Critical Infrastructure Vulnerability Intelligence

Advisories for Industrial Defenders

Compiled, structured vulnerability reports for operational technology and industrial control system security teams.

31
KEV Listed
34
Exploited
4
EPSS-Imminent
508
Total Advisories
Filter by Sector
ChemicalCommercialCommunicationsManufacturingDamsDefense IndustrialEmergency SvcsEnergyFinancial SvcsFood & AgGovernmentHealthcareInfo TechnologyNuclearTransportationWater
Filter by Status
OT runs on IT. While they aren't ICS products, a vulnerability in the underlayer can breach the whole system. We track them separately so this index stays ICS/OT. But we want you to have the option to see supporting infrastructure when you need to. Don't expect to find every OS, firewall, or embedded kernel vulnerability here. These are the ones that most impact OT. Switch views to see them.
FromToShow
UpdatedAdvisory IDTitleCVSSStatus
2026-10-09CVE-2026-15688Mitsubishi Electric GX Works3 Block Password Validation Bypassed via In-Memory Executable Modification, Letting Local Users View, Tamper with, or Delete Control Programs9.2 CriticalUpdated
2026-10-08CVE-2026-34499Johnson Controls ADVMS Embeds a Hard-Coded Cryptographic Key, Exposing Sensitive Key Material to Local Low-Privilege Users on Versions Before 3.108.5 HighUpdated
2026-10-07CVE-2026-107194Sungrow iSolarCloud login_type Authentication Bypass Enables Account Takeover on Solar Grid Infrastructure, with NVD Citing Potential for Europe-Wide Outages9.2 CriticalUpdated
2026-10-06CVE-2026-98050CVE-2026-980507.5 HighUpdated
2026-10-06CVE-2026-94293Murrelektronik AAS Edge Client All Versions Allow Unauthenticated Remote Attacker to Read and Modify Asset Administration Shell Submodel Data9.8 CriticalUpdated
2026-10-06CVE-2026-79655CVE-2026-796557.8 HighUpdated
2026-10-06CVE-2026-7507CVE-2026-75077.5 HighUpdated
2026-10-06CVE-2026-74860CVE-2026-748608.5 HighUpdated
2026-10-06CVE-2026-7307CVE-2026-73077.5 HighUpdated
2026-10-06CVE-2026-56211Red Hat AI Inference Server 3.3 libaom Remote Code Execution Reachable by Unauthenticated Remote Attackers (CVSS 7.1)7.1 HighUpdated
2026-10-06CVE-2026-56210Red Hat AI Inference Server 3.3 libaom Denial of Service Reachable by Unauthenticated Remote Attackers (CVSS 7.1)7.1 HighUpdated
2026-10-06CVE-2026-56209Red Hat AI Inference Server 3.3 libaom Arbitrary Filesystem Write Reachable by Unauthenticated Remote Attackers (CVSS 7.1)7.1 HighUpdated
2026-10-06CVE-2026-56208Red Hat AI Inference Server 3.3 libaom Buffer Overflow Reachable by Unauthenticated Remote Attackers (CVSS 7.6)7.6 HighUpdated
2026-10-06CVE-2026-4634CVE-2026-46347.5 HighUpdated
2026-10-05CVE-2026-97185CVE-2026-971857.8 HighUpdated
2026-10-05CVE-2026-96512CVE-2026-965127.8 HighUpdated
2026-10-05CVE-2026-92248CVE-2026-922487.8 HighUpdated
2026-10-05CVE-2026-90948CVE-2026-909487.8 HighUpdated
2026-10-05CVE-2026-90947CVE-2026-909477.8 HighUpdated
2026-10-05CVE-2026-89793CVE-2026-897937.8 HighUpdated
2026-10-05CVE-2026-89058CVE-2026-890587.4 HighUpdated
2026-10-05CVE-2026-76561CVE-2026-765617.2 HighUpdated
2026-10-05CVE-2026-64042CVE-2026-640428.8 HighUpdated
2026-10-05CVE-2026-64041CVE-2026-640417.8 HighUpdated
2026-10-04CVE-2026-86060MikroTik RouterOS's Argument Injection in a Command-Processing Component Allows Unauthenticated Attackers to Execute Arbitrary Commands on the Router; CISA's September 13th KEV Deadline Has Passed9.8 CriticalKEV
2026-10-04CVE-2026-67276MikroTik RouterOS SSH Key Comparison Omits RSA Exponent, Letting an Attacker with a Known Modulus Authenticate as Another User8.1 HighEPSS-Imminent
2026-10-04CVE-2026-20181Cisco Identity Services Engine Authenticated Admin Command Injection Enables Arbitrary OS Command Execution on the Underlying System9.1 CriticalEPSS-Imminent
2026-10-03CVE-2026-98154Linux Kernel nvme-rdma: Failure to Fix -EIO cleanup order in queue_rq7.0 HighUpdated
2026-10-03CVE-2026-98130Linux Kernel sctp: Failure to Fix a TOCTOU race in SCTP_CMD_TIMER_START, Reachable from the Network Without Credentials (CVSS 8.1)8.1 HighUpdated
2026-10-03CVE-2026-98122Linux Kernel vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()7.8 HighUpdated
2026-10-03CVE-2026-98116Linux Kernel ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF7.8 HighUpdated
2026-10-03CVE-2026-98108Linux Kernel Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan7.5 HighUpdated
2026-10-03CVE-2026-98096Linux Kernel ipv6: sr: restore network header before routing and forwarding, Reachable from the Network Without Credentials (CVSS 7.4)7.4 HighUpdated
2026-10-03CVE-2026-98083Linux Kernel btrfs: Failure to Fix transaction use-after-free in raid stripe insertion7.0 HighUpdated
2026-10-03CVE-2026-98070Linux Kernel net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks(), Reachable from the Network Without Credentials (CVSS 8.1)8.1 HighUpdated
2026-10-03CVE-2026-98069Linux Kernel net/rds: acquire the fastpath locks in rds_conn_shutdown(), Reachable from the Network Without Credentials (CVSS 8.1)8.1 HighUpdated
2026-10-03CVE-2026-98052Linux Kernel net: bcmasp: clear txcb->last before writing each descriptor7.8 HighUpdated
2026-10-03CVE-2026-98030Linux Kernel net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size7.0 HighUpdated
2026-10-03CVE-2026-98027Linux Kernel net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size7.0 HighUpdated
2026-10-03CVE-2026-98023Linux Kernel vxlan: reject dynamic fdb entries that reference a nexthop id7.8 HighUpdated
2026-10-03CVE-2026-98017Linux Kernel net/sched: defer qdisc freeing after failed creation7.8 HighUpdated
2026-10-03CVE-2026-97991Linux Kernel vdpa_sim_blk: reject out-of-range sector starts7.8 HighUpdated
2026-10-03CVE-2026-97990Linux Kernel vdpa_sim_net: Failure to Check TX pull result before RX copy7.5 HighUpdated
2026-10-03CVE-2026-97957Linux Kernel net: hinic: fix mailbox segment buffer overflow8.8 HighUpdated
2026-10-03CVE-2026-97509Linux Kernel thunderbolt: Keep XDomain reference during the lifetime of a service8.8 HighUpdated
2026-10-03CVE-2026-97508Linux Kernel thunderbolt: Set tb->root_switch to NULL when domain is stopped7.5 HighUpdated
2026-10-03CVE-2026-97497Linux Kernel drm/amdkfd: Failure to Check bounds for allocate_sdma_queue restore_sdma_id7.8 HighUpdated
2026-10-03CVE-2026-97496Linux Kernel drm/amdkfd: Failure to Fix OOB memory exposure in get_wave_state()7.1 HighUpdated
2026-10-03CVE-2026-97455Linux Kernel ACPICA: Failure to Fix use-after-free in acpi_ds_terminate_control_method()8.4 HighUpdated
2026-10-03CVE-2026-97454Linux Kernel ACPICA: Failure to Add boundary checks in acpi_ps_get_next_field()7.7 HighUpdated
2026-10-03CVE-2026-97452Linux Kernel ACPICA: Failure to Prevent adding invalid references8.4 HighUpdated
2026-10-03CVE-2026-97451Linux Kernel ACPICA: Failure to Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op)8.4 HighUpdated
2026-10-03CVE-2026-97450Linux Kernel ACPICA: Failure to Validate handler object type in two places8.4 HighUpdated
2026-10-03CVE-2026-97448Linux Kernel ACPICA: Failure to Add validation for node in acpi_ns_build_normalized_path()7.7 HighUpdated
2026-10-03CVE-2026-93196Linux Kernel nvdimm: virtio_pmem: refcount requests for token lifetime8.4 HighUpdated
2026-10-03CVE-2026-90030Linux Kernel usb: dwc3: clear forceRM when issuing EndTransfer7.8 HighUpdated
2026-10-03CVE-2026-90016Linux Kernel staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()7.1 HighUpdated
2026-10-03CVE-2026-90013Linux Kernel tracing: Take trace_array reference when opening options file7.8 HighUpdated
2026-10-03CVE-2026-90002Linux Kernel ftrace: Take trace_array reference before accessing its ftrace_ops7.8 HighUpdated
2026-10-03CVE-2026-89972Linux Kernel nvme: Failure to Add missing SRCU grace period in error path, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-10-03CVE-2026-89971Linux Kernel nvme: skip the zoned limits update if the zone info query failed, Reachable from the Network Without Credentials (CVSS 7.5)7.5 HighUpdated
2026-10-03CVE-2026-89840Linux Kernel f2fs: Failure to Validate MOVE_RANGE destination size7.1 HighUpdated
2026-10-03CVE-2026-89838Linux Kernel f2fs: limit recovery filename logging to stored length7.1 HighUpdated
2026-10-03CVE-2026-89832Linux Kernel f2fs: Failure to Fix to clear dirty flag on folio in error path7.8 HighUpdated
2026-10-03CVE-2026-89806Linux Kernel drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation8.4 HighUpdated
2026-10-03CVE-2026-89795Linux Kernel PCI: Allow per function PCI slots to fix slot reset on s3908.4 HighUpdated
2026-10-03CVE-2026-89792Linux Kernel ksmbd: Failure to Prevent out-of-bounds reads in share config responses7.1 HighUpdated
2026-10-03CVE-2026-89560Linux Kernel landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation8.4 HighUpdated
2026-10-03CVE-2026-89520Linux Kernel sched/core: Make core-sched flips wait for in-flight selections7.8 HighUpdated
2026-10-03CVE-2026-89503Linux Kernel ring-buffer: Failure to Fix subbuf resize race with ring_buffer_alloc_read_page()7.8 HighUpdated
2026-10-03CVE-2026-89500Linux Kernel ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page7.8 HighUpdated
2026-10-03CVE-2026-89452Linux Kernel iommu/msm: Unwind probe state on registration failure8.4 HighUpdated
2026-10-03CVE-2026-89445Linux Kernel iommufd: Failure to Fix UAF in selftest IOPF reporting8.8 HighUpdated
2026-10-03CVE-2026-89441Linux Kernel mmc: via-sdmmc: cancel card-detect work on remove7.8 HighUpdated
2026-10-03CVE-2026-81016Linux Kernel platform/x86/amd/pmc: Propagate SMU errors and validate S2D address7.7 HighUpdated
2026-10-03CVE-2026-81015Linux Kernel platform/x86/amd/pmc: Failure to Fix LPS0 and debugfs leaks when STB init fails7.8 HighUpdated
2026-10-03CVE-2026-80980Linux Kernel net/smc: stop killed, freed and out_of_sync sharing a byte, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-10-03CVE-2026-80937Linux Kernel wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy8.8 HighUpdated
2026-10-03CVE-2026-80935Linux Kernel wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy8.8 HighUpdated
2026-10-03CVE-2026-80926Linux Kernel ksmbd: Failure to Fix use-after-free in oplock break notification, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-10-03CVE-2026-80726Linux Kernel KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (CVSS 9.3)9.3 CriticalUpdated
2026-10-03CVE-2026-80521Linux Kernel af_unix: Unlink scc_entry in unix_del_edge()7.8 HighUpdated
2026-10-03CVE-2026-76504CISA's October 3rd KEV Remediation Deadline for Cisco Catalyst SD-WAN Manager URI Encoding Bypass Has Passed; Covered Entities Still Exposed Are Out of Compliance9.8 CriticalKEV
2026-10-03CVE-2026-74743Linux Kernel macvlan: inherit needed_headroom and needed_tailroom from lowerdev, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-10-03CVE-2026-74521Linux Kernel ksmbd: Failure to Use memcmp() to compare ClientGUIDs, Reachable Without Authentication (CVSS 9.1)9.1 CriticalUpdated
2026-10-03CVE-2026-74496Linux Kernel fou: Failure to Fix use-after-free in fou_create()7.8 HighUpdated
2026-10-03CVE-2026-74347Linux Kernel netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount7.8 HighUpdated
2026-10-03CVE-2026-74294Linux Kernel ASoC: meson: aiu: Validate written enum values7.3 HighUpdated
2026-10-03CVE-2026-74289Linux Kernel ipv4: fib: Don't dump dying fib_info in fib_leaf_notify()7.8 HighUpdated
2026-10-03CVE-2026-74258Linux Kernel bpf: Guard __get_user acesss with access_ok for uprobe_multi data7.8 HighUpdated
2026-10-03CVE-2026-72496Linux Kernel RDMA/bnxt_re: Proper rollback if the ioremap fails (CVSS 9.2)9.2 CriticalUpdated
2026-10-03CVE-2026-72485Linux Kernel coresight: platform: defer connection counter increment until alloc succeeds7.8 HighUpdated
2026-10-03CVE-2026-72334Linux Kernel Bluetooth: ISO: fix malformed ISO_END/CONT handling8.8 HighUpdated
2026-10-03CVE-2026-68391Linux Kernel Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds7.8 HighUpdated
2026-10-03CVE-2026-68287Linux Kernel drop_monitor: Failure to Fix size calculations for 64-bit attributes, Reachable from the Network Without Credentials (CVSS 7.5)7.5 HighUpdated
2026-10-03CVE-2026-68236Linux Kernel drm/amd/display: set new_stream to NULL after release7.8 HighUpdated
2026-10-03CVE-2026-68161Linux Kernel sctp: close UDP tunnel sockets during netns teardown, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-10-03CVE-2026-68155Linux Kernel libceph: Reject monmaps advertising zero monitors, Reachable from the Network Without Credentials (CVSS 7.5)7.5 HighUpdated
2026-10-03CVE-2026-68097Linux Kernel ksmbd: Failure to Validate ACE size against SID sub-authorities8.8 HighUpdated
2026-10-03CVE-2026-53359Linux Kernel KVM: x86: Fix shadow paging use-after-free due to unexpected role8.8 HighUpdated
2026-10-03CVE-2026-53005Linux Kernel AF_UNIX SOCKMAP Redirect Hides Inflight File Descriptors from the Garbage Collector, Leaking Inflight Sockets Indefinitely7.8 HighUpdated
2026-10-03CVE-2026-52988Linux Kernel netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase7.1 HighUpdated
2026-10-03CVE-2026-46242Linux Kernel eventpoll: Failure to Fix ep_remove struct eventpoll / struct file UAF7.8 HighUpdated
2026-10-03CVE-2026-46113Linux Kernel KVM: x86: Fix shadow paging use-after-free due to unexpected GFN8.8 HighUpdated
2026-10-03CVE-2026-20273Cisco IOS XE's Improper Input Validation Allows a Remote Attacker to Trigger a Device Crash or Disruption via a Specially Crafted Input8.6 HighUpdated
2026-10-03CVE-2026-20272Cisco IOS XE's Injection Flaw Allows Remote Attackers to Execute Arbitrary Commands via a Specially Crafted Input Reaching a Downstream Component9.8 CriticalUpdated
2026-10-03CVE-2026-20271Cisco IOS XE's Insufficient Control Flow Management Allows a Remote Attacker to Disrupt Device Operation via a Crafted Packet8.6 HighUpdated
