Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

52113
Total
4140
Critical
15446
High
15158
Medium
CVE ID Severity Score Description Published
CVE-2026-13585 UNKNOWN — Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS … Jul 15, 2026
CVE-2026-13385 UNKNOWN — An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router … Jul 15, 2026
CVE-2026-11851 UNKNOWN — Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote … Jul 15, 2026
CVE-2026-9770 UNKNOWN — Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices. An attacker … Jul 15, 2026
CVE-2026-13230 UNKNOWN — An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without … Jul 15, 2026
CVE-2026-5270 CRITICAL 9.8 An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue … Jul 14, 2026
CVE-2026-5269 CRITICAL 9.8 In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these … Jul 14, 2026
CVE-2026-51808 CRITICAL 9.8 Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, invoke_line_based, invoke_line_based_stream, and invoke_line_based_predecoded function in source/core/interface/decoder.cpp Jul 14, 2026
CVE-2026-51807 CRITICAL 9.8 Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the j2k_precinct_subband::parse_packet_header() in source/core/coding/coding_units.cpp Jul 14, 2026
CVE-2026-36035 MEDIUM 6.5 Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service … Jul 14, 2026
CVE-2026-15753 MEDIUM 5.4 A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown functionality of the file /api/v1/payment/withdraw/review?action=approve. Executing a manipulation can … Jul 14, 2026
CVE-2026-15752 HIGH 7.3 A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the file /api/v1/users/ of the component Backend User Endpoint. … Jul 14, 2026
CVE-2026-15751 MEDIUM 5.3 A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is the function execute of the file mastergo/component-workflow.md of the … Jul 14, 2026
CVE-2025-56365 HIGH 7.5 A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to … Jul 14, 2026
CVE-2025-56364 HIGH 7.5 A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestinationGroupId().Value()` method is called without first checking whether a … Jul 14, 2026
CVE-2025-56363 HIGH 7.5 A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used in multiple clusters (Channel, Account Login, TargetNavigator, … Jul 14, 2026
CVE-2025-56362 HIGH 7.5 A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Level Control cluster's periodic server tick logic. When a MoveToLevel … Jul 14, 2026
CVE-2026-55139 MEDIUM 5.5 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. Jul 14, 2026
CVE-2026-55138 MEDIUM 5.5 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Jul 14, 2026
CVE-2026-55137 HIGH 7.8 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Jul 14, 2026
CVE-2026-55136 HIGH 7.8 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Jul 14, 2026
CVE-2026-55135 MEDIUM 4.6 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Jul 14, 2026
CVE-2026-55134 HIGH 7.8 Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. Jul 14, 2026
CVE-2026-55133 HIGH 7.8 Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally. Jul 14, 2026
CVE-2026-55132 HIGH 7.8 Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Jul 14, 2026