U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

NVD Dashboard

CVEs Received and Processed

CVEs Received and Processed

Please Wait

CVE Status Count

Please Wait

CVSS Score Spread

Please Wait

CVSS V3 Score Distribution

Severity Number of Vulns

CVSS V2 Score Distribution

Severity Number of Vulns


For information on how to the cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2023-37507 - HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.
    Published: July 21, 2026; 2:16:27 AM -0400

    V3.1: 7.5 HIGH

  • CVE-2023-37508 - HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present.
    Published: July 21, 2026; 1:16:33 AM -0400

    V3.1: 6.1 MEDIUM

  • CVE-2026-43797 - This issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6. An app may be able to access information about a user's contacts.
    Published: July 27, 2026; 5:17:03 PM -0400

  • CVE-2026-43800 - An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
    Published: July 27, 2026; 5:17:03 PM -0400

  • CVE-2026-43810 - The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote user may be able to cause unexpec... read CVE-2026-43810
    Published: July 27, 2026; 5:17:04 PM -0400

  • CVE-2026-43816 - An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
    Published: July 27, 2026; 5:17:04 PM -0400

  • CVE-2026-53401 - In the Linux kernel, the following vulnerability has been resolved: fbdev: omap2: fix use-after-free in omapfb_mmap omapfb_mmap() has a race condition with OMAPFB_SETUP_PLANE ioctl that can lead to use-after-free: The fb_mmap() entry point hold... read CVE-2026-53401
    Published: July 19, 2026; 8:16:51 AM -0400

  • CVE-2026-43817 - An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
    Published: July 27, 2026; 5:17:04 PM -0400

  • CVE-2026-16802 - Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when n... read CVE-2026-16802
    Published: July 24, 2026; 11:17:13 AM -0400

  • CVE-2026-16801 - Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a craf... read CVE-2026-16801
    Published: July 24, 2026; 11:17:13 AM -0400

  • CVE-2026-53392 - In the Linux kernel, the following vulnerability has been resolved: NFSv4/flexfiles: reject zero filehandle version count ff_layout_alloc_lseg() decodes the filehandle-version array count from the flexfiles layout body. The value is used as the ... read CVE-2026-53392
    Published: July 19, 2026; 8:16:50 AM -0400

  • CVE-2026-16800 - Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via craf... read CVE-2026-16800
    Published: July 24, 2026; 11:17:12 AM -0400

  • CVE-2026-53393 - In the Linux kernel, the following vulnerability has been resolved: nfsd: reset write verifier on deferred writeback errors nfsd_vfs_write() and nfsd_commit() both call filemap_check_wb_err() to detect deferred writeback errors, but neither rota... read CVE-2026-53393
    Published: July 19, 2026; 8:16:50 AM -0400

    V3.1: 5.5 MEDIUM

  • CVE-2026-53394 - In the Linux kernel, the following vulnerability has been resolved: nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race When find_or_alloc_open_stateowner() encounters an unconfirmed owner, it calls release_openowner() and sets... read CVE-2026-53394
    Published: July 19, 2026; 8:16:50 AM -0400

  • CVE-2026-16799 - Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via m... read CVE-2026-16799
    Published: July 24, 2026; 11:17:12 AM -0400

  • CVE-2026-53395 - In the Linux kernel, the following vulnerability has been resolved: nfsd: fix dead ACL conflict guard in nfsd4_create nfsd4_create() steals create->cr_dpacl/cr_pacl into the local nfsd_attrs via the designated initializer, then immediately sets ... read CVE-2026-53395
    Published: July 19, 2026; 8:16:50 AM -0400

  • CVE-2026-53396 - In the Linux kernel, the following vulnerability has been resolved: nfsd: fix posix_acl leak and ignored error in nfsd4_create_file nfsd4_create_file() has two bugs in its ACL handling: The return value of nfsd4_acl_to_attr() is silently discar... read CVE-2026-53396
    Published: July 19, 2026; 8:16:50 AM -0400

  • CVE-2026-16798 - Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refr... read CVE-2026-16798
    Published: July 24, 2026; 11:17:12 AM -0400

  • CVE-2026-53397 - In the Linux kernel, the following vulnerability has been resolved: nfsd: fix posix_acl leak on SETACL decode failure nfsaclsvc_decode_setaclargs() and nfs3svc_decode_setaclargs() each call nfs_stream_decode_acl() twice, first for NFS_ACL and th... read CVE-2026-53397
    Published: July 19, 2026; 8:16:50 AM -0400

  • CVE-2026-53398 - In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() currently initializes sin_exp after decoding sin_style. If the XDR stream is truncated, the decoder... read CVE-2026-53398
    Published: July 19, 2026; 8:16:50 AM -0400