Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56672
Total
4490
Critical
16802
High
16633
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-25294 | HIGH | 7.4 | Transient DOS while parsing frame during channel usage. | Sep 17, 2026 |
| CVE-2026-25290 | HIGH | 7.8 | Memory Corruption when validating large data buffers from external sources using addition to check buffer length. | Sep 17, 2026 |
| CVE-2026-25284 | HIGH | 7.3 | Information Disclosure when a pointer is reused after being deallocated. | Sep 17, 2026 |
| CVE-2026-25283 | HIGH | 8.8 | Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size. | Sep 17, 2026 |
| CVE-2026-25282 | HIGH | 7.9 | Transient DOS when processing unverified data from a neighboring system causes out of bound memory access. | Sep 17, 2026 |
| CVE-2026-25281 | HIGH | 7.4 | Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation. | Sep 17, 2026 |
| CVE-2026-25280 | HIGH | 7.8 | Memory corruption when processing escape handling flow with insufficient user buffer sizes. | Sep 17, 2026 |
| CVE-2026-25278 | HIGH | 7.8 | Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying. | Sep 17, 2026 |
| CVE-2026-25275 | HIGH | 7.5 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. | Sep 17, 2026 |
| CVE-2026-25261 | MEDIUM | 6.7 | Memory corruption while processing rear sensor IOCTL calls. | Sep 17, 2026 |
| CVE-2026-24081 | HIGH | 7.4 | Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled. | Sep 17, 2026 |
| CVE-2026-24075 | HIGH | 7.8 | Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions. | Sep 17, 2026 |
| CVE-2026-24074 | HIGH | 7.8 | Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations. | Sep 17, 2026 |
| CVE-2026-24073 | HIGH | 7.8 | Memory corruption when processing decode statistics due to insufficient validation of offset against structure size. | Sep 17, 2026 |
| CVE-2025-59607 | HIGH | 7.8 | Memory Corruption when copying large input data exceeds normal allocation limits. | Sep 17, 2026 |
| CVE-2026-92839 | MEDIUM | 4.3 | Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the … | Sep 17, 2026 |
| CVE-2026-86311 | MEDIUM | 6.4 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions … | Sep 17, 2026 |
| CVE-2026-50603 | UNKNOWN | — | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a … | Sep 17, 2026 |
| CVE-2026-89064 | MEDIUM | 5.3 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.110. This is due … | Sep 17, 2026 |
| CVE-2026-92838 | HIGH | 7.8 | A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search … | Sep 17, 2026 |
| CVE-2026-81546 | HIGH | 7.7 | The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based … | Sep 17, 2026 |
| CVE-2026-85789 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 16, 2026 |
| CVE-2026-65388 | HIGH | 7.5 | A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and … | Sep 16, 2026 |
| CVE-2026-61599 | UNKNOWN | — | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the djust live transport resolves the LiveView to mount … | Sep 16, 2026 |
| CVE-2026-61596 | HIGH | 7.1 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced … | Sep 16, 2026 |