Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.0 HIGH
CVE-2026-12663 — ControlFLASH ® – Improper Access Control

A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resu…

| Misconfiguration
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
4.8 MEDIUM
CVE-2026-12661 — FactoryTalk® Historian Machine Edition - Out-of-Bounds Write Vulnerability

A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition.  A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting …

| Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.6 HIGH
CVE-2025-12768 — FactoryTalk® Historian Machine Edition - Out-of-Bounds Write Vulnerability

A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected devi…

| Authentication
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
7.2 HIGH
CVE-2024-14047 — Improper Link Resolution Before File Access ('Link Following') in Winlogbeat Leading to A…

A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with existing access to the system…

winlogbeat | Denial of Service
Sep 01, 2026 Sep 10, 2026
Sep 01, 2026
Sep 10, 2026
8.2 HIGH
CVE-2024-10085 — OPC UA Communication Platform Resource Exhaustion Vulnerability

CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large number of OPC UA requests are s…

Remote | Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.7 HIGH
CVE-2026-84235 — Rockwell Automation 1756-ENBT Denial of Service Vulnerability

A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device requires a restart to recover.

Remote | Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.2 CRITICAL
CVE-2026-84149 — Information Disclosure Vulnerability in Manacle Technologies ERP System

This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability…

Remote | Information Disclosure
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.2 CRITICAL
CVE-2026-84148 — Insecure Direct Object Reference Vulnerability in Manacle Technologies ERP System

This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manip…

Remote | Authentication
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
10.0 CRITICAL
CVE-2026-84147 — Remote Code Execution Vulnerability in Manacle Technologies ERP System

This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vuln…

Remote | Authentication
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
7.5 HIGH
CVE-2026-84145 — Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR…

Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we …

firefox thunderbird | Remote | Memory Corruption
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-84144 — Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2

Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough…

firefox thunderbird | Remote | Memory Corruption
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84143 — Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR…

Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we …

firefox thunderbird | Remote | Memory Corruption
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84142 — Internally found bugs fixed in Thunderbird 155

Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these coul…

firefox thunderbird | Remote | Memory Corruption
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84141 — Integer overflow in the Graphics: ImageLib component

Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

firefox thunderbird | Remote | Memory Corruption
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84140 — Site isolation issue in the DOM: Navigation component

Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

firefox thunderbird | Remote | Misconfiguration
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84139 — Clickjacking issue in the DOM: Events component

Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

firefox thunderbird | Remote | Cross-Site Request Forgery
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-84138 — Denial-of-service in the PDF Viewer component

Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

firefox thunderbird | Remote | Denial of Service
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84137 — Spoofing issue in the DOM: Core & HTML component

Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

firefox thunderbird | Remote | Information Disclosure
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84136 — Other issue in the DOM: Navigation component

Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

firefox thunderbird | Remote
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-84135 — Other issue in Firefox Focus for Android

Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.

Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
Showing 20 of 15072 Results