Tagged “cve.org”
CVEs tagged cve.org, newest first.
15880 CVEsRSS
CVE-2026-25261Medium· 6.7Memory corruption while processing rear sensor IOCTL calls.
Memory corruption while processing rear sensor IOCTL calls.
CVE-2025-59607High· 7.8Memory Corruption when copying large input data exceeds normal allocation limits.
Memory Corruption when copying large input data exceeds normal allocation limits.
CVE-2026-25281High· 7.4Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
CVE-2026-25275High· 7.5Transient DOS when processing authentication frames with invalid FILS information element header lengths.
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-25282High· 7.9Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
CVE-2026-25278High· 7.8Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
CVE-2026-25290High· 7.8Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
CVE-2026-25284High· 7.3Information Disclosure when a pointer is reused after being deallocated.
Information Disclosure when a pointer is reused after being deallocated.
CVE-2026-25283High· 8.8Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
CVE-2026-25294High· 7.4Transient DOS while parsing frame during channel usage.
Transient DOS while parsing frame during channel usage.
CVE-2026-25280High· 7.8Memory corruption when processing escape handling flow with insufficient user buffer sizes.
Memory corruption when processing escape handling flow with insufficient user buffer sizes.
CVE-2026-87935High· 8.1The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function
The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_…
CVE-2026-87796Critical· 9.8PoCThe Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked uplo…
CVE-2026-86311Medium· 6.4The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization…
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization…
CVE-2026-92839Medium· 4.3Canva Desktop before v1.125.0 performed double decoding in the deeplink handler
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.
CVE-2026-50603Medium· 4.9A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstance…
CVE-2026-89064Medium· 5.3The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.110
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.110. This is due to the `Ai1wm_Main_Controller::init()` method — registered on the `admin…
CVE-2026-81546High· 7.7The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow
The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity documen…
CVE-2026-92838High· 7.8A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application
A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in …
CVE-2026-55061Low· 1.0uniget is a universal installer and updater for (container) tools
uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go parses UNIGET_EDITOR or EDITOR with strings.Split(editor, " ") and passes every space-delimited suffix as a…
CVE-2026-55062High· 8.4PoCuniget is a universal installer and updater for (container) tools
uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory comp…
CVE-2026-54546Medium· 5.0PoCCloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK
CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22.1, the authenticated PUT /api/basemap endpoint passes an attacker-controlled URL through importBasemapURL() in api/ro…
CVE-2026-50285High· 7.5PoCPomerium is an identity and context-aware access proxy
Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs zstd decompression of attacker-controlled data without an output-memory limit when DecryptURLValues processes HPKE V…
CVE-2026-54504High· 8.8PoCMCP Documentation Server is a local-first document management and semantic search server for AI coding agents
MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/server.ts calls startWebServer in src/web-server.ts with STA…
CVE-2026-54495Medium· 4.3The OpenFeature Operator allows users to expose feature flags to applications
The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant who can create a controller-owned workload can use the openfeature.dev/featureflagsource annotation with NAMESPACE/NAME…
CVE-2026-54451High· 8.2PoCElixir protobuf is a pure Elixir implementation of Google Protobuf
Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains a self-referential o…
CVE-2026-54446High· 8.1PoCNetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing
NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing. Prior to 0.1.6, network-reachable HTTP transport requests to /mcp that omit x-ne…
CVE-2026-50158High· 7.7yutu is an AI-powered toolkit for managing and growing YouTube channels
yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool accepts a caller-controlled file parameter through cmd/caption/download.go and passes it to Caption.Download() in pkg…
CVE-2026-50125High· 7.5PoCMKP is a Model Context Protocol server for Kubernetes
MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpoint and pkg/mcp/server.go registers the unauthenticated get_resource tool, which accepts attacker-controlled limitByt…
CVE-2026-47252Critical· 9.0PoCAnyquery is an SQL query engine built on top of SQLite
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-system commands because the Chrome plugin and equivalent Brav…