Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45339
Total
3649
Critical
13458
High
13386
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-65985 | UNKNOWN | — | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the device-webapi-request Socket.IO handler in server/runtime/index.js permits an authenticated non-admin runtime user to … | Aug 18, 2026 |
| CVE-2026-65984 | UNKNOWN | — | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST /api/refresh in server/api/auth/index.js falls back from current user data to decoded.groups, including … | Aug 18, 2026 |
| CVE-2026-59915 | HIGH | 7.3 | Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit … | Aug 18, 2026 |
| CVE-2026-57826 | UNKNOWN | — | An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certificate chain verification, the basic constraints extension and CA flag processing of intermediate … | Aug 18, 2026 |
| CVE-2026-52829 | HIGH | 7.5 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra node using the … | Aug 18, 2026 |
| CVE-2026-52739 | MEDIUM | 5.9 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can terminate zebrad by placing the same shielded transaction … | Aug 18, 2026 |
| CVE-2026-52738 | UNKNOWN | — | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a consensus-valid block containing a long chain of transparent self-spends to one address … | Aug 18, 2026 |
| CVE-2026-52737 | MEDIUM | 5.3 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious unauthenticated P2P peer can answer Zebra's outbound getblocks or FindBlocks request … | Aug 18, 2026 |
| CVE-2026-52736 | UNKNOWN | — | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node by racing an … | Aug 18, 2026 |
| CVE-2026-52735 | UNKNOWN | — | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects because the P2SH signature-operation counter … | Aug 18, 2026 |
| CVE-2026-52734 | MEDIUM | 5.3 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can cause the mempool download pipeline to retain transactions … | Aug 18, 2026 |
| CVE-2026-52733 | MEDIUM | 6.5 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave stale Sapling and Orchard note-commitment … | Aug 18, 2026 |
| CVE-2026-52732 | MEDIUM | 5.3 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can monopolize all 25 MAX_INBOUND_CONCURRENCY slots in Zebra's inbound … | Aug 18, 2026 |
| CVE-2026-52731 | MEDIUM | 6.5 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoint can terminate zebrad by … | Aug 18, 2026 |
| CVE-2026-52481 | HIGH | 7.5 | An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the tcp_actions() function | Aug 18, 2026 |
| CVE-2026-52480 | UNKNOWN | — | An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service | Aug 18, 2026 |
| CVE-2026-49500 | MEDIUM | 6.0 | Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with … | Aug 18, 2026 |
| CVE-2026-47721 | MEDIUM | 6.3 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api/scheduler/index.js do not consistently enforce authJwt.haveAdminPermission for scheduler … | Aug 18, 2026 |
| CVE-2026-47720 | MEDIUM | 5.3 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runtime/storage/tdengine/index.js doubles single quotes but does … | Aug 18, 2026 |
| CVE-2026-47719 | HIGH | 8.2 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO handlers in server/runtime/index.js omit isSocketWriteAuthorized and accept attacker-controlled property.address … | Aug 18, 2026 |
| CVE-2026-19671 | MEDIUM | 6.5 | Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied when the … | Aug 18, 2026 |
| CVE-2026-19670 | MEDIUM | 5.4 | Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upload … | Aug 18, 2026 |
| CVE-2026-12520 | MEDIUM | 6.4 | The Sierra Wireless HL7800 cellular modem driver (drivers/modem/vendor_standalone/hl7800.c, located at drivers/modem/hl7800.c in v4.4.0 and earlier) parses AT responses with roughly twenty handlers that call net_buf_linearize(value, … | Aug 18, 2026 |
| CVE-2026-70667 | MEDIUM | 6.3 | Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificates/verify.py checked the original CRL or OCSP URL but the later request could reach a … | Aug 18, 2026 |
| CVE-2026-65959 | MEDIUM | 5.3 | Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoint() in go/vt/vttablet/tabletmanager/vreplication/vrlog.go invokes vrlogStatsHandler() … | Aug 18, 2026 |