CVE Find is a real-time vulnerability database indexing 400 086 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 3233 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-101283 |
2026-09-30 21h32 +00:00 |
iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256... |
9.2 |
Critical |
|
CVE-2026-102149 |
2026-09-30 21h17 +00:00 |
Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could b... Authorization problems |
9.4 |
Critical |
|
CVE-2026-102147 |
2026-09-30 21h17 +00:00 |
A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attack... Cross-site Scripting |
9.3 |
Critical |
|
CVE-2026-102125 |
2026-09-30 21h17 +00:00 |
The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the cod... |
8.8 |
High |
|
CVE-2026-102121 |
2026-09-30 21h17 +00:00 |
A form-rendering interface in the Advanced Forms component is reachable without authentication so th... Authorization problems |
8.6 |
High |
|
CVE-2026-102120 |
2026-09-30 21h17 +00:00 |
A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obt... OS Command InjectionImproper Privilege Management |
8.8 |
High |
|
CVE-2026-102115 |
2026-09-30 21h16 +00:00 |
Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An u... |
9.8 |
Critical |
|
CVE-2026-102106 |
2026-09-30 21h16 +00:00 |
Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administr... Authorization problems |
9.1 |
Critical |
|
CVE-2026-102105 |
2026-09-30 21h16 +00:00 |
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery... Server-Side Request Forgery - SSRF |
9.1 |
Critical |
|
CVE-2026-102104 |
2026-09-30 21h16 +00:00 |
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery... Server-Side Request Forgery - SSRF |
9.1 |
Critical |