Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42739
Total
3465
Critical
12744
High
12574
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-73839 | MEDIUM | 4.6 | Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the risk of credential compromise through visual or remote observation. This … | Aug 28, 2026 |
| CVE-2026-73809 | HIGH | 7.5 | A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer … | Aug 28, 2026 |
| CVE-2026-73125 | CRITICAL | 9.8 | Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, … | Aug 28, 2026 |
| CVE-2026-71396 | MEDIUM | 5.4 | Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control. | Aug 28, 2026 |
| CVE-2026-71187 | CRITICAL | 9.8 | The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass … | Aug 28, 2026 |
| CVE-2026-69658 | CRITICAL | 9.8 | MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging … | Aug 28, 2026 |
| CVE-2026-68967 | MEDIUM | 6.5 | Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that could establish an arbitrary write … | Aug 28, 2026 |
| CVE-2026-68929 | UNKNOWN | — | FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, the WeChat (iLink) share-channel endpoints authorize … | Aug 28, 2026 |
| CVE-2026-67560 | HIGH | 7.5 | Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then … | Aug 28, 2026 |
| CVE-2026-61783 | UNKNOWN | — | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, an authenticated low-privilege … | Aug 28, 2026 |
| CVE-2026-5706 | UNKNOWN | — | In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must … | Aug 28, 2026 |
| CVE-2026-54330 | HIGH | 8.1 | Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) … | Aug 28, 2026 |
| CVE-2026-54085 | HIGH | 7.1 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.2.0 through 4.14.6, multiple active response … | Aug 28, 2026 |
| CVE-2026-54084 | MEDIUM | 5.3 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.0.0 through 4.14.6, a malicious or … | Aug 28, 2026 |
| CVE-2026-54083 | HIGH | 8.1 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. The ip-customblock active response script contains a path … | Aug 28, 2026 |
| CVE-2026-50152 | CRITICAL | 9.1 | Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails … | Aug 28, 2026 |
| CVE-2026-44629 | HIGH | 7.9 | Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows … | Aug 28, 2026 |
| CVE-2026-39944 | HIGH | 8.8 | Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the RADOS Gateway (RGW) protects … | Aug 28, 2026 |
| CVE-2026-38350 | HIGH | 7.5 | An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. | Aug 28, 2026 |
| CVE-2026-38349 | HIGH | 7.5 | An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image … | Aug 28, 2026 |
| CVE-2026-38348 | HIGH | 7.5 | An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file. | Aug 28, 2026 |
| CVE-2026-38347 | UNKNOWN | — | A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted … | Aug 28, 2026 |
| CVE-2026-38346 | HIGH | 7.5 | An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video … | Aug 28, 2026 |
| CVE-2026-38345 | UNKNOWN | — | A Division-by-Zero vulnerability in the ff_sws_init_single_context function (/libswscale/utils.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Aug 28, 2026 |
| CVE-2026-38344 | UNKNOWN | — | A NULL pointer dereference in the get_min_buffer_size function (/libswscale/slice.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted … | Aug 28, 2026 |