2026-10-03CVE-2026-20270Cisco IOS XE's Incorrect Calculation Vulnerability Allows a Remote Attacker to Cause an Unrecoverable Device Condition via a Specially Crafted Input8.6 HighUpdated
2026-10-03CVE-2026-20269Cisco IOS XE's Improper Resource Lifetime Management Allows Remote Attackers to Exhaust Device Resources and Cause a Denial of Service8.6 HighUpdated
2026-10-03CVE-2026-20268Cisco IOS XE's Improper Restriction of Memory Buffer Operations Allows Remote Attackers to Potentially Execute Code or Crash the Device via a Malformed Packet8.6 HighUpdated
2026-10-03CVE-2026-20267Cisco IOS XE's Improper Access Control Allows Network-Based Attackers to Access Protected Functions or Data Without Proper Authorization9.0 CriticalUpdated
2026-10-03CVE-2026-102555Red Hat Enterprise Linux 10 libsoup Out-of-Bounds Read Reachable by Unauthenticated Remote Attackers (CVSS 8.2)8.2 HighUpdated
2026-10-02CVE-2026-98163Linux Kernel cgroup: Failure to Avoid iteration of dying tasks with zero refcount7.0 HighUpdated
2026-10-02CVE-2026-98115Linux Kernel ksmbd: Failure to Safely drain sessions during logoff8.8 HighUpdated
2026-10-02CVE-2026-97415Linux Kernel btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF7.8 HighUpdated
2026-10-02CVE-2026-94422Red Hat Enterprise Linux 10 Remote Code Execution Reachable by Unauthenticated Remote Attackers (CVSS 8.8)8.8 HighUpdated
2026-10-02CVE-2026-86345Red Hat Enterprise Linux 10 389-ds-base Security Flaw Reachable by Unauthenticated Remote Attackers (CVSS 9.0)9.0 CriticalUpdated
2026-10-02CVE-2026-86344Red Hat Enterprise Linux 10 389-ds-base Security Flaw Reachable by Unauthenticated Remote Attackers (CVSS 7.5)7.5 HighUpdated
2026-10-02CVE-2026-86326Moxa MGate MB3170 Series Security Vulnerability Exploitable by Authenticated Admin Network Attackers (CVSS 8.6)8.6 HighUpdated
2026-10-02CVE-2026-86325Moxa MGate MB3170 Series Buffer Overflow Exploitable by Low-Privilege Network Attackers (CVSS 9.4)9.4 CriticalUpdated
2026-10-02CVE-2026-84411MikroTik RouterOS Remote Code Execution Reachable Without Authentication at CVSS 9.89.8 CriticalUpdated
2026-10-02CVE-2026-84233Red Hat Enterprise Linux 10 rpm Security Flaw Reachable by Unauthenticated Local Attackers (CVSS 7.0)7.0 HighUpdated
2026-10-02CVE-2026-75937Digi International IX Family Security Vulnerability Reachable by Adjacent Unauthenticated Attackers (CVSS 9.4)9.4 CriticalUpdated
2026-10-02CVE-2026-71452Johnson Controls EasyIO FS32 Command Injection Exploitable by Authenticated Admin Adjacent-Network Attackers (CVSS 7.2)7.2 HighUpdated
2026-10-02CVE-2026-71449Johnson Controls EasyIO FS32 Security Vulnerability Reachable Without Authentication at CVSS 9.39.3 CriticalUpdated
2026-10-02CVE-2026-6893Red Hat Enterprise Linux 10 dracut Remote Code Execution Reachable by Unauthenticated Adjacent-Network Attackers (CVSS 7.5)7.5 HighUpdated
2026-10-02CVE-2026-64893Johnson Controls EasyIO NEO Security Vulnerability Exploitable by Low-Privilege Network (High-Complexity Exploit) Attackers (CVSS 7.3)7.3 HighUpdated
2026-10-02CVE-2026-64008Linux Kernel accel/rocket: Failure to Fix UAF via dangling GEM handle in create_bo7.8 HighUpdated
2026-10-02CVE-2026-64001Linux Kernel ALSA: pcm: oss: Fix setup list UAF on proc write error7.8 HighUpdated
2026-10-02CVE-2026-63996Linux Kernel ethtool: cmis: require exact CDB reply length7.8 HighUpdated
2026-10-02CVE-2026-63993Linux Kernel vxlan: Missing Guard: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu(), Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-10-02CVE-2026-63975Linux Kernel Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp8.8 HighUpdated
2026-10-02CVE-2026-63972Linux Kernel net: mana: Skip redundant detach on already-detached port, Reachable from the Network Without Credentials (CVSS 7.5)7.5 HighUpdated
2026-10-02CVE-2026-63971Linux Kernel sctp: Failure to Fix race between sctp_wait_for_connect and peeloff7.8 HighUpdated
2026-10-02CVE-2026-63970Linux Kernel vsock/virtio: bind uarg before filling zerocopy skb7.8 HighUpdated
2026-10-02CVE-2026-63622Red Hat Enterprise Linux 10 libvirt Arbitrary Filesystem Write Reachable by Low-Privilege Local Attackers (CVSS 7.8)7.8 HighUpdated
2026-10-02CVE-2026-58016Enterprise Linux GLib Out-of-Bounds Read Reachable by Unauthenticated Remote Attackers (CVSS 7.5)7.5 HighUpdated
2026-10-02CVE-2026-58014Enterprise Linux GLib Denial of Service Reachable by Unauthenticated Remote Attackers (CVSS 7.3)7.3 HighUpdated
2026-10-02CVE-2026-55396Teledyne FLIR Aware2 Security Vulnerability Reachable by Adjacent Unauthenticated Attackers (CVSS 8.5)8.5 HighUpdated
2026-10-02CVE-2026-55395Teledyne FLIR Aware2 Security Vulnerability Reachable by Adjacent Unauthenticated Attackers (CVSS 9.4)9.4 CriticalUpdated
2026-10-02CVE-2026-55393Teledyne FLIR Aware2 Path Traversal Reachable Without Authentication at CVSS 10.010.0 CriticalUpdated
2026-10-02CVE-2026-5260Red Hat OpenShift AI 3.4 libgnutls Heap Overread Reachable by Unauthenticated Remote Attackers (CVSS 8.2)8.2 HighUpdated
2026-10-02CVE-2026-48864Enterprise Linux libsolv Buffer Overflow Reachable by Unauthenticated Local Attackers (CVSS 7.8)7.8 HighUpdated
2026-10-02CVE-2026-42013Red Hat OpenShift AI 3.4 gnutls Security Flaw Reachable by Unauthenticated Remote Attackers (CVSS 8.2)8.2 HighUpdated
2026-10-02CVE-2026-42012Red Hat OpenShift AI 3.4 gnutls Information Disclosure Reachable by Unauthenticated Remote Attackers (CVSS 7.1)7.1 HighUpdated
2026-10-02CVE-2026-42011Red Hat OpenShift AI 3.4 gnutls Authorization Bypass Reachable by Unauthenticated Remote Attackers (CVSS 7.4)7.4 HighUpdated
2026-10-02CVE-2026-42010Enterprise Linux gnutls Authorization Bypass Reachable by Low-Privilege Remote Attackers (CVSS 7.1)7.1 HighUpdated
2026-10-02CVE-2026-42009Enterprise Linux gnutls Denial of Service Reachable by Unauthenticated Remote Attackers (CVSS 7.5)7.5 HighUpdated
2026-10-02CVE-2026-34494Johnson Controls Neo Series MVP2 Unauthenticated Security Vulnerability over Network (CVSS 7.2)7.2 HighUpdated
2026-10-02CVE-2026-34493Johnson Controls EasyIO FS32 Unauthenticated Security Vulnerability over Network (CVSS 7.2)7.2 HighUpdated
2026-10-02CVE-2026-33846Red Hat OpenShift AI 3.4 Buffer Overflow Reachable by Unauthenticated Remote Attackers (CVSS 7.5)7.5 HighUpdated
2026-10-02CVE-2026-33845Enterprise Linux Out-of-Bounds Read Reachable by Unauthenticated Remote Attackers (CVSS 7.5)7.5 HighUpdated
2026-10-02CVE-2026-18917Red Hat Enterprise Linux 10 libvirt Buffer Overflow Reachable by Low-Privilege Local Attackers (CVSS 7.8)7.8 HighUpdated
2026-10-02CVE-2026-17615Red Hat Enterprise Linux 8 RESTEasy's Security Flaw Reachable by Unauthenticated Remote Attackers (CVSS 7.5)7.5 HighUpdated
2026-10-02CVE-2026-17523Linux Kernel can: bcm: switch timer to HRTIMER_MODE_SOFT and remove hrtimer_tasklet7.8 HighUpdated
2026-10-02CVE-2026-16529Red Hat Enterprise Linux 10 Integer Overflow Reachable by Unauthenticated Remote Attackers (CVSS 7.5)7.5 HighUpdated
2026-10-02CVE-2026-16527Red Hat Enterprise Linux 10 Remote Code Execution Reachable by Unauthenticated Remote Attackers (CVSS 7.3)7.3 HighUpdated
2026-10-02CVE-2026-16526PCP linux_sockets module unsecured internal connection allows local code execution attacker to escalate to root8.8 HighUpdated
2026-10-02CVE-2026-16524PCP linux_sockets PMDA command injection via network.persocket.filter metric allows arbitrary command execution as PMDA user7.8 HighUpdated
2026-10-02CVE-2026-16118Red Hat OpenShift AI 3.3 xdgmime Buffer Overflow Reachable by Unauthenticated Local Attackers (CVSS 7.1)7.1 HighUpdated
2026-10-02CVE-2026-15816Red Hat Enterprise Linux 10 dracut Security Flaw Reachable by Unauthenticated Adjacent-Network Attackers (CVSS 7.5)7.5 HighUpdated
2026-10-02CVE-2026-14984Teledyne FLIR Aware2 Security Vulnerability Reachable by Adjacent Unauthenticated Attackers (CVSS 9.4)9.4 CriticalUpdated
2026-10-02CVE-2026-14983Teledyne FLIR Aware2 Denial of Service Reachable by Adjacent Unauthenticated Attackers (CVSS 7.1)7.1 HighUpdated
2026-10-02CVE-2026-14164Red Hat OpenShift AI 3.4 Double-Free Reachable by Unauthenticated Remote Attackers (CVSS 7.5)7.5 HighUpdated
2026-10-02CVE-2026-12912Red Hat OpenShift AI 3.4 libtiff Buffer Overflow Reachable by Low-Privilege Local Attackers (CVSS 7.3)7.3 HighUpdated
2026-10-02CVE-2026-104988Red Hat Enterprise Linux 10 Dogtag Security Flaw Reachable by Low-Privilege Remote Attackers (CVSS 8.1)8.1 HighUpdated
2026-10-02CVE-2026-102010Red Hat Enterprise Linux 10 GCC Use-After-Free Reachable by Unauthenticated Remote Attackers (CVSS 7.0)7.0 HighUpdated
2026-10-02CVE-2026-10118Red Hat AI Inference Server 3.3 Poppler's Out-of-Bounds Write Reachable by Unauthenticated Local Attackers (CVSS 7.8)7.8 HighUpdated
2026-10-02CVE-2026-100075Linux Kernel RDMA/srpt: Failure to Fix srpt_alloc_rw_ctxs() unwind counters, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-10-01CVE-2026-90949Red Hat Enterprise Linux 8 GIMP's Buffer Overflow Reachable by Unauthenticated Local Attackers (CVSS 7.8)7.8 HighUpdated
2026-10-01CVE-2026-88924Red Hat Enterprise Linux 10 Arbitrary Filesystem Write Reachable by Low-Privilege Local Attackers (CVSS 7.0)7.0 HighUpdated
2026-10-01CVE-2026-84268Red Hat Enterprise Linux 10 Remote Code Execution Reachable by Unauthenticated Remote Attackers (CVSS 8.8)8.8 HighUpdated
2026-10-01CVE-2026-69594Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally7.8 HighUpdated
2026-10-01CVE-2026-69576Use after free in Graphic Fonts allows an authorized attacker to elevate privileges locally7.8 HighUpdated
2026-10-01CVE-2026-69549Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-10-01CVE-2026-69546Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network8.1 HighUpdated
2026-10-01CVE-2026-69541Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally7.8 HighUpdated
2026-10-01CVE-2026-69524Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network8.1 HighUpdated
2026-10-01CVE-2026-48710Kludex Starlette's HTTP Request Smuggling Vulnerability Allows Network-Adjacent Attackers to Bypass Security Controls and Poison Shared HTTP Connections6.5 MediumKEV
2026-10-01CVE-2026-42965OpenShift Container Platform Security Flaw Reachable by Low-Privilege Remote Attackers (CVSS 7.7)7.7 HighUpdated
2026-10-01CVE-2026-3012Enterprise Linux Samba’s Security Flaw Reachable by Unauthenticated Adjacent-Network Attackers (CVSS 8.0)8.0 HighUpdated
2026-10-01CVE-2026-1784OpenShift Container Platform Injection Reachable by Low-Privilege Local Attackers (CVSS 8.8)8.8 HighUpdated
2026-10-01CVE-2026-16313Red Hat Enterprise Linux 10 sg3_utils Security Flaw Reachable by Unauthenticated Local Attackers (CVSS 7.6)7.6 HighUpdated
2026-10-01CVE-2025-41753WAGO 0751-9x01 Security Vulnerability Reachable Without Authentication at CVSS 9.89.8 CriticalUpdated
2026-09-30CVE-2026-91191Lantronix G520 Boot Process Disables Firmware Signature Verification, Allowing Unauthorized Software to Pass as Authentic7.5 HighUpdated
2026-09-30CVE-2026-84409Lantronix G520 Management Interface Returns Metadata Fetched Over Unencrypted HTTP, Enabling Man-in-the-Middle Attacks on Update Mechanism7.5 HighUpdated
2026-09-30CVE-2026-79625CODESYS Runtime Monitoring Race Condition Under Concurrent Client Requests Risks Incorrect Reads, Writes, and Data Corruption8.1 HighUpdated
2026-09-30CVE-2026-76992CODESYS Gateway Client Allocates Unbounded Memory from Server-Controlled Size Field, Enabling Unauthenticated Remote Denial of Service7.5 HighUpdated
2026-09-30CVE-2025-53844Siemens RUGGEDCOM APE1808 FortiOS Out-of-Bounds Write in Specific Versions Allows Attacker to Execute Unauthorized Code8.8 HighUpdated
2026-09-30CVE-2025-14272Rockwell Automation FactoryTalk PavilionX API Improper Authorization Allows Unauthenticated Actors to Execute Privileged Operations8.3 HighUpdated
2026-09-30CVE-2025-13036Rockwell Automation FactoryTalk Historian SE Login Endpoint Race Condition Allows Unauthenticated Authentication Token Harvest9.2 CriticalUpdated
2026-09-30CVE-2025-12659Siemens Simcenter Femap Memory Corruption on Parsing Specially Crafted IPT Files Enables Code Execution in Current Process7.8 HighUpdated
2026-09-30CVE-2025-11694Rockwell Automation 1769 CompactLogix Missing CIP Protocol Sequence Number Validation Enables Denial of Service by Network Attacker8.7 HighUpdated
2026-09-29CVE-2026-8066Hitachi Energy RTU500 End-of-Life Firmware Directory Traversal via File Upload Allows Unauthenticated Attacker to Write Arbitrary Files9.1 CriticalUpdated
2026-09-29CVE-2026-8065Hitachi Energy RTU500 End-of-Life Firmware Update Endpoint Bypasses Authentication, Allowing Unauthenticated Arbitrary Firmware Upload9.1 CriticalUpdated
2026-09-29CVE-2026-7395Hitachi Energy Asset Suite Exposes Configuration Upload Servlet to Unauthenticated Users Without Network Restrictions8.5 HighUpdated
2026-09-29CVE-2025-7639AVEVA Enterprise SCADA Authenticated Operator Can Tamper Serialized Data to Achieve Code Execution Under DNA Apps Security Privileges7.1 HighUpdated
2026-09-29CVE-2025-41770Phoenix Contact AXC F PLC PLCnext Engineer Communication Interface Unauthenticated Denial-of-Service Vulnerability7.5 HighUpdated
2026-09-29CVE-2025-41769Phoenix Contact AXC F PLC PROFINET Service Buffer Overflow in Default Configuration Allows Unauthenticated Remote Reboot9.8 CriticalUpdated
2026-09-29CVE-2025-12012Rockwell Automation CompactLogix and ControlLogix 5370/5570 Can Be Forced into Non-Recoverable Fault via Invalid Project File Write9.2 CriticalUpdated
2026-09-29CVE-2025-12011Rockwell Automation CompactLogix 5370 and ControlLogix 5570 Can Be Forced into Non-Recoverable Fault by Invalid Project File Write9.2 CriticalUpdated
2026-09-29CVE-2025-11698Rockwell Automation 5380/5480/5580 Controller Boot Firmware Below Version 1.072 Allows Invalid File Writes That Force Non-Recoverable Device Fault9.2 CriticalUpdated
