Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.0 HIGH
CVE-2026-81192 — OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijack…

`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS. Prior to version 1.16.0-beta.2,…

| Misconfiguration
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.5 MEDIUM
CVE-2026-80162 — Acrobat Reader | Use After Free (CWE-416)

Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploi…

acrobat acrobat_reader | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.8 HIGH
CVE-2026-80161 — Acrobat Reader | Access of Resource Using Incompatible Type ('Type Confusion') (CWE-843)

Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. An attac…

acrobat acrobat_reader | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.5 MEDIUM
CVE-2026-80160 — Acrobat Reader | Out-of-bounds Read (CWE-125)

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. E…

acrobat acrobat_reader | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
4.0 MEDIUM
CVE-2026-80159 — Acrobat Reader | Untrusted Search Path (CWE-426)

Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability to gain elevated acc…

acrobat acrobat_reader | Misconfiguration
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.5 MEDIUM
CVE-2026-79910 — Acrobat Reader | Out-of-bounds Read (CWE-125)

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. E…

acrobat acrobat_reader | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.8 HIGH
CVE-2026-79909 — Acrobat Reader | Use After Free (CWE-416)

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in …

acrobat acrobat_reader | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.8 HIGH
CVE-2026-79908 — Acrobat Reader | Out-of-bounds Write (CWE-787)

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti…

acrobat acrobat_reader | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.8 HIGH
CVE-2026-79907 — Acrobat Reader | Double Free (CWE-415)

Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in tha…

acrobat acrobat_reader | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
0.0 NA
CVE-2026-79588 — U-speed WIFI4 N300 T1 Pro Cleartext Transmission of Credentials

U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP.

| Misconfiguration
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
0.0 NA
CVE-2026-78971 — Halo Arbitrary Command Execution via Plugin Management

In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions.

| Supply Chain
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
0.0 NA
CVE-2026-78742 — Silverpeas Core Cross-Site Scripting

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.

| Cross-Site Scripting
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
0.0 NA
CVE-2026-78741 — Silverpeas Core Cross-Site Scripting Vulnerability

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.

| Cross-Site Scripting
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
0.0 NA
CVE-2026-78738 — Silverpeas Core Cross-Site Scripting Vulnerability

Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature.

| Cross-Site Scripting
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.0 MEDIUM
CVE-2026-78635 — Improper Input Validation in the Okta Privileged Access SSH Client URL Handler Argument

The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a …

Remote | Misconfiguration
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.3 MEDIUM
CVE-2026-78631 — Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Logging

The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information…

| Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.7 MEDIUM
CVE-2026-78630 — Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing

The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to construct OS commands. An authenticated local user with access to…

access_gateway | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.6 MEDIUM
CVE-2026-78629 — Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling

The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean …

| Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.0 MEDIUM
CVE-2026-78622 — Improper Link Resolution in Okta Verify for Windows Uninstaller Data Removal

The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows th…

| Path Traversal
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.4 HIGH
CVE-2026-77827 — Maono Link local privilege escalation

Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'. Fixed in 4.0.80.

| Misconfiguration
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
Showing 20 of 13962 Results