Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-45848 — apparmor: fix NULL sock in aa_sock_file_perm

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix NULL sock in aa_sock_file_perm Deal with the potential that sock and sock-sk can be NULL during socket setup or tea…

linux_kernel | Memory Corruption
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
0.0 NA
CVE-2026-45847 — net: remove WARN_ON_ONCE when accessing forward path array

In the Linux kernel, the following vulnerability has been resolved: net: remove WARN_ON_ONCE when accessing forward path array Although unlikely, recent support for IPIP tunnels increases chances o…

linux_kernel | Misconfiguration
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
6.3 MEDIUM
CVE-2026-42791 — OCSP responder certificate validity period not checked in public_key

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses signed with an expired responder certificate to be accepted as valid. OCSP re…

erlang\/otp | Remote | Cryptography
May 27, 2026 Jun 02, 2026
May 27, 2026
Jun 02, 2026
7.0 HIGH
CVE-2026-42789 — Non-CA certificate accepted as intermediate issuer in public_key path validation

Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issuer, enabling certifi…

erlang\/otp | Remote | Authorization
May 27, 2026 Jun 05, 2026
May 27, 2026
Jun 05, 2026
6.5 MEDIUM
CVE-2026-3676 — There are multiple vulnerabilities in IBM DB2 bundled with IBM Application Performance Ma…

IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of se…

May 27, 2026 Jun 02, 2026
May 27, 2026
Jun 02, 2026
7.8 HIGH
CVE-2026-3623 — Vulnerabilities exists in IBM Netezza Performance Server Replication Services

IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker with low‑privileged access to escalate their privileges to root. By exploiting this flaw, the attacker c…

May 27, 2026 Jun 02, 2026
May 27, 2026
Jun 02, 2026
7.5 HIGH
CVE-2026-3366 — InfoSphere Optim Test Data Fabrication is affected by Arbitrary File Read

IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, 1.0.2.7 could allow a remote attacker to traverse directories on the system. An…

infosphere_optim_test_data_fabrication | Remote | Path Traversal
May 27, 2026 Jun 02, 2026
May 27, 2026
Jun 02, 2026
7.3 HIGH
CVE-2026-38427 — Tasmota Heap Buffer Overflow

An issue in fetch_jpg() in xdrv_10_scripter.ino in Tasmota through 15.3.0.3 allows a remote attacker to cause heap buffer overflow. The Content-Length from a JPEG stream is stored in a uint16_t varia…

Remote | Memory Corruption
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
7.3 HIGH
CVE-2026-38426 — Arendst Tasmota Buffer Overflow Vulnerability

Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the xdrv_10_scripter.ino, fetch_jpg(), jpg_task.boundary[40], strcpy() fu…

Remote | Memory Corruption
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
7.3 HIGH
CVE-2026-38422 — Arendst Tasmota Buffer Overflow Vulnerability

Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the tasmota/tasmota_xdrv_driver/xdrv_10_scripter.ino, fetch_jpg() functio…

Remote | Memory Corruption
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.3 HIGH
CVE-2026-36540 — Netis AC1200 Router Unauthenticated Command Injection Vulnerability

Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the /cgi-bin/skk_set.cgi endpoint. The password and new_pwd_confirm POST parameters are passed directly to …

Remote | Injection
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.3 HIGH
CVE-2026-36539 — Netis AC1200 Router Unauthenticated Configuration Disclosure

Netis AC1200 Router NC21 V4.0.1.4296 exposes a CGI endpoint /cgi-bin/skk_get.cgi that returns the entire router configuration as a JSON response with no authentication required. Any attacker on the L…

Remote | Information Disclosure
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.3 HIGH
CVE-2026-36538 — Netis AC1200 Router Root Credential Hard-Coded Vulnerability

Netis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential stored in /etc/shadow.sample. The password for the root account is set to the trivially weak value root, allowing an attacke…

Remote | Authentication
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.3 HIGH
CVE-2026-36045 — Picoclaw OS Command Injection

picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using a d…

Remote | Injection
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
8.8 HIGH
CVE-2026-36044 — Apex OS Command Injection Vulnerability

@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenati…

Remote | Injection
May 27, 2026 Jun 03, 2026
May 27, 2026
Jun 03, 2026
9.3 CRITICAL
CVE-2026-35090 — Authentication Bypass in Slican telephone exchanges

In Slican telephone exchanges it is possible to manage the control panel remotely. An unauthenticated attacker can connect to the modem via a telephone with a specific caller ID. This allows them to …

Remote | Authentication
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
8.7 HIGH
CVE-2026-35089 — Use of Weak Credentials in Slican telephone exchanges

In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can be obtained without authentication. An unauthenticated attacker can …

Remote | Authentication
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
9.3 CRITICAL
CVE-2026-35087 — Authentication Bypass in Slican telephone exchanges

Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter login credentials by executing the appropriate command. This issue was fixed…

ncp_firmware | Remote | Authentication
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
5.1 MEDIUM
CVE-2026-2607 — Multiple vulnerabilities in IBM MQ Operator and Queue manager container images

IBM MQ Operator SC2: v3.2.0 through 3.2.23CD:  v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0 - v3.7.2, v3.8.0, v3.8.1, v3.9.0, v3.9.1LTS: v2.0.0 - 2.0.29 and IBM supplied M…

May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
6.5 MEDIUM
CVE-2026-2340 — Samba: vfs_worm does not block directory modification

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to i…

May 27, 2026 Jun 04, 2026
May 27, 2026
Jun 04, 2026
Showing 20 of 7032 Results