2026-09-28CVE-2026-20263Cisco IOS XE BEEP Feature Crashes on a Specific Malformed SOAP Request, Enabling Unauthenticated Remote Denial of Service8.6 HighUpdated
2026-09-26CVE-2026-80152Lantronix SLC/EMG/SLB Web Management Services Endpoint Lets Authenticated Users Inject OS Commands as Root9.1 CriticalUpdated
2026-09-26CVE-2026-80151Lantronix SLC/EMG/SLB Web Management Services Endpoint Contains a Second Command Injection Path Allowing Root Execution by Authenticated Users9.1 CriticalUpdated
2026-09-26CVE-2026-80150Lantronix SLC8000/SLC9000/EMG/SLB882 WebSSH Listener Accepts Unauthenticated Server-Side Request Forgery Targets7.5 HighUpdated
2026-09-26CVE-2026-80149Lantronix WebSSH and WebTelnet Server-Side Request Forgery Lets Unauthenticated Attackers Redirect Device Requests to Internal Hosts8.6 HighUpdated
2026-09-26CVE-2026-80148Lantronix SLC/EMG/SLB882 WebSSH Listener Processes SSRF Probes From Unauthenticated Callers, Enabling Internal Network Mapping8.6 HighUpdated
2026-09-26CVE-2026-80146A Second Lantronix SLC/EMG/SLB Stack Buffer Overflow via Undocumented Interface Allows Authenticated Attackers to Execute Arbitrary Code9.9 CriticalUpdated
2026-09-26CVE-2026-67279MikroTik RouterOS Unauthenticated Session Bypass Carries Federal Remediation Deadline of September 286.5 MediumKEV
2026-09-26CVE-2023-45796Pilz PASvisu and PMI v8xx Stored Cross-Site Scripting in Runtime Component Exploitable by Low-Privilege Unauthenticated Remote Attacker8.1 HighUpdated
2026-09-26CVE-2023-45795Pilz PASvisu Builder Component Cross-Site Scripting Allows Local Unauthenticated Attacker to Gain Full Device Control7.8 HighUpdated
2026-09-25CVE-2026-76460Cisco Identity Services Engine's Incorrect Use of Privileged APIs Allows Unauthenticated Remote Attackers to Gain Full Administrative Control; CISA's September 19th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-25CVE-2026-97941Linux Kernel SLAB Allocator Optimistic Freelist Return Races Against Concurrent Object Free, Enabling Local Privilege Escalation7.8 HighUpdated
2026-09-25CVE-2026-97940Linux Kernel IPv6 fib6 Route Walker Use-After-Free on seq Stop Allows Local Privilege Escalation7.8 HighUpdated
2026-09-25CVE-2026-97937Linux Kernel ftrace Function Graph State Initialized After Task Structure Copy, Enabling Local Privilege Escalation on Fork7.8 HighUpdated
2026-09-25CVE-2026-97931Linux Kernel ALSA us122l mmap Leaves VM_MAYWRITE on Read-Only Mappings, Enabling Privilege Escalation7.0 HighUpdated
2026-09-25CVE-2026-97926Linux Kernel UFS Filesystem Caches On-Disk Cylinder Group Metadata Without Validation, Enabling Local Memory Corruption7.0 HighUpdated
2026-09-25CVE-2026-97911Linux Kernel Arm Ethos-U NPU Driver Allows Zero-Size SRAM Job Configuration While Command Stream Still Accesses SRAM7.8 HighUpdated
2026-09-25CVE-2026-97910Linux Kernel Spreadtrum ASoC Compress Driver Does Not Validate Buffer Sizes Against Fixed Allocations, Enabling Local Privilege Escalation7.8 HighUpdated
2026-09-25CVE-2026-97903Linux Kernel Process Exit Releases thread_pid Reference Before proc_flush_pid Completes, Enabling Use-After-Free7.8 HighUpdated
2026-09-25CVE-2026-97612Linux Kernel MPLS Stack Pop Leaves Stale Inner Protocol Record Set by Prior Push, Enabling Local Memory Corruption7.8 HighUpdated
2026-09-25CVE-2026-97611Linux Kernel Open vSwitch Flow Table Mask Array Retired to RCU Before Last Dereference Completes, Enabling Use-After-Free7.8 HighUpdated
2026-09-25CVE-2026-97609Linux Kernel Netfilter Connection Timeout Module Unload Unregisters Per-Net Operations Before Clearing Global Hook, Enabling Use-After-Free7.0 HighUpdated
2026-09-25CVE-2026-97608Linux Kernel Netfilter Logger Teardown Leaves sysctl Exposed After Logger Unregistered but Before Backend Removed7.0 HighUpdated
2026-09-25CVE-2026-97602Linux Kernel IP Fragment Queue Flushed While Completion State Unchanged Allows Concurrent Fragment to Acquire Lock7.8 HighUpdated
2026-09-25CVE-2026-97595Linux Kernel 802.15.4 Receiver Queues Beacon Frames Against Interface Being Torn Down, Enabling Use-After-Free7.5 HighUpdated
2026-09-25CVE-2026-97594Linux Kernel Landlock Security Module Reads Parent Directory Without Reference or Lock, Enabling Use-After-Free7.8 HighUpdated
2026-09-25CVE-2026-97589Linux Kernel s390 Crypto Engine Wrong Async Callback Return Code Causes Request Re-queue Loop, Enabling Denial of Service7.0 HighUpdated
2026-09-25CVE-2026-97584Linux Kernel AFS Server Lookup Frees Existing Endpoint State When Cleaning Up Candidate, Enabling Use-After-Free7.8 HighUpdated
2026-09-25CVE-2026-97583Linux Kernel AFS File Server Leaves Stale Peer App Data After Address List Change, Causing Crash on Reconnect7.5 HighUpdated
2026-09-25CVE-2026-97580Linux Kernel Rockchip HEVC Decoder Unbounded Tile Loop and Unvalidated PPS ID Enable Local Privilege Escalation7.8 HighUpdated
2026-09-25CVE-2026-97579Linux Kernel MediaTek AV1 Video Decoder Tile Start Array Copy Exceeds Array Capacity, Enabling Local Privilege Escalation7.8 HighUpdated
2026-09-25CVE-2026-97578Linux Kernel Rockchip VPU981 AV1 Decoder Missing Divisor Guard Allows Local Privilege Escalation7.8 HighUpdated
2026-09-25CVE-2026-97577Linux Kernel Rockchip VPU981 AV1 Decoder Tile Group Entry Indexing Past Array Capacity Enables Local Privilege Escalation7.8 HighUpdated
2026-09-25CVE-2026-97576Linux Kernel V4L2 Stateless HEVC Decoder Uses Unvalidated Tile Counts as Loop Bounds, Enabling Local Privilege Escalation7.8 HighUpdated
2026-09-25CVE-2026-97575Linux Kernel V4L2 Stateless AV1 Decoder Uses Unvalidated Tile Counts as Array Indices and Loop Bounds, Enabling Local Privilege Escalation7.8 HighUpdated
2026-09-25CVE-2026-97573Linux Kernel Broadcom bnxt_en Ignores Ring Buffer Allocation Failure During RX Ring Reset, Enabling Local Memory Corruption8.1 HighUpdated
2026-09-25CVE-2026-97570Linux Kernel Broadcom bnxt_en TPA ID Indexing Without Software Bound Allows Memory Corruption on High-ID Aggregations8.1 HighUpdated
2026-09-25CVE-2026-97562Linux Kernel CIFS DFS Superblock Iterator Stores Raw Pointer Before Reference Acquired, Enabling Race-Condition Use-After-Free7.5 HighUpdated
2026-09-25CVE-2026-97557Linux Kernel CIFS Oplock Break Queue Takes File Reference Unconditionally, Leaking It on Failure Paths7.5 HighUpdated
2026-09-25CVE-2026-97555Linux Kernel CIFS DACL Rewrite Allocates Buffer From On-Disk Length Then Writes Beyond It, Enabling Cross-Scope Heap Overflow8.8 HighUpdated
2026-09-25CVE-2026-97548Linux Kernel XFS Realtime Block Map and Refcount Cursor Size Miscalculation Enables Local Memory Corruption7.8 HighUpdated
2026-09-25CVE-2026-97536Linux Kernel Qla2xxx FC Adapter Schedules Work Against Queue Pair Freed During Teardown, Enabling Use-After-Free7.5 HighUpdated
2026-09-25CVE-2026-97531Linux Kernel Qla2xxx FC Driver Takes Reference on Vport Under Active Deletion, Enabling Use-After-Free7.5 HighUpdated
2026-09-25CVE-2026-97528Linux Kernel Qla2xxx NVMe Unsolicited Context Freed While Still Linked in fcport List, Enabling Cross-Scope Use-After-Free8.8 HighUpdated
2026-09-25CVE-2026-97527Linux Kernel Qla2xxx NVMe Unsolicited Context List Modified From Multiple Contexts Without Locking, Enabling Cross-Scope Use-After-Free8.8 HighUpdated
2026-09-25CVE-2026-97525Linux Kernel x86 PAT Large-Page Split Allocates Page Tables Outside Standard Path, Enabling Cross-Scope Memory Corruption8.2 HighUpdated
2026-09-25CVE-2026-97524Linux Kernel MPTCP Subflow Reset Triggers Recursive Data-Ready Call, Causing Double Lock and Denial of Service7.5 HighUpdated
2026-09-25CVE-2026-97523Linux Kernel MPTCP Scheduler Uses Zero MSS When Subflow State Changes Race Data Transmission7.5 HighUpdated
2026-09-25CVE-2026-97445Linux Kernel ACPICA AML Resource Walker Insufficient Buffer Validation Allows Cross-Scope Overflow7.7 HighUpdated
2026-09-25CVE-2026-97444Linux Kernel ACPICA Parser Missing Boundary Checks in Two Namestring and Opcode Functions Allow Out-of-Scope Memory Access7.7 HighUpdated
2026-09-25CVE-2026-97442Linux Kernel ath11k Wi-Fi Driver Out-of-Bounds Write on Oversized Native Wi-Fi Headers Enables Cross-Scope Memory Corruption8.8 HighUpdated
2026-09-25CVE-2026-97438Linux Kernel NTFS3 Directory Index Entry Accepts Advertised key_size Exceeding Actual Payload, Enabling Out-of-Bounds Read7.1 HighUpdated
2026-09-25CVE-2026-97437Linux Kernel NTFS3 Directory Entry Bounds Check Confuses Character Count with Byte Count, Enabling Out-of-Bounds Read7.1 HighUpdated
2026-09-25CVE-2026-97433Linux Kernel NVMe FDP Configuration Log Parser Accepts Zero Descriptor Size, Enabling Unbounded Iteration and Cross-Scope Memory Access8.2 HighUpdated
2026-09-25CVE-2026-97429Linux Kernel AMD KFD Queue Destruction Drops Locks While Waiting for Resume, Enabling Concurrent Use-After-Free7.8 HighUpdated
2026-09-25CVE-2026-97428Linux Kernel AMD GPU FRU PIA TLV Parser Reads EEPROM Data Without Bounds, Allowing Cross-Scope Out-of-Bounds Access7.7 HighUpdated
2026-09-25CVE-2026-97421Linux Kernel RDMA umem iova Truncated to 32-Bit on Page-Size Selection, Enabling Local Memory Corruption7.8 HighUpdated
2026-09-25CVE-2026-97417Linux Kernel Netfilter Connection Tracker TCP SACK Parser Dereferences Unaligned Pointer, Enabling Remote Memory Corruption7.5 HighUpdated
2026-09-25CVE-2026-97413Linux Kernel RDMA/RTRS Server Integer Underflow in Network-Supplied Length Field Enables Unauthenticated Remote Code Execution9.8 CriticalUpdated
2026-09-25CVE-2026-97409Linux Kernel NVMe-FC Aborts Inflight Admin Requests Before Controller Initialization Completes, Enabling Out-of-Scope Memory Corruption8.8 HighUpdated
2026-09-25CVE-2026-96889CVE-2026-968897.8 HighUpdated
2026-09-25CVE-2026-96275CVE-2026-962758.8 HighUpdated
2026-09-25CVE-2026-95519CVE-2026-955197.8 HighUpdated
2026-09-25CVE-2026-93830Linux Kernel stmmac XGMAC2 Default Interrupt Mask Triggers a MAC Interrupt Storm Reaching 695 Times the Actual RX Completion Rate7.5 HighUpdated
2026-09-25CVE-2026-93827Linux Kernel virtio-fs Double-Free on Failed Queue Setup Leads to Cross-Component Memory Corruption8.4 HighUpdated
2026-09-25CVE-2026-93826Linux Kernel HID++ Driver Keeps Stale Input Device Pointer After Failed Registration, Enabling Use-After-Free7.5 HighUpdated
2026-09-25CVE-2026-93817Linux Kernel perf Subsystem addr_filter_ranges RCU Use-After-Free Exposes Local Privilege Escalation7.8 HighUpdated
2026-09-25CVE-2026-93816Linux Kernel F2FS Inline Dentry Conversion Copies Names Before Validating Length Against Available Slots, Enabling Out-of-Bounds Write7.1 HighUpdated
2026-09-25CVE-2026-93813Linux Kernel btrfs Tree Checker Accepts Malformed INODE_REF namelen, Enabling Local Privilege Escalation via Crafted Image7.8 HighUpdated
2026-09-25CVE-2026-93810Linux Kernel cachefiles Double File Reference Release in tmpfile Error Path Allows Local Privilege Escalation7.0 HighUpdated
2026-09-25CVE-2026-93806Linux Kernel cfg80211 Wi-Fi Association Response Parser Accesses Status Fields Before Length Validation, Enabling Cross-Scope Memory Corruption8.8 HighUpdated
2026-09-25CVE-2026-93801Linux Kernel CIFS Client Stack-Allocated cifs_open_info_data May Expose Uninitialized Kernel Memory7.0 HighUpdated
2026-09-25CVE-2026-93799Linux Kernel iwlwifi BA Window Status Handler Indexes Station Data Using Unvalidated Firmware-Supplied ID, Enabling Out-of-Scope Write8.8 HighUpdated
2026-09-25CVE-2026-93798Linux Kernel btrfs Relocation Root Reset Without Memory Barrier Exposes Race Condition Leading to Local Privilege Escalation7.8 HighUpdated
2026-09-25CVE-2026-93796Linux Kernel iwlwifi PCIe Transport Keeps Non-Null RX Pointers After Free, Enabling Use-After-Free on Reinitialize7.0 HighUpdated
2026-09-25CVE-2026-93793Linux Kernel iwlwifi TX_CMD Response Parser Uses Firmware-Supplied frame_count Without Validation, Allowing Out-of-Scope Memory Access8.8 HighUpdated
2026-09-25CVE-2026-93790Linux Kernel iwlwifi BA Handler Indexes tid_data by Loop Counter Instead of Actual TID, Enabling Cross-Scope Out-of-Bounds Write8.8 HighUpdated
2026-09-25CVE-2026-93787Linux Kernel CIFS filldir Copies Directory Entry Name Using Server-Supplied Length Without Bounding to Response, Enabling Heap Overflow8.1 HighUpdated
2026-09-25CVE-2026-93786Linux Kernel ksmbd SMB Server Mutates Parent POSIX ACL Instead of Inheriting It, Corrupting Child Access Permissions8.1 HighUpdated
2026-09-25CVE-2026-93782Linux Kernel vhost-scsi Races VHOST_SET_MEM_TABLE Against Async Command Completion, Enabling Local Privilege Escalation7.8 HighUpdated
2026-09-25CVE-2026-93345MikroTik RouterOS Labelled-VPN NLRI Iterator Accepts Below-Minimum Prefix Length in BGP UPDATE, Enabling On-Path Service Crash7.5 HighUpdated
2026-09-25CVE-2026-93288Linux Kernel Netfilter Logging Namespace Teardown Clears Logger Pointer Without RCU Grace Period, Enabling Use-After-Free7.8 HighUpdated
2026-09-25CVE-2026-93287Linux Kernel I2C SMBus Block Transfer Length Validated After Tracepoint Use, Enabling Local Memory Corruption7.8 HighUpdated
2026-09-25CVE-2026-93284Linux Kernel DRM Pagemap Migration Clears Page Array Before DMA Unmap Walk, Enabling Out-of-Scope Memory Corruption on Failure8.8 HighUpdated
2026-09-25CVE-2026-93282Linux ksmbd Accumulates ACEs from Every Principal Rather Than the Requesting User, Granting Authenticated Network Clients File Rights They Were Not Assigned8.1 HighUpdated
2026-09-25CVE-2026-93280Linux Kernel Greybus Audio Driver Walks Module-Supplied Topology Sections Without Bounding Sub-Section Sizes, Enabling Local Code Execution8.8 HighUpdated
2026-09-25CVE-2026-93277Linux Kernel bnxt_re RDMA Destroy Callback Writes Output Before Validating Userspace Access, Enabling Double-Destroy Privilege Escalation7.8 HighUpdated
