CVE Feed

    Dashboard / CVE

    5.7
    Medium

    CVE-2026-11835

    Last Modified: 5 Aug 2026

    Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mode allows a compromised local attacker to silently bypass secure boot by supplying an AXI staging address that is not validated against the strap-configured SS_EXTERNAL_STAGING_AREA_BASE_ADDR, enabling firmware to be modified between verification and loading into ICCM. Attestation continues to report the originally verified image digest, masking the compromise. Exploitation requires a compromised MCU firmware with AXI manager access to unprotected SRAM reachable by Caliptra. This issue affects Core ROM: 2.1.0 through 2.1.1.

    Published: 4 Aug 2026
    1.8
    Low

    CVE-2026-11836

    Last Modified: 7 Aug 2026

    Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to the integrator's debug unlock signing service to unlock production debug on an unintended device by presenting a valid token issued for a different device sharing the same debug unlock key hash. The 384-bit challenge nonce continues to prevent replay of previously issued tokens. Practical impact is limited to loss of per-device scope enforcement within a set of devices that share the same unlock authority by design; it does not enable debug unlock on devices outside that set. This issue affects Core ROM: 2.0.0 through 2.0.2, 2.1.0 through 2.1.1; Core Firmware: 2.0.0 through 2.0.1, 2.1.0.

    Published: 4 Aug 2026
    8.9
    High

    CVE-2026-18686

    Last Modified: 4 Aug 2026

    A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

    Published: 4 Aug 2026
    7.7
    High

    CVE-2026-51401

    Last Modified: 4 Sept 2026

    An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c

    Published: 4 Aug 2026
    9.8
    Critical

    CVE-2026-64564

    Last Modified: 19 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds to the Address Parameter, which need not be the packet's source address. sctp_process_asconf_param() rejects a DEL-IP for the packet source address (ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport. A single ASCONF can therefore carry, in order: [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0] where L differs from the source. The DEL-IP for L passes the D8 check and calls sctp_assoc_rm_peer() on the transport that asconf->transport still points at, freeing it (RCU-deferred). The following wildcard DEL-IP then reuses the now-dangling asconf->transport in sctp_assoc_set_primary() and sctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed transport (->ipaddr, ->state) and plants the dangling pointer into asoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping only the pointer that is no longer on the list, removes every real transport, leaving the association with a transport_count of 0 and primary_path/active_path pointing at freed memory. Reject a DEL-IP that targets the transport the ASCONF is being processed against, mirroring the existing source-address guard, so the wildcard branch can never reuse a freed transport.

    Published: 4 Aug 2026
    8.8
    High

    CVE-2026-64561

    Last Modified: 27 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. If reclaiming shadow pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to map memory into an invalid root. On its own, populating an invalid root is "fine", but because child shadow pages inherit their parent's role, any children created during the map/fetch will be created as invalid pages, thus violating KVM's invariant that invalid pages are never on the list of active MMU pages. Note, the underlying flaw has existed since KVM first started tracking invalid roots in 2008 (commit 2e53d63acba7, "KVM: MMU: ignore zapped root pagetables"), but the true badness only came along in 2020 (Linux 5.9) with the invariant that invalid shadow pages can't be on the list of active pages. Note #2, inheriting role.invalid when creating child shadow pages is also far from ideal; that flaw will be addressed separately.

    Published: 4 Aug 2026
    8.4
    High

    CVE-2026-51400

    Last Modified: 4 Sept 2026

    An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c

    Published: 4 Aug 2026
    7.5
    High

    CVE-2026-67860

    Last Modified: 5 Aug 2026

    open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend.

    Published: 4 Aug 2026
    7.5
    High

    CVE-2026-67856

    Last Modified: 5 Aug 2026

    An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions requests

    Published: 4 Aug 2026
    7.5
    High

    CVE-2026-67862

    Last Modified: 5 Aug 2026

    open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attacker to cause a denial of service.

    Published: 4 Aug 2026
    8.1
    High

    CVE-2026-8400

    Last Modified: 6 Aug 2026

    IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.

    Published: 4 Aug 2026
    7.5
    High

    CVE-2026-67859

    Last Modified: 5 Aug 2026

    Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.

    Published: 4 Aug 2026
    7.5
    High

    CVE-2026-67857

    Last Modified: 5 Aug 2026

    open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.

    Published: 4 Aug 2026
    9.8
    Critical

    CVE-2025-29296

    Last Modified: 5 Aug 2026

    H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in the /api/esps request handler. The affected object interfaces and methods are esps.dhcpd.vlan (getlist, delete), esps.filter.url (add, modify), esps.apcm.version (delete, H3C Magic NX15 only), esps.swcm.version (delete, upgrade, all affected models except H3C Magic NX15), and esps.system.ntp (set, all affected models except H3C Magic NX15). Attacker-controlled request parameters are incorporated into shell expressions executed by eval without adequate validation, allowing a remote attacker to execute arbitrary commands as root and gain complete control of the affected device.

    Published: 4 Aug 2026
    9.1
    Critical

    CVE-2026-67979

    Last Modified: 5 Aug 2026

    Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.

    Published: 4 Aug 2026
    7.5
    High

    CVE-2026-67855

    Last Modified: 5 Aug 2026

    open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service.

    Published: 4 Aug 2026
    7.5
    High

    CVE-2026-67861

    Last Modified: 5 Aug 2026

    An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component

    Published: 4 Aug 2026
    7.5
    High

    CVE-2026-67858

    Last Modified: 5 Aug 2026

    Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request containing many unique discoveryUrls. This allows remote attackers to cause a denial of service.

