Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-3366 — InfoSphere Optim Test Data Fabrication is affected by Arbitrary File Read

IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, 1.0.2.7 could allow a remote attacker to traverse directories on the system. An…

infosphere_optim_test_data_fabrication | Remote | Path Traversal
May 27, 2026 Jun 02, 2026
May 27, 2026
Jun 02, 2026
7.3 HIGH
CVE-2026-38427 — Tasmota Heap Buffer Overflow

An issue in fetch_jpg() in xdrv_10_scripter.ino in Tasmota through 15.3.0.3 allows a remote attacker to cause heap buffer overflow. The Content-Length from a JPEG stream is stored in a uint16_t varia…

Remote | Memory Corruption
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
7.3 HIGH
CVE-2026-38426 — Arendst Tasmota Buffer Overflow Vulnerability

Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the xdrv_10_scripter.ino, fetch_jpg(), jpg_task.boundary[40], strcpy() fu…

Remote | Memory Corruption
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
7.3 HIGH
CVE-2026-38422 — Arendst Tasmota Buffer Overflow Vulnerability

Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the tasmota/tasmota_xdrv_driver/xdrv_10_scripter.ino, fetch_jpg() functio…

Remote | Memory Corruption
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.3 HIGH
CVE-2026-36540 — Netis AC1200 Router Unauthenticated Command Injection Vulnerability

Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the /cgi-bin/skk_set.cgi endpoint. The password and new_pwd_confirm POST parameters are passed directly to …

Remote | Injection
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.3 HIGH
CVE-2026-36539 — Netis AC1200 Router Unauthenticated Configuration Disclosure

Netis AC1200 Router NC21 V4.0.1.4296 exposes a CGI endpoint /cgi-bin/skk_get.cgi that returns the entire router configuration as a JSON response with no authentication required. Any attacker on the L…

Remote | Information Disclosure
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.3 HIGH
CVE-2026-36538 — Netis AC1200 Router Root Credential Hard-Coded Vulnerability

Netis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential stored in /etc/shadow.sample. The password for the root account is set to the trivially weak value root, allowing an attacke…

Remote | Authentication
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.3 HIGH
CVE-2026-36045 — Picoclaw OS Command Injection

picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using a d…

Remote | Injection
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
8.8 HIGH
CVE-2026-36044 — Apex OS Command Injection Vulnerability

@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenati…

Remote | Injection
May 27, 2026 Jun 03, 2026
May 27, 2026
Jun 03, 2026
9.3 CRITICAL
CVE-2026-35090 — Authentication Bypass in Slican telephone exchanges

In Slican telephone exchanges it is possible to manage the control panel remotely. An unauthenticated attacker can connect to the modem via a telephone with a specific caller ID. This allows them to …

Remote | Authentication
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
8.7 HIGH
CVE-2026-35089 — Use of Weak Credentials in Slican telephone exchanges

In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can be obtained without authentication. An unauthenticated attacker can …

Remote | Authentication
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
9.3 CRITICAL
CVE-2026-35087 — Authentication Bypass in Slican telephone exchanges

Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter login credentials by executing the appropriate command. This issue was fixed…

ncp_firmware | Remote | Authentication
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
5.1 MEDIUM
CVE-2026-2607 — Multiple vulnerabilities in IBM MQ Operator and Queue manager container images

IBM MQ Operator SC2: v3.2.0 through 3.2.23CD:  v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0 - v3.7.2, v3.8.0, v3.8.1, v3.9.0, v3.9.1LTS: v2.0.0 - 2.0.29 and IBM supplied M…

May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
6.5 MEDIUM
CVE-2026-2340 — Samba: vfs_worm does not block directory modification

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to i…

May 27, 2026 Jun 04, 2026
May 27, 2026
Jun 04, 2026
6.9 MEDIUM
CVE-2026-23679 — libusb < 1.0.30 NULL Pointer Dereference in parse_interface()

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface cla…

libusb | Memory Corruption
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.1 HIGH
CVE-2026-1933 — Samba: missing access check on reparse point operations

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem wri…

May 27, 2026 Jun 04, 2026
May 27, 2026
Jun 04, 2026
7.5 HIGH
CVE-2026-1718 — IBM® Db2® is vulnerable to a denial of service with a specially crafted query when runnin…

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled.

linux_kernel db2 linux_on_ibm_z | Remote | Denial of Service
May 27, 2026 Jun 02, 2026
May 27, 2026
Jun 02, 2026
0.0 NA
CVE-2025-71312 — fs/ntfs3: fix ntfs_mount_options leak in ntfs_fill_super()

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix ntfs_mount_options leak in ntfs_fill_super() In ntfs_fill_super(), the fc->fs_private pointer is set to NULL withou…

linux_kernel | Memory Corruption
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
0.0 NA
CVE-2025-71311 — fs/ntfs3: Initialize new folios before use

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN reports an uninitialized value in longest_match_std(), invoked from ntfs_compres…

linux_kernel | Memory Corruption
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
0.0 NA
CVE-2025-71309 — fs/ntfs3: fix deadlock in ni_read_folio_cmpr

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix deadlock in ni_read_folio_cmpr Syzbot reported a task hung in ni_readpage_cmpr (now ni_read_folio_cmpr). This is ca…

linux_kernel | Race Condition
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
Showing 20 of 7089 Results