2026-09-25CVE-2026-93265Linux Kernel tc9563 PCI Power Controller Misparses Integrated Ethernet MAC Endpoint, Enabling Cross-Component Impact7.7 HighUpdated
2026-09-25CVE-2026-93262Linux Kernel RAID5 PPL Log Flush Iterator Continues After Entry Freed, Enabling Use-After-Free7.8 HighUpdated
2026-09-25CVE-2026-93260Linux Kernel PowerPC XIVE IPI Init Error Ignored in SMP Probe, Enabling Use-After-Free on Freed xive_ipis Array7.4 HighUpdated
2026-09-25CVE-2026-93250Linux Kernel VXLAN MDB Flush Continues Iterating Past Removed Entry, Enabling Use-After-Free7.8 HighUpdated
2026-09-25CVE-2026-93237Linux Kernel LoongArch's Compile-Time DIRECT_MAP_PHYSMEM_END Ignores cpu_pabits, Letting vmemmap_populate() Wrap Into Low Memory and Corrupt Page Tables on Loongson-2K CPUs7.8 HighUpdated
2026-09-25CVE-2026-93229Linux Kernel NFS Server RPC Status Dump Missing Read Memory Barrier Before Seqcount Retry Enables Information Disclosure Race7.1 HighUpdated
2026-09-25CVE-2026-93228Linux Kernel RDMA svcrdma Accepts Zero-Segment Write/Reply Chunks From Unauthenticated Peers, Enabling Remote Memory Corruption9.1 CriticalUpdated
2026-09-25CVE-2026-93225Linux Kernel fsl-imx8mq USB PHY Driver Leaks typec Switch Reference on Probe Failure7.4 HighUpdated
2026-09-25CVE-2026-93224Linux Kernel svcrdma Accept Error Path Calls Unregister Notification Before Register Succeeds, Enabling Double-Unregister Corruption8.1 HighUpdated
2026-09-25CVE-2026-93221Linux Kernel NFS Server Boolean Flags Accessed Without Serialization Enable Data Race Leading to Memory Corruption8.1 HighUpdated
2026-09-25CVE-2026-93207Linux Kernel SUNRPC GSS Credential Decoder Uses Uninitialized Stack Memory, Enabling Unauthenticated Remote Code Execution9.8 CriticalUpdated
2026-09-25CVE-2026-78002CVE-2026-780027.5 HighUpdated
2026-09-25CVE-2026-72463Linux Kernel xfrm IPsec Async Resumption Modifies Device Pointer Without Reference, Enabling Unauthenticated Remote Code Execution9.8 CriticalUpdated
2026-09-25CVE-2026-72315Linux Kernel CIFS Client Deferred Close Holds Dentry Reference, Causing Use-After-Free on Unmount After Direct I/O7.8 HighUpdated
2026-09-25CVE-2026-69458Windows BitLocker Out-of-Bounds Read Lets Authorized Attackers Escalate Privileges Over a Network Connection8.0 HighUpdated
2026-09-25CVE-2026-69456Windows Speech Heap Buffer Overflow Spans Windows Server 2012 Through Server 2025, Letting Authorized Local Attackers Elevate Privileges7.8 HighUpdated
2026-09-25CVE-2026-69455Windows Remote Access Connection Manager Heap Buffer Overflow Lets Authorized Local Attackers Escalate Privileges7.8 HighUpdated
2026-09-25CVE-2026-69451Windows Management Instrumentation Use-After-Free Lets Authorized Attackers Escalate Privileges Over a Network Connection7.1 HighUpdated
2026-09-25CVE-2026-69448Windows Bluetooth Service Race Condition Lets a Local Low-Privilege User Gain Elevated Privileges on Windows 10, 11, and Server7.0 HighUpdated
2026-09-25CVE-2026-69447Windows Audio Service Heap Buffer Overflow Lets Authorized Local Attackers Elevate Privileges7.8 HighUpdated
2026-09-25CVE-2026-69445Windows Compressed Folder Path Traversal Lets Authorized Local Attackers Elevate Privileges Across All Supported Windows Versions7.8 HighUpdated
2026-09-25CVE-2026-69444Windows Speech Heap Buffer Overflow from Windows Server 2016 Upward Lets Authorized Local Attackers Elevate Privileges7.8 HighUpdated
2026-09-25CVE-2026-69441Windows Installer Race Condition Lets Authorized Local Attackers Escalate Privileges Across All Supported Windows Versions7.0 HighUpdated
2026-09-25CVE-2026-69440Windows MIDI Service TOCTOU Race Condition Enables Local Privilege Escalation on Windows 117.0 HighUpdated
2026-09-25CVE-2026-69436Windows Error Reporting Heap Buffer Overflow from Windows 10 Version 1809 Upward Lets Authorized Local Attackers Escalate Privileges7.8 HighUpdated
2026-09-25CVE-2026-69434Windows URL Moniker Heap Buffer Overflow Lets Unauthenticated Network Attackers Execute Code Across All Supported Windows Versions8.8 HighUpdated
2026-09-25CVE-2026-69433Windows Error Reporting Heap Buffer Overflow, Including Windows Server 2012, Lets Authorized Local Attackers Escalate Privileges7.8 HighUpdated
2026-09-25CVE-2026-69396Windows NDIS Use-After-Free Lets Authorized Attackers Escalate Privileges Over a Network Connection7.1 HighUpdated
2026-09-25CVE-2026-69394Windows Audio Service Heap Buffer Overflow Lets a Low-Privilege Local User Elevate Privileges Across Windows 10 Through Server 20257.0 HighUpdated
2026-09-25CVE-2026-69392Windows Shell Use-After-Free Lets Authorized Local Attackers Escalate Privileges on Windows 11 and Server 20257.8 HighUpdated
2026-09-25CVE-2026-69391Windows Broker Infrastructure Service Stack Buffer Overflow Lets Authorized Local Attackers Elevate Privileges7.8 HighUpdated
2026-09-25CVE-2026-69389Windows Storage Management Provider Heap Buffer Overflow Lets Authorized Local Attackers Escalate Privileges7.8 HighUpdated
2026-09-25CVE-2026-67281MikroTik RouterOS WebFig Stale Session Pointer Lets Unauthenticated Attackers Read Arbitrary Files7.5 HighUpdated
2026-09-25CVE-2026-67278MikroTik RouterOS Accepts Malformed RSA/PKCS#1 v1.5 Signatures Across TLS and SSH, and Its Trust Store Includes an e=3 Root CA, Letting a Network Attacker Forge Valid Signatures Without the Private Key9.1 CriticalUpdated
2026-09-25CVE-2026-33824Microsoft Windows IKE Service Extensions' Double Free Enables Unauthenticated Remote Attackers to Execute Arbitrary Code; CISA's August 21st KEV Deadline Has Passed9.8 CriticalKEV
2026-09-25CVE-2026-32157Windows Remote Desktop Client Use-After-Free Lets Unauthenticated Network Attackers Execute Code8.8 HighUpdated
2026-09-25CVE-2026-26174Windows Server Update Service Race Condition Lets Authorized Local Attackers Escalate Privileges Across All Supported Windows Versions7.0 HighUpdated
2026-09-25CVE-2026-20190Cisco Identity Services Engine Improper Authorization Exposes Sensitive Information to Unauthenticated Remote Attackers7.5 HighUpdated
2026-09-25CVE-2026-20147Critical Cisco ISE and ISE-PIC Command Injection Scores 9.99.9 CriticalEPSS-Imminent
2026-09-24CVE-2026-22619Eaton Intelligent Power Protector Uncontrolled Search Path Scores 7.87.8 HighUpdated
2026-09-24CVE-2026-21662Critical Johnson Controls FMS Employee Unrestricted File Upload Scores 9.89.8 CriticalUpdated
2026-09-24CVE-2026-89028MikroTik RouterOS SMB1 Session Setup Handler Accepts Crafted uniPwdLen That Corrupts Adjacent Heap Memory7.5 HighUpdated
2026-09-24CVE-2026-89025Belden Hirschmann HiOS Switch Platform Missing HTTP Content Validation Allows Unauthenticated Attacker to Cause Web Server Denial of Service7.5 HighUpdated
2026-09-24CVE-2026-85880Microsoft Windows' Heap-Based Buffer Overflow Allows Local Attackers to Escalate Privileges by Corrupting Heap Memory; CISA's September 22nd KEV Deadline Has Passed7.8 HighKEV
2026-09-24CVE-2026-80156Lantronix SLC8000/SLC9000/EMG Series Web Upload Path Traversal Lets Authenticated Attackers Write Arbitrary Files9.1 CriticalUpdated
2026-09-24CVE-2026-80155Lantronix SLC8000/SLC9000/EMG Series Web Upload Authentication Bypass Lets Unauthenticated Attackers Write Arbitrary Files10.0 CriticalUpdated
2026-09-24CVE-2026-80154All Lantronix SLC/EMG/SLB Firmware Versions Use Predictable Session Tokens, Letting Unauthenticated Attackers Hijack Active Sessions9.6 CriticalUpdated
2026-09-24CVE-2026-80147Lantronix SLC8000/SLC9000/EMG/SLB Stack Buffer Overflow via Undocumented Interface Allows Authenticated Attackers to Execute Arbitrary Code9.9 CriticalUpdated
2026-09-24CVE-2026-80145Lantronix SLC8000/SLC9000/EMG Series Services Permission Allows Authenticated Command Injection as Root via a Distinct Injection Path9.1 CriticalUpdated
2026-09-24CVE-2026-80144Lantronix SLC/EMG/SLB Undocumented Management Feature Lets Authenticated Attackers Execute Arbitrary Root Shell Commands9.9 CriticalUpdated
2026-09-24CVE-2026-80143A Second Undocumented Lantronix SLC/EMG/SLB Command Path Lets Authenticated Attackers Execute Arbitrary Root Shell Commands9.9 CriticalUpdated
2026-09-24CVE-2026-78312Delta DIAEnergie Path Traversal Allows Unauthenticated Attackers to Write or Overwrite Arbitrary Files9.1 CriticalUpdated
2026-09-24CVE-2026-78311Delta DIAEnergie SQL Injection Allows Authenticated Remote Code Execution8.8 HighUpdated
2026-09-24CVE-2026-78309Delta DIAEnergie SQL Injection Allows Authenticated Remote Code Execution8.8 HighUpdated
2026-09-24CVE-2026-78308Delta DIAEnergie Authentication Bypass Vulnerability Allows Unauthenticated Access to Protected Functions9.8 CriticalUpdated
2026-09-24CVE-2026-69571Windows USB Audio Class driver (usbaudio.sys) Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69567Windows NTFS Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69564Windows Online Certificate Status Protocol (OCSP) Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69563Windows Program Compatibility Assistant Service Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69561Windows CD-ROM Driver Out-of-bounds read Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69560Windows Work Folder Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69553Windows Hyper-V Missing authorization Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69551Windows DNS Use after free Lets Authorized Attackers Execute Code over the Network (CVSS 8.8)8.8 HighUpdated
2026-09-24CVE-2026-69547Windows DHCP Server Heap-based buffer overflow Lets Authorized Attackers Execute Code over the Network (CVSS 8.8)8.8 HighUpdated
2026-09-24CVE-2026-69544Windows SMB Client Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69542Windows Camera Frame Server Monitor Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69540Windows Audio Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69539Windows Remote Desktop Services Use after free Lets Authorized Attackers Execute Code over the Network (CVSS 7.5)7.5 HighUpdated
2026-09-24CVE-2026-69538Windows Spaceport.sys Out-of-bounds read Lets Authorized Attackers Execute Code Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69535Windows Spaceport.sys Numeric Truncation Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.8 HighUpdated
2026-09-24CVE-2026-69534Windows Program Compatibility Assistant Service Command Injection Lets Authorized Attackers Escalate Privileges Locally7.8 HighUpdated
2026-09-24CVE-2026-69532Windows NTFS Out-of-bounds read Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69525Windows Remote Desktop Services Use after free Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8)9.8 CriticalUpdated
2026-09-24CVE-2026-69518Windows Remote Desktop Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8)8.8 HighUpdated
2026-09-24CVE-2026-69514Windows Remote Desktop Services Heap-based buffer overflow Lets Authorized Attackers Execute Code over the Network (CVSS 7.5)7.5 HighUpdated
2026-09-24CVE-2026-69511Microsoft Windows Media Foundation Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8)8.8 HighUpdated
2026-09-24CVE-2026-69510Windows DHCP Server Stack-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.1)8.1 HighUpdated
2026-09-24CVE-2026-69509Windows Fax Service Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69505Windows NTFS Out-of-Bounds Read Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69500Windows Image Acquisition Use after free Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69500)7.0 HighUpdated
2026-09-24CVE-2026-69496Windows Compressed Folder Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8)9.8 CriticalUpdated
2026-09-24CVE-2026-69491Windows Microsoft DirectMusic Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8)9.8 CriticalUpdated
2026-09-24CVE-2026-69479Windows NTFS Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code Locally (CVSS 8.4)8.4 HighUpdated
2026-09-24CVE-2026-69475Windows Remote Desktop Services Untrusted Pointer Dereference Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69473Windows Kernel Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69466Windows Kernel TOCTOU Race Condition Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69463Windows NTFS Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8)9.8 CriticalUpdated
2026-09-24CVE-2026-69461Windows NTFS Stack-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8)8.8 HighUpdated
2026-09-24CVE-2026-69450Windows Error Reporting Out-of-bounds read Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69430Windows Embedded Mode Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69429Windows IKE Extension Heap-based buffer overflow Lets Authorized Attackers Execute Code over the Network (CVSS 7.5)7.5 HighUpdated
2026-09-24CVE-2026-69428Windows LDAP - Lightweight Directory Access Protocol Out-of-bounds read Lets Unauthenticated Attackers Disclose Sensitive Information over the Network (CVSS 7.5)7.5 HighUpdated
2026-09-24CVE-2026-69427Windows VOLSNAP.SYS Out-of-bounds read Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69426Windows VOLSNAP.SYS Heap-based buffer overflow Lets Authorized Attackers Execute Code Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69424Windows Distributed File System (DFS) Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69423Windows USB Video Driver Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69421Windows Kernel Mode Driver Integer Underflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.8 HighUpdated
2026-09-24CVE-2026-69420Windows VOLSNAP.SYS Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69413Windows USB Audio Class driver (usbaudio.sys) Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69412Windows DHCP Server Stack-based buffer overflow Lets Authorized Attackers Execute Code (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69410Windows Win32K Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69408Microsoft Windows Media Foundation Integer overflow or wraparound Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8)9.8 CriticalUpdated
