Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50089
Total
4047
Critical
14897
High
14637
Medium
CVE ID Severity Score Description Published
CVE-2026-18686 CRITICAL 9.8 A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web … Aug 04, 2026
CVE-2026-18685 CRITICAL 9.8 A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. … Aug 04, 2026
CVE-2026-11836 UNKNOWN Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to the integrator's debug … Aug 04, 2026
CVE-2026-11835 UNKNOWN Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mode allows a compromised local attacker to silently bypass … Aug 04, 2026
CVE-2026-67978 HIGH 7.5 An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN … Aug 03, 2026
CVE-2026-67673 UNKNOWN A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is triggered when processing the edl fw_flash command, where … Aug 03, 2026
CVE-2026-48399 HIGH 7.5 Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could … Aug 03, 2026
CVE-2026-48333 CRITICAL 9.8 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain … Aug 03, 2026
CVE-2026-48331 CRITICAL 10.0 Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not … Aug 03, 2026
CVE-2026-48330 CRITICAL 10.0 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in … Aug 03, 2026
CVE-2026-48326 CRITICAL 9.9 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in … Aug 03, 2026
CVE-2026-48323 CRITICAL 10.0 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code … Aug 03, 2026
CVE-2026-48317 CRITICAL 9.6 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code … Aug 03, 2026
CVE-2026-18684 CRITICAL 9.8 A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. … Aug 03, 2026
CVE-2026-18667 CRITICAL 9.6 A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to … Aug 03, 2026
CVE-2026-69249 UNKNOWN python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invalid certificate chains that include duplicate … Aug 03, 2026
CVE-2026-69248 UNKNOWN cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS … Aug 03, 2026
CVE-2026-69247 UNKNOWN cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome … Aug 03, 2026
CVE-2026-67977 UNKNOWN An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input. Aug 03, 2026
CVE-2026-67975 UNKNOWN Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands. Aug 03, 2026
CVE-2026-67974 UNKNOWN A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial … Aug 03, 2026
CVE-2026-67973 UNKNOWN An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs. Aug 03, 2026
CVE-2026-67970 UNKNOWN Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal. Aug 03, 2026
CVE-2026-67969 UNKNOWN An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry. Aug 03, 2026
CVE-2026-67617 MEDIUM 4.8 Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting … Aug 03, 2026