Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-86511 — java-json-tools jackson-coreutils JacksonUtils.java BigDecimal.toPlainString resource con…

A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/github/fge/jackson/JacksonUti…

jackson-coreutils | Remote | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.8 MEDIUM
CVE-2026-75811 — ASUS Armoury Crate Improper Restriction of Software Interfaces to Hardware Features

Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause hardware damage by bypassing…

armoury_crate | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.7 MEDIUM
CVE-2026-75810 — ASUS Armoury Crate Improper Access Control Vulnerability

Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interr…

armoury_crate | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.9 MEDIUM
CVE-2026-75809 — ASUS Armoury Crate Driver Improper Access Control Vulnerability

Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver authentication and using IOCT…

armoury_crate | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.7 MEDIUM
CVE-2026-75808 — ASUS Armoury Crate Resource Exhaustion Vulnerability

Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by bypassing driver authenticati…

armoury_crate | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.7 HIGH
CVE-2026-19397 — ASUS Control Center Express Agent Missing Authentication Vulnerability

Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an…

control_center_express_agent | Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.7 MEDIUM
CVE-2026-18023 — ASUS Armoury Crate Driver Information Disclosure Vulnerability

Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request tha…

armoury_crate | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.7 MEDIUM
CVE-2026-16006 — ASUS Armoury Crate Driver Information Disclosure Vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing the …

armoury_crate | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.8 MEDIUM
CVE-2026-16005 — ASUS Armoury Crate Driver Arbitrary Memory Deallocation Vulnerability

Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data…

armoury_crate | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.9 MEDIUM
CVE-2026-16004 — ASUS Armoury Crate Driver Arbitrary PCI Configuration Space Access Vulnerability

Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the driver'…

armoury_crate | Misconfiguration
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
2.0 LOW
CVE-2026-16003 — ASUS Armoury Crate Driver Improper Access Control Vulnerability

Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IOCTL request by bypassing th…

armoury_crate | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.3 MEDIUM
CVE-2026-12962 — ASUS Armoury Crate Cross-Domain Policy NTLM Credential Disclosure

A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sends…

armoury_crate | Remote | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.9 CRITICAL
CVE-2026-86510 — D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The a…

Remote | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.6 CRITICAL
CVE-2026-86509 — D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow

A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffe…

| Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
2.3 LOW
CVE-2026-82710 — Terminal escape sequence injection in mix usage_rules.search_docs via package documentati…

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control sequences into the output of mix…

usage_rules | Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
4.3 MEDIUM
CVE-2026-76977 — Clickjacking vulnerability in SAPUI5(Frame Options Allowlist)

SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authen…

sapui5 | Remote | Cross-Site Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-76971 — Server-Side Request Forgery in SAP Manufacturing Integration and Intelligence

Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed b…

manufacturing_integration_and_intelligence | Remote | Server-Side Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.4 CRITICAL
CVE-2026-76969 — Credential disclosure in multitenant applications using SAP Cloud Application Programming…

@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially…

Remote | Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-76968 — Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manage…

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensit…

Remote | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.8 HIGH
CVE-2026-76967 — Insecure Deserialization in SAP NetWeaver Business Client

SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could …

netweaver_business_client | Misconfiguration
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
Showing 20 of 12533 Results