2026-09-24CVE-2026-69404Windows TCP/IP Race Condition Lets Authorized Attackers Execute Code over the Network (CVSS 8.1)7.0 HighUpdated
2026-09-24CVE-2026-69398Windows Bluetooth Service Race Condition Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69397OpenSSH for Windows Use after free Lets Unauthenticated Attackers Execute Code over the Network (CVSS 7.5)7.5 HighUpdated
2026-09-24CVE-2026-69388Windows Bluetooth Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69386Microsoft Windows Media Foundation Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8)8.8 HighUpdated
2026-09-24CVE-2026-69385Windows TCP/IP Race Condition Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69383Windows Shell Arbitrary File Path Control Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69377Windows Modern Device Management (MDM) Missing authorization Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69371Windows Overlay Filter Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69368Windows Overlay Filter Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69366Windows Kernel Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69364Windows Print Spooler Components Race Condition Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69362Windows Error Reporting Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69357Windows NDIS Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69347Windows Fast FAT Driver Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code Locally (CVSS 7.4)7.4 HighUpdated
2026-09-24CVE-2026-69346Windows Print Spooler Components Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69342Windows DHCP Server Out-of-bounds read Lets Unauthenticated Attackers Disclose Sensitive Information over the Network (CVSS 7.5)7.5 HighUpdated
2026-09-24CVE-2026-69341Windows Image Acquisition Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69340Windows NTFS Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69337Windows Registry Double free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69335Windows Win32K Use after free Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69335)7.0 HighUpdated
2026-09-24CVE-2026-69334Windows Volume Manager Extension Driver Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8)8.8 HighUpdated
2026-09-24CVE-2026-69332Windows NTFS Out-of-bounds read Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69331Windows Remote Access Connection Manager Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69328Windows Storage Untrusted search path Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69324Windows Performance Monitor Type Confusion Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.8 HighUpdated
2026-09-24CVE-2026-69322Microsoft Windows Search Component Double free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69319Windows USB Video Driver Race Condition Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69312Windows NTFS Out-of-Bounds Read Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69312)7.8 HighUpdated
2026-09-24CVE-2026-69311Windows Audio Service Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69310Windows DNS Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69309Windows Print Spooler Components Double free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69307Windows USB Audio Class driver (usbaudio.sys) Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69305Microsoft Windows Search Component Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69301Windows Win32K Stack-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-69300Windows Push Notifications Use after free Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69300)7.0 HighUpdated
2026-09-24CVE-2026-69299Microsoft COM for Windows Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69296Windows Device Association Service Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69295Windows USB Driver Out-of-bounds read Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69291Windows Volume Manager Extension Driver Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 8.8)8.8 HighUpdated
2026-09-24CVE-2026-69290Windows Storage Spaces Controller Stack-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69289Windows Setup Files Cleanup Symbolic Link Following Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69287Windows Remote Desktop Services Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69284Windows DCOM Server Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69283Windows CD-ROM Driver Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-69281Windows License Manager Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69280Windows Push Notifications Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69279Windows Cloud Files Mini Filter Driver Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-69274Windows Win32K Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-69270Windows USB Audio Class driver (usbaudio.sys) Heap-based buffer overflow Lets Authorized Attackers Execute Code Locally (CVSS 7.8) (CVE-2026-69270)7.8 HighUpdated
2026-09-24CVE-2026-69266Windows DHCP Server Integer Overflow or Wraparound Lets Unauthenticated Attackers Execute Code over the Network8.8 HighUpdated
2026-09-24CVE-2026-69265Windows NTFS Out-of-Bounds Read Lets Authorized Attackers Escalate Privileges Locally (CVE-2026-69265)7.8 HighUpdated
2026-09-24CVE-2026-68896Microsoft Windows Search Component Absolute path traversal Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-68894Windows Error Reporting Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network8.0 HighUpdated
2026-09-24CVE-2026-68893Windows Remote Desktop Licensing Service Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-68887Windows Message Queuing Queue Manager Out-of-Bounds Read Lets Unauthenticated Attackers Access Sensitive Data over the Network7.5 HighUpdated
2026-09-24CVE-2026-68880Windows Win32K Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network8.0 HighUpdated
2026-09-24CVE-2026-68878Windows Fast FAT Driver Stack-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network8.0 HighUpdated
2026-09-24CVE-2026-68877Windows Storage Spaces Controller Heap-Based Buffer Overflow Lets Authorized Attackers Execute Code Locally (CVE-2026-68877)7.8 HighUpdated
2026-09-24CVE-2026-68876Windows Program Compatibility Assistant Service Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network8.0 HighUpdated
2026-09-24CVE-2026-68875Windows NTFS Buffer Over-read Lets Authorized Attackers Execute Code Locally7.8 HighUpdated
2026-09-24CVE-2026-68848Windows Print Spooler Components Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges Locally7.8 HighUpdated
2026-09-24CVE-2026-68846Windows Kernel Use after free Lets Authorized Attackers Escalate Privileges over the Network (CVSS 7.1)7.1 HighUpdated
2026-09-24CVE-2026-68845Windows Program Compatibility Assistant Service Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges Locally7.8 HighUpdated
2026-09-24CVE-2026-68844Windows Storage Spaces Controller Heap-Based Buffer Overflow Lets Authorized Attackers Execute Code Locally7.8 HighUpdated
2026-09-24CVE-2026-68841Windows NTFS Heap-based buffer overflow Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-24CVE-2026-68840Windows USB Driver Concurrent execution using shared resource with improper synchronization ('race condition') Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-68839Windows USB Mass Storage Class Driver Heap-based buffer overflow Lets Unauthenticated Attackers Execute Code over the Network (CVSS 9.8)9.8 CriticalUpdated
2026-09-24CVE-2026-68838Windows NTFS Stack-based buffer overflow Lets Authorized Attackers Escalate Privileges over the Network (CVSS 8.0)8.0 HighUpdated
2026-09-24CVE-2026-68835Windows Print Spooler Components Use-After-Free Lets Authorized Attackers Escalate Privileges over the Network7.1 HighUpdated
2026-09-24CVE-2026-68834Windows NTFS Stack-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network (CVE-2026-68834)8.0 HighUpdated
2026-09-24CVE-2026-68832Windows NTFS Integer Overflow Lets Authorized Attackers Escalate Privileges Locally7.8 HighUpdated
2026-09-24CVE-2026-68827Windows GDI+ Integer Underflow Lets Authorized Attackers Escalate Privileges over the Network8.0 HighUpdated
2026-09-24CVE-2026-62759Windows Netlogon Authentication Bypass Lets Unauthenticated Attackers Compromise the System Locally7.5 HighUpdated
2026-09-24CVE-2026-62706Microsoft Windows Media Foundation Out-of-Bounds Read Lets Unauthenticated Attackers Execute Code over the Network8.8 HighUpdated
2026-09-24CVE-2026-62694Windows Installer Use after free Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.0)7.0 HighUpdated
2026-09-24CVE-2026-5857Contiki-NG MQTT Client Over-Length Topic Sets Received Flag Before Rejection, Enabling Out-of-Bounds Write on Subsequent TCP Segment8.1 HighUpdated
2026-09-24CVE-2026-50349Windows Ancillary Function Driver for WinSock Race Condition Lets Authorized Attackers Escalate Privileges Locally7.0 HighUpdated
2026-09-24CVE-2026-19654Privilege Escalation in Enterprise Linux 9, Allowing Privilege Escalation7.5 HighUpdated
2026-09-24CVE-2026-15711libsoup WebSocket Frame Parsing Denial of Service Affects Red Hat Enterprise Linux and SAP Solutions (CVSS 7.5)7.5 HighUpdated
2026-09-24CVE-2026-15709libsoup WebSocket permessage-deflate Decompression Loop Denial of Service Affects Red Hat Enterprise Linux (CVSS 7.5)7.5 HighUpdated
2026-09-24CVE-2026-13249Honeywell PD45 Industrial Printer Web Management Interface Accepts Unauthenticated File Uploads That Enable Remote Code Execution9.8 CriticalUpdated
2026-09-24CVE-2026-13248Honeywell PD45 Industrial Printer Intermec Fingerprint Interface Lets Authenticated Admin Accounts Write Arbitrary Files, Enabling Remote Code Execution8.8 HighUpdated
2026-09-23CVE-2026-83998Remote Desktop Client Heap-Based Buffer Overflow Lets Unauthenticated Attackers Execute Code over the Network8.8 HighUpdated
2026-09-23CVE-2026-82028absmach magistrala SQL Injection Reachable by Authenticated Remote Attackers with High Severity (CVSS 8.8)8.8 HighUpdated
2026-09-23CVE-2026-73176Advantech EKI-1242IEIMS Firmware V1.06.01 Web Management Interface Command Injection Lets Authenticated Remote Attackers Execute OS Commands8.6 HighUpdated
2026-09-23CVE-2026-73175Advantech EKI-1242EIMS OPC UA Gateway Session Pool Exhaustion Lets Adjacent Unauthenticated Attackers Cause Complete Denial of Service7.1 HighUpdated
2026-09-23CVE-2026-73174Advantech EKI-1242EIMS edgserver Management Protocol Transmits Credentials in Cleartext, Exposing Them to Network-Adjacent Observers8.7 HighUpdated
2026-09-23CVE-2026-73173Advantech EKI-1242EIMS edgserver Management Protocol Exposes Critical Device Management Functions Without Authentication8.8 HighUpdated
2026-09-23CVE-2026-73172Advantech EKI-1242EIMS edgserver Management Service Unauthenticated OS Command Injection Allows Remote Root Execution9.3 CriticalUpdated
2026-09-23CVE-2026-73171Advantech EKI-1242EIMS Backup-Restore Upload Lets Authenticated Remote Attackers Overwrite Arbitrary Device Filesystem Files8.6 HighUpdated
2026-09-23CVE-2026-73170Advantech EKI-1242EIMS Modbus CSV Import Executes Attacker-Controlled Lua Code via Crafted Upload8.6 HighUpdated
2026-09-23CVE-2026-73167Advantech EKI-1242IEIMS Web Management Interface Contains a Second OS Command Injection Path Exploitable by Authenticated Remote Attackers8.6 HighUpdated
2026-09-23CVE-2026-73166Advantech EKI-1242IEIMS Web Management Interface Code Injection Lets Authenticated Remote Attackers Execute Arbitrary OS Commands8.6 HighUpdated
2026-09-23CVE-2026-73165Advantech EKI-1242IEIMS Web Management Interface Has a Third Command Injection Path Exploitable by Authenticated Remote Attackers8.6 HighUpdated
2026-09-23CVE-2026-73164Advantech EKI-1242IEIMS Web Management Interface Contains a Fourth OS Command Injection Path Exploitable by Authenticated Remote Attackers8.6 HighUpdated
2026-09-23CVE-2026-73163Advantech EKI-1242IEIMS Web Management Interface Authenticated Command Injection Allows Remote OS Command Execution via Web Interface8.6 HighUpdated
2026-09-23CVE-2026-73014Data Sharing Service Client Missing authorization Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-23CVE-2026-70584Windows Core Messaging Type Confusion Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-23CVE-2026-69528Windows Shell Missing Authentication Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighUpdated
2026-09-23CVE-2026-69517Windows Wireless Networking Use-After-Free Lets Authorized Attackers Escalate Privileges Locally7.0 HighUpdated
2026-09-23CVE-2026-69512Windows Spaceport.sys Heap-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges over the Network8.0 HighUpdated
2026-09-23CVE-2026-69508Windows MIDI Service Module Stack-Based Buffer Overflow Lets Authorized Attackers Escalate Privileges Locally7.8 HighUpdated
2026-09-23CVE-2026-69443Microsoft Azure Attestation service and Device Health Attestation Service Out-of-Bounds Read Lets Unauthenticated Attackers Access Sensitive Data over the Network7.5 HighUpdated
2026-09-23CVE-2026-53985Ground Station Prior to 0.6.0 Socket.IO service_control Handler Allows Unauthenticated Peer to Force Service Shutdown7.5 HighUpdated
2026-09-23CVE-2026-53984Ground Station Prior to 0.6.0 Socket.IO database_backup Handler Allows Unauthenticated Peer to Destroy Database and Inject Arbitrary Data9.1 CriticalUpdated
2026-09-23CVE-2026-53983Ground Station Orbital-Source Configuration Path Accepts Unauthenticated Socket.IO SSRF Requests, Causing Outbound HTTP Requests to Attacker-Chosen Destinations8.6 HighUpdated
