Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-108978 — Samsung rlottie Heap-based Buffer Overflow

Heap-based buffer overflow vulnerability in Samsung Opensource rlottie allows Buffer Overflow via Environment Variables. This issue affects rlottie: e57b094f03c39a751a1fded6f7d6c13f1ed95ec9.

| Memory Corruption
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.3 MEDIUM
CVE-2026-108769 — zhayujie CowAgent Markdown Rendering Markdown.tsx denial of service

A security flaw has been discovered in zhayujie CowAgent up to 2.2.0. This affects an unknown part of the file Markdown.tsx of the component Markdown Rendering. The manipulation results in denial of …

cowagent | Remote | Denial of Service
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
0.0 NA
CVE-2026-108770 — Appwrite Browser Screenshot Service Get.php PublicHostname server-side request forgery

A weakness has been identified in Appwrite up to 2.3.0. This vulnerability affects the function PublicHostname of the file src/Appwrite/Platform/Modules/Avatars/Http/Screenshots/Get.php of the compon…

| Server-Side Request Forgery
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.8 HIGH
CVE-2026-108976 — GNU Emacs TRAMP OS Command Injection

GNU Emacs before 31.2 (and TRAMP through 2.8.2) allows OS command injection via a filename because tramp-user-regexp has an incomplete list of disallowed inputs. NOTE: this issue exists because of an…

emacs | Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.8 HIGH
CVE-2026-108963 — Databasement Argument Injection Remote Code Execution

databasement before 1.8.2 allows remote code execution because it runs certain commands (e.g., mariadb-dump) with a database name that can be specified by any authenticated user. For example, --resul…

databasement | Remote | Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.1 MEDIUM
CVE-2026-108925 — Cohesity - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Bas…

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Cohesity NetBackup Administration Console web interface. This issue affects NetBackup Administration Co…

Remote | Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.3 MEDIUM
CVE-2026-108768 — zhayujie CowAgent Streaming Tool-Call Argument json.loads allocation of resources

A vulnerability was identified in zhayujie CowAgent up to 2.2.0. Affected by this issue is the function json.loads of the component Streaming Tool-Call Argument Handler. The manipulation leads to all…

cowagent | Remote | Denial of Service
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.9 MEDIUM
CVE-2026-59508 — Interuse i-Bos CWE-89: Improper Neutralization of Special Elements used in an SQL Command…

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Interuse i-Bos. This issue affects i-Bos: 3.0.

Remote | Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.5 HIGH
CVE-2026-19935 — Use-after-free of an L2CAP CoC channel object in the Zephyr Bluetooth host: RX work item …

The Bluetooth LE host queues received L2CAP connection-oriented channel (CoC) data for deferred processing through a struct k_work embedded in the channel object (le_chan->rx_work, handler l2cap_rx_p…

zephyr zephyr | Race Condition
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.5 MEDIUM
CVE-2026-19740 — Bluetooth LE Controller: retained RX node leak and reachable assertion in the PHY Update …

The Link Layer Control Procedure (LLCP) implementation of the Zephyr software Bluetooth LE Controller retains the receive node that carried an accepted LL_PHY_UPDATE_IND so that it can later be reuse…

zephyr zephyr | Denial of Service
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.5 MEDIUM
CVE-2026-19739 — Bluetooth LE controller leaks a retained RX node when an unexpected LL Control PDU arrive…

The Bluetooth Link Layer control procedure code in subsys/bluetooth/controller/ll_sw/ull_llcp_conn_upd.c retains the received RX node while a Connection Update / Connection Parameter procedure waits …

zephyr zephyr | Denial of Service
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.5 MEDIUM
CVE-2026-19738 — Retained RX node leak and reachable assertion in Bluetooth Controller CIS Create procedur…

The Bluetooth Link Layer Control Procedure (LLCP) implementation for Connected Isochronous Stream (CIS) creation retains an RX node (ctx->node_ref.rx, marked NODE_RX_TYPE_RETAIN) so it can later be r…

zephyr zephyr | Memory Corruption
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.5 MEDIUM
CVE-2026-19737 — NULL pointer dereference in the ESP32 I2S driver when triggering an unsupported direction

i2s_esp32_trigger_check() in drivers/i2s/i2s_esp32.c validates the requested direction only for I2S_DIR_BOTH. The I2S_DIR_RX and I2S_DIR_TX branches read dev_cfg->rx.data->configured / dev_cfg->tx.da…

zephyr zephyr | Denial of Service
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.8 HIGH
CVE-2026-19736 — Out-of-bounds write in the NXP MCUX TRNG entropy driver for non-word-multiple request len…

The NXP MCUX TRNG entropy driver in drivers/entropy/entropy_mcux_trng.c passed the caller's byte count straight to the vendor SDK routine TRNG_GetRandomData(). On i.MX RT5xx and RT6xx parts the SDK c…

zephyr zephyr | Memory Corruption
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.8 MEDIUM
CVE-2026-19735 — Predictable TCP initial sequence numbers when the RFC 6528 secret key generation fails si…

The RFC 6528 initial-sequence-number implementation in subsys/net/ip/tcp.c derived every TCP ISN from SHA-256(unique_key || four-tuple) plus a uptime-derived offset, where unique_key is a 128-bit sec…

zephyr zephyr | Cryptography
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.8 HIGH
CVE-2026-19669 — Unbounded variable-length array in fuel gauge syscall verifiers allows kernel stack overf…

The user-mode syscall verifiers z_vrfy_fuel_gauge_get_props() and z_vrfy_fuel_gauge_set_props() in drivers/fuel_gauge/fuel_gauge_syscall_handlers.c declared two variable-length arrays, union fuel_gau…

zephyr zephyr | Memory Corruption
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.1 HIGH
CVE-2026-19577 — Out-of-bounds read in IPv6 route forwarding when the nexthop neighbor has no link-layer a…

net_route_ipv6_packet() in subsys/net/ip/route_ipv6.c resolved the nexthop's link-layer address with net_nbr_get_lladdr(nbr->idx) without first checking whether the neighbor cache entry actually had …

zephyr zephyr | Memory Corruption
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.8 MEDIUM
CVE-2026-19576 — Stack out-of-bounds write in the Goodix GT911 touch controller driver from an unvalidated…

The Goodix GT9xx input driver in drivers/input/input_gt911.c reads the touch point count from the controller's status register and masks it with GT911_TOUCH_POINTS_MSK (0x0F), yielding a value of 0..…

zephyr zephyr | Memory Corruption
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
3.4 LOW
CVE-2026-18418 — Out-of-bounds read when the zbus proxy agent IPC backend logs a rejected peer frame's cha…

The zbus proxy agent IPC backend in subsys/zbus/proxy_agent/zbus_proxy_agent_ipc.c logged the channel name of a rejected inter-domain frame with a plain %s conversion. The frame type struct zbus_prox…

zephyr zephyr | Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.1 HIGH
CVE-2026-108913 — Omarchy Arbitrary Code Execution Vulnerability

omarchy-theme-set in Omarchy 4 before 4.0.1 allows code execution via a third-party theme because the files placed into ~/.local/state/omarchy/current/theme may include executable content from an unt…

Remote | Supply Chain
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
Showing 20 of 13655 Results