Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-66318 — Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.4 MEDIUM
CVE-2026-66317 — Microsoft Edge (Chromium-based) Tampering Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.4 MEDIUM
CVE-2026-66316 — Microsoft Edge (Chromium-based) Spoofing Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.5 HIGH
CVE-2026-66315 — Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.5 MEDIUM
CVE-2026-66314 — Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.8 MEDIUM
CVE-2026-66313 — Microsoft Edge (Chromium-based) Tampering Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.5 MEDIUM
CVE-2026-66312 — Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.2 MEDIUM
CVE-2026-66311 — Microsoft Edge (Chromium-based) Tampering Vulnerability

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.7 HIGH
CVE-2026-66310 — Microsoft Edge for Android Information Disclosure Vulnerability

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.1 MEDIUM
CVE-2026-65804 — Microsoft Edge (Chromium-based) Spoofing Vulnerability

Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.4 HIGH
CVE-2026-65802 — Microsoft Edge for Android Information Disclosure Vulnerability

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.8 HIGH
CVE-2026-62870 — Microsoft Excel Remote Code Execution Vulnerability

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
10.0 HIGH
CVE-2026-18686 — GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipu…

Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
10.0 HIGH
CVE-2026-18685 — GL.iNet GL-MT3000 modem.so glc set_upgrade command injection

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to comman…

Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
1.8 LOW
CVE-2026-11836 — Production Debug-Unlock Token Verification Missing Device Binding

Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to the integrator's debug unlock…

| Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.6 MEDIUM
CVE-2026-11835 — Caliptra Update-Reset Secure-Boot Bypass via Attacker-Chosen AXI Staging Address (TOCTOU)

Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mode allows a compromised local attacker to silently…

| Race Condition
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
0.0 NA
CVE-2026-67978 — NASA cFS SBN UDP Interface Denial of Service Vulnerability

An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame.

| Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-67673 — OreSat Firmware Stack-Based Buffer Overflow

A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is triggered when processing the edl fw_flash command, where the <filename> argum…

| Memory Corruption
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-48399 — Adobe Campaign Classic (ACC) | Violation of Secure Design Principles (CWE-657)

Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypa…

campaign_classic | Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
9.8 CRITICAL
CVE-2026-48333 — Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privilege…

campaign_classic | Remote | Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
Showing 20 of 9397 Results