Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.7 HIGH
CVE-2026-14903 — Ivanti Xtraction Path Traversal Vulnerability

Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.

xtraction | Remote | Path Traversal
Jul 14, 2026 Aug 06, 2026
Jul 14, 2026
Aug 06, 2026
6.1 MEDIUM
CVE-2026-14902 — Ivanti Xtraction Open Redirect Vulnerability

An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs.

xtraction | Remote | Misconfiguration
Jul 14, 2026 Aug 06, 2026
Jul 14, 2026
Aug 06, 2026
8.8 HIGH
CVE-2026-10714 — Rockwell Automation FactoryTalk® Services Platform FTSP - Weak Authentication via JWT Val…

A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the applicat…

Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
9.1 CRITICAL
CVE-2026-10672 — Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI)

subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, size CONFIG_LWM2M_SWMGMT_PACKAGE_URI_LEN, default 128) with memcpy(context.ur…

zephyr zephyr | Remote | Information Disclosure
Jul 14, 2026 Aug 06, 2026
Jul 14, 2026
Aug 06, 2026
7.1 HIGH
CVE-2026-10671 — User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_…

In Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_pipe_init() in kernel/pipe.c used K_SYSCALL_OBJ() (which requires the kernel object to already be initialized) instead …

zephyr zephyr | Misconfiguration
Jul 14, 2026 Aug 06, 2026
Jul 14, 2026
Aug 06, 2026
5.5 MEDIUM
CVE-2026-10670 — User-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall …

The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system call (z_vrfy_k_thread_name_copy() in kernel/thread.c) calls k_object_find() on the caller-supplied thread pointer and the…

zephyr zephyr | Misconfiguration
Jul 14, 2026 Aug 06, 2026
Jul 14, 2026
Aug 06, 2026
7.8 HIGH
CVE-2026-10669 — Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall po…

On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/mpu.c — the architecture hook that verifies a user-mode-supplied buffer is accessible to t…

zephyr zephyr | Memory Corruption
Jul 14, 2026 Aug 06, 2026
Jul 14, 2026
Aug 06, 2026
8.7 HIGH
CVE-2026-10573 — 1734 POINT I/OTM - Denial of Service via Malformed Inputs on CIP Object

A denial-of-service security issue exists in 1734 POINT I/O™ module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A re…

Remote | Denial of Service
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
9.2 CRITICAL
CVE-2025-12012 — CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow

A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a…

Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
9.2 CRITICAL
CVE-2025-12011 — CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow

A denial-of-service issue exists in  5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fa…

Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
6.8 MEDIUM
CVE-2026-53566 — Out-of-bounds memory read

Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20.

| Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
9.0 HIGH
CVE-2026-15693 — Tenda BE12 Pro SafeMacFilter fromSafeMacFilter stack-based overflow

A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. This issue affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page le…

Remote | Memory Corruption
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
7.3 HIGH
CVE-2026-8314 — Rockwell Automation Arena® - Memory Corruption Vulnerability

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, w…

arena arena_simulation | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.3 HIGH
CVE-2026-8313 — Rockwell Automation Arena® - Memory Corruption Vulnerability

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, …

arena arena_simulation | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.3 HIGH
CVE-2026-8312 — Rockwell Automation Arena® - Memory Corruption Vulnerability

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, w…

arena | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.3 HIGH
CVE-2026-8085 — Rockwell Automation Arena® - Memory Corruption Vulnerability

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, w…

arena arena_simulation | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
4.3 MEDIUM
CVE-2026-62393 — Apache Kylin: Improper authorization in job information retrieval

Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs i…

kylin | Remote | Authorization
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
9.8 CRITICAL
CVE-2026-62392 — Apache Kylin: OS Command Injection via Async Query API

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue…

kylin | Remote | Injection
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
9.8 CRITICAL
CVE-2026-62390 — Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL…

kylin | Remote | Injection
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
8.5 HIGH
CVE-2026-53565 — Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges

Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. This issue affects Secure Access Client for Windows: befor…

| Authorization
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
Showing 20 of 10907 Results