Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-86514 — vgmstream txth-txtp txth.c sscanf stack-based overflow

A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer ove…

vgmstream | Remote | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.5 MEDIUM
CVE-2026-86513 — java-json-tools jackson-coreutils JSON Pointer parser TreePointer.java TreePointer.tokens…

A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/com/github/fge/jackson/json…

jackson-coreutils | Remote | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-86512 — java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperation.apply ac…

A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOpera…

json-patch | Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.5 MEDIUM
CVE-2026-86511 — java-json-tools jackson-coreutils JacksonUtils.java BigDecimal.toPlainString resource con…

A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/github/fge/jackson/JacksonUti…

jackson-coreutils | Remote | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.8 MEDIUM
CVE-2026-75811 — ASUS Armoury Crate Improper Restriction of Software Interfaces to Hardware Features

Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause hardware damage by bypassing…

armoury_crate | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.7 MEDIUM
CVE-2026-75810 — ASUS Armoury Crate Improper Access Control Vulnerability

Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interr…

armoury_crate | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.9 MEDIUM
CVE-2026-75809 — ASUS Armoury Crate Driver Improper Access Control Vulnerability

Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver authentication and using IOCT…

armoury_crate | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.7 MEDIUM
CVE-2026-75808 — ASUS Armoury Crate Resource Exhaustion Vulnerability

Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by bypassing driver authenticati…

armoury_crate | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.7 HIGH
CVE-2026-19397 — ASUS Control Center Express Agent Missing Authentication Vulnerability

Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an…

control_center_express_agent | Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.7 MEDIUM
CVE-2026-18023 — ASUS Armoury Crate Driver Information Disclosure Vulnerability

Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request tha…

armoury_crate | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.7 MEDIUM
CVE-2026-16006 — ASUS Armoury Crate Driver Information Disclosure Vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing the …

armoury_crate | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.8 MEDIUM
CVE-2026-16005 — ASUS Armoury Crate Driver Arbitrary Memory Deallocation Vulnerability

Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data…

armoury_crate | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.9 MEDIUM
CVE-2026-16004 — ASUS Armoury Crate Driver Arbitrary PCI Configuration Space Access Vulnerability

Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the driver'…

armoury_crate | Misconfiguration
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
2.0 LOW
CVE-2026-16003 — ASUS Armoury Crate Driver Improper Access Control Vulnerability

Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IOCTL request by bypassing th…

armoury_crate | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.3 MEDIUM
CVE-2026-12962 — ASUS Armoury Crate Cross-Domain Policy NTLM Credential Disclosure

A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sends…

armoury_crate | Remote | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.9 CRITICAL
CVE-2026-86510 — D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The a…

Remote | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.6 CRITICAL
CVE-2026-86509 — D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow

A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffe…

| Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
2.3 LOW
CVE-2026-82710 — Terminal escape sequence injection in mix usage_rules.search_docs via package documentati…

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control sequences into the output of mix…

usage_rules | Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
4.3 MEDIUM
CVE-2026-76977 — Clickjacking vulnerability in SAPUI5(Frame Options Allowlist)

SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authen…

sapui5 | Remote | Cross-Site Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-76971 — Server-Side Request Forgery in SAP Manufacturing Integration and Intelligence

Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed b…

manufacturing_integration_and_intelligence | Remote | Server-Side Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
Showing 20 of 12520 Results