Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-10669 — Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall po…

On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/mpu.c — the architecture hook that verifies a user-mode-supplied buffer is accessible to t…

zephyr zephyr | Memory Corruption
Jul 14, 2026 Aug 06, 2026
Jul 14, 2026
Aug 06, 2026
8.7 HIGH
CVE-2026-10573 — 1734 POINT I/OTM - Denial of Service via Malformed Inputs on CIP Object

A denial-of-service security issue exists in 1734 POINT I/O™ module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A re…

Remote | Denial of Service
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
9.2 CRITICAL
CVE-2025-12012 — CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow

A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a…

Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
9.2 CRITICAL
CVE-2025-12011 — CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow

A denial-of-service issue exists in  5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fa…

Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
6.8 MEDIUM
CVE-2026-53566 — Out-of-bounds memory read

Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20.

| Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
9.0 HIGH
CVE-2026-15693 — Tenda BE12 Pro SafeMacFilter fromSafeMacFilter stack-based overflow

A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. This issue affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page le…

Remote | Memory Corruption
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
7.3 HIGH
CVE-2026-8314 — Rockwell Automation Arena® - Memory Corruption Vulnerability

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, w…

arena arena_simulation | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.3 HIGH
CVE-2026-8313 — Rockwell Automation Arena® - Memory Corruption Vulnerability

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, …

arena arena_simulation | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.3 HIGH
CVE-2026-8312 — Rockwell Automation Arena® - Memory Corruption Vulnerability

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, w…

arena | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.3 HIGH
CVE-2026-8085 — Rockwell Automation Arena® - Memory Corruption Vulnerability

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, w…

arena arena_simulation | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
4.3 MEDIUM
CVE-2026-62393 — Apache Kylin: Improper authorization in job information retrieval

Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs i…

kylin | Remote | Authorization
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
9.8 CRITICAL
CVE-2026-62392 — Apache Kylin: OS Command Injection via Async Query API

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue…

kylin | Remote | Injection
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
9.8 CRITICAL
CVE-2026-62390 — Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL…

kylin | Remote | Injection
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
8.5 HIGH
CVE-2026-53565 — Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges

Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. This issue affects Secure Access Client for Windows: befor…

| Authorization
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
6.5 MEDIUM
CVE-2026-49488 — Apache OpenMeetings: Arbitrary File Read

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with…

openmeetings | Remote | Path Traversal
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
5.4 MEDIUM
CVE-2026-15719 — Site isolation issue in the DOM: Navigation component

We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 115.38, Firefox E…

firefox thunderbird | Remote
Jul 14, 2026 Jul 22, 2026
Jul 14, 2026
Jul 22, 2026
4.3 MEDIUM
CVE-2026-15718 — Invalid pointer in the JavaScript: WebAssembly component

We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 140.13, and Thund…

firefox thunderbird | Remote
Jul 14, 2026 Jul 22, 2026
Jul 14, 2026
Jul 22, 2026
9.0 HIGH
CVE-2026-15692 — Tenda BE12 Pro SafeUrlFilter fromSafeUrlFilter stack-based overflow

A weakness has been identified in Tenda BE12 Pro 16.03.66.23. This vulnerability affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Executing a manipulation of the argument pag…

Remote | Memory Corruption
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
9.0 HIGH
CVE-2026-15691 — Tenda BE12 Pro SafeClientFilter fromSafeClientFilter stack-based overflow

A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. This affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument page …

Remote | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
6.3 MEDIUM
CVE-2026-15305 — TYPO3 CMS - Unrestricted File Upload in Form Framework

Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. The restriction was not enforced server-side because the …

typo3 | Remote | Misconfiguration
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
Showing 20 of 10921 Results