Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41940
Total
3420
Critical
12400
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-85441 | HIGH | 7.5 | MOOS core-moos through 10.4.0 fails to validate that serialized string lengths are non-negative in CMOOSMsg::operator>>. Unauthenticated attackers can send a crafted message with a negative … | Sep 03, 2026 |
| CVE-2026-85440 | CRITICAL | 9.8 | MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that allows remote attackers to write arbitrary data by declaring a … | Sep 03, 2026 |
| CVE-2026-85439 | HIGH | 7.8 | MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() function that fails to sanitize shell metacharacters in log file pathnames. Attackers can … | Sep 03, 2026 |
| CVE-2026-85438 | CRITICAL | 9.8 | MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used as allocation sizes … | Sep 03, 2026 |
| CVE-2026-85437 | CRITICAL | 9.8 | MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled length fields without validation. Attackers can craft malicious encoded … | Sep 03, 2026 |
| CVE-2026-85436 | HIGH | 7.5 | MOOS essential-moos through 10.0.1 contains a buffer overflow vulnerability in CMOOSUDPLink::ReadPktFromArray() that allows remote attackers to corrupt heap memory by sending UDP datagrams with negative … | Sep 03, 2026 |
| CVE-2026-85435 | CRITICAL | 9.1 | MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers … | Sep 03, 2026 |
| CVE-2026-85434 | CRITICAL | 9.1 | MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to … | Sep 03, 2026 |
| CVE-2026-85433 | CRITICAL | 9.8 | MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send … | Sep 03, 2026 |
| CVE-2026-85432 | HIGH | 8.2 | MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by supplying arbitrary … | Sep 03, 2026 |
| CVE-2026-85431 | HIGH | 7.5 | MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerability in pMOOSBridge when configured with UDPListen. Attackers can send crafted UDP packets to … | Sep 03, 2026 |
| CVE-2026-85430 | CRITICAL | 9.1 | MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity … | Sep 03, 2026 |
| CVE-2026-85429 | HIGH | 7.5 | MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE … | Sep 03, 2026 |
| CVE-2026-85428 | CRITICAL | 9.8 | MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send … | Sep 03, 2026 |
| CVE-2026-85427 | HIGH | 8.1 | MOOS essential-moos pAntler through 10.0.1 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary programs by publishing a crafted MISSION_FILE message … | Sep 03, 2026 |
| CVE-2026-85426 | CRITICAL | 9.8 | MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into client names to execute arbitrary … | Sep 03, 2026 |
| CVE-2026-85425 | CRITICAL | 9.8 | MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. Attackers can … | Sep 03, 2026 |
| CVE-2026-85424 | CRITICAL | 9.8 | MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can … | Sep 03, 2026 |
| CVE-2026-85378 | HIGH | 7.3 | A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function AuthController::_initialize of the file App/Admin/Controller/ChapterController.class.php of the component Chapter Controller. … | Sep 03, 2026 |
| CVE-2026-85241 | MEDIUM | 6.3 | A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the component … | Sep 03, 2026 |
| CVE-2026-85225 | HIGH | 7.3 | A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email … | Sep 03, 2026 |
| CVE-2026-83711 | CRITICAL | 10.0 | Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | Sep 03, 2026 |
| CVE-2026-80098 | CRITICAL | 9.3 | Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network. | Sep 03, 2026 |
| CVE-2026-70352 | CRITICAL | 10.0 | Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network. | Sep 03, 2026 |
| CVE-2026-70178 | HIGH | 8.5 | Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | Sep 03, 2026 |