Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42239
Total
3441
Critical
12474
High
12431
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-14368 | MEDIUM | 5.4 | The LwM2M JSON content formatter's get_string() in subsys/net/lib/lwm2m/lwm2m_rw_json.c copies a parsed JSON string into a caller-supplied buffer and NUL-terminates it. The length guard used if … | Aug 31, 2026 |
| CVE-2026-14367 | LOW | 3.1 | The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out statically-allocated work nodes through a free-list i3c_ibi_work_nodes_free implemented as a plain sys_slist_t, which provides no synchronization. The … | Aug 31, 2026 |
| CVE-2023-31308 | LOW | 3.3 | A malicious virtual function can invoke the certain command handlers in the SMU, causing a denial of service due to out-of-bounds memory read. | Aug 31, 2026 |
| CVE-2023-20511 | MEDIUM | 6.4 | Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow a privileged attacker to create a double free condition potentially leading … | Aug 31, 2026 |
| CVE-2026-82817 | MEDIUM | 6.3 | A vulnerability was found in dibo-software diboot 3.8.0. Affected by this issue is some unknown functionality of the file /admin/ of the component Tenant Administrator … | Aug 31, 2026 |
| CVE-2026-82816 | MEDIUM | 6.3 | A vulnerability has been found in dibo-software diboot 3.8.0. Affected by this vulnerability is an unknown functionality of the file /api/ai-session/ of the component AI … | Aug 31, 2026 |
| CVE-2026-82815 | HIGH | 7.3 | A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file web/server.go of the component Middleware. This … | Aug 31, 2026 |
| CVE-2026-82813 | MEDIUM | 5.4 | A vulnerability was detected in BEN Group TubeBuddy for YouTube Extension up to 5.8.4 on Chrome. This impacts the function TBGlobal.GetToken of the file tubebuddymaster1.js. … | Aug 31, 2026 |
| CVE-2026-82811 | MEDIUM | 5.4 | A security vulnerability has been detected in Toggl OÜ Toggl Track Extension 4.11.16. This affects an unknown function of the component postMessage Handler. The manipulation … | Aug 31, 2026 |
| CVE-2026-79750 | HIGH | 7.7 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.30, … | Aug 31, 2026 |
| CVE-2026-79749 | UNKNOWN | — | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, … | Aug 31, 2026 |
| CVE-2026-79748 | CRITICAL | 9.9 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, … | Aug 31, 2026 |
| CVE-2026-79747 | HIGH | 7.1 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, … | Aug 31, 2026 |
| CVE-2026-79746 | HIGH | 8.1 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.31, … | Aug 31, 2026 |
| CVE-2026-79745 | HIGH | 7.1 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, … | Aug 31, 2026 |
| CVE-2026-79744 | HIGH | 8.8 | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.29, … | Aug 31, 2026 |
| CVE-2026-79743 | UNKNOWN | — | MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.13, … | Aug 31, 2026 |
| CVE-2026-51730 | CRITICAL | 9.1 | Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-51729 | CRITICAL | 9.1 | Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a … | Aug 31, 2026 |
| CVE-2026-51728 | UNKNOWN | — | Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to upload a crafted firmware image via sending a crafted POST … | Aug 31, 2026 |
| CVE-2026-51727 | MEDIUM | 5.3 | Incorrect access control in the SystemSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve administrative import and export endpoint information via sending a … | Aug 31, 2026 |
| CVE-2026-51726 | CRITICAL | 9.1 | Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending a crafted POST request to … | Aug 31, 2026 |
| CVE-2026-51725 | CRITICAL | 9.1 | Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request … | Aug 31, 2026 |
| CVE-2026-19953 | MEDIUM | 6.5 | URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep. nameprep lowercases each host label but … | Aug 31, 2026 |
| CVE-2026-82810 | LOW | 3.3 | A weakness has been identified in extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome. The impacted element is the function chrome.runtime.onMessageExternal.addListener of the component Background Service … | Aug 31, 2026 |