Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54298
Total
4306
Critical
16144
High
15836
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84895 | UNKNOWN | — | In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which … | Sep 28, 2026 |
| CVE-2026-18416 | LOW | 3.7 | The CoAP link-format helper match_path_uri() in subsys/net/lib/coap/coap_link_format.c compares a registered resource path against the URI carried in a Uri-Query href= option. That URI is not … | Sep 28, 2026 |
| CVE-2026-18415 | MEDIUM | 6.3 | ieee802154_send() in subsys/net/l2/ieee802154/ieee802154.c copies the outgoing packet into a single fixed 125-byte transmit buffer (tx_frame_buf_pool, sized IEEE802154_MTU). In builds with CONFIG_NET_L2_IEEE802154_FRAGMENT enabled (the default whenever … | Sep 28, 2026 |
| CVE-2026-18414 | HIGH | 7.8 | The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h … | Sep 28, 2026 |
| CVE-2026-18413 | HIGH | 7.8 | The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h … | Sep 28, 2026 |
| CVE-2026-16513 | HIGH | 7.8 | The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c before v4.3.0) validated the RTIO object handle and the sqes input array, but not the handle out-parameter. On … | Sep 28, 2026 |
| CVE-2026-102279 | LOW | 3.1 | Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured … | Sep 28, 2026 |
| CVE-2026-102278 | HIGH | 7.5 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() … | Sep 28, 2026 |
| CVE-2026-102277 | MEDIUM | 5.3 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped … | Sep 28, 2026 |
| CVE-2026-102276 | HIGH | 7.5 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the … | Sep 28, 2026 |
| CVE-2026-102275 | MEDIUM | 6.5 | PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does … | Sep 28, 2026 |
| CVE-2026-102274 | MEDIUM | 5.9 | PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain ValueError raised for malformed RSA … | Sep 28, 2026 |
| CVE-2026-102273 | HIGH | 7.4 | PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because HMAC key guard only recognizes top-level … | Sep 28, 2026 |
| CVE-2026-102272 | HIGH | 7.4 | PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize … | Sep 28, 2026 |
| CVE-2026-102271 | HIGH | 7.4 | PyJWT is a Python implementation of JSON Web Token standards. From 2.4.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because asymmetric-key guard relies on textual markers … | Sep 28, 2026 |
| CVE-2026-102270 | MEDIUM | 4.4 | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because lazy PEM regular expression backtracks extensively. This … | Sep 28, 2026 |
| CVE-2026-102269 | MEDIUM | 4.8 | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside … | Sep 28, 2026 |
| CVE-2026-102268 | CRITICAL | 9.1 | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected because is_pem_format does not recognize every PEM … | Sep 28, 2026 |
| CVE-2026-102267 | HIGH | 7.4 | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect destinations are not revalidated against the … | Sep 28, 2026 |
| CVE-2026-102266 | HIGH | 7.4 | PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affected because PyJWK verification path used the decoded key … | Sep 28, 2026 |
| CVE-2026-102265 | MEDIUM | 5.3 | PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not … | Sep 28, 2026 |
| CVE-2026-102006 | MEDIUM | 5.5 | In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process management subsystem failing to properly release allocated kernel … | Sep 28, 2026 |
| CVE-2026-102005 | MEDIUM | 5.5 | Wind River VxWorks 7 24.03 through 26.03, a memory leak occurs under specific, non-default configuration states when processing specific service routines, causing the system to … | Sep 28, 2026 |
| CVE-2026-101918 | MEDIUM | 5.3 | PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_key_from_jwt is affected because payload parser catches ValueError but not … | Sep 28, 2026 |
| CVE-2026-101917 | MEDIUM | 5.3 | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT get_signing_key_from_jwt is affected because unknown kid misses force refreshes without a … | Sep 28, 2026 |