Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50089
Total
4047
Critical
14897
High
14637
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-18686 | CRITICAL | 9.8 | A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web … | Aug 04, 2026 |
| CVE-2026-18685 | CRITICAL | 9.8 | A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. … | Aug 04, 2026 |
| CVE-2026-11836 | UNKNOWN | — | Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to the integrator's debug … | Aug 04, 2026 |
| CVE-2026-11835 | UNKNOWN | — | Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mode allows a compromised local attacker to silently bypass … | Aug 04, 2026 |
| CVE-2026-67978 | HIGH | 7.5 | An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN … | Aug 03, 2026 |
| CVE-2026-67673 | UNKNOWN | — | A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is triggered when processing the edl fw_flash command, where … | Aug 03, 2026 |
| CVE-2026-48399 | HIGH | 7.5 | Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could … | Aug 03, 2026 |
| CVE-2026-48333 | CRITICAL | 9.8 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain … | Aug 03, 2026 |
| CVE-2026-48331 | CRITICAL | 10.0 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not … | Aug 03, 2026 |
| CVE-2026-48330 | CRITICAL | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in … | Aug 03, 2026 |
| CVE-2026-48326 | CRITICAL | 9.9 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in … | Aug 03, 2026 |
| CVE-2026-48323 | CRITICAL | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code … | Aug 03, 2026 |
| CVE-2026-48317 | CRITICAL | 9.6 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code … | Aug 03, 2026 |
| CVE-2026-18684 | CRITICAL | 9.8 | A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. … | Aug 03, 2026 |
| CVE-2026-18667 | CRITICAL | 9.6 | A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to … | Aug 03, 2026 |
| CVE-2026-69249 | UNKNOWN | — | python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invalid certificate chains that include duplicate … | Aug 03, 2026 |
| CVE-2026-69248 | UNKNOWN | — | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS … | Aug 03, 2026 |
| CVE-2026-69247 | UNKNOWN | — | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome … | Aug 03, 2026 |
| CVE-2026-67977 | UNKNOWN | — | An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Aug 03, 2026 |
| CVE-2026-67975 | UNKNOWN | — | Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands. | Aug 03, 2026 |
| CVE-2026-67974 | UNKNOWN | — | A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial … | Aug 03, 2026 |
| CVE-2026-67973 | UNKNOWN | — | An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs. | Aug 03, 2026 |
| CVE-2026-67970 | UNKNOWN | — | Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal. | Aug 03, 2026 |
| CVE-2026-67969 | UNKNOWN | — | An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry. | Aug 03, 2026 |
| CVE-2026-67617 | MEDIUM | 4.8 | Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting … | Aug 03, 2026 |