Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52113
Total
4140
Critical
15446
High
15158
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-13585 | UNKNOWN | — | Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS … | Jul 15, 2026 |
| CVE-2026-13385 | UNKNOWN | — | An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router … | Jul 15, 2026 |
| CVE-2026-11851 | UNKNOWN | — | Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote … | Jul 15, 2026 |
| CVE-2026-9770 | UNKNOWN | — | Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices. An attacker … | Jul 15, 2026 |
| CVE-2026-13230 | UNKNOWN | — | An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without … | Jul 15, 2026 |
| CVE-2026-5270 | CRITICAL | 9.8 | An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue … | Jul 14, 2026 |
| CVE-2026-5269 | CRITICAL | 9.8 | In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these … | Jul 14, 2026 |
| CVE-2026-51808 | CRITICAL | 9.8 | Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, invoke_line_based, invoke_line_based_stream, and invoke_line_based_predecoded function in source/core/interface/decoder.cpp | Jul 14, 2026 |
| CVE-2026-51807 | CRITICAL | 9.8 | Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the j2k_precinct_subband::parse_packet_header() in source/core/coding/coding_units.cpp | Jul 14, 2026 |
| CVE-2026-36035 | MEDIUM | 6.5 | Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service … | Jul 14, 2026 |
| CVE-2026-15753 | MEDIUM | 5.4 | A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown functionality of the file /api/v1/payment/withdraw/review?action=approve. Executing a manipulation can … | Jul 14, 2026 |
| CVE-2026-15752 | HIGH | 7.3 | A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the file /api/v1/users/ of the component Backend User Endpoint. … | Jul 14, 2026 |
| CVE-2026-15751 | MEDIUM | 5.3 | A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is the function execute of the file mastergo/component-workflow.md of the … | Jul 14, 2026 |
| CVE-2025-56365 | HIGH | 7.5 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to … | Jul 14, 2026 |
| CVE-2025-56364 | HIGH | 7.5 | A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestinationGroupId().Value()` method is called without first checking whether a … | Jul 14, 2026 |
| CVE-2025-56363 | HIGH | 7.5 | A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used in multiple clusters (Channel, Account Login, TargetNavigator, … | Jul 14, 2026 |
| CVE-2025-56362 | HIGH | 7.5 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Level Control cluster's periodic server tick logic. When a MoveToLevel … | Jul 14, 2026 |
| CVE-2026-55139 | MEDIUM | 5.5 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | Jul 14, 2026 |
| CVE-2026-55138 | MEDIUM | 5.5 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | Jul 14, 2026 |
| CVE-2026-55137 | HIGH | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Jul 14, 2026 |
| CVE-2026-55136 | HIGH | 7.8 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Jul 14, 2026 |
| CVE-2026-55135 | MEDIUM | 4.6 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | Jul 14, 2026 |
| CVE-2026-55134 | HIGH | 7.8 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | Jul 14, 2026 |
| CVE-2026-55133 | HIGH | 7.8 | Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally. | Jul 14, 2026 |
| CVE-2026-55132 | HIGH | 7.8 | Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | Jul 14, 2026 |