Vulnerabilities (CVE)

Total 398697 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-53472 2026-08-14 N/A 6.3 MEDIUM
A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authenticated attacker to store a malicious `javascript:` URL. When a victim views this URL in the Hybrid Cloud Console, it can lead to Cross-Site Scripting (XSS), enabling script execution in the victim's session and potentially disclosing sensitive information.
CVE-2026-18941 2026-08-14 N/A 7.7 HIGH
A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no security manager is installed. This default allows unauthenticated and unauthorized access to feature-server, registry-server, and offline-server endpoints. A remote attacker, by exploiting this missing authentication, could achieve remote code execution (RCE) by storing a malicious User-Defined Function (UDF) on the feature-server, trigger a denial of service (DoS) by forcing re-materialization of all tenant features, and gain unauthorized access to cross-tenant data.
CVE-2026-71218 2026-08-14 N/A 5.3 MEDIUM
A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS) through memory exhaustion, severe slowdown, or termination of the iperf3 service.
CVE-2026-19411 2026-08-14 N/A 3.9 LOW
A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack on a system that uses shim application for UEFI bootloader.
CVE-2026-18428 2026-08-14 N/A 8.8 HIGH
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint.
CVE-2026-27790 1 Gallagher 6 Command Centre, High Sec T20 Reader, High Sec T20 Reader Multi Tech and 3 more 2026-08-14 N/A 2.7 LOW
Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected: * 9.50 prior to vCR9.50.260616a (distributed in 9.50.1587(MR1)) * 9.40 prior to vCR9.40.260616a (distributed in 9.40.3130(MR3)) * 9.30 prior to vCR9.30.260616a (distributed in 9.30.3983(MR5)) * 9.20 prior to vCR9.20.260616a (distributed in 9.20.4349(MR7)) * all versions of 9.10 and prior.
CVE-2025-47147 1 Gallagher 1 Command Centre Mobile 2026-08-14 N/A 5.7 MEDIUM
Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration. This issue affects Command Centre Mobile Client versions prior to 9.40.123.
CVE-2026-27844 1 Gallagher 7 Command Centre, Controller 6000, Controller 7000 and 4 more 2026-08-14 N/A 2.7 LOW
Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denial of service.  Version of Command Centre affected: * 9.50 prior to vCR9.50.260616a (distributed in 9.50.1587(MR1)) * 9.40 prior to vCR9.40.260616a (distributed in 9.40.3130(MR3)) * 9.30 prior to vCR9.30.260616a (distributed in 9.30.3983(MR5)) * 9.20 prior to vCR9.20.260616a (distributed in 9.20.4349(MR7)) * all versions of 9.10 and prior.
CVE-2026-62815 1 Microsoft 6 Windows 11 23h2, Windows 11 24h2, Windows 11 25h2 and 3 more 2026-08-14 N/A 9.8 CRITICAL
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
CVE-2026-65788 1 Microsoft 5 Windows 11 23h2, Windows 11 24h2, Windows 11 25h2 and 2 more 2026-08-14 N/A 7.0 HIGH
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-58651 1 Microsoft 4 365 Apps, Microsoft 365, Office 2021 and 1 more 2026-08-14 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-72971 1 Microsoft 1 Windows 11 26h1 2026-08-14 N/A 5.5 MEDIUM
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
CVE-2026-70348 1 Microsoft 3 Windows 11 24h2, Windows 11 25h2, Windows 11 26h1 2026-08-14 N/A 5.5 MEDIUM
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
CVE-2025-14300 1 Tp-link 2 Tapo C200, Tapo C200 Firmware 2026-08-14 N/A 8.1 HIGH
The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).
CVE-2026-66804 1 Microsoft 4 Windows 10 22h2, Windows 11 24h2, Windows 11 25h2 and 1 more 2026-08-14 N/A 7.8 HIGH
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
CVE-2026-65656 1 Microsoft 4 365 Apps, Office 2019, Office 2021 and 1 more 2026-08-14 N/A 7.8 HIGH
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64909 1 Microsoft 6 365 Apps, Microsoft 365, Office 2016 and 3 more 2026-08-14 N/A 7.8 HIGH
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-65664 1 Microsoft 5 365 Apps, Microsoft 365, Office 2019 and 2 more 2026-08-14 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-66809 1 Microsoft 6 365 Apps, Microsoft 365, Office 2019 and 3 more 2026-08-14 N/A 5.5 MEDIUM
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70317 1 Microsoft 6 365 Apps, Microsoft 365, Office 2016 and 3 more 2026-08-14 N/A 5.5 MEDIUM
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.