Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54243
Total
4300
Critical
16125
High
15819
Medium
CVE ID Severity Score Description Published
CVE-2026-102144 MEDIUM 5.3 A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial … Sep 30, 2026
CVE-2026-102143 HIGH 7.5 An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not … Sep 30, 2026
CVE-2026-102142 HIGH 7.2 A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated expressions contained in the stored template body. An authenticated … Sep 30, 2026
CVE-2026-102141 MEDIUM 6.7 Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could … Sep 30, 2026
CVE-2026-102140 MEDIUM 4.9 An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header … Sep 30, 2026
CVE-2026-102139 MEDIUM 6.5 An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party … Sep 30, 2026
CVE-2026-102138 LOW 3.3 An authenticated administrator on a node with an optional, separately licensed gateway role enabled could supply a connector URL that the server retrieved without sufficient … Sep 30, 2026
CVE-2026-102137 MEDIUM 4.1 An authenticated administrator could bypass the content validation applied to an administrative file upload and store a file containing dangerous content on the appliance. This … Sep 30, 2026
CVE-2026-102136 MEDIUM 6.3 In multi-node deployments, an attacker who had already obtained code execution on one appliance node could submit a value through an internal cluster interface that … Sep 30, 2026
CVE-2026-102135 MEDIUM 6.6 On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was … Sep 30, 2026
CVE-2026-102134 MEDIUM 5.4 Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service. An authenticated user could reach … Sep 30, 2026
CVE-2026-102133 MEDIUM 6.6 An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. … Sep 30, 2026
CVE-2026-102132 HIGH 7.2 An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A … Sep 30, 2026
CVE-2026-102131 HIGH 7.2 Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator … Sep 30, 2026
CVE-2026-102130 HIGH 7.2 Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. … Sep 30, 2026
CVE-2026-102129 HIGH 7.2 A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated … Sep 30, 2026
CVE-2026-102128 HIGH 7.5 An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not … Sep 30, 2026
CVE-2026-102127 HIGH 7.0 An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote … Sep 30, 2026
CVE-2026-102126 HIGH 8.1 A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content … Sep 30, 2026
CVE-2026-102125 HIGH 8.8 The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the code running inside it. Code already executing within that sandbox … Sep 30, 2026
CVE-2026-102124 MEDIUM 6.5 A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance … Sep 30, 2026
CVE-2026-102123 HIGH 7.4 A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended directory, which could allow an unauthenticated attacker to write a … Sep 30, 2026
CVE-2026-102122 MEDIUM 4.3 Kiteworks did not correctly enforce which roles a shared folder's manager was permitted to assign. In a default configuration, an authenticated user holding the Manager … Sep 30, 2026
CVE-2026-102121 HIGH 8.6 A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned … Sep 30, 2026
CVE-2026-102120 HIGH 8.8 A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment … Sep 30, 2026