Security Risk Category

Network Security Risks — Page 3

Published vulnerability pages connected to Network Security. Each page keeps one canonical URL and focused remediation guidance.

253 published Network Security risks

Network Security risks

Showing 73–108 of 253 published risks.

mediumEPSS 0.002

CVE-2026-57213 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the consumer_tag field on the Federation Status page without HTML escaping, allowing a user who can configure a federation upstream or...

CVE-2026-57213network-securityweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-57214 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to...

CVE-2026-57214network-securityweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-57215 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted at bind and route time but are missing from Khepri-backed...

CVE-2026-57215network-securityauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.005

CVE-2026-57216 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol...

CVE-2026-57216network-securityauthentication-bypass

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-57217 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined,...

CVE-2026-57217network-securityauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-57218 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized...

CVE-2026-57218network-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.004

CVE-2026-57219 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to...

CVE-2026-57219network-securityapi-securityinformation-disclosure

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-57220 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticated remote client to declare...

CVE-2026-57220network-securitydenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-57221 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can connect to a virtual host to...

CVE-2026-57221network-securityapi-securityauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-52747 in ModSecurity

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-file form-field values before exporting...

CVE-2026-52747network-securityweb-applicationinput-validation

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-52761 in ModSecurity

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8toUnicode transformation in src/actions/transformations/utf8_to_unicode.cc produces wrong output on i386...

CVE-2026-52761network-securityweb-applicationinput-validation

Updated Jul 15, 2026

highEPSS 0.004

CVE-2026-59835 in FortiSandbox

A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.

CVE-2026-59835network-securityauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

highEPSS 0.001

CVE-2026-59836 in FortiClient EMS

A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>

CVE-2026-59836network-securityinformation-disclosurecryptography

Updated Jul 15, 2026

mediumEPSS 0.006

CVE-2026-59837 in FortiProxy

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions,...

CVE-2026-59837network-securityremote-code-executionmemory-corruption

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-59839 in FortiProxy

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM...

CVE-2026-59839network-securityremote-code-executionpath-traversal

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-59840 in FortiProxy

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions may allow attacker to information...

CVE-2026-59840network-securityinformation-disclosurememory-corruption

Updated Jul 15, 2026

mediumEPSS 0.002

Anti-Malware Security and Brute-Force Firewall <= 4.23.89 - Unauthenticated Stored Cross-Site Scripting

Anti-Malware Security and Brute-Force Firewall has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57691wordpressbrowsernetwork-securityxss

Updated Jul 15, 2026

highEPSS 0.002

WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce <= 4.7.4 - Authenticated (Subscriber+) SQL Injection

WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce has a SQL injection issue. An attacker with the needed access can change a request and may read database data.

CVE-2026-57810wordpresswoocommercenetwork-securitysql-injection

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-5138 in Red Hat Satellite

A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information disclosure vulnerability. This flaw occurs because the taxonomy_scope controller method does not properly validate organization and location IDs from nested request parameters, bypassing existing authorization checks. This allows the user to leak sensitive infrastructure metadata, including subnet topology, IP ranges, gateways, DNS servers, and VLAN IDs, from organizations and locations they are not authorized to access.

CVE-2026-5138linuxnetwork-securitydevopsweb-application

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-5142 in Red Hat Satellite

A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.

CVE-2026-5142linuxnetwork-securitydevopsweb-application

Updated Jul 15, 2026

criticalEPSS 0.010

CVE-2026-58126 in PACSgear PACS Scan

PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.exe without any authentication requirement. Attackers can chain the arbitrary file write primitive with DLL hijacking in PGImageExchangeQueueSvc.exe, which loads missing DLLs such as CRYPTSP.DLL from the application directory, to achieve remote code execution as NT Authority\SYSTEM upon service restart.

