Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-34681 — Substance3D - Designer | Out-of-bounds Write (CWE-787)

Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

substance_3d_designer | Memory Corruption
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
6.3 MEDIUM
CVE-2026-34664 — Substance3D - Designer | Improper Limitation of a Pathname to a Restricted Directory ('Pa…

Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file sy…

substance_3d_designer | Path Traversal
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
9.3 CRITICAL
CVE-2026-34660 — Adobe Connect | Incorrect Authorization (CWE-863)

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An …

connect connect_desktop_application | Remote | Authorization
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
9.6 CRITICAL
CVE-2026-34659 — Adobe Connect | Deserialization of Untrusted Data (CWE-502)

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current …

connect connect_desktop_application | Remote | Memory Corruption
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
7.2 HIGH
CVE-2026-23823 — Authenticated Command Injection leads to RCE in AOS-10 CLI Command

A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacke…

Remote | Injection
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
5.3 MEDIUM
CVE-2026-23822 — Unauthenticated XML External Entity Injection in AOS-8 Instant allows Denial of Service

A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an at…

Remote | Denial of Service
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
7.2 HIGH
CVE-2026-23821 — Inconsistent input filtering allows Authenticated Command Injection in AOS-10 CLI

A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Su…

Remote | Injection
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
7.2 HIGH
CVE-2026-23820 — Inconsistent input filtering allows Authenticated Command Injection in AOS-8 Instant and …

A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environme…

Remote | Injection
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.8 HIGH
CVE-2026-23819 — Error in SSID Processing allows Stored XSS in Web Management Interface

A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim…

| Cross-Site Scripting
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
Showing 20 of 7149 Results