Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-19740 — Bluetooth LE Controller: retained RX node leak and reachable assertion in the PHY Update …

The Link Layer Control Procedure (LLCP) implementation of the Zephyr software Bluetooth LE Controller retains the receive node that carried an accepted LL_PHY_UPDATE_IND so that it can later be reuse…

zephyr zephyr | Denial of Service
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.5 MEDIUM
CVE-2026-19739 — Bluetooth LE controller leaks a retained RX node when an unexpected LL Control PDU arrive…

The Bluetooth Link Layer control procedure code in subsys/bluetooth/controller/ll_sw/ull_llcp_conn_upd.c retains the received RX node while a Connection Update / Connection Parameter procedure waits …

zephyr zephyr | Denial of Service
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.5 MEDIUM
CVE-2026-19738 — Retained RX node leak and reachable assertion in Bluetooth Controller CIS Create procedur…

The Bluetooth Link Layer Control Procedure (LLCP) implementation for Connected Isochronous Stream (CIS) creation retains an RX node (ctx->node_ref.rx, marked NODE_RX_TYPE_RETAIN) so it can later be r…

zephyr zephyr | Memory Corruption
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.5 HIGH
CVE-2026-19935 — Use-after-free of an L2CAP CoC channel object in the Zephyr Bluetooth host: RX work item …

The Bluetooth LE host queues received L2CAP connection-oriented channel (CoC) data for deferred processing through a struct k_work embedded in the channel object (le_chan->rx_work, handler l2cap_rx_p…

zephyr zephyr | Race Condition
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.5 MEDIUM
CVE-2026-19737 — NULL pointer dereference in the ESP32 I2S driver when triggering an unsupported direction

i2s_esp32_trigger_check() in drivers/i2s/i2s_esp32.c validates the requested direction only for I2S_DIR_BOTH. The I2S_DIR_RX and I2S_DIR_TX branches read dev_cfg->rx.data->configured / dev_cfg->tx.da…

zephyr zephyr | Denial of Service
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
3.4 LOW
CVE-2026-18418 — Out-of-bounds read when the zbus proxy agent IPC backend logs a rejected peer frame's cha…

The zbus proxy agent IPC backend in subsys/zbus/proxy_agent/zbus_proxy_agent_ipc.c logged the channel name of a rejected inter-domain frame with a plain %s conversion. The frame type struct zbus_prox…

zephyr zephyr | Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.8 HIGH
CVE-2026-19736 — Out-of-bounds write in the NXP MCUX TRNG entropy driver for non-word-multiple request len…

The NXP MCUX TRNG entropy driver in drivers/entropy/entropy_mcux_trng.c passed the caller's byte count straight to the vendor SDK routine TRNG_GetRandomData(). On i.MX RT5xx and RT6xx parts the SDK c…

zephyr zephyr | Memory Corruption
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.8 MEDIUM
CVE-2026-19735 — Predictable TCP initial sequence numbers when the RFC 6528 secret key generation fails si…

The RFC 6528 initial-sequence-number implementation in subsys/net/ip/tcp.c derived every TCP ISN from SHA-256(unique_key || four-tuple) plus a uptime-derived offset, where unique_key is a 128-bit sec…

zephyr zephyr | Cryptography
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.1 HIGH
CVE-2026-19577 — Out-of-bounds read in IPv6 route forwarding when the nexthop neighbor has no link-layer a…

net_route_ipv6_packet() in subsys/net/ip/route_ipv6.c resolved the nexthop's link-layer address with net_nbr_get_lladdr(nbr->idx) without first checking whether the neighbor cache entry actually had …

zephyr zephyr | Memory Corruption
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.8 MEDIUM
CVE-2026-19576 — Stack out-of-bounds write in the Goodix GT911 touch controller driver from an unvalidated…

The Goodix GT9xx input driver in drivers/input/input_gt911.c reads the touch point count from the controller's status register and masks it with GT911_TOUCH_POINTS_MSK (0x0F), yielding a value of 0..…

zephyr zephyr | Memory Corruption
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.8 HIGH
CVE-2026-19669 — Unbounded variable-length array in fuel gauge syscall verifiers allows kernel stack overf…

The user-mode syscall verifiers z_vrfy_fuel_gauge_get_props() and z_vrfy_fuel_gauge_set_props() in drivers/fuel_gauge/fuel_gauge_syscall_handlers.c declared two variable-length arrays, union fuel_gau…

zephyr zephyr | Memory Corruption
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.1 HIGH
CVE-2026-108913 — Omarchy Arbitrary Code Execution Vulnerability

omarchy-theme-set in Omarchy 4 before 4.0.1 allows code execution via a third-party theme because the files placed into ~/.local/state/omarchy/current/theme may include executable content from an unt…

Remote | Supply Chain
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-107761 — Channel tokens and organization API key exposed in API responses

Several Postiz endpoints return the complete database row of the record they operate on instead of only the fields the client needs. Two of them include secrets the caller is not meant to receive. T…

postiz | Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.7 HIGH
CVE-2026-108905 — pH7Builder before 18.6.0 Hard-Coded API Key Bypass via Host Header

pH7Builder (pH7 Social Dating CMS) before 18.6.0 contains a hard-coded API key vulnerability in Tool.class.php that allows unauthenticated attackers to bypass API access checks by spoofing the Host h…

Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.1 HIGH
CVE-2026-108904 — pH7Builder before 18.5.0 Sensitive Data Exposure via Member API UserController

pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an information disclosure vulnerability that allows API clients to obtain sensitive member data because UserController::users() and user() re…

Remote | Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.9 MEDIUM
CVE-2026-108903 — pH7Builder before 19.3.0 CAPTCHA Bypass via Client-Chosen Form ID

pH7Builder (pH7 Social Dating CMS) before 19.3.0 contains a CAPTCHA bypass vulnerability that allows unauthenticated attackers to skip form validation by supplying a client-chosen form ID to PFBC For…

Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.1 HIGH
CVE-2026-108902 — pH7Builder before 18.5.0 Path Traversal Arbitrary File Deletion via picture_link

pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains a path traversal vulnerability in the picture module deletePhoto() action that allows authenticated members to delete arbitrary files. Attack…

Remote | Path Traversal
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108891 — JeecgBoot through 3.9.5 Missing Authorization via /sys/user/getUserDetailByUserId

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController getUserDetailByUserId handler that allows any authenticated user to read other users' details. Low-priv…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108888 — JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartRole/exportXls

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartRoleController exportXls handler that allows any authenticated user to export department roles. Low-privileged a…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108887 — JeecgBoot through 3.9.5 Missing Authorization via /sys/comment/exportXls

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCommentController exportXls handler that allows any authenticated user to export all comments. Low-privileged attacker…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
Showing 20 of 14185 Results