Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54243
Total
4300
Critical
16125
High
15819
Medium
CVE ID Severity Score Description Published
CVE-2026-102119 HIGH 7.2 A path traversal weakness in an optional, non-default administrative feature allowed an authenticated administrator to move files to unintended locations outside the feature's designated directory. … Sep 30, 2026
CVE-2026-102118 HIGH 7.8 A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root … Sep 30, 2026
CVE-2026-102117 HIGH 7.2 On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect … Sep 30, 2026
CVE-2026-102116 HIGH 7.2 -A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to … Sep 30, 2026
CVE-2026-102115 CRITICAL 9.8 Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user … Sep 30, 2026
CVE-2026-102114 HIGH 7.2 A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful … Sep 30, 2026
CVE-2026-102113 HIGH 7.8 A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance … Sep 30, 2026
CVE-2026-102112 HIGH 7.8 A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance … Sep 30, 2026
CVE-2026-102111 MEDIUM 4.9 Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside its intended range so … Sep 30, 2026
CVE-2026-102110 MEDIUM 5.9 An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation … Sep 30, 2026
CVE-2026-102109 HIGH 7.1 A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a … Sep 30, 2026
CVE-2026-102108 HIGH 7.2 An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, … Sep 30, 2026
CVE-2026-102107 MEDIUM 4.6 Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from … Sep 30, 2026
CVE-2026-102106 CRITICAL 9.1 Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so … Sep 30, 2026
CVE-2026-102105 CRITICAL 9.1 Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway … Sep 30, 2026
CVE-2026-102104 CRITICAL 9.1 Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway … Sep 30, 2026
CVE-2026-102103 CRITICAL 9.1 Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway … Sep 30, 2026
CVE-2026-102102 CRITICAL 9.1 Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway … Sep 30, 2026
CVE-2026-102101 HIGH 8.1 Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data … Sep 30, 2026
CVE-2026-102100 HIGH 8.7 Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user … Sep 30, 2026
CVE-2026-102099 HIGH 7.2 Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature … Sep 30, 2026
CVE-2026-102098 HIGH 7.2 Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated … Sep 30, 2026
CVE-2026-102097 HIGH 7.2 Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose … Sep 30, 2026
CVE-2026-102096 HIGH 7.2 Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not … Sep 30, 2026
CVE-2026-102095 CRITICAL 9.1 Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the … Sep 30, 2026