Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42275
Total
3446
Critical
12492
High
12441
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81849 | HIGH | 8.8 | Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand … | Aug 28, 2026 |
| CVE-2026-77939 | MEDIUM | 6.5 | Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing … | Aug 28, 2026 |
| CVE-2026-77586 | HIGH | 8.0 | In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text … | Aug 28, 2026 |
| CVE-2026-77218 | MEDIUM | 4.9 | PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi. The web_login_first_post handler copies the usrPass POST parameter into a fixed-size stack … | Aug 28, 2026 |
| CVE-2026-77217 | MEDIUM | 4.9 | PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow and null pointer dereference vulnerabilities in /cgi-bin/dispatcher.cgi. The web_radiusSrv*_post family of handlers copies the radKey, … | Aug 28, 2026 |
| CVE-2026-77184 | MEDIUM | 5.2 | In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the comment text of the DDL returned by … | Aug 28, 2026 |
| CVE-2026-76798 | MEDIUM | 6.3 | The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its generated HTML report without encoding them … | Aug 28, 2026 |
| CVE-2026-76797 | MEDIUM | 6.3 | The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas. … | Aug 28, 2026 |
| CVE-2026-76794 | MEDIUM | 4.6 | MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML. A MongoDB user with write access can introduce crafted … | Aug 28, 2026 |
| CVE-2026-75486 | HIGH | 8.0 | Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands … | Aug 28, 2026 |
| CVE-2026-75126 | MEDIUM | 4.9 | PLANET GS-4210-16P2S firmware before 3.441b260626 contains multiple authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi. The following handlers copy attacker-controlled POST parameters into fixed-size stack buffers … | Aug 28, 2026 |
| CVE-2026-75125 | MEDIUM | 4.9 | PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /cgi-bin/dispatcher.cgi. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its presence. … | Aug 28, 2026 |
| CVE-2026-75124 | HIGH | 7.5 | PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query … | Aug 28, 2026 |
| CVE-2026-75123 | HIGH | 7.2 | PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_smtp_test_post handler incorporates a caller-supplied SMTP server value directly into … | Aug 28, 2026 |
| CVE-2026-75122 | HIGH | 7.2 | PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/httpuploadcert.cgi. The certificate password field in a certificate upload request is incorporated … | Aug 28, 2026 |
| CVE-2026-75121 | HIGH | 7.2 | PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter into a shell … | Aug 28, 2026 |
| CVE-2026-72984 | HIGH | 8.8 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | Aug 28, 2026 |
| CVE-2026-70331 | MEDIUM | 5.4 | Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. | Aug 28, 2026 |
| CVE-2026-70309 | MEDIUM | 5.4 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | Aug 28, 2026 |
| CVE-2026-66798 | MEDIUM | 4.3 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | Aug 28, 2026 |
| CVE-2026-66324 | MEDIUM | 6.5 | External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | Aug 28, 2026 |
| CVE-2026-66323 | MEDIUM | 5.4 | Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | Aug 28, 2026 |
| CVE-2026-62904 | MEDIUM | 5.4 | Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | Aug 28, 2026 |
| CVE-2026-58616 | MEDIUM | 4.4 | Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network. | Aug 28, 2026 |
| CVE-2026-56100 | HIGH | 8.1 | SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by … | Aug 28, 2026 |