U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-40106 - Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap-based buffer overflow vulnerability in the syscheck component of the Wazuh agent for Windows. Whe... read CVE-2026-40106
    Published: July 16, 2026; 10:18:05 PM -0400

    V3.1: 7.8 HIGH

  • CVE-2026-44251 - Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazu... read CVE-2026-44251
    Published: July 16, 2026; 10:18:05 PM -0400

  • CVE-2026-33434 - Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and above, prior to 4.14.5, a logic error in CheckRateLimitsMiddleware.dispatch() causes the /events endpoint rate check to uncondition... read CVE-2026-33434
    Published: July 16, 2026; 8:16:24 PM -0400

    V3.1: 7.1 HIGH

  • CVE-2026-15058 - Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.
    Published: July 14, 2026; 3:16:50 PM -0400

  • CVE-2026-15637 - Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a d... read CVE-2026-15637
    Published: July 14, 2026; 3:16:51 PM -0400

  • CVE-2026-15641 - Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypas... read CVE-2026-15641
    Published: July 14, 2026; 3:16:51 PM -0400

  • CVE-2026-45737 - Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configuration annot... read CVE-2026-45737
    Published: July 15, 2026; 4:17:04 PM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2026-45738 - Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rendered by ui/... read CVE-2026-45738
    Published: July 15, 2026; 4:17:05 PM -0400

    V3.1: 8.7 HIGH

  • CVE-2026-45568 - zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to urllib.parse.urljoin, allowing the requested path ... read CVE-2026-45568
    Published: July 16, 2026; 1:16:56 PM -0400

    V3.1: 9.1 CRITICAL

  • CVE-2026-45576 - zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or zrok drive paths such as /../outside.txt in the source inventory and passes them to FilesystemTarge... read CVE-2026-45576
    Published: July 16, 2026; 1:16:56 PM -0400

    V3.1: 7.5 HIGH

  • CVE-2026-46562 - Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a... read CVE-2026-46562
    Published: July 16, 2026; 1:16:56 PM -0400

  • CVE-2026-46621 - Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through the JSR-223 ScriptEngine API without enforcing a... read CVE-2026-46621
    Published: July 16, 2026; 1:16:57 PM -0400

  • CVE-2026-47729 - Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the Type... read CVE-2026-47729
    Published: July 16, 2026; 1:16:57 PM -0400

  • CVE-2026-50012 - Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's on-the-w... read CVE-2026-50012
    Published: July 16, 2026; 1:16:57 PM -0400

    V3.1: 5.5 MEDIUM

  • CVE-2026-55548 - Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request omitted spec... read CVE-2026-55548
    Published: July 16, 2026; 1:16:57 PM -0400

  • CVE-2026-41721 - Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled in conjunction with a Controller method using @ProjectedPayload, when an attacker sends a specially crafted HTT... read CVE-2026-41721
    Published: June 09, 2026; 8:16:51 PM -0400

  • CVE-2026-41728 - Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 through 3.7.19;... read CVE-2026-41728
    Published: June 09, 2026; 8:16:52 PM -0400

  • CVE-2026-41729 - Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segment used a... read CVE-2026-41729
    Published: June 09, 2026; 8:16:52 PM -0400

  • CVE-2026-41730 - Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 th... read CVE-2026-41730
    Published: June 09, 2026; 8:16:52 PM -0400

  • CVE-2026-41837 - Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Spring Data REST 3.7.0 through 3... read CVE-2026-41837
    Published: June 09, 2026; 8:16:52 PM -0400

Created September 20, 2022 , Updated August 27, 2024