U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-62643 - In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: thi... read CVE-2026-62643
    Published: July 14, 2026; 12:17:04 PM -0400

  • CVE-2026-49788 - Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.
    Published: July 14, 2026; 1:16:54 PM -0400

  • CVE-2026-49783 - Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
    Published: July 14, 2026; 1:16:53 PM -0400

  • CVE-2026-62644 - In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
    Published: July 14, 2026; 12:17:04 PM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2026-49789 - Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
    Published: July 14, 2026; 1:16:54 PM -0400

    V3.1: 7.8 HIGH

  • CVE-2026-49792 - Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
    Published: July 14, 2026; 1:16:54 PM -0400

  • CVE-2026-49793 - Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
    Published: July 14, 2026; 1:16:55 PM -0400

  • CVE-2026-49790 - Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
    Published: July 14, 2026; 1:16:54 PM -0400

    V3.1: 7.8 HIGH

  • CVE-2026-49791 - Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
    Published: July 14, 2026; 1:16:54 PM -0400

    V3.1: 7.8 HIGH

  • CVE-2026-40106 - Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap-based buffer overflow vulnerability in the syscheck component of the Wazuh agent for Windows. Whe... read CVE-2026-40106
    Published: July 16, 2026; 10:18:05 PM -0400

    V3.1: 7.8 HIGH

  • CVE-2026-44251 - Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazu... read CVE-2026-44251
    Published: July 16, 2026; 10:18:05 PM -0400

  • CVE-2026-33434 - Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and above, prior to 4.14.5, a logic error in CheckRateLimitsMiddleware.dispatch() causes the /events endpoint rate check to uncondition... read CVE-2026-33434
    Published: July 16, 2026; 8:16:24 PM -0400

    V3.1: 7.1 HIGH

  • CVE-2026-15058 - Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.
    Published: July 14, 2026; 3:16:50 PM -0400

  • CVE-2026-15637 - Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a d... read CVE-2026-15637
    Published: July 14, 2026; 3:16:51 PM -0400

  • CVE-2026-15641 - Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypas... read CVE-2026-15641
    Published: July 14, 2026; 3:16:51 PM -0400

  • CVE-2026-45737 - Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configuration annot... read CVE-2026-45737
    Published: July 15, 2026; 4:17:04 PM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2026-45738 - Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rendered by ui/... read CVE-2026-45738
    Published: July 15, 2026; 4:17:05 PM -0400

    V3.1: 8.7 HIGH

  • CVE-2026-45568 - zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to urllib.parse.urljoin, allowing the requested path ... read CVE-2026-45568
    Published: July 16, 2026; 1:16:56 PM -0400

    V3.1: 9.1 CRITICAL

  • CVE-2026-45576 - zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or zrok drive paths such as /../outside.txt in the source inventory and passes them to FilesystemTarge... read CVE-2026-45576
    Published: July 16, 2026; 1:16:56 PM -0400

    V3.1: 7.5 HIGH

  • CVE-2026-46562 - Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a... read CVE-2026-46562
    Published: July 16, 2026; 1:16:56 PM -0400

Created September 20, 2022 , Updated August 27, 2024