CVE-2026-85378
— light0011 cms Chapter Controller ChapterController.class.php _initialize authorization
A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function AuthController::_initialize o…
|
Authorization
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-62916
— Microsoft Entra ID Elevation of Privilege Vulnerability
None
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
None
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
None
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-83711
— Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
None
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
None
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-70352
— Azure AI Language Elevation of Privilege Vulnerability
None
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-70178
— Microsoft Fabric Elevation of Privilege Vulnerability
None
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-62906
— Microsoft Discovery Studio Information Disclosure Vulnerability
None
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85456
— MOOS-IvP through 24.8.1 alog Splitting Path Traversal on Windows
MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowing attackers to write files outside the split directory. Attackers can supply cr…
|
Path Traversal
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85455
— MOOS core-moos through 10.4.0 MOOSDB Out-of-Bounds Read via Short Packet
MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP …
|
Memory Corruption
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85454
— MOOS core-moos through 10.4.0 Off-by-One Buffer Overflow in Serial Telegram Handling
MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer. Attackers control…
|
Memory Corruption
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85453
— MOOS core-moos through 10.4.0 MOOSDB HTTP Pages Stored Cross-Site Scripting
MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set variable values containing…
|
Cross-Site Scripting
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85452
— MOOS ui-moos through 50b9c6c uMS Buffer Overflow via Long MOOS Identifiers
MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf wi…
|
Memory Corruption
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85451
— MOOS core-moos through 10.4.0 Remote Process Termination via Hard-Coded Multicast Passphr…
MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast…
|
Authentication
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85450
— MOOS core-moos through 10.4.0 MOOSDB HTTP Server Resource Exhaustion
MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections a…
|
Denial of Service
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85449
— MOOS-IvP through 24.8.1 pMarineViewer Unbounded Memory Consumption via NODE_REPORT
MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT messages, allowing attackers to exhaust memory by supplying unbounded distinct node names. …
|
Denial of Service
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85448
— MOOS-IvP through 24.8.1 uFldShoreBroker Unbounded Community State Retention
MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of claimed communities stored in parallel vectors within ShoreBroker::handleMailNodePing(). A single publisher can supply unbounded d…
|
Denial of Service
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85447
— MOOS-IvP through 24.8.1 pRealm Unbounded REALMCAST_REQ Subscription Denial of Service
MOOS-IvP pRealm through version 24.8.1 accepts unbounded REALMCAST_REQ subscriptions without validating duration or variable list limits. Attackers can register long-lived pipeways with many variable…
|
Denial of Service
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
CVE-2026-85446
— MOOS-IvP through 24.8.1 uFldNodeComms Quadratic Processing Denial of Service
MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a ledger entry and triggers all-pairs distribution work. Attackers …
|
Denial of Service
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Sep 03, 2026