Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42275
Total
3446
Critical
12492
High
12441
Medium
CVE ID Severity Score Description Published
CVE-2026-81849 HIGH 8.8 Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand … Aug 28, 2026
CVE-2026-77939 MEDIUM 6.5 Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing … Aug 28, 2026
CVE-2026-77586 HIGH 8.0 In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text … Aug 28, 2026
CVE-2026-77218 MEDIUM 4.9 PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi. The web_login_first_post handler copies the usrPass POST parameter into a fixed-size stack … Aug 28, 2026
CVE-2026-77217 MEDIUM 4.9 PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow and null pointer dereference vulnerabilities in /cgi-bin/dispatcher.cgi. The web_radiusSrv*_post family of handlers copies the radKey, … Aug 28, 2026
CVE-2026-77184 MEDIUM 5.2 In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the comment text of the DDL returned by … Aug 28, 2026
CVE-2026-76798 MEDIUM 6.3 The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its generated HTML report without encoding them … Aug 28, 2026
CVE-2026-76797 MEDIUM 6.3 The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas. … Aug 28, 2026
CVE-2026-76794 MEDIUM 4.6 MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML. A MongoDB user with write access can introduce crafted … Aug 28, 2026
CVE-2026-75486 HIGH 8.0 Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands … Aug 28, 2026
CVE-2026-75126 MEDIUM 4.9 PLANET GS-4210-16P2S firmware before 3.441b260626 contains multiple authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi. The following handlers copy attacker-controlled POST parameters into fixed-size stack buffers … Aug 28, 2026
CVE-2026-75125 MEDIUM 4.9 PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /cgi-bin/dispatcher.cgi. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its presence. … Aug 28, 2026
CVE-2026-75124 HIGH 7.5 PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query … Aug 28, 2026
CVE-2026-75123 HIGH 7.2 PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_smtp_test_post handler incorporates a caller-supplied SMTP server value directly into … Aug 28, 2026
CVE-2026-75122 HIGH 7.2 PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/httpuploadcert.cgi. The certificate password field in a certificate upload request is incorporated … Aug 28, 2026
CVE-2026-75121 HIGH 7.2 PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter into a shell … Aug 28, 2026
CVE-2026-72984 HIGH 8.8 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Aug 28, 2026
CVE-2026-70331 MEDIUM 5.4 Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. Aug 28, 2026
CVE-2026-70309 MEDIUM 5.4 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. Aug 28, 2026
CVE-2026-66798 MEDIUM 4.3 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Aug 28, 2026
CVE-2026-66324 MEDIUM 6.5 External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Aug 28, 2026
CVE-2026-66323 MEDIUM 5.4 Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Aug 28, 2026
CVE-2026-62904 MEDIUM 5.4 Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. Aug 28, 2026
CVE-2026-58616 MEDIUM 4.4 Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network. Aug 28, 2026
CVE-2026-56100 HIGH 8.1 SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by … Aug 28, 2026