Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51713
Total
4098
Critical
15342
High
14990
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-46876 | CRITICAL | 9.8 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle … | Jul 21, 2026 |
| CVE-2026-43947 | UNKNOWN | — | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Code Execution vulnerability when `secureEnabled` is set to `true`. The `POST … | Jul 21, 2026 |
| CVE-2026-43946 | UNKNOWN | — | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when … | Jul 21, 2026 |
| CVE-2026-43945 | UNKNOWN | — | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as … | Jul 21, 2026 |
| CVE-2026-35290 | CRITICAL | 9.8 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP … | Jul 21, 2026 |
| CVE-2026-35287 | HIGH | 7.5 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP … | Jul 21, 2026 |
| CVE-2026-34316 | MEDIUM | 6.1 | Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). The supported version that is affected is 11.4.0. Easily exploitable … | Jul 21, 2026 |
| CVE-2026-21954 | MEDIUM | 4.3 | Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. … | Jul 21, 2026 |
| CVE-2026-21953 | LOW | 3.3 | Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. … | Jul 21, 2026 |
| CVE-2026-16484 | HIGH | 7.3 | A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_subjecta.php. … | Jul 21, 2026 |
| CVE-2026-10680 | HIGH | 7.6 | The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/bluetooth/host/classic/l2cap_br.c validated the minimum command size against buf->len (the bytes remaining in the whole received … | Jul 21, 2026 |
| CVE-2026-10679 | LOW | 3.3 | The DesignWare SPI driver (drivers/spi/spi_dw.c) computed the SPI BAUDR clock divider as info->clock_frequency / config->frequency without validating config->frequency. spi_transceive is a Zephyr __syscall and its … | Jul 21, 2026 |
| CVE-2026-10678 | HIGH | 8.1 | The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writes from an I2C bus master byte-by-byte in mctp_i2c_gpio_target_write_received() without validating the order or the receive … | Jul 21, 2026 |
| CVE-2026-10677 | MEDIUM | 6.5 | The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy of the user-supplied k_poll_event[] via z_thread_malloc() and then validates each event's object handle. Before … | Jul 21, 2026 |
| CVE-2026-10675 | MEDIUM | 4.3 | In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() rescheduled the provisioning protocol watchdog timer unconditionally at the top of the function, before the FCS … | Jul 21, 2026 |
| CVE-2026-10674 | MEDIUM | 5.5 | The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UART_USE_RUNTIME_CONFIGURE is enabled, called LPUART_Deinit() at the start of mcux_lpuart_configure(), which disables the LPUART peripheral clocks. The requested … | Jul 21, 2026 |
| CVE-2026-8983 | UNKNOWN | — | Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the … | Jul 21, 2026 |
| CVE-2026-8982 | UNKNOWN | — | Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing … | Jul 21, 2026 |
| CVE-2026-65058 | MEDIUM | 5.3 | Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow. For contract interactions, the device … | Jul 21, 2026 |
| CVE-2026-65057 | CRITICAL | 9.3 | Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supplying attacker-controlled host … | Jul 21, 2026 |
| CVE-2026-65056 | HIGH | 8.2 | mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to … | Jul 21, 2026 |
| CVE-2026-65055 | MEDIUM | 5.3 | Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal workflow configuration of any private project … | Jul 21, 2026 |
| CVE-2026-65054 | LOW | 3.1 | MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to expose private media metadata belonging to other users by adding arbitrary media tokens … | Jul 21, 2026 |
| CVE-2026-64881 | HIGH | 8.8 | The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection … | Jul 21, 2026 |
| CVE-2026-64822 | MEDIUM | 5.3 | djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPasswordView within djangosige/apps/login/views.py that allows unauthenticated attackers to identify valid accounts by observing distinct … | Jul 21, 2026 |