Live feed

CVE Feed

Last 30 days — 9,311 matching across all industries.

Showing 40

Auto-refreshupdated just now
CVE-2026-54836
CRITICAL· 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue affects YMC Filter: from n/a through 3.11.5.

29d ago
CVE-2026-54830
HIGH· 7.5

Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.

29d ago
CVE-2026-54829
HIGH· 7.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection. This issue affects WP Photo Album Plus: from n/a through 9.1.13.005.

29d ago
CVE-2026-54828
HIGH· 7.5

Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.

29d ago
CVE-2026-54823
CRITICAL· 9.9

Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.

29d ago
CVE-2026-54822
HIGH· 8.5

Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.

29d ago
CVE-2026-54821
HIGH· 7.4

Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.

29d ago
CVE-2026-52690
MEDIUM· 5.9

Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail.

29d ago
CVE-2026-4526
MEDIUM· 6.5

In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed.

silabs
29d ago
CVE-2026-49506
HIGH· 7.2

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

dell
29d ago
CVE-2026-47154
MEDIUM· 6.5

In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Simple Metering cluster may be impacted.

silabs
29d ago
CVE-2026-47153
MEDIUM· 6.5

In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.

silabs
29d ago
CVE-2026-47152
MEDIUM· 6.5

In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.

silabs
29d ago
CVE-2026-47151
HIGH· 7.1

In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is limited. These messages must come from a device that has already joined the network. Only devices supporting the Door Lock cluster may be impacted.

silabs
29d ago
CVE-2026-47150
HIGH· 7.1

In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The size and location of this write is limited. These messages must come from a device that has already joined the network. Only devices supporting the IAS Zone cluster may be impacted.

silabs
29d ago
CVE-2026-47149
MEDIUM· 6.5

In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Door Lock cluster may be impacted.

silabs
29d ago
CVE-2026-47148
MEDIUM· 6.5

In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed. Only devices supporting the Groups cluster may be impacted.

silabs
29d ago
CVE-2026-47147
HIGH· 7.1

In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is limited. These requests must come from a device that has already joined the network. Only devices supporting the OTA Server cluster may be impacted.

silabs
29d ago
CVE-2026-47146
MEDIUM· 6.5

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.

silabs
29d ago
CVE-2026-47145
MEDIUM· 6.5

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.

silabs
29d ago
CVE-2026-46734
HIGH· 7.3

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

dell
29d ago
CVE-2026-46733
HIGH· 7.8

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

dell
29d ago
CVE-2026-46732
MEDIUM· 6.7

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

dell
29d ago
CVE-2026-42390
MEDIUM· 5.3

An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.

29d ago
CVE-2026-42389
MEDIUM· 5.3

This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.

29d ago
CVE-2026-42388
MEDIUM· 5.9

Incomplete validation of the SOA record present in a catalog zone might lead to a crash.

29d ago
CVE-2026-42387
MEDIUM· 5.9

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input validation.

29d ago
CVE-2026-41120
CRITICAL· 9.8

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

dell
29d ago
CVE-2026-40012
MEDIUM· 5.3

ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;

29d ago
CVE-2026-2815
NONE

Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys

29d ago
CVE-2026-27366
HIGH· 7.5

Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.

29d ago
CVE-2026-12755
LOW· 2.7

Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host, exposing PAM provider credentials as a NTLMv2 challenge-response, via a crafted DomainName parameter.

devolutions
29d ago
CVE-2026-42004
LOW· 3.7

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.

29d ago
CVE-2026-40211
MEDIUM· 5.3

An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will be freed at the end of the QUIC connection, but on some setups it might be possible to open enough concurrent DoH3 streams to trigger an out-of-memory condition, resulting in a denial of service.

29d ago
CVE-2026-40210
MEDIUM· 4.8

An out-of-bounds read might happen when SetMacAddrAction is used, potentially resulting in uninitialized memory being sent over the network or a crash.

29d ago
CVE-2026-40209
MEDIUM· 5.3

An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by sending IXFR queries. This could be used to cause a denial of service if there is a limit to the number of concurrent connections to this backend, or if the process runs out of file descriptors.

29d ago
CVE-2026-40208
LOW· 3.7

An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame.

29d ago
CVE-2026-40011
LOW· 3.7

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.

29d ago
CVE-2026-33612
HIGH· 7.5

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.

29d ago
CVE-2026-42005
MEDIUM· 4.3

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

29d ago
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000