Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45339
Total
3649
Critical
13458
High
13386
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-12632 | MEDIUM | 6.5 | Zephyr's Precision Time Protocol receive handler ptp_msg_post_recv() in subsys/net/lib/ptp/msg.c takes the 4-bit message type straight off the wire via ptp_msg_type() (msg->header.type_major_sdo_id & 0xF, range 0-15) … | Aug 18, 2026 |
| CVE-2026-12631 | MEDIUM | 6.5 | The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscall in include/zephyr/kernel.h) through thread_obj_validate() in kernel/thread.c. Its default switch branch is the access-denied … | Aug 18, 2026 |
| CVE-2026-76032 | MEDIUM | 4.3 | Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/link/{Uuid} in idm/share/rest/handler.go reads the workspace UUID from … | Aug 18, 2026 |
| CVE-2026-75936 | HIGH | 7.5 | Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of … | Aug 18, 2026 |
| CVE-2026-75935 | HIGH | 7.5 | Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via … | Aug 18, 2026 |
| CVE-2026-75877 | CRITICAL | 9.9 | A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChanged/SystemFTPChanged/websCheckRealm/FUN_00432574/FUN_0043372C of the component alphapd. Executing a manipulation can lead to … | Aug 18, 2026 |
| CVE-2026-75876 | MEDIUM | 6.3 | A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is some unknown functionality of the file ModuleController.java of … | Aug 18, 2026 |
| CVE-2026-73529 | MEDIUM | 5.3 | Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthenticated attackers to send unbounded login requests to the POST … | Aug 18, 2026 |
| CVE-2026-73112 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 18, 2026 |
| CVE-2026-73111 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 18, 2026 |
| CVE-2026-73106 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 18, 2026 |
| CVE-2026-73105 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 18, 2026 |
| CVE-2026-73104 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 18, 2026 |
| CVE-2026-73103 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 18, 2026 |
| CVE-2026-71676 | HIGH | 7.5 | Buffer Overflow vulnerability in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the NAS 5GS decoder chain, triggered when the … | Aug 18, 2026 |
| CVE-2026-71675 | HIGH | 7.5 | An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the ngap_send_to_nas() function in src/amf/ngap-path.c | Aug 18, 2026 |
| CVE-2026-71417 | HIGH | 7.3 | Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to create a duplicate row using another certificate body, authority_id, serial, … | Aug 18, 2026 |
| CVE-2026-71322 | MEDIUM | 4.3 | Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePermission ownership check inside the plugin.requires_key branch for POST /api/1/certificates//export. A plugin declaring requires_key … | Aug 18, 2026 |
| CVE-2026-71317 | MEDIUM | 6.5 | Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require AuthorityPermission on the parent authority when ADMIN_ONLY_AUTHORITY_CREATION was false. AssociatedAuthoritySchema … | Aug 18, 2026 |
| CVE-2026-71308 | HIGH | 8.1 | Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements identifiers that AssociatedCertificateSchema resolved with fetch_objects … | Aug 18, 2026 |
| CVE-2026-71307 | HIGH | 7.7 | Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only on authentication while sibling write handlers required admin_permission. DestinationOutputSchema returned … | Aug 18, 2026 |
| CVE-2026-71303 | HIGH | 7.7 | Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_HOST_ALLOWLIST when an authority was created, but PUT /api/1/authorities/ passed options to lemur/authorities/service.py without applying … | Aug 18, 2026 |
| CVE-2026-70666 | HIGH | 7.4 | Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT /api/1/authorities/ without revalidation and direct setup_acme_client_no_retry to an attacker-controlled … | Aug 18, 2026 |
| CVE-2026-67443 | UNKNOWN | — | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integrations/node-red/index.js calls authJwt.verify for /nodered without inspecting the … | Aug 18, 2026 |
| CVE-2026-67440 | UNKNOWN | — | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVICE_NODE_ATTRIBUTE, HOST_INTERFACES, and DEVICE_TAGS_REQUEST handlers in server/runtime/index.js return device-discovery, node-attribute, host-network-interface, … | Aug 18, 2026 |