2026-09-23CVE-2026-42784sequoia-openpgp Incorrect Key Flags Inference for Older Certificates Enables Unauthenticated Attackers to Forge Signatures (CVSS 7.4)7.4 HighUpdated
2026-09-23CVE-2026-19535Advantech EKI-1242IEIMS LuCI Administrative Interface CSRF Lets Unauthenticated Attackers Perform Unauthorized State Changes via Logged-In Users8.6 HighUpdated
2026-09-23CVE-2026-19438ABB Mint Workbench I Path Traversal Lets Unauthenticated Remote Attackers Access Sensitive Files (CVSS 7.5)7.5 HighUpdated
2026-09-23CVE-2026-18649Denial of Service in the GStreamer gst-plugins-good package Affects Enterprise Linux 8.8 Telecommunications Update Service, Leading to Service Disruption7.5 HighUpdated
2026-09-23CVE-2026-12974Forcepoint NGFW Security Policy Bypass via Overly Permissive Input Validation Affects Versions 7.1 Through 7.57.9 HighUpdated
2026-09-22CVE-2026-83549SonicWall SMA1000 Appliances' OS Command Injection Allows Authenticated Local Attackers to Execute Arbitrary Commands with Root Privileges; CISA's September 5th KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-83548SonicWall SMA1000 Appliances' Server-Side Request Forgery Allows Unauthenticated Remote Attackers to Reach Internal Services and Compromise the Secure Mobile Access Gateway; CISA's September 5th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSock's Use-After-Free Allows a Local Attacker to Gain Elevated Privileges via a Freed Memory Reference; CISA's August 25th KEV Deadline Has Passed7.0 HighKEV
2026-09-22CVE-2026-64849MLflow's Server-Side Request Forgery Flaw Allows Remote Attackers to Use the ML Platform Server as a Proxy to Access Internal Services and Steal Credentials; CISA's September 2nd KEV Deadline Has Passed9.3 CriticalKEV
2026-09-22CVE-2026-48558SimpleHelp Accepts Unverified Cryptographic Signatures, Letting Remote Attackers Bypass Authentication; CISA's July 2nd KEV Deadline for Covered Entities Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-45498Microsoft Defender's Unspecified Vulnerability Allows for Denial of Service; CISA's June 3rd KEV Deadline Has Passed4.0 MediumKEV
2026-09-22CVE-2026-41091Microsoft Defender's Link Following Flaw Enables an Authorized Attacker to Elevate Privileges Locally; CISA's June 3rd KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-34486Apache Tomcat's Missing Encryption of Sensitive Session Data Exposes Credentials and Tokens to Network Interception; CISA's August 7th KEV Deadline Has Passed7.5 HighKEV
2026-09-22CVE-2026-34197Apache ActiveMQ's Improper Input Validation Enables Code Injection Affecting Both ActiveMQ and Broker Deployments; CISA's April 30th KEV Deadline Has Passed8.8 HighKEV
2026-09-22CVE-2026-33825Microsoft Defender's Insufficient Access Control Allows an Authorized Attacker to Escalate Privileges Locally; CISA's May 6th KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-32202Microsoft Windows Shell's Protection Mechanism Failure Allows an Unauthorized Attacker to Perform Spoofing Over the Network; CISA's May 12th KEV Deadline Has Passed4.3 MediumKEV
2026-09-22CVE-2026-31431Linux Kernel Resource Mishandling That Allows Privilege Escalation Carries a Lapsed May 15th CISA KEV Mandate; Covered Entities on Unpatched Kernels Remain Out of Compliance7.8 HighKEV
2026-09-22CVE-2026-20316Cisco Secure Firewall Management Center Hard-Coded Password Lets Attackers Bypass Authentication; CISA's August 1st KEV Deadline for Covered Entities Has Passed5.3 MediumKEV
2026-09-22CVE-2026-20262Authenticated Path Traversal in Cisco Catalyst SD-WAN Manager Lets Remote Attackers Write Files Outside Allowed Directories; CISA's June 29th KEV Deadline Has Passed6.5 MediumKEV
2026-09-22CVE-2026-20245Cisco Catalyst SD-WAN Manager's Improper Encoding Allows an Authenticated Local Attacker to Execute Arbitrary Commands as Root via a Crafted File; CISA's June 23rd KEV Deadline Has Passed7.8 HighKEV
2026-09-22CVE-2026-20230Cisco Unified Communications Manager SSRF Flaw Routes Attacker Requests to Internal Resources; CISA's June 28th KEV Deadline for Covered Entities Has Lapsed8.6 HighKEV
2026-09-22CVE-2026-20200Cisco IMC web management command injection allows authenticated low-privilege attacker to execute commands as root8.8 HighExploited
2026-09-22CVE-2026-20182Cisco Catalyst SD-WAN Controller and Manager's Authentication Bypass Gives Unauthenticated Remote Attackers Administrative Privileges; CISA's May 17th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-20180Critical Cisco ISE Path Traversal Enables Remote Code Execution, Scores 9.99.9 CriticalEPSS-Imminent
2026-09-22CVE-2026-20133Cisco Catalyst SD-WAN Manager Leaks Sensitive Configuration Data to Unauthorized Users; CISA's April 23rd KEV Remediation Requirement Has Expired for Covered Entities6.5 MediumKEV
2026-09-22CVE-2026-20128Cisco Catalyst SD-WAN Manager Stores Credentials in a Recoverable Format, Enabling Credential Theft; CISA's April 23rd KEV Mandate for Covered Entities Has Lapsed7.5 HighKEV
2026-09-22CVE-2026-20122Cisco Catalyst SD-WAN Manager Exposes Privileged API Functions to Unauthorized Callers; CISA's April 23rd KEV Remediation Deadline for Covered Entities Has Long Passed5.4 MediumKEV
2026-09-22CVE-2026-20079Cisco Firewall Management Center's Authentication Bypass via an Alternate Path Grants Unauthenticated Remote Attackers Full Administrative Control; CISA's September 12th KEV Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-15410SonicWall SMA1000's Code Injection Allows a Remote Authenticated Administrator to Execute Arbitrary OS Commands Under Specific Conditions; CISA's July 17th KEV Deadline Has Passed7.2 HighKEV
2026-09-22CVE-2026-15409SonicWall SMA1000 Secure Access Appliances Accept Forged Server-Side Requests, Enabling Internal Network Pivoting; CISA's July 17th KEV Remediation Deadline Has Passed10.0 CriticalKEV
2026-09-22CVE-2026-12569PTC Windchill and FlexPLM's Improper Input Validation Allows Unauthenticated Remote Attackers to Execute Arbitrary Code via Malicious Network Requests; CISA's June 28th KEV Deadline Has Passed9.8 CriticalKEV
2026-09-22CVE-2026-0300PAN-OS Out-of-Bounds Write Enabling Code Execution Affects Both Palo Alto Networks Firewalls and Siemens RUGGEDCOM APE1808 Industrial Appliances; CISA's May 9th KEV Window Has Closed9.8 CriticalKEV
2026-09-22CVE-2026-0257PAN-OS Authentication Bypass Enabling Unauthorized VPN Tunnels Affects Palo Alto Networks Prisma Access and Siemens RUGGEDCOM APE1808; Now Listed in CISA's Known Exploited Vulnerabilities Catalog9.1 CriticalKEV
2026-09-22CVE-2026-95619Integer Overflow in libstdc++ Affects Enterprise Linux 97.7 HighUpdated
2026-09-22CVE-2026-95508Heap-Based Buffer Overflow in Enterprise Linux 8, Leading to Service Disruption7.4 HighUpdated
2026-09-22CVE-2026-93569Netty HTTP/1 to HTTP/2 Upgrade Process Flaw Lets Remote Unauthenticated Attackers Modify Data and Partially Access Sensitive Information (CVSS 8.2)8.2 HighUpdated
2026-09-22CVE-2026-93568Netty HTTP/2 Extended CONNECT Handling Flaw Lets Remote Unauthenticated Attackers Modify Data in Transit via Specially Crafted Requests (CVSS 7.5)7.5 HighUpdated
2026-09-22CVE-2026-93567Security Flaw in Netty's HTTP/2 codec Affects Single Sign-On 77.5 HighUpdated
2026-09-22CVE-2026-93565Security Flaw in Netty RtspDecoder Affects Single Sign-On 77.5 HighUpdated
2026-09-22CVE-2026-93564Netty HAProxy PROXY-v2 Decoder Reference-Count Leak Lets Unauthenticated Remote Attackers Cause Denial of Service (CVSS 7.5)7.5 HighUpdated
2026-09-22CVE-2026-93558Netty WebSocketServerExtensionHandler Flaw Lets Unauthenticated Remote Attackers Cause Denial of Service in Red Hat AMQ Broker (CVSS 7.5)7.5 HighUpdated
2026-09-22CVE-2026-93491Denial of Service in Netty's HttpServerCodec Affects Single Sign-On 7, Leading to Service Disruption7.5 HighUpdated
2026-09-22CVE-2026-93488Denial of Service in Netty Affects Single Sign-On 7, Leading to Service Disruption (CVE-2026-93488)7.5 HighUpdated
2026-09-22CVE-2026-92925Out-of-Bounds Access in Redis community Affects Enterprise Linux 9, Leading to Service Disruption7.1 HighUpdated
2026-09-22CVE-2026-87766Red Hat Enterprise Linux 10 bubblewrap Arbitrary Filesystem Write Reachable by Low-Privilege Local Attackers (CVSS 8.8)8.8 HighUpdated
2026-09-22CVE-2026-87742Quarkus WebSockets Next Streaming Message Handling Lets Remote Attackers Cause Denial of Service (CVSS 7.5)7.5 HighUpdated
2026-09-22CVE-2026-72946Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally7.8 HighUpdated
2026-09-22CVE-2026-72940Heap-based buffer overflow in Windows Schannel allows an unauthorized attacker to execute code over a network8.8 HighUpdated
2026-09-22CVE-2026-72936Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network8.1 HighUpdated
2026-09-22CVE-2026-72929Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally7.8 HighUpdated
2026-09-22CVE-2026-72926Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-7273Zyxel GS1900 Series Switches' CGI Program Stack-Based Buffer Overflow Allows a LAN-Side Unauthenticated Attacker to Execute OS Commands via Crafted HTTP Requests; CISA's September 24th KEV Deadline Has Passed8.8 HighKEV
2026-09-22CVE-2026-71221Enterprise Linux gfs2-utils Code Execution Reachable by Unauthenticated Local Attackers (CVSS 7.0)7.0 HighUpdated
2026-09-22CVE-2026-71220Enterprise Linux gfs2-utils Buffer Overflow Reachable by Unauthenticated Local Attackers (CVSS 7.0)7.0 HighUpdated
2026-09-22CVE-2026-69791Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-69790Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to elevate privileges locally7.8 HighUpdated
2026-09-22CVE-2026-69784Windows Hello Use-After-Free Lets Authorized Attackers Escalate Privileges Locally8.8 HighUpdated
2026-09-22CVE-2026-69775Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network7.1 HighUpdated
2026-09-22CVE-2026-69762Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network8.0 HighUpdated
2026-09-22CVE-2026-69760Out-of-bounds read in Windows Kerberos allows an unauthorized attacker to deny service over a network7.5 HighUpdated
2026-09-22CVE-2026-69757Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network7.1 HighUpdated
2026-09-22CVE-2026-69744Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network7.5 HighUpdated
2026-09-22CVE-2026-69740Use after free in Windows Hello allows an authorized attacker to elevate privileges locally8.8 HighUpdated
2026-09-22CVE-2026-69735Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-69729Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to execute code over a network8.8 HighUpdated
2026-09-22CVE-2026-69725Double free in Windows Hello allows an authorized attacker to elevate privileges locally7.8 HighUpdated
2026-09-22CVE-2026-69720Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally7.8 HighUpdated
2026-09-22CVE-2026-69711Windows Device Association Service Use-After-Free Lets Authorized Attackers Escalate Privileges Locally7.0 HighUpdated
2026-09-22CVE-2026-69710Windows Hello Race Condition Lets Authorized Attackers Escalate Privileges Locally7.5 HighUpdated
2026-09-22CVE-2026-69708Use after free in Windows Web Platform Storage allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-69694Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-69693Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-69689Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges over a network8.0 HighUpdated
2026-09-22CVE-2026-69682Use after free in Windows Host Guardian Service allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-69654Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-69652Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-22CVE-2026-5680Red Hat Enterprise Linux 9 Undertow Denial of Service Reachable by Unauthenticated Remote Attackers (CVSS 7.5)7.5 HighUpdated
2026-09-22CVE-2026-43961Red Hat Enterprise Linux 10 Vim's Security Flaw Reachable by Unauthenticated Local Attackers (CVSS 7.8)7.8 HighUpdated
2026-09-22CVE-2026-31278Suprema BioStar 2 Active Directory Settings Endpoint Exposes Service Account Credentials in Cleartext to Crafted GET Requests7.7 HighUpdated
2026-09-21CVE-2026-90042Linux Kernel ceph properly decrypt filenames in vmalloc() buffers, Reachable Without Authentication at CVSS 9.89.8 CriticalUpdated
2026-09-21CVE-2026-90041Linux Kernel HID: sony: clean up device list on probe failure8.8 HighUpdated
2026-09-21CVE-2026-90037Linux Kernel NFSD: Failure to Prevent client use-after-free during close_lru reaping, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-09-21CVE-2026-90036Linux Kernel NFSD Prevent client use-after-free during blocked-lock reaping, Reachable Without Authentication at CVSS 9.89.8 CriticalUpdated
2026-09-21CVE-2026-89815Linux Kernel drm/ttm: Memory Safety Issue Allows Local Privilege Escalation7.8 HighUpdated
2026-09-21CVE-2026-89799Linux Kernel bpf: Disable preemption in bpf_get_stackid7.8 HighUpdated
2026-09-21CVE-2026-89763Linux Kernel KEYS trusted: Fix TPM teardown ordering7.8 HighUpdated
2026-09-21CVE-2026-89755Linux Kernel mm/migrate_device: Failure to Clear stale mapping after freeing swapcache7.8 HighUpdated
2026-09-21CVE-2026-89731Linux Kernel cxl/ras: Out-of-Bounds Read Allows Local Privilege Escalation7.1 HighUpdated
2026-09-21CVE-2026-89708Linux Kernel nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-09-21CVE-2026-89685Linux Kernel nfsd fix clock domain mismatch in clients_still_reclaiming(), Reachable from the Network Without Credentials (CVSS 7.5)7.5 HighUpdated
2026-09-21CVE-2026-89676Linux Kernel nfsd: Reference Count Error Enables Remote Code Execution (CVSS 9.8)9.8 CriticalUpdated
2026-09-21CVE-2026-89667Linux Kernel nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache, Reachable from the Network Without Credentials (CVSS 8.1)8.1 HighUpdated
2026-09-21CVE-2026-89660Linux Kernel NFSD Prevent client use-after-free during admin state revocation, Reachable Without Authentication at CVSS 9.89.8 CriticalUpdated
