Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54274
Total
4303
Critical
16132
High
15830
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84414 | HIGH | 7.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of … | Sep 29, 2026 |
| CVE-2026-12345 | UNKNOWN | — | The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a … | Sep 29, 2026 |
| CVE-2026-102811 | HIGH | 7.5 | Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content … | Sep 29, 2026 |
| CVE-2026-102810 | HIGH | 7.5 | Marmite through 0.4.2 contains a path traversal vulnerability in the development server started by --serve that allows unauthenticated attackers to read arbitrary files. The handle_request … | Sep 29, 2026 |
| CVE-2026-102809 | MEDIUM | 6.5 | PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation vulnerability in the file2 test command that fails to validate the write chunk size parameter. Attackers … | Sep 29, 2026 |
| CVE-2026-102808 | MEDIUM | 6.5 | PX4 Autopilot through 1.17.0 contains a NULL pointer dereference vulnerability in the sd_stress command where the -b byte count parameter is parsed without validation before … | Sep 29, 2026 |
| CVE-2026-102807 | MEDIUM | 5.3 | OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped operators to execute MCP App tools requiring operator.write scope. Attackers … | Sep 29, 2026 |
| CVE-2026-102806 | MEDIUM | 6.3 | OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that breaks filesystem isolation between sandboxed sessions. Sandboxed sessions or … | Sep 29, 2026 |
| CVE-2026-102762 | UNKNOWN | — | The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from … | Sep 29, 2026 |
| CVE-2026-102761 | UNKNOWN | — | NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound … | Sep 29, 2026 |
| CVE-2026-102760 | UNKNOWN | — | When NetX Secure is built with `NX_SECURE_KEY_CLEAR`, every TLS record sent on an active session is wiped after it has been handed to TCP. By … | Sep 29, 2026 |
| CVE-2026-102759 | UNKNOWN | — | NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated … | Sep 29, 2026 |
| CVE-2026-102758 | UNKNOWN | — | The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and … | Sep 29, 2026 |
| CVE-2026-102757 | UNKNOWN | — | An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that … | Sep 29, 2026 |
| CVE-2026-102730 | UNKNOWN | — | Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer … | Sep 29, 2026 |
| CVE-2026-102729 | UNKNOWN | — | `gx_binres_theme_load()` sizes its theme buffer for the theme it was asked for, and allocates it even when the resource holds no theme with that id. … | Sep 29, 2026 |
| CVE-2026-102728 | UNKNOWN | — | Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. … | Sep 29, 2026 |
| CVE-2026-102727 | UNKNOWN | — | FTP Passive Data Connection Not Bound to the Authenticated Control Peer | Sep 29, 2026 |
| CVE-2026-102726 | UNKNOWN | — | Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read | Sep 29, 2026 |
| CVE-2026-102725 | UNKNOWN | — | Out-of-bounds Read from Unvalidated MSRP Attribute List Length | Sep 29, 2026 |
| CVE-2026-102724 | UNKNOWN | — | NULL Pointer Dereference When Evicting the Sole MSRP Attribute | Sep 29, 2026 |
| CVE-2026-102723 | UNKNOWN | — | NULL Pointer Dereference on MSRP Attribute Table Exhaustion | Sep 29, 2026 |
| CVE-2026-102722 | UNKNOWN | — | In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the … | Sep 29, 2026 |
| CVE-2026-102721 | UNKNOWN | — | A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path … | Sep 29, 2026 |
| CVE-2026-102720 | UNKNOWN | — | A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a kilobyte past the end of … | Sep 29, 2026 |