Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.4 HIGH
CVE-2026-65802 — Microsoft Edge for Android Information Disclosure Vulnerability

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.8 HIGH
CVE-2026-62870 — Microsoft Excel Remote Code Execution Vulnerability

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
10.0 HIGH
CVE-2026-18686 — GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipu…

gl-mt3000_firmware | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
10.0 HIGH
CVE-2026-18685 — GL.iNet GL-MT3000 modem.so glc set_upgrade command injection

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to comman…

gl-mt3000_firmware | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
1.8 LOW
CVE-2026-11836 — Production Debug-Unlock Token Verification Missing Device Binding

Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to the integrator's debug unlock…

| Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.6 MEDIUM
CVE-2026-11835 — Caliptra Update-Reset Secure-Boot Bypass via Attacker-Chosen AXI Staging Address (TOCTOU)

Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mode allows a compromised local attacker to silently…

| Race Condition
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
0.0 NA
CVE-2026-67978 — NASA cFS SBN UDP Interface Denial of Service Vulnerability

An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame.

| Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-67673 — OreSat Firmware Stack-Based Buffer Overflow

A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is triggered when processing the edl fw_flash command, where the <filename> argum…

| Memory Corruption
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-48399 — Adobe Campaign Classic (ACC) | Violation of Secure Design Principles (CWE-657)

Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypa…

campaign_classic | Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
9.8 CRITICAL
CVE-2026-48333 — Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privilege…

campaign_classic | Remote | Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
10.0 CRITICAL
CVE-2026-48331 — Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction.…

campaign_classic | Remote | Server-Side Request Forgery
Aug 03, 2026 Aug 04, 2026
Aug 03, 2026
Aug 04, 2026
10.0 CRITICAL
CVE-2026-48330 — Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL…

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the …

campaign_classic | Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
9.9 CRITICAL
CVE-2026-48326 — Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL…

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the …

campaign_classic | Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
10.0 CRITICAL
CVE-2026-48323 — Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Temp…

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the …

campaign_classic | Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
9.6 CRITICAL
CVE-2026-48317 — Adobe Campaign Classic (ACC) | Improper Neutralization of Directives in Dynamically Evalu…

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in th…

campaign_classic | Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
10.0 HIGH
CVE-2026-18684 — GL.iNet GL-MT3000 modem.so glc remove_profile command injection

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command in…

gl-mt3000_firmware | Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
9.6 CRITICAL
CVE-2026-18667 — Sensor Proxy Version 1.4.2 Fixes One Vulnerability

A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host.

Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.7 HIGH
CVE-2026-69249 — python-cryptography: Duplicate self-signed intermediates can cause exponential path-build…

python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invalid certificate chains that include duplicate copies…

cryptography | Remote | Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.9 MEDIUM
CVE-2026-69248 — python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSub…

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and th…

cryptography | Remote | Cryptography
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.2 HIGH
CVE-2026-69247 — cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through dis…

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reporte…

cryptography | Remote | Cryptography
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
Showing 20 of 9425 Results