CVE-2026-58126dotnetwindowsnetwork-securityremote-code-execution

Updated Jul 15, 2026

criticalEPSS 0.010

CVE-2026-58127 in PACSgear MediaWriter

PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By exploiting the MarshalByRefObject object unmarshalling technique and implementing .NET WebClient class methods, an unauthenticated remote attacker can read and write arbitrary files on the host filesystem. The ObjectURIs are identical across all installations by default. Chaining the arbitrary file write primitive with DLL hijacking opportunities in the MediaWriter service (which runs as NT Authority\\SYSTEM and loads missing DLLs such as CRYPTBASE.DLL from the application directory) enables unauthenticated remote code execution as SYSTEM upon service restart.

CVE-2026-58127dotnetwindowsnetwork-securityremote-code-execution

Updated Jul 15, 2026

high

CVE-2026-20213 in ClamAV

A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PE files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains PE content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

CVE-2026-20213network-securitydenial-of-servicememory-corruption

Updated Jul 15, 2026

high

CVE-2026-20214 in ClamAV

A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in FSG files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains portable executable content compressed with FSG to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

CVE-2026-20214network-securitydenial-of-servicememory-corruption

Updated Jul 15, 2026

high

CVE-2026-20215 in ClamAV

A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in 7z files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains 7z&nbsp;content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

CVE-2026-20215network-securitydenial-of-servicememory-corruption

Updated Jul 15, 2026

high

CVE-2026-20216 in ClamAV

A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a crafted InstallShield file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process and temporarily consume available system resources, resulting in a DoS condition on the affected software.

CVE-2026-20216network-securityinput-validationdenial-of-service

Updated Jul 15, 2026

high

CVE-2026-20217 in ClamAV

A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains PESpin content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

CVE-2026-20217network-securitydenial-of-servicememory-corruption

Updated Jul 15, 2026

high

CVE-2026-20243 in ClamAV

A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in ALZ files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains ALZ content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

CVE-2026-20243network-securitydenial-of-servicememory-corruption

Updated Jul 15, 2026

high

CVE-2026-20244 in ClamAV

A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in DMG files during scanning, which may result in an integer overflow on 32-bit platforms only. An attacker could exploit this vulnerability by submitting a crafted file that contains DMG content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

CVE-2026-20244network-securitydenial-of-servicememory-corruption

Updated Jul 15, 2026

highEPSS 0.006

CVE-2026-54399 in Apache HttpComponents Core

Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length

CVE-2026-54399javanetwork-securitydenial-of-service

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-58065 in Apache Airflow Providers Git

The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server (man-in-the-middle), capturing the SSH deploy key or injecting malicious repository content. Deployments that use the Git DAG bundle or Git provider to clone over SSH with a deploy key are affected. The fix changes the default to verify host keys; upgrade to apache-airflow-providers-git `0.4.1` or later and configure a `known_hosts` file.

CVE-2026-58065pythonnetwork-securitydevopssupply-chain

Updated Jul 15, 2026

low

CVE-2025-62675 in FortiProxy and FortiOS

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link.

CVE-2025-62675network-securityinput-validation

Updated Jul 15, 2026

low

CVE-2025-62826 in FortiProxy and FortiOS

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker able to intercept and modify a user's captive portal authentication request to inject arbitrary headers via crafted HTTP requests.

CVE-2025-62826network-securityinput-validation

Updated Jul 15, 2026

medium

CVE-2026-23573 in FortiProxy and FortiOS

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.3, FortiProxy 7.2.0 through 7.2.9 may allow an authenticated remote user to execute code or commands via crafted requests.

CVE-2026-23573network-securityinput-validationxss

Updated Jul 15, 2026

high

CVE-2026-59841 in FortiSIEM Windows Agent

A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>

CVE-2026-59841windowsnetwork-securityprivilege-escalation

Updated Jul 15, 2026

criticalCISA KEV

CVE-2026-15409 in SonicWall SMA 1000 Series

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

CVE-2026-15409network-securityssrf

Updated Jul 15, 2026