Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26391
Total
1955
Critical
7971
High
8223
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-10640 | MEDIUM | 4.2 | Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ipv6_send_ns, net_ipv6_send_rs in subsys/net/ip/ipv6_nbr.c) updated the per-interface ICMP-sent statistics by calling net_pkt_iface(pkt) after net_send_data(pkt) had already returned successfully. … | Jun 16, 2026 |
| CVE-2026-10639 | MEDIUM | 4.8 | In Zephyr's native IPv4 stack, icmpv4_handle_echo_request() in subsys/net/ip/icmpv4.c builds an echo-reply packet (reply), hands it to net_try_send_data(), and then, on success, calls net_stats_update_icmp_sent(net_pkt_iface(reply)). net_try_send_data() transfers … | Jun 16, 2026 |
| CVE-2026-10638 | MEDIUM | 5.9 | subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after that packet has been handed to net_try_send_data(). In icmpv6_handle_echo_request() and net_icmpv6_send_error(), the post-send statistics update calls … | Jun 16, 2026 |
| CVE-2026-10637 | MEDIUM | 5.9 | subsys/net/ip/ipv6_mld.c:mld_send() read the packet interface via net_pkt_iface(pkt) after net_send_data(pkt) returned successfully. Per the network stack's ownership contract (include/zephyr/net/net_core.h, and the explicit warning in subsys/net/ip/net_core.c:453-460 'do … | Jun 16, 2026 |
| CVE-2026-10636 | LOW | 3.7 | In Zephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp.c read the network interface back out of the packet via net_pkt_iface(pkt) after the packet had been handed … | Jun 16, 2026 |
| CVE-2026-0647 | UNKNOWN | — | An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface … | Jun 16, 2026 |
| CVE-2026-0646 | UNKNOWN | — | A denial-of-service security issue exists within the 1794-AENTR adapter due to improper memory handling of CIP protocol requests. This vulnerability can result in the adapter … | Jun 16, 2026 |
| CVE-2025-14272 | UNKNOWN | — | A security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerability can allow an unauthorized actor to execute privileged … | Jun 16, 2026 |
| CVE-2025-13036 | UNKNOWN | — | An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid … | Jun 16, 2026 |
| CVE-2025-11694 | UNKNOWN | — | A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This … | Jun 16, 2026 |
| CVE-2024-22447 | MEDIUM | 6.7 | Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious dll., … | Jun 16, 2026 |
| CVE-2026-9507 | UNKNOWN | — | A session fixation vulnerability has been identified in osTicket v1.18.2. This security flaw allows an attacker to hijack a victim’s account by keeping the initial … | Jun 16, 2026 |
| CVE-2026-53900 | MEDIUM | 4.3 | Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies … | Jun 16, 2026 |
| CVE-2026-53899 | MEDIUM | 6.5 | Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suffix domain to receive cookies belonging … | Jun 16, 2026 |
| CVE-2026-12330 | MEDIUM | 5.4 | Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 140.12. | Jun 16, 2026 |
| CVE-2026-12329 | MEDIUM | 5.3 | Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12. | Jun 16, 2026 |
| CVE-2026-12328 | HIGH | 8.1 | Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence … | Jun 16, 2026 |
| CVE-2026-12327 | HIGH | 7.3 | Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption … | Jun 16, 2026 |
| CVE-2026-12326 | HIGH | 7.3 | Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough … | Jun 16, 2026 |
| CVE-2026-12325 | MEDIUM | 6.5 | Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | Jun 16, 2026 |
| CVE-2026-12324 | HIGH | 7.3 | Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | Jun 16, 2026 |
| CVE-2026-12323 | MEDIUM | 5.4 | Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | Jun 16, 2026 |
| CVE-2026-12322 | MEDIUM | 5.4 | Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | Jun 16, 2026 |
| CVE-2026-12321 | MEDIUM | 5.4 | JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | Jun 16, 2026 |
| CVE-2026-12320 | MEDIUM | 4.3 | Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | Jun 16, 2026 |