Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.7 MEDIUM
CVE-2026-95393 — Heap-based Buffer Overflow in Wireshark

CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

| Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.5 MEDIUM
CVE-2026-95392 — Buffer Over-read in Wireshark

MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

| Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.5 MEDIUM
CVE-2026-95391 — Use After Free in Wireshark

ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service

| Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.5 MEDIUM
CVE-2026-95390 — NULL Pointer Dereference in Wireshark

PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of service

| Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.1 HIGH
CVE-2026-95389 — Heap-based Buffer Overflow in Wireshark

SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Remote | Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.5 MEDIUM
CVE-2026-95388 — Heap-based Buffer Overflow in Wireshark

Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

| Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.1 HIGH
CVE-2026-95387 — Heap-based Buffer Overflow in Wireshark

SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Remote | Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.5 MEDIUM
CVE-2026-95386 — Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark

TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service

| Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.3 MEDIUM
CVE-2026-8937 — Missing Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authentic…

Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.5 MEDIUM
CVE-2026-8067 — Hitachi Energy RTU500 Improper Authorization Vulnerability

An improper authorization vulnerability in the RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause te…

Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.1 CRITICAL
CVE-2026-8066 — Hitachi Energy RTU500 Directory Traversal Vulnerability

A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depen…

Remote | Path Traversal
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.1 CRITICAL
CVE-2026-8065 — Hitachi Energy RTU500 Authentication Bypass and Arbitrary Firmware Upload Vulnerability

An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Success…

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-86843 — Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute…

The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, whic…

| Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.7 HIGH
CVE-2026-84739 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in G…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenti…

Remote | Cross-Site Scripting
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-81930 — Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer tok…

Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.sn…

| Server-Side Request Forgery
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-81914 — Apache Airflow Google provider: Google Drive query injection via unescaped file and folde…

Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character that de…

| Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-81862 — Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credent…

Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` and `AzureBlobStorageToTeradataOperator` interpolate the source bucket's cre…

| Information Disclosure
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.5 HIGH
CVE-2026-7395 — Asset Suite HTTPPublishAdapterTestServlet Improper Authorization

Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPu…

asset_suite asset_suite | Remote | Misconfiguration
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.3 MEDIUM
CVE-2026-76720 — HPE OneView - URL Redirect vulnerability

A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect.

Remote | Misconfiguration
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.2 HIGH
CVE-2026-76719 — HPE OneView - Cross-site scripting vulnerability

A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions.

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
Showing 20 of 14348 Results