Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-66374 — Knot Resolver Heap-Based Buffer Overflow Remote Code Execution

Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.

knot_resolver | Remote | Memory Corruption
Jul 25, 2026 Jul 25, 2026
Jul 25, 2026
Jul 25, 2026
7.5 HIGH
CVE-2026-66373 — Redis Double Free Vulnerability

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by mo…

Remote | Memory Corruption
Jul 25, 2026 Jul 25, 2026
Jul 25, 2026
Jul 25, 2026
6.5 MEDIUM
CVE-2026-66339 — Libsoup: libsoup: proxy credentials leak to destination server via proxy-authorization he…

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tu…

enterprise_linux enterprise_linux | Remote | Information Disclosure
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
5.4 MEDIUM
CVE-2026-66338 — Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_i…

A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plu…

enterprise_linux enterprise_linux | Remote | Misconfiguration
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
6.5 MEDIUM
CVE-2026-66337 — Libsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream…

A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP…

enterprise_linux enterprise_linux | Remote | Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.8 HIGH
CVE-2026-61892 — Weintek cMT3092X Incorrect Permission Assignment for Critical Resource

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

easyweb | Remote | Authorization
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
6.5 MEDIUM
CVE-2026-61886 — Weintek cMT3092X Plaintext Storage of a Password

Weintek cMT3092X HMI stores user account passwords in plaintext.

easyweb | Remote | Information Disclosure
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
6.5 MEDIUM
CVE-2026-60135 — Weintek cMT3092X Incorrect User Management

An attacker can modify data that should be restricted to read‑only access.

easyweb | Remote | Authorization
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.8 HIGH
CVE-2026-60134 — Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Secur…

Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.

easyweb | Remote | Authentication
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-16280 — GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffset

An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings an…

| Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
9.8 CRITICAL
CVE-2026-61884 — Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel

The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fiel…

Remote | Authentication
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
4.3 MEDIUM
CVE-2026-55985 — Tycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Sensitive Information

The web management interface in  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party wit…

Remote | Information Disclosure
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
7.8 HIGH
CVE-2025-71408 — NLTK < 3.9.2 Eval Injection via collocations.py Command-Line Arguments

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute ar…

| Injection
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.8 HIGH
CVE-2026-66041 — FFmpeg 7.0 - 8.1.2 Heap Out-of-Bounds Write via vf_quirc Filter

FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/S…

Remote | Memory Corruption
Jul 24, 2026 Jul 25, 2026
Jul 24, 2026
Jul 25, 2026
8.8 HIGH
CVE-2026-66040 — FFmpeg Heap Out-of-Bounds Write via PNG/APNG eXIf Encoder

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a…

Remote | Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.8 HIGH
CVE-2026-66039 — FFmpeg MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file…

Remote | Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
6.5 MEDIUM
CVE-2026-66038 — FFmpeg LCL/ZLIB Video Decoder Information Disclosure via lcldec.c

FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a …

Remote | Information Disclosure
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
6.5 MEDIUM
CVE-2026-66037 — FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu()

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory a…

Remote | Denial of Service
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.8 HIGH
CVE-2026-66036 — FFmpeg Heap Out-of-Bounds Write in vf_hqdn3d Filter

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whos…

Remote | Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
9.3 CRITICAL
CVE-2026-62835 — Azure Portal Information Disclosure Vulnerability

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

Jul 24, 2026 Jul 25, 2026
Jul 24, 2026
Jul 25, 2026
Showing 20 of 9429 Results