Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26387
Total
1955
Critical
7970
High
8222
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-42789 | UNKNOWN | — | Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate … | May 27, 2026 |
| CVE-2026-3676 | MEDIUM | 6.5 | IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could … | May 27, 2026 |
| CVE-2026-3623 | HIGH | 7.8 | IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker with low‑privileged access to escalate their privileges to root. By exploiting this flaw, … | May 27, 2026 |
| CVE-2026-3366 | HIGH | 7.5 | IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, 1.0.2.7 could allow a remote attacker to traverse directories on … | May 27, 2026 |
| CVE-2026-38427 | HIGH | 7.3 | An issue in fetch_jpg() in xdrv_10_scripter.ino in Tasmota through 15.3.0.3 allows a remote attacker to cause heap buffer overflow. The Content-Length from a JPEG stream … | May 27, 2026 |
| CVE-2026-38426 | HIGH | 7.3 | Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the xdrv_10_scripter.ino, fetch_jpg(), jpg_task.boundary[40], strcpy() function. | May 27, 2026 |
| CVE-2026-38422 | UNKNOWN | — | Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the tasmota/tasmota_xdrv_driver/xdrv_10_scripter.ino, fetch_jpg() function. | May 27, 2026 |
| CVE-2026-36540 | UNKNOWN | — | Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the /cgi-bin/skk_set.cgi endpoint. The password and new_pwd_confirm POST parameters are passed directly to … | May 27, 2026 |
| CVE-2026-36539 | UNKNOWN | — | Netis AC1200 Router NC21 V4.0.1.4296 exposes a CGI endpoint /cgi-bin/skk_get.cgi that returns the entire router configuration as a JSON response with no authentication required. Any … | May 27, 2026 |
| CVE-2026-36538 | UNKNOWN | — | Netis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential stored in /etc/shadow.sample. The password for the root account is set to the trivially weak … | May 27, 2026 |
| CVE-2026-36045 | UNKNOWN | — | picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using … | May 27, 2026 |
| CVE-2026-36044 | HIGH | 8.8 | @pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenating unsanitized … | May 27, 2026 |
| CVE-2026-35090 | UNKNOWN | — | In Slican telephone exchanges it is possible to manage the control panel remotely. An unauthenticated attacker can connect to the modem via a telephone with … | May 27, 2026 |
| CVE-2026-35089 | UNKNOWN | — | In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can be obtained without authentication. An … | May 27, 2026 |
| CVE-2026-35087 | UNKNOWN | — | Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter login credentials by executing the appropriate command. This issue … | May 27, 2026 |
| CVE-2026-2607 | MEDIUM | 5.1 | IBM MQ Operator SC2: v3.2.0 through 3.2.23CD: v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0 - v3.7.2, v3.8.0, v3.8.1, v3.9.0, v3.9.1LTS: v2.0.0 … | May 27, 2026 |
| CVE-2026-2340 | MEDIUM | 6.5 | A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a … | May 27, 2026 |
| CVE-2026-23679 | MEDIUM | 6.2 | libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an … | May 27, 2026 |
| CVE-2026-1933 | HIGH | 7.1 | A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, … | May 27, 2026 |
| CVE-2026-1718 | HIGH | 7.1 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are … | May 27, 2026 |
| CVE-2025-71312 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix ntfs_mount_options leak in ntfs_fill_super() In ntfs_fill_super(), the fc->fs_private pointer is set to NULL … | May 27, 2026 |
| CVE-2025-71311 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN reports an uninitialized value in longest_match_std(), invoked from … | May 27, 2026 |
| CVE-2025-71309 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix deadlock in ni_read_folio_cmpr Syzbot reported a task hung in ni_readpage_cmpr (now ni_read_folio_cmpr). This … | May 27, 2026 |
| CVE-2025-71308 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix potential NULL pointer dereference in context cleanup aie_destroy_context() is invoked during error handling … | May 27, 2026 |
| CVE-2025-71307 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix NULL pointer dereference on panthor_fw_unplug This patch removes the MCU halt and wait … | May 27, 2026 |