Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42739
Total
3465
Critical
12744
High
12574
Medium
CVE ID Severity Score Description Published
CVE-2026-73839 MEDIUM 4.6 Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the risk of credential compromise through visual or remote observation. This … Aug 28, 2026
CVE-2026-73809 HIGH 7.5 A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer … Aug 28, 2026
CVE-2026-73125 CRITICAL 9.8 Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, … Aug 28, 2026
CVE-2026-71396 MEDIUM 5.4 Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control. Aug 28, 2026
CVE-2026-71187 CRITICAL 9.8 The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass … Aug 28, 2026
CVE-2026-69658 CRITICAL 9.8 MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging … Aug 28, 2026
CVE-2026-68967 MEDIUM 6.5 Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that could establish an arbitrary write … Aug 28, 2026
CVE-2026-68929 UNKNOWN FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, the WeChat (iLink) share-channel endpoints authorize … Aug 28, 2026
CVE-2026-67560 HIGH 7.5 Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then … Aug 28, 2026
CVE-2026-61783 UNKNOWN Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, an authenticated low-privilege … Aug 28, 2026
CVE-2026-5706 UNKNOWN In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must … Aug 28, 2026
CVE-2026-54330 HIGH 8.1 Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) … Aug 28, 2026
CVE-2026-54085 HIGH 7.1 Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.2.0 through 4.14.6, multiple active response … Aug 28, 2026
CVE-2026-54084 MEDIUM 5.3 Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.0.0 through 4.14.6, a malicious or … Aug 28, 2026
CVE-2026-54083 HIGH 8.1 Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. The ip-customblock active response script contains a path … Aug 28, 2026
CVE-2026-50152 CRITICAL 9.1 Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails … Aug 28, 2026
CVE-2026-44629 HIGH 7.9 Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows … Aug 28, 2026
CVE-2026-39944 HIGH 8.8 Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the RADOS Gateway (RGW) protects … Aug 28, 2026
CVE-2026-38350 HIGH 7.5 An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. Aug 28, 2026
CVE-2026-38349 HIGH 7.5 An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image … Aug 28, 2026
CVE-2026-38348 HIGH 7.5 An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file. Aug 28, 2026
CVE-2026-38347 UNKNOWN A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted … Aug 28, 2026
CVE-2026-38346 HIGH 7.5 An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video … Aug 28, 2026
CVE-2026-38345 UNKNOWN A Division-by-Zero vulnerability in the ff_sws_init_single_context function (/libswscale/utils.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via a crafted input. Aug 28, 2026
CVE-2026-38344 UNKNOWN A NULL pointer dereference in the get_min_buffer_size function (/libswscale/slice.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted … Aug 28, 2026