Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-52732 — ZEBRA: Mempool transaction admission denial via single-peer inbound queue saturation

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can monopolize all 25 MAX_INBOUND_CONCURRENCY slots in Zebra's inbound mempool download and verification p…

zebrad | Remote | Denial of Service
Aug 18, 2026 Sep 09, 2026
Aug 18, 2026
Sep 09, 2026
6.5 MEDIUM
CVE-2026-52731 — ZEBRA: Full node denial of service via non-ASCII LongPollId in getblocktemplate

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoint can terminate zebrad by supplying a getblocktemplate LongPollId containing m…

zebrad | Remote | Denial of Service
Aug 18, 2026 Sep 09, 2026
Aug 18, 2026
Sep 09, 2026
7.5 HIGH
CVE-2026-52481 — SJRC F11 SJ-GPS-PRO Information Disclosure Vulnerability

An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the tcp_actions() function

Remote | Information Disclosure
Aug 18, 2026 Sep 09, 2026
Aug 18, 2026
Sep 09, 2026
6.5 MEDIUM
CVE-2026-52480 — SJRC F11 SJ-GPS-PRO Information Disclosure

An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service

| Information Disclosure
Aug 18, 2026 Aug 31, 2026
Aug 18, 2026
Aug 31, 2026
6.0 MEDIUM
CVE-2026-49500 — Dell Alienware Command Center Improper Link Resolution Vulnerability

Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access…

| Denial of Service
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
6.3 MEDIUM
CVE-2026-47721 — FUXA: Scheduler API missing admin check enables operator-to-admin escalation via schedule…

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api/scheduler/index.js do not consistently enforce au…

fuxa | Remote | Authorization
Aug 18, 2026 Sep 09, 2026
Aug 18, 2026
Sep 09, 2026
5.3 MEDIUM
CVE-2026-47720 — FUXA: SQL injection in TDengine DAQ connector via backslash bypass of escapeTdString

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runtime/storage/tdengine/index.js doub…

fuxa | Remote | Injection
Aug 18, 2026 Sep 09, 2026
Aug 18, 2026
Sep 09, 2026
8.2 HIGH
CVE-2026-47719 — FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with r…

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO handlers in server/runtime/index.js omit isSocketWrit…

fuxa | Remote | Server-Side Request Forgery
Aug 18, 2026 Sep 09, 2026
Aug 18, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-19671 — Improper handling of highly compressed data (data amplification) in CISA Malcolm

Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchiv…

Remote | Denial of Service
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
5.4 MEDIUM
CVE-2026-19670 — Incorrect Authorization in CISA Malcolm

Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upl…

Remote | Authorization
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
6.4 MEDIUM
CVE-2026-12520 — Stack buffer overflow and off-by-one writes in Zephyr HL7800 modem AT response handlers

The Sierra Wireless HL7800 cellular modem driver (drivers/modem/vendor_standalone/hl7800.c, located at drivers/modem/hl7800.c in v4.4.0 and earlier) parses AT responses with roughly twenty handlers t…

zephyr zephyr | Memory Corruption
Aug 18, 2026 Aug 26, 2026
Aug 18, 2026
Aug 26, 2026
Showing 20 of 15311 Results