Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-59648 — OpenPGP Argon2 S2K honours attacker-chosen memory and passes

In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS…

Remote | Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.9 MEDIUM
CVE-2026-59647 — CRMF/CMP password-MAC honours unbounded iteration count

In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-…

Remote | Cryptography
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.7 HIGH
CVE-2026-59646 — DTLS handshake reassembler allocates buffer from unchecked 24-bit length

In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle f…

Remote | Memory Corruption
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.7 HIGH
CVE-2026-59645 — OER parser recurses without depth limit on self-referential IEEE 1609.2 schema

In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Ca…

Remote | Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.7 HIGH
CVE-2026-59644 — MLS hash-ratchet honours arbitrary 32-bit generation counter from sender

In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.

Remote | Cryptography
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.7 HIGH
CVE-2026-59643 — OpenPGP inline-signature policy failures silently ignored

In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.

Remote | Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.7 HIGH
CVE-2026-59642 — CMS AuthenticatedData content not bound to MAC when authAttrs present

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for …

Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.7 HIGH
CVE-2026-59641 — S/MIME validator trusts signer-asserted signingTime for path validation

In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle fo…

Remote | Cryptography
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.7 HIGH
CVE-2026-59640 — OpenPGP CFB quick-check oracle active on symmetric/session-key paths

In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for J…

Remote | Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.7 HIGH
CVE-2026-59639 — CMS verifySignatures returns true for SignedData with zero signers

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Jav…

Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
9.3 CRITICAL
CVE-2026-59638 — JSSE hostname verifier CN-fallback enabled by default despite documented opt-in

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy C…

Remote | Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
3.3 LOW
CVE-2026-18581 — ggml-org llama.cpp Jinja Minja Template parser.cpp assertion

A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinja Minja Template Parser. Ex…

llama.cpp | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
5.3 MEDIUM
CVE-2026-15055 — PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input

In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FI…

Remote | Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.1 HIGH
CVE-2026-12185 — BKS/UBER keystore allocates from untrusted lengths before integrity check

In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

Remote | Memory Corruption
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-3245 — PRISMAproduction Deserialization Arbitrary Code Execution

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

| Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.2 HIGH
CVE-2026-18577 — Incomplete patch leads to administrative account takeover

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

n-central | Remote | Authentication
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
7.0 HIGH
CVE-2026-10848 — Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)

The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message…

zephyr zephyr | Remote | Memory Corruption
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
7.1 HIGH
CVE-2026-9856 — Path Traversal in huggingface/transformers

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreT…

transformers | Remote | Path Traversal
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
9.8 CRITICAL
CVE-2026-65321 — PyAthena 3.35.4 SQL Injection via DefaultParameterFormatter DELETE/CTAS

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format…

Remote | Injection
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
2.4 LOW
CVE-2026-10774 — PSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoS

Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into a PS…

zephyr zephyr | Misconfiguration
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
Showing 20 of 9208 Results