2026-09-21CVE-2026-89659Linux Kernel NFSD Prevent client use-after-free during delegation revoke, Reachable Without Authentication at CVSS 9.89.8 CriticalUpdated
2026-09-21CVE-2026-89624Linux Kernel HID: universal-pidff: stop the device when force-feedback init fails7.8 HighUpdated
2026-09-21CVE-2026-89622Linux Kernel HID mcp2221: clear rxbuf after I2C/SMBus transfer completes7.8 HighUpdated
2026-09-21CVE-2026-89602Linux Kernel erofs: skip sufficiently large global buffers when resizing7.8 HighUpdated
2026-09-21CVE-2026-89564Linux Kernel ip orphan prefetched skbs before multicast forwarding7.8 HighUpdated
2026-09-21CVE-2026-89561Linux Kernel ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv(), Reachable from the Network Without Credentials (CVSS 7.5)7.5 HighUpdated
2026-09-21CVE-2026-89545Linux Kernel sunrpc: defer rq_argp and rq_resp free until after RCU grace period7.8 HighUpdated
2026-09-21CVE-2026-89544Linux Kernel SUNRPC: Failure to Fix gssx_dec_option_array error path bugs, Reachable from the Network Without Credentials (CVSS 7.5)7.5 HighUpdated
2026-09-21CVE-2026-89535Linux Kernel svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id, Reachable from the Network Without Credentials (CVSS 8.1)8.1 HighUpdated
2026-09-21CVE-2026-89492Linux Kernel ocfs2: Failure to Validate directory-index entry counts when reading metadata, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-09-21CVE-2026-85150Red Hat Enterprise Linux 10 GStreamer's Denial of Service Reachable by Unauthenticated Remote Attackers (CVSS 7.5)7.5 HighUpdated
2026-09-21CVE-2026-85013Red Hat Enterprise Linux 10 environment-modules Security Flaw Reachable by Low-Privilege Local Attackers (CVSS 7.3)7.3 HighUpdated
2026-09-21CVE-2026-81627Security Flaw in QEMU Affects Enterprise Linux 98.2 HighUpdated
2026-09-21CVE-2026-80945Linux Kernel crypto: iaa - unmap dst before software fallback on decompress, Reachable Without Authentication (CVSS 9.1)9.1 CriticalUpdated
2026-09-21CVE-2026-80734Linux Kernel btrfs: Failure to Initialize inode mapping flags for cached inodes8.8 HighUpdated
2026-09-21CVE-2026-80685Linux Kernel mm/util: Missing Guard: don't read __page_2 for order-1 folios in snapshot_page()7.1 HighUpdated
2026-09-21CVE-2026-74407Linux Kernel wifi ath11k: cancel SSR work items during PCI shutdown8.8 HighUpdated
2026-09-21CVE-2026-74269Linux Kernel bnxt: Failure to Fix head underflow on XDP head-grow, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-09-21CVE-2026-72989Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network7.5 HighUpdated
2026-09-21CVE-2026-72962Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally8.2 HighUpdated
2026-09-21CVE-2026-72961Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally8.2 HighUpdated
2026-09-21CVE-2026-72960Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network8.8 HighUpdated
2026-09-21CVE-2026-72958Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally8.2 HighUpdated
2026-09-21CVE-2026-72953Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally7.8 HighUpdated
2026-09-21CVE-2026-72952Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally7.0 HighUpdated
2026-09-21CVE-2026-72949Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network7.5 HighUpdated
2026-09-21CVE-2026-72494Linux Kernel RDMA/irdma Replace waitqueue and flag with completion, Reachable Without Authentication at CVSS 9.89.8 CriticalUpdated
2026-09-21CVE-2026-72438Linux Kernel md/raid10: Failure to Fix writes_pending and barrier reference leaks on discard failures, Reachable from the Network Without Credentials (CVSS 7.5)7.5 HighUpdated
2026-09-21CVE-2026-72355Linux Kernel netfs: Failure to Fix barriering when walking subrequest list, Reachable Without Authentication (CVSS 9.8)9.8 CriticalUpdated
2026-09-21CVE-2026-71226Enterprise Linux Memory Corruption Reachable by Unauthenticated Local Attackers (CVSS 7.3)7.3 HighUpdated
2026-09-21CVE-2026-69648Use after free in Windows Notification allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-21CVE-2026-69625Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network8.0 HighUpdated
2026-09-21CVE-2026-69617Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-21CVE-2026-69606Use after free in Windows Shell allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-21CVE-2026-69602Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network7.1 HighUpdated
2026-09-21CVE-2026-69597Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network7.1 HighUpdated
2026-09-21CVE-2026-69586Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network9.8 CriticalUpdated
2026-09-21CVE-2026-69575Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally7.0 HighUpdated
2026-09-21CVE-2026-54230Enterprise Linux Arbitrary Filesystem Write Reachable by Low-Privilege Local Attackers (CVSS 7.0)7.0 HighUpdated
2026-09-21CVE-2026-19611Red Hat JBoss Enterprise Application Platform 7 WildFly Security Flaw Reachable by Unauthenticated Remote Attackers (CVSS 7.4)7.4 HighUpdated
2026-09-21CVE-2026-16445Red Hat Enterprise Linux 8 dracut Remote Code Execution Reachable by Unauthenticated Adjacent-Network Attackers (CVSS 7.5)7.5 HighUpdated
2026-09-20CVE-2026-87886Acronis Backup's Incorrect Default Permissions Allow a Local Attacker to Access Backup Files and Configurations Not Intended for Their Account; CISA's September 19th KEV Deadline Has Passed7.8 HighKEV
2026-09-20CVE-2026-84869ConnectWise ScreenConnect's Improper Privilege Management and Missing Authorization Allow Unauthenticated Attackers to Gain Administrative Control of the Remote Support Platform; CISA's September 14th KEV Deadline Has Passed9.9 CriticalKEV
2026-09-20CVE-2026-81963Windows Update Stack Symbolic Link Following Lets Authorized Attackers Escalate Privileges Locally (CVSS 7.8)7.8 HighKEV
2026-09-20CVE-2026-67277MikroTik RouterOS's Missing Authentication for a Critical Function Allows Unauthenticated Attackers to Access and Modify Router Configuration; CISA's September 13th KEV Deadline Has Passed8.2 HighKEV
2026-09-20CVE-2026-53362Linux Kernel's Unspecified Flaw Allows Local Attackers to Gain Elevated Privileges on Affected Systems; CISA's August 30th KEV Deadline Has Passed7.8 HighKEV
2026-09-20CVE-2026-53266Linux Kernel's Out-of-Bounds Write Vulnerability Allows Local Attackers to Escalate Privileges or Cause a Kernel Crash; CISA's September 21st KEV Deadline Has Passed8.8 HighKEV
2026-09-20CVE-2026-50516Microsoft Azure Kubernetes Service's Missing Authentication on a Critical Function Allows Unauthenticated Attackers to Interact with Privileged Cluster Management Endpoints9.4 CriticalUpdated
2026-09-20CVE-2026-20349Cisco Secure Firewall ASA and FTD's Heap Inspection Vulnerability Allows Remote Attackers to Extract Sensitive Memory Contents from the Firewall Device; CISA's August 14th KEV Deadline Has Passed8.6 HighKEV
2026-09-20CVE-2026-20301Cisco IOS and IOS XE malformed XMCP packet causes denial of service via unauthenticated remote attacker8.6 HighExploited
2026-09-20CVE-2026-20124Cisco IOS XE malformed SNMP request causes device reload affecting SNMP versions 1, 2c, and 37.7 HighExploited
2026-09-18CVE-2026-80469Sick AG Sentio Creator Device Manager Extension Bypasses Driver Signature Verification, Allowing Malicious Package to Execute Arbitrary Code8.3 HighUpdated
2026-09-18CVE-2026-3869Schneider Electric Modicon M580 Incorrect Authentication Algorithm Implementation Risks Full PLC Compromise When a Lower Application Level Project Is Running9.2 CriticalUpdated
2026-09-18CVE-2026-27563Crafted GET Request to the Datastorage API Lets Admin Credentials Trigger Root Command Execution on Pepperl+Fuchs ICE-Series IO-Link Masters7.2 HighUpdated
2026-09-18CVE-2026-27558Operator Access to the IODD File Removal Endpoint on Pepperl+Fuchs ICE-Series IO-Link Masters Allows Root Command Injection8.8 HighUpdated
2026-09-18CVE-2026-27548Command Injection in the IODD Port Info Endpoint Grants Root Access on Pepperl+Fuchs ICE-Series IO-Link Masters to Any User or Operator Account8.8 HighUpdated
2026-09-18CVE-2026-15579Moxa TN-4500B Series Ethernet Switch Out-of-Bounds Write in Web Login Username Field Allows Remote Unauthenticated Attacker to Execute Code8.8 HighUpdated
2026-09-18CVE-2023-5778ABB Freelance Controller DCP, AC700, AC800, and AC900 Improper Length Parameter Handling Allows Remote Denial of Service7.5 HighUpdated
2026-09-16CVE-2026-53006Linux Kernel ICMPv6 Use-After-Free via Pointer Cached Before pskb_pull on Siemens SIMATIC S7-1500 MFP9.8 CriticalUpdated
2026-09-16CVE-2026-27565Unauthenticated IODD File Upload on Pepperl+Fuchs ICE-Series IO-Link Masters Executes a Root Shell Script That Persists Across Reboots9.8 CriticalUpdated
2026-09-16CVE-2026-27564Pepperl+Fuchs ICE-Series IO-Link Masters Run Injected Root Commands When Admin Credentials Submit a Crafted PUT Request to the Datastorage API7.2 HighUpdated
2026-09-16CVE-2026-27562Admin-Level PUT Requests to the IODD Configuration API Execute Injected Commands as Root on Pepperl+Fuchs ICE-Series IO-Link Masters7.2 HighUpdated
2026-09-16CVE-2026-27561Admin Credentials Enable Root Command Injection via the IODD Config GET API on Pepperl+Fuchs ICE-Series IO-Link Masters7.2 HighUpdated
2026-09-16CVE-2026-27560Admin-Credentialed DELETE Requests to Pepperl+Fuchs ICE-Series IO-Link Masters' Status API Carry Injected Commands Executed at Root7.2 HighUpdated
2026-09-16CVE-2026-27559User Credentials Are Enough to Inject Root-Level Commands via the Status Data API on Pepperl+Fuchs ICE-Series IO-Link Masters8.8 HighUpdated
2026-09-16CVE-2026-27557Unauthenticated Path Traversal in Pepperl+Fuchs ICE-Series IO-Link Masters Exposes the Device's SSH Server Private Keys7.5 HighUpdated
2026-09-16CVE-2026-27556Operator Cookie Enables Arbitrary PHP Code Execution on Pepperl+Fuchs ICE-Series IO-Link Masters via Local File Inclusion in the IODD Parameter Save Endpoint8.8 HighUpdated
2026-09-16CVE-2026-27555A Valid User Cookie Triggers Arbitrary PHP Code Execution on Pepperl+Fuchs ICE-Series IO-Link Masters via Local File Inclusion in the IODD Port Info Endpoint8.8 HighUpdated
2026-09-16CVE-2026-27554IODD Parameter Save Endpoint on Pepperl+Fuchs ICE-Series IO-Link Masters Accepts Injected Commands from Operator-Level Accounts, Yielding Root Access8.8 HighUpdated
2026-09-16CVE-2026-27552Pepperl+Fuchs ICE-Series IO-Link Masters Allow Low-Privileged Users to Upload Arbitrary IODD Files via a Missing Authorization Check, Enabling Device Manipulation or Crashes8.1 HighUpdated
2026-09-16CVE-2026-27551User-Level Credentials Give Root Shell on Pepperl+Fuchs ICE-Series IO-Link Masters via the Parameter Management Endpoint8.8 HighUpdated
2026-09-16CVE-2026-27550Operator Credentials Can Inject Root-Level OS Commands via the Field_Shadow_Password Handler on Pepperl+Fuchs ICE-Series IO-Link Masters8.8 HighUpdated
2026-09-16CVE-2026-27549Operator-Level Credentials Suffice to Run Root Commands on Pepperl+Fuchs ICE-Series IO-Link Masters via the IODD Upload Endpoint8.8 HighUpdated
2026-09-16CVE-2026-27547IODD Menu Info Request on Pepperl+Fuchs ICE-Series IO-Link Masters Passes Unvalidated Parameters to Root-Level Commands, Reachable with User-Level Credentials8.8 HighUpdated
2026-09-16CVE-2026-27546The _account_log Function in Pepperl+Fuchs ICE-Series IO-Link Masters Lets Unauthenticated Attackers Log In as Admin Regardless of Account Configuration9.8 CriticalUpdated
2026-09-15CVE-2026-46116Linux Kernel xfrm_state List Defensively Not Unhashed in __xfrm_state_delete on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-14CVE-2026-62647Siemens Reyrolle 7SR5 Weak Random Number Generator Produces Low-Entropy Session Identifiers7.4 HighUpdated
2026-09-14CVE-2026-34223Siemens Desigo CC ClickOnce Client Code Injection Vulnerability Across All Versions from V6 Through V98.2 HighUpdated
2026-09-11CVE-2026-81822AVEVA Pipeline Integrity Monitor Weak Password Hashing in PIMBoards Project Files Allows Credential Recovery via Brute Force8.4 HighUpdated
2026-09-11CVE-2026-81821AVEVA Pipeline Integrity Monitor Hard-Coded Encryption Key in PIMBoards Project Files Exposes Sensitive Information to File Read Access8.4 HighUpdated
2026-09-11CVE-2026-63298LXD NVIDIA Instance Configuration Handler Accepts Newline Characters in nvidia.driver.capabilities and nvidia.require.* Values, Letting Authenticated Attackers Inject Arbitrary Directives into the GPU Configuration9.9 CriticalUpdated
2026-09-10CVE-2026-62646Siemens Reyrolle 7SR5 Session Identifier Generated with Insufficient Randomness, Enabling Token Prediction Attacks7.4 HighUpdated
2026-09-10CVE-2026-53002Linux Kernel netfilter Conntrack sprintf Usage Risks Buffer Overrun on Siemens SIMATIC S7-1500 MFP9.8 CriticalUpdated
2026-09-10CVE-2026-32589Red Hat Quay authenticated push access enables interference with other users' in-progress image uploads across repositories7.4 HighUpdated
2026-09-09CVE-2026-9854Hitachi Energy MicroSCADA X SYS600 Engineering Tool Access Can Escalate Privileges to Administrator on the Underlying Windows Host7.8 HighUpdated
2026-09-09CVE-2026-9853Hitachi Energy MicroSCADA X SYS600 RBAC Flaw Lets Any OS-Authenticated User Access and Modify Application Objects Without Application Login7.8 HighUpdated
2026-09-09CVE-2026-9852Hitachi Energy MicroSCADA X SYS600 CSV Injection Vulnerability Allows Authenticated Users to Inject Formulas into Exported Spreadsheets7.8 HighUpdated
2026-09-09CVE-2026-8044Schneider Electric EcoStruxure IT Data Center Expert Argument Injection in Privileged Account Context Enables Remote Code Execution8.6 HighUpdated
2026-09-09CVE-2026-77120Schneider Electric PowerLogic T300 OS Command Injection via Admin-Privileged Context Allows Privilege Escalation to Root8.7 HighUpdated
