Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.1 CRITICAL
CVE-2026-51731 — TOTOLINK T6 Incorrect Access Control Vulnerability

Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi…

Remote | Authorization
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
6.5 MEDIUM
CVE-2026-14697 — IPv6 Neighbor Solicitation packet leak causes TX pool exhaustion denial of service

net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a transmit net_pkt for a Neighbor Solicitation. When it is called with a data packet pending on an unresolved neighbor and that neighbor's pen…

zephyr zephyr | Denial of Service
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
7.8 HIGH
CVE-2026-13732 — Gdb: gdb: out-of-bounds write in stabs parser read_member_functions() via crafted elf

A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructo…

Aug 31, 2026 Sep 29, 2026
Aug 31, 2026
Sep 29, 2026
8.8 HIGH
CVE-2026-83497 — Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination

Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitra…

Aug 31, 2026 Sep 03, 2026
Aug 31, 2026
Sep 03, 2026
5.0 MEDIUM
CVE-2026-82821 — FLVMeta AMF Object Parsing amf.c amf_object_get null pointer dereference

A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this vulnerability is the function amf_object_get of the file src/amf.c of the component AMF Object Parsing. This manipulation cause…

flvmeta | Remote | Memory Corruption
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.0 MEDIUM
CVE-2026-82820 — FLVMeta AMF String Processing amf.c amf_string_new heap-based overflow

A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amf_string_new of the file src/amf.c of the component AMF String Processing. The manipulation of the argument length results…

flvmeta | Remote | Memory Corruption
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
6.5 MEDIUM
CVE-2026-82818 — dibo-software diboot Tenant Resource Assignment resource access control

A vulnerability was determined in dibo-software diboot 3.8.0. This affects an unknown part of the file /api/iam/tenant/resource of the component Tenant Resource Assignment Handler. Executing a manipu…

diboot | Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.6 HIGH
CVE-2026-72001 — Pangolin < 1.22.0 Authentication Bypass via Share-Link Endpoint

Pangolin before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any protected resource by supplying an attacker-controlled URL parameter to the …

pangolin | Remote | Authentication
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
7.7 HIGH
CVE-2026-53553 — Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server C…

Goploy is an open-source automation deployment system. Prior to version 1.18.0, a severe path traversal vulnerability exists in its backend API endpoints, specifically /deploy/fileDiff (File Compare)…

Remote | Path Traversal
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
9.6 CRITICAL
CVE-2026-53552 — Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file…

Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accep…

Remote | Authorization
Aug 31, 2026 Sep 08, 2026
Aug 31, 2026
Sep 08, 2026
6.0 MEDIUM
CVE-2026-53508 — oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF …

oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, oasdiff did not enforce --allow-external-refs=false (…

Remote | Misconfiguration
Aug 31, 2026 Sep 09, 2026
Aug 31, 2026
Sep 09, 2026
8.3 HIGH
CVE-2026-53507 — oasdiff actions resolve external $refs by default, enabling SSRF and disclosure of struct…

oasdiff-action is a GitHub Action that detects breaking changes in OpenAPI specs and post a review on every pull request. Before version 0.0.51, the oasdiff actions resolved external $refs in the Ope…

Remote | Server-Side Request Forgery
Aug 31, 2026 Sep 09, 2026
Aug 31, 2026
Sep 09, 2026
6.5 MEDIUM
CVE-2026-14696 — Ethernet bridge RX packet leak enables denial of service via RX buffer-pool exhaustion

When Ethernet bridging is enabled (CONFIG_NET_ETHERNET_BRIDGE), eth_bridge_input_process() in subsys/net/l2/ethernet/bridge/bridge_input.c decides how each frame received on a bridge member interface…

zephyr zephyr | Denial of Service
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
5.4 MEDIUM
CVE-2026-14368 — Off-by-one out-of-bounds NUL write in Zephyr LwM2M JSON string parser

The LwM2M JSON content formatter's get_string() in subsys/net/lib/lwm2m/lwm2m_rw_json.c copies a parsed JSON string into a caller-supplied buffer and NUL-terminates it. The length guard used if (stri…

zephyr zephyr | Memory Corruption
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
3.1 LOW
CVE-2026-14367 — I3C IBI work-node free-list data race between ISR and workqueue thread

The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out statically-allocated work nodes through a free-list i3c_ibi_work_nodes_free implemented as a plain sys_slist_t, which provides no synchr…

zephyr zephyr | Race Condition
Aug 31, 2026 Sep 01, 2026
Aug 31, 2026
Sep 01, 2026
3.3 LOW
CVE-2023-31308 — AMD SMU Out-of-Bounds Read Denial of Service

A malicious virtual function can invoke the certain command handlers in the SMU, causing a denial of service due to out-of-bounds memory read.

| Memory Corruption
Aug 31, 2026 Sep 03, 2026
Aug 31, 2026
Sep 03, 2026
6.4 MEDIUM
CVE-2023-20511 — AMD Kernel Mode Driver Double Free Vulnerability

Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow a privileged attacker to create a double free condition potentially leading to arbitrary code execution.

Remote | Memory Corruption
Aug 31, 2026 Sep 03, 2026
Aug 31, 2026
Sep 03, 2026
Showing 20 of 14957 Results