The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.
For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
Legal Disclaimer:
Here is where you can read the NVD legal disclaimer.
-
CVE-2026-62643 - In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: thi... read CVE-2026-62643
Published: July 14, 2026; 12:17:04 PM -0400V3.1: 10.0 CRITICAL
-
CVE-2026-49788 - Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.
Published: July 14, 2026; 1:16:54 PM -0400 -
CVE-2026-49783 - Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Published: July 14, 2026; 1:16:53 PM -0400 -
CVE-2026-62644 - In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
Published: July 14, 2026; 12:17:04 PM -0400V3.1: 9.8 CRITICAL
-
CVE-2026-49789 - Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
Published: July 14, 2026; 1:16:54 PM -0400V3.1: 7.8 HIGH
-
CVE-2026-49792 - Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
Published: July 14, 2026; 1:16:54 PM -0400 -
CVE-2026-49793 - Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
Published: July 14, 2026; 1:16:55 PM -0400 -
CVE-2026-49790 - Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Published: July 14, 2026; 1:16:54 PM -0400V3.1: 7.8 HIGH
-
CVE-2026-49791 - Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
Published: July 14, 2026; 1:16:54 PM -0400V3.1: 7.8 HIGH
-
CVE-2026-40106 - Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap-based buffer overflow vulnerability in the syscheck component of the Wazuh agent for Windows. Whe... read CVE-2026-40106
Published: July 16, 2026; 10:18:05 PM -0400V3.1: 7.8 HIGH
-
CVE-2026-44251 - Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazu... read CVE-2026-44251
Published: July 16, 2026; 10:18:05 PM -0400 -
CVE-2026-33434 - Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and above, prior to 4.14.5, a logic error in CheckRateLimitsMiddleware.dispatch() causes the /events endpoint rate check to uncondition... read CVE-2026-33434
Published: July 16, 2026; 8:16:24 PM -0400V3.1: 7.1 HIGH
-
CVE-2026-15058 - Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.
Published: July 14, 2026; 3:16:50 PM -0400 -
CVE-2026-15637 - Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a d... read CVE-2026-15637
Published: July 14, 2026; 3:16:51 PM -0400 -
CVE-2026-15641 - Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypas... read CVE-2026-15641
Published: July 14, 2026; 3:16:51 PM -0400 -
CVE-2026-45737 - Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configuration annot... read CVE-2026-45737
Published: July 15, 2026; 4:17:04 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-45738 - Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rendered by ui/... read CVE-2026-45738
Published: July 15, 2026; 4:17:05 PM -0400V3.1: 8.7 HIGH
-
CVE-2026-45568 - zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to urllib.parse.urljoin, allowing the requested path ... read CVE-2026-45568
Published: July 16, 2026; 1:16:56 PM -0400V3.1: 9.1 CRITICAL
-
CVE-2026-45576 - zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or zrok drive paths such as /../outside.txt in the source inventory and passes them to FilesystemTarge... read CVE-2026-45576
Published: July 16, 2026; 1:16:56 PM -0400V3.1: 7.5 HIGH
-
CVE-2026-46562 - Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a... read CVE-2026-46562
Published: July 16, 2026; 1:16:56 PM -0400