The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.
For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
Legal Disclaimer:
Here is where you can read the NVD legal disclaimer.
-
CVE-2026-40106 - Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap-based buffer overflow vulnerability in the syscheck component of the Wazuh agent for Windows. Whe... read CVE-2026-40106
Published: July 16, 2026; 10:18:05 PM -0400V3.1: 7.8 HIGH
-
CVE-2026-44251 - Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazu... read CVE-2026-44251
Published: July 16, 2026; 10:18:05 PM -0400 -
CVE-2026-33434 - Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and above, prior to 4.14.5, a logic error in CheckRateLimitsMiddleware.dispatch() causes the /events endpoint rate check to uncondition... read CVE-2026-33434
Published: July 16, 2026; 8:16:24 PM -0400V3.1: 7.1 HIGH
-
CVE-2026-15058 - Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.
Published: July 14, 2026; 3:16:50 PM -0400 -
CVE-2026-15637 - Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a d... read CVE-2026-15637
Published: July 14, 2026; 3:16:51 PM -0400 -
CVE-2026-15641 - Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypas... read CVE-2026-15641
Published: July 14, 2026; 3:16:51 PM -0400 -
CVE-2026-45737 - Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configuration annot... read CVE-2026-45737
Published: July 15, 2026; 4:17:04 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-45738 - Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can set link.argocd.argoproj.io/* annotations whose pipe-separated values are rendered by ui/... read CVE-2026-45738
Published: July 15, 2026; 4:17:05 PM -0400V3.1: 8.7 HIGH
-
CVE-2026-45568 - zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to urllib.parse.urljoin, allowing the requested path ... read CVE-2026-45568
Published: July 16, 2026; 1:16:56 PM -0400V3.1: 9.1 CRITICAL
-
CVE-2026-45576 - zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or zrok drive paths such as /../outside.txt in the source inventory and passes them to FilesystemTarge... read CVE-2026-45576
Published: July 16, 2026; 1:16:56 PM -0400V3.1: 7.5 HIGH
-
CVE-2026-46562 - Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a... read CVE-2026-46562
Published: July 16, 2026; 1:16:56 PM -0400 -
CVE-2026-46621 - Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through the JSR-223 ScriptEngine API without enforcing a... read CVE-2026-46621
Published: July 16, 2026; 1:16:57 PM -0400 -
CVE-2026-47729 - Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the Type... read CVE-2026-47729
Published: July 16, 2026; 1:16:57 PM -0400 -
CVE-2026-50012 - Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's on-the-w... read CVE-2026-50012
Published: July 16, 2026; 1:16:57 PM -0400V3.1: 5.5 MEDIUM
-
CVE-2026-55548 - Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request omitted spec... read CVE-2026-55548
Published: July 16, 2026; 1:16:57 PM -0400 -
CVE-2026-41721 - Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled in conjunction with a Controller method using @ProjectedPayload, when an attacker sends a specially crafted HTT... read CVE-2026-41721
Published: June 09, 2026; 8:16:51 PM -0400 -
CVE-2026-41728 - Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 through 3.7.19;... read CVE-2026-41728
Published: June 09, 2026; 8:16:52 PM -0400 -
CVE-2026-41729 - Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segment used a... read CVE-2026-41729
Published: June 09, 2026; 8:16:52 PM -0400 -
CVE-2026-41730 - Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 th... read CVE-2026-41730
Published: June 09, 2026; 8:16:52 PM -0400 -
CVE-2026-41837 - Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Spring Data REST 3.7.0 through 3... read CVE-2026-41837
Published: June 09, 2026; 8:16:52 PM -0400