Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.6 HIGH
CVE-2024-13942 — Rockchip RK3588s Secure BootROM TOCTOU (time-of-check to time-of-use) vulnerability leadi…

Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external media (SPI NOR or NAND, EMMC or SD). The code reads the header of the next-st…

| Authentication
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-20320 — Cisco BroadWorks XML External Entity Injection Vulnerability

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. …

broadworks | XML External Entity
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
3.5 LOW
CVE-2026-75583 — keeper.sh Calendar version prior to 2.18.14 SSRF Guard Bypass via DNS Rebinding

keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) guard bypass vulnerability that allows authenticated attackers to reach private network addresses by…

Remote | Server-Side Request Forgery
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.1 HIGH
CVE-2026-75147 — FFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.c

FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that searches for a sequence header OBU advanced its poin…

| Memory Corruption
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.1 HIGH
CVE-2026-75146 — FFmpeg Out-of-Bounds Read in DASH Demuxer via dashdec.c

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous valu…

Remote | Misconfiguration
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
5.8 MEDIUM
CVE-2026-75145 — FFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP Packetizer

FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The OBU size is cast to long before comparison against the remain…

| Memory Corruption
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.5 HIGH
CVE-2026-75144 — FFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer

FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplyin…

| Memory Corruption
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
9.8 CRITICAL
CVE-2026-75143 — FFmpeg Heap Buffer Overflow via RIST Protocol Reader

FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length …

Remote | Memory Corruption
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.5 HIGH
CVE-2026-75142 — FFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, …

| Memory Corruption
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.5 HIGH
CVE-2026-75141 — FFmpeg Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent,…

| Memory Corruption
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-49392 — Wazuh: Local SQL injection in FIM db due to path lookup interpolation in wazuh-syscheckd

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/f…

| Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-20327 — Cisco Unified Intelligence Center SQL Injection Vulnerability

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected dev…

Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-44256 — Wazuh: CRLF Log Injection via Unsanitized Basic-Auth Username

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.4.0 until 4.14.6 and 5.0.0-beta2, api/api/middlewares.py decodes the Basic authentication username…

| Information Disclosure
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-45798 — Wazuh: Pre-auth stack-buffer-overflow in compare_wazuh_versions reachable from wazuh-auth…

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the a…

| Memory Corruption
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-20314 — Cisco Packaged Contact Center Enterprise & Cisco Unified Contact Center Enterprise Server…

A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-si…

Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-20319 — Cisco Secure Workload Software Security Hardening Release August 2026 - Buffer Management…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulte…

secure_workload | Memory Corruption
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-49441 — Wazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allow…

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 and 5.0.0-beta3, the non-merged branch of process_files_from_worker() in framewor…

| Path Traversal
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-20315 — Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access C…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulte…

secure_workload | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-20317 — Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Authenti…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulte…

secure_workload | Authentication
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-20318 — Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Input Va…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulte…

secure_workload | Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Showing 20 of 12470 Results