Sort by:
    8.7
    High

    CVE-2026-88260

    Last Modified: 11 Sept 2026

    Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM (Build 109).

    Published:11 Sept 2026
    3.5
    Low

    CVE-2026-89151

    Last Modified: 11 Sept 2026

    Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.

    Published:11 Sept 2026
    5.6
    Medium

    CVE-2026-78135

    Last Modified: 11 Sept 2026

    libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.

    Published:11 Sept 2026
    7.1
    High

    CVE-2026-78134

    Last Modified: 11 Sept 2026

    strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

    Published:11 Sept 2026
    7.5
    High

    CVE-2026-78133

    Last Modified: 11 Sept 2026

    libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.

    Published:11 Sept 2026
    7.5
    High

    CVE-2026-78132

    Last Modified: 11 Sept 2026

    strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.

    Published:11 Sept 2026
    3.7
    Low

    CVE-2026-78131

    Last Modified: 11 Sept 2026

    strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.

    Published:11 Sept 2026
    7.5
    High

    CVE-2026-78130

    Last Modified: 11 Sept 2026

    strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.

    Published:11 Sept 2026
    5.9
    Medium

    CVE-2026-78129

    Last Modified: 11 Sept 2026

    strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.

    Published:11 Sept 2026
    3.7
    Low

    CVE-2026-78127

    Last Modified: 11 Sept 2026

    libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.

    Published:11 Sept 2026
    Items Per Page
    ...