Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-81886 — radare2: Uncontrolled memory allocation in radare2 dmp64 parser

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 parser used an…

radare2 radare2 | Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.5 MEDIUM
CVE-2026-81885 — radare2: Infinite relocation-chain loop causes denial of service in radare2 NE parser

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's NE relocation fixup-chain parser was vulnerable because the NE relocation parser followed fixu…

radare2 radare2 | Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
2.5 LOW
CVE-2026-81884 — radare2: Heap out-of-bounds read in radare2 Mach-O LC_DATA_IN_CODE parser

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_IN_CODE parser was vulnerable because the Mach-O LC_DATA_IN_CODE parser trusted…

radare2 radare2 | Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
3.3 LOW
CVE-2026-81883 — radare2: Out-of-bounds Read at the end of string in the LUA 5.3 bytecode

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Lua 5.3 bytecode function parser was vulnerable because the Lua 5.3 bytecode function parser r…

radare2 radare2 | Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
3.3 LOW
CVE-2026-81882 — radare2: Missing string termination causes heap out-of-bounds read in radare2 bplist pars…

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property-list Unicode parser was vulnerable because the binary-property-list Unicode pa…

radare2 radare2 | Information Disclosure
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
3.3 LOW
CVE-2026-81881 — radare2: Heap out-of-bounds read in radare2 Mach-O Swift metadata parser

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could…

radare2 radare2 | Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.5 MEDIUM
CVE-2026-81880 — radare2: Uncontrolled resource consumption in radare2 PEF loader

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred Executable Format loader was vulnerable because the PEF loader accepted relocS…

radare2 radare2 | Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.5 MEDIUM
CVE-2026-81879 — radare2: Heap out-of-bounds read in radare2 ELF PN_XNUM handling

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's ELF PN_XNUM handling was vulnerable because the ELF parser allocated the program-header array …

radare2 radare2 | Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.5 MEDIUM
CVE-2026-81878 — radare2: Integer overflow causes heap out-of-bounds write in radare2 PYC parser

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecode .pyc marshal parser was vulnerable because the CPython marshal readers accept…

radare2 radare2 | Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.4 CRITICAL
CVE-2026-80156 — Lantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validat…

Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a path traversal vulnerability in the web management …

Remote | Path Traversal
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
10.0 CRITICAL
CVE-2026-80155 — Lantronix Autonomous Out-of-Band Devices Unauthenticated Authentication Bypass via snprin…

Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain an authentication bypass vulnerability in the web man…

Remote | Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.6 CRITICAL
CVE-2026-80154 — Lantronix Autonomous Out-of-Band Devices Predictable Session Token with Validation Bypass

All firmware versions of Lantronix SLC8000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated atta…

Remote | Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.4 CRITICAL
CVE-2026-80152 — Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script schedule

Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authent…

Remote | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.4 CRITICAL
CVE-2026-80151 — Lantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs download

Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authent…

Remote | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.7 HIGH
CVE-2026-80150 — Lantronix Autonomous Out-of-Band Devices WebTelnet SSRF via rooturl Parameter

Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet l…

Remote | Server-Side Request Forgery
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.6 HIGH
CVE-2026-80149 — Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via rooturl Parameter

Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet l…

Remote | Server-Side Request Forgery
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.6 HIGH
CVE-2026-80148 — Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via Username Truncation

Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet l…

Remote | Server-Side Request Forgery
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.9 CRITICAL
CVE-2026-80147 — Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom write

Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allo…

Remote | Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.9 CRITICAL
CVE-2026-80146 — Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom read

Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allo…

Remote | Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.4 CRITICAL
CVE-2026-80145 — Lantronix Autonomous Out-of-Band Devices CLI Command Injection via set cifs password

Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authent…

Remote | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
Showing 20 of 14045 Results