    Published: 4 Aug 2026
    6.1
    Medium

    CVE-2026-52370

    Last Modified: 5 Aug 2026

    A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.

    Published: 4 Aug 2026
    6.1
    Medium

    CVE-2026-51144

    Last Modified: 5 Aug 2026

    Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via the Role Name, First Name, Last Name, and Username fields.

    Published: 4 Aug 2026
    8.9
    High

    CVE-2026-18685

    Last Modified: 4 Aug 2026

    A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

    Published: 3 Aug 2026
    8.8
    High

    CVE-2026-62870

    Last Modified: 5 Aug 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

    Published: 3 Aug 2026
    6.5
    Medium

    CVE-2026-66326

    Last Modified: 4 Aug 2026

    Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Aug 2026
    6.1
    Medium

    CVE-2026-66325

    Last Modified: 4 Aug 2026

    Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

    Published: 3 Aug 2026
    7.1
    High

    CVE-2026-66322

    Last Modified: 4 Aug 2026

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

    Published: 3 Aug 2026
    5.4
    Medium

    CVE-2026-66317

    Last Modified: 4 Aug 2026

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

    Published: 3 Aug 2026
    6.2
    Medium

    CVE-2026-66311

    Last Modified: 4 Aug 2026

    Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

    Published: 3 Aug 2026
    6.1
    Medium

    CVE-2026-65804

    Last Modified: 5 Aug 2026

    Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

    Published: 3 Aug 2026
    7.4
    High

    CVE-2026-65802

    Last Modified: 4 Aug 2026

    External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

    Published: 3 Aug 2026
    5.4
    Medium

    CVE-2026-66316

    Last Modified: 5 Aug 2026

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

    Published: 3 Aug 2026
    7.5
    High

    CVE-2026-66315

    Last Modified: 4 Aug 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Aug 2026
    6.5
    Medium

    CVE-2026-66314

    Last Modified: 5 Aug 2026

    Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

    Published: 3 Aug 2026
    6.8
    Medium

    CVE-2026-66313

    Last Modified: 4 Aug 2026

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

    Published: 3 Aug 2026
    6.5
    Medium

    CVE-2026-66312

    Last Modified: 5 Aug 2026

    Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

    Published: 3 Aug 2026
    7.7
    High

    CVE-2026-66310

    Last Modified: 5 Aug 2026

    External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

    Published: 3 Aug 2026
    7.4
    High

    CVE-2026-66321

    Last Modified: 4 Aug 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 3 Aug 2026
    8.1
    High

    CVE-2026-66318

    Last Modified: 4 Aug 2026

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

    Published: 3 Aug 2026
    8.9
    High

    CVE-2026-18684

    Last Modified: 4 Aug 2026

    A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

    Published: 3 Aug 2026
    10
    Critical

    CVE-2026-48323

    Last Modified: 5 Aug 2026

    Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 3 Aug 2026
    9.8
    Critical

    CVE-2026-48333

    Last Modified: 5 Aug 2026

    Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not require user interaction.

    Published: 3 Aug 2026
    9.6
    Critical

    CVE-2026-48317

    Last Modified: 5 Aug 2026

    Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 3 Aug 2026
    10
    Critical

    CVE-2026-48331

    Last Modified: 5 Aug 2026

    Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 3 Aug 2026
    10
    Critical

    CVE-2026-48330

    Last Modified: 5 Aug 2026

    Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the application. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 3 Aug 2026
    7.5
    High

    CVE-2026-48399

    Last Modified: 5 Aug 2026

    Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.

    Published: 3 Aug 2026
    9.9
    Critical

    CVE-2026-48326

    Last Modified: 5 Aug 2026

    Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 3 Aug 2026
    9.3
    Critical

    CVE-2026-18667

    Last Modified: 5 Aug 2026

    A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host.

    Published: 3 Aug 2026
    5.1
    Medium

    CVE-2026-46714

    Last Modified: 5 Aug 2026

    Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause the Misskey web client to slow down or crash when it applies a malformed theme. This issue has been fixed in version 2026.5.4.

    Published: 3 Aug 2026
    8.9
    High

    CVE-2026-47746

    Last Modified: 5 Aug 2026

    Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks during JSON-LD signature validation and the compaction process. Because the JSON-LD parsing context is not shared between signature verification and subsequent processing, the application may trust information that should not be trusted, resulting in a time-of-check to time-of-use (TOCTOU) flaw. This allows an attacker to have fraudulent activities accepted as valid, leading to a loss of integrity. This issue has been fixed in version 2026.5.4.

    Published: 3 Aug 2026
    4.8
    Medium

    CVE-2026-67617

    Last Modified: 14 Aug 2026

    Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names parameter of the GET /api/save_content_admin endpoint, bypassing three independent sanitization controls including XSS middleware that ignores GET requests, a strip_unsafe() function that only matches double-quoted onerror attributes, and a titlecase normalizer that passes HTML decimal entity-encoded payloads through unchanged. Attackers can store malicious scripts that execute without user interaction for every visitor to the public blog page and within the admin post editor, enabling session riding through same-origin fetch requests using the CSRF token embedded in the page.

    Published: 3 Aug 2026
    5.3
    Medium

    CVE-2026-67616

    Last Modified: 14 Aug 2026

    Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue.

    Published: 3 Aug 2026