Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-105778 — Tenda AC5 Wifi setWifi stack-based overflow

A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of th…

ac5 | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-105701 — ACPT (Premium) <= 2.0.66 - Authenticated (Subscriber+) Remote Code Execution via REST API…

The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the RES…

| Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
9.8 CRITICAL
CVE-2026-94293 — Missing authentication for critical function in the aas-edge-client REST API

An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.

Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.8 HIGH
CVE-2026-57559 — Use After Free in DSP_Services

Memory corruption while processing service requests.

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.8 HIGH
CVE-2026-57555 — Use After Free in DSP Service

Memory Corruption when executing system service routines due to improper handling of user input buffers.

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.8 HIGH
CVE-2026-57554 — Use After Free in DSP Service

Memory Corruption when asynchronous threads access shared performance counter data simultaneously during FastRPC invocations.

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.5 HIGH
CVE-2026-57546 — Buffer Over-read in WLAN HAL

Transient DOS when processing a continuous receive command with a zero-sized global configuration override.

Remote | Denial of Service
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.8 HIGH
CVE-2026-57545 — Untrusted Pointer Dereference in Graphics

Memory corruption when processing draw objects of incorrect type during graphics command list execution.

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.8 HIGH
CVE-2026-57537 — Use After Free in DSP Service

Memory Corruption when accessing and modifying geographic mapping data concurrently without proper synchronization.

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.1 HIGH
CVE-2026-25302 — Improper Verification of Cryptographic Signature in Boot

Cryptographic Issue when processing non-ELF partitions, authentication and signature checks are bypassed, allowing unsigned or corrupted images to be mounted and processed.

| Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.8 HIGH
CVE-2026-25291 — Use After Free in Graphics

Memory corruption when performing concurrent operations on shared memory page lists due to lack of proper synchronization mechanisms.

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.7 MEDIUM
CVE-2026-25274 — Use After Free in Windows WLAN Host

Memory Corruption when processing concurrent DMA buffer allocation and deallocation commands without proper synchronization.

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.7 MEDIUM
CVE-2026-25273 — Out-of-bounds Write in Camera Driver

Memory Corruption when processing camera operations due to out-of-bounds write during driver updates.

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.7 MEDIUM
CVE-2026-25272 — Out-of-bounds Write in Camera Driver

Memory Corruption when processing camera CRE driver operations with improper handling of buffer limits during hardware update preparation.

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.7 MEDIUM
CVE-2026-25270 — Out-of-bounds Write in Camera Driver

Memory corruption when processing command buffer requests with invalid length parameters in the Android Camera driver.

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.7 MEDIUM
CVE-2026-25269 — Out-of-bounds Write in Camera Driver

Memory corruption when processing camera requests with excessive batch and IO buffer configurations exceeds allocated memory size.

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.8 HIGH
CVE-2026-25267 — Missing Authorization in Core

Memory corruption when non-secure loader rewrites page tables before secure memory initialization.

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.6 MEDIUM
CVE-2026-25263 — Out of Bounds write in Linux Camera

Memory corruption while processing IOCTL command called from user space to the kernel with invalid parameters.

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.5 MEDIUM
CVE-2026-97300 — WordPress WP Event Solution plugin <= 4.1.25 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.2 HIGH
CVE-2026-75962 — Post SMTP <= 4.0.1 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'user_emai…

The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email…

Remote | Cross-Site Scripting
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Showing 20 of 14561 Results