: August 13, 2026; 9:17:45 AM -0400

  • CVE-2026-14677 - Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating syste... read CVE-2026-14677
    Published: August 13, 2026; 9:17:45 AM -0400

  • CVE-2026-14673 - Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling ... read CVE-2026-14673
    Published: August 13, 2026; 9:17:44 AM -0400

  • CVE-2026-14676 - Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions bef... read CVE-2026-14676
    Published: August 13, 2026; 9:17:44 AM -0400

  • CVE-2026-6471 - Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs ... read CVE-2026-6471
    Published: August 13, 2026; 9:19:16 AM -0400

  • CVE-2026-56089 - Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
    Published: August 17, 2026; 10:20:20 AM -0400

  • CVE-2026-56090 - Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
    Published: August 17, 2026; 10:20:21 AM -0400

  • CVE-2026-56685 - Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnera... read CVE-2026-56685
    Published: August 17, 2026; 10:20:21 AM -0400

  • CVE-2026-56686 - Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnera... read CVE-2026-56686
    Published: August 17, 2026; 10:20:21 AM -0400

  • CVE-2026-59909 - Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
    Published: August 17, 2026; 10:20:21 AM -0400

  • CVE-2026-59910 - Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnera... read CVE-2026-59910
    Published: August 17, 2026; 10:20:21 AM -0400

  • CVE-2026-59911 - Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Inform... read CVE-2026-59911
    Published: August 17, 2026; 10:20:21 AM -0400

  • CVE-2026-21070 - Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.
    Published: August 10, 2026; 5:17:20 AM -0400

    V3.1: 4.6 MEDIUM

  • CVE-2026-21073 - Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.
    Published: August 10, 2026; 5:17:20 AM -0400

    V3.1: 6.1 MEDIUM

  • CVE-2026-21058 - Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
    Published: August 10, 2026; 4:16:47 AM -0400

    V3.1: 7.1 HIGH

  • CVE-2026-21059 - Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
    Published: August 10, 2026; 4:16:47 AM -0400

    V3.1: 7.1 HIGH

  • CVE-2026-21060 - Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.
    Published: August 10, 2026; 4:16:48 AM -0400

    V3.1: 4.6 MEDIUM

Created September 20, 2022 , Updated August 27, 2024