2026-09-09CVE-2026-67367Siemens SIMOVE Fleetmanager Path Traversal Allows Unauthenticated Attacker to Read Sensitive Files via Relative Path Manipulation8.6 HighUpdated
2026-09-09CVE-2026-62649Siemens Reyrolle 7SR5 Web Server Resource Exhaustion Under High Concurrent HTTP Request Volume Causes Denial of Service7.5 HighUpdated
2026-09-09CVE-2026-54100Red Hat's Windows Machine Config Operator skips SSH host-key checks, letting adjacent attackers capture node bootstrap credentials8.3 HighUpdated
2026-09-09CVE-2026-54099A compromised Windows node can forge a cluster-administrator certificate through WMCO's CSR auto-approver, CVSS 8.88.8 HighUpdated
2026-09-09CVE-2026-32590Unsafe Deserialization in Red Hat Quay Resumable Upload Handling7.1 HighUpdated
2026-09-09CVE-2026-19233Schneider Electric EcoStruxure IT Data Center Expert Server-Side Request Forgery in Privileged Account Context Risks Unauthorized Command Execution8.6 HighUpdated
2026-09-09CVE-2026-11841Sick AG InspectorP Sensor AppEngine HTTP Fileaccess Allows Unauthenticated Read and Write Operations on Sensitive Filesystem Areas9.4 CriticalUpdated
2026-09-08CVE-2026-80465Siemens Mendix SAML Module JWT Algorithm Substitution Flaw Allows Unauthenticated Remote Authentication Bypass8.7 HighUpdated
2026-09-08CVE-2026-77393Inductive Automation Ignition Blank Project Role Creation Setting Allowed Any Authenticated User to Create Projects in Versions Up to 8.1.538.8 HighUpdated
2026-09-08CVE-2026-64560Linux Kernel POSIX CPU Timer Use-After-Free via Non-Leader exec() Race on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-64552Linux Kernel virtio-net receive_big() Length Bounds Check Error Allows Malicious Device to Trigger Out-of-Bounds Write on Siemens SIMATIC S7-1500 MFP8.4 HighUpdated
2026-09-08CVE-2026-64545Linux Kernel XDP Master Redirect NULL Pointer Dereference on Siemens SIMATIC S7-1500 MFP7.5 HighUpdated
2026-09-08CVE-2026-64423Linux Kernel IPv4 IGMP Use-After-Free During Network Device Teardown on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-64422Linux Kernel IPv4 TCP Reordering Sysctl and MTU Probe Size Validation Gap on Siemens SIMATIC S7-1500 MFP7.1 HighUpdated
2026-09-08CVE-2026-64413Linux Kernel ebtables chainstack Array Not Zeroed Before Use on Siemens SIMATIC S7-1500 MFP7.0 HighUpdated
2026-09-08CVE-2026-64412Linux Kernel ebtables Module Name Not Null-Terminated Before Lookup on Siemens SIMATIC S7-1500 MFP7.1 HighUpdated
2026-09-08CVE-2026-64411Linux Kernel ebtables Update Counter Path Does Not Null-Terminate Table Name Before Lookup on Siemens SIMATIC S7-1500 MFP7.1 HighUpdated
2026-09-08CVE-2026-64375Linux Kernel proc ptrace_may_access Race via FD Links Not Locked by exec_update_lock on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-64317Linux Kernel ISO 9660 Rock Ridge Symlink Component Bounds Not Enforced Against SL Record on Siemens SIMATIC S7-1500 MFP7.1 HighUpdated
2026-09-08CVE-2026-64279Linux Kernel I2C Adapter Deregistration Race Condition on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-62650Siemens Reyrolle 7SR5 Web Management Server-Side Authorization Not Enforced, Allowing Role-Based Access Control Bypass8.8 HighUpdated
2026-09-08CVE-2026-62648Siemens Reyrolle 7SR5 Web Server URL Component Length Not Validated Before Use in Pre-Authenticated HTTP Messages, Enabling Denial of Service7.5 HighUpdated
2026-09-08CVE-2026-62645Siemens Reyrolle 7SR5 Web Interface Exposes Session ID Calculation Information, Allowing Session Hijacking Without Credentials9.8 CriticalUpdated
2026-09-08CVE-2026-53400Linux Kernel I2C Adapter Registration Race Condition on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-53275Linux Kernel IPv6 Multicast MLD Query Processing Use-After-Free on Siemens SIMATIC S7-1500 MFP8.8 HighUpdated
2026-09-08CVE-2026-53268Linux Kernel netfilter conntrack_irc Out-of-Bounds Read on Command Parse Failure on Siemens SIMATIC S7-1500 MFP8.2 HighUpdated
2026-09-08CVE-2026-53239Linux Kernel xfrm Policy Inexact Bin Use-After-Free in xfrm_policy_bysel_ctx on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-53223Linux Kernel Timestamp Control Message Handling Gap in Non-Error Queue skbs on Siemens SIMATIC S7-1500 MFP7.1 HighUpdated
2026-09-08CVE-2026-53050Linux Kernel Quota dquot_scan_active Race with Quota Deactivation on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-52999Linux Kernel netfilter nfnetlink_osf Out-of-Bounds Read in Option Matching on Siemens SIMATIC S7-1500 MFP9.1 CriticalUpdated
2026-09-08CVE-2026-52998Linux Kernel netfilter nfnetlink_osf NULL Pointer Dereference in TTL Check on Siemens SIMATIC S7-1500 MFP7.5 HighUpdated
2026-09-08CVE-2026-52986Linux Kernel SIP Conntrack NULL Pointer Dereference via Unsafe Port Parsing on Siemens SIMATIC S7-1500 MFP9.8 CriticalUpdated
2026-09-08CVE-2026-52946Linux Kernel fcntl Async Signal Lock Order Inversion Between SOFTIRQ-Safe and SOFTIRQ-Unsafe Paths on Siemens SIMATIC S7-1500 MFP7.5 HighUpdated
2026-09-08CVE-2026-52943Linux Kernel sk_buff Zerocopy Reference Missing in pskb_carve Helpers on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-52942Linux Kernel netfilter nf_log MAC Header Dump Not Guarded Against Unset Headers on Siemens SIMATIC S7-1500 MFP7.1 HighUpdated
2026-09-08CVE-2026-52933Linux Kernel io_uring Poll Ownership Check Uses Signed Comparison, Creating Race Condition on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-52912Linux Kernel netfilter nf_queue Bridge Device Reference Held Too Briefly in br_pass_frame_up on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-52910Linux Kernel BPF Reuseport cBPF Program Free Before RCU Grace Period on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-50093Siemens Siveillance Control Arbitrary File Upload Exploitable by Low-Privilege Authenticated Remote Attacker9.0 CriticalUpdated
2026-09-08CVE-2026-4740Red Hat Advanced Cluster Management lets a managed-cluster admin forge certificates for cross-cluster privilege escalation8.2 HighUpdated
2026-09-08CVE-2026-46323Linux Kernel GRO zcopy Frags Use-After-Free on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-46306Linux Kernel Flow Dissector PPPoE PFC Frames Dissected When They Should Be Skipped on Siemens SIMATIC S7-1500 MFP7.5 HighUpdated
2026-09-08CVE-2026-46303Linux Kernel ISO 9660 Rock Ridge CE Continuation Extent Not Validated Against Volume Size on Siemens SIMATIC S7-1500 MFP8.2 HighUpdated
2026-09-08CVE-2026-46300Linux Kernel SKBFL_SHARED_FRAG Marker Lost During sk_buff Coalescing on Siemens SIMATIC S7-1500 MFP Enables ESP In-Place Decrypt over Page-Cache Memory7.8 HighUpdated
2026-09-08CVE-2026-46173Linux Kernel Exit Path Race Causes Preemption of Oopsing TASK_DEAD Task on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-46037Linux Kernel IPv4 ICMP Extended Echo Reply Type Not Validated Before Pointer Use on Siemens SIMATIC S7-1500 MFP8.2 HighUpdated
2026-09-08CVE-2026-46033Linux Kernel authencesn Instance Creation Accepts Short Hash Digests That Could Lead to Incorrect Authentication on Siemens SIMATIC S7-1500 MFP7.1 HighUpdated
2026-09-08CVE-2026-46015Linux Kernel TCP Listener Migration Race on Siemens SIMATIC S7-1500 MFP After Listening Socket Closes7.8 HighUpdated
2026-09-08CVE-2026-43501Linux Kernel IPv6 RPL Source Routing Header Recompression Buffer Headroom Not Reserved on Siemens SIMATIC S7-1500 MFP9.8 CriticalUpdated
2026-09-08CVE-2026-43499Linux Kernel rtmutex Slow Lock Waiter Task Reference Incorrect in remove_waiter on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-43303Linux Kernel Page Allocator Free Path Leaves page->private Stale on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-43284Linux Kernel ESP In-Place Decrypt on Pipe-Spliced Shared Frags Risks Memory Corruption on Siemens SIMATIC S7-1500 MFP8.8 HighUpdated
2026-09-08CVE-2026-43116Linux Kernel netfilter ctnetlink Master Conntrack Access Without Sufficient Reference on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-43071Linux Kernel dcache Hashtable Out-of-Bounds Read When dhash_entries Set to 1 on Siemens SIMATIC S7-1500 MFP9.1 CriticalUpdated
2026-09-08CVE-2026-31700Linux Kernel PACKET_VNET_HDR TOCTOU Race on mmap'd vnet_hdr in tpacket_snd on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-31449Linux Kernel ext4 Extent Tree Index Bounds Validation Gap on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-09-08CVE-2026-18963Siemens Industrial Edge Management Keycloak Reset-Credentials Flow Flaw Allows Unauthenticated Account Takeover9.1 CriticalUpdated
2026-09-08CVE-2025-46418Westermo WeOS OS Command Injection via Media Definition Requires Authenticated Attacker with High Privileges7.6 HighUpdated
2026-09-05CVE-2026-71474Red Hat insights-client logs a long-lived OpenShift pull-secret token that local pod-log access can expose7.1 HighUpdated
2026-09-03CVE-2026-78319Sauter modu680 Building Automation Controller TOCTOU Race Condition Allows Unauthenticated Remote Security Bypass9.3 CriticalUpdated
2026-09-03CVE-2026-65423open62541 OPC UA Integer Overflow in arrayDimensions Computation Allows Remote Attacker to Trigger Out-of-Bounds Write8.8 HighUpdated
2026-09-03CVE-2026-63559open62541 OPC UA Integer Overflow in arrayDimensions Computation Allows Remote Out-of-Bounds Heap Memory Read7.5 HighUpdated
2026-09-03CVE-2026-63035open62541 OPC UA TransferSubscriptions Service Heap Use-After-Free Allows Authenticated Attacker to Cause Denial of Service or Code Execution8.1 HighUpdated
2026-09-03CVE-2026-6071Rockwell Automation Arena Simulation Out-of-Bounds Write When Parsing DOE Files Enables Code Execution When a User Opens a Malicious File7.5 HighUpdated
2026-09-03CVE-2024-7956Rockwell Automation DataMosaix Private Cloud Authorization Flaw Lets Low-Privilege Users Access Other Users' Projects7.6 HighUpdated
2026-09-01CVE-2026-9637Rockwell Automation CompactLogix 5380 and ControlLogix 5580 CIP Message Input Length Validation Gap Causes Denial of Service8.7 HighUpdated
2026-09-01CVE-2026-9634Rockwell Automation Redundancy Module Configuration Tool DLL Search Order Hijack via Unquoted System Path7.0 HighUpdated
2026-09-01CVE-2026-9633Rockwell Automation Redundancy Module Configuration Tool DLL Search Order Hijack via Unquoted System Path in RM3ConfigTool.exe7.0 HighUpdated
2026-09-01CVE-2026-9625Rockwell Automation RSLinx Classic Oversized Embedded CIP Message Request Crashes Service, Requiring Manual Restart8.7 HighUpdated
2026-09-01CVE-2026-9624Rockwell Automation RSLinx Classic Integer Underflow on CIP Packet Data Length Validation Crashes Service8.7 HighUpdated
2026-09-01CVE-2026-9622Rockwell Automation RSLinx Classic Forward Close CIP Packet Handling Crash Requires Manual Service Restart8.7 HighUpdated
2026-09-01CVE-2026-9621Rockwell Automation RSLinx Classic Crashes on Malformed CIP Packet Due to Integer Overflow, Requiring Manual Service Restart9.2 CriticalUpdated
2026-09-01CVE-2026-84235Rockwell Automation 1756-ENBT Module Crashes on Crafted CIP Packet, Requiring Device Restart to Recover8.7 HighUpdated
2026-09-01CVE-2026-78317Delta DIAEnergie SQL Injection Allows Authenticated Remote Code Execution8.8 HighUpdated
2026-09-01CVE-2026-78316Delta DIAEnergie SQL Injection Allows Authenticated Remote Code Execution8.8 HighUpdated
2026-09-01CVE-2026-78315Delta DIAEnergie SQL Injection Allows Authenticated Remote Code Execution8.8 HighUpdated
2026-09-01CVE-2026-78314Delta DIAEnergie SQL Injection Allows Authenticated Remote Code Execution8.8 HighUpdated
2026-09-01CVE-2026-35535Sudo Privilege Drop Failure in setuid/setgid Not Treated as Fatal Error, Enabling Privilege Escalation During Mailer Execution7.4 HighUpdated
2026-09-01CVE-2026-19472Rockwell Automation ArmorStart LT Embedded Web Server Crashes on Crafted HTTP PUT Request, Causing Denial of Service8.7 HighUpdated
2026-09-01CVE-2026-16675Rockwell Automation FactoryTalk Activation Manager Installer Custom Action Spawns SYSTEM-Level Console Window, Enabling Privilege Escalation8.5 HighUpdated
2026-09-01CVE-2026-13336Schneider Electric NetBotz 5 OS Command Injection During System Backup Restore Lets Authenticated Admin Execute Arbitrary Linux Commands7.3 HighUpdated
2026-09-01CVE-2026-12663Rockwell Automation ControlFLASH Installer Grants Write Access to Everyone Group on Installation Directory, Enabling Arbitrary Code Execution7.0 HighUpdated
2026-09-01CVE-2025-12768Rockwell Automation FactoryTalk Historian Machine Edition Out-of-Bounds Write Accessible to Low-Privilege Adjacent Network Attackers8.6 HighUpdated
2026-09-01CVE-2024-7953Rockwell Automation DataMosaix Private Cloud Lets Any Authenticated User Self-Promote to Project Administrator and Modify Project Data8.7 HighUpdated
2026-09-01CVE-2024-7952Rockwell Automation DataMosaix Private Cloud Hardcoded Source Code Links Expose JSON Files Containing Sensitive Data Without Authentication8.7 HighUpdated
2026-09-01CVE-2024-10085Schneider Electric EcoStruxure OPC UA Server Expert Unconstrained OPC UA Request Allocation Causes Denial of Service8.2 HighUpdated
2026-08-28CVE-2026-66155Siemens Element maps-ng Cross-Site Scripting in si-map Component Affects Multiple Software Versions7.6 HighUpdated
2026-08-28CVE-2026-64629Siemens Parasolid Out-of-Bounds Read on Specially Crafted File Parse Can Lead to Code Execution7.8 HighUpdated
2026-08-28CVE-2026-59701Siemens Simcenter Femap Out-of-Bounds Read Parsing BMP Files Can Lead to Code Execution in the Current User Context7.8 HighUpdated
2026-08-28CVE-2026-59700Siemens Simcenter Femap Out-of-Bounds Read on Parsing Specially Crafted BMP Files Can Lead to Code Execution7.8 HighUpdated
2026-08-28CVE-2026-59086Siemens Simcenter Femap and Nastran Stack-Based Buffer Overflow When Parsing Specially Crafted Files Can Lead to Code Execution7.8 HighUpdated
2026-08-28CVE-2026-58115Siemens SIMATIC IoT2050 Advanced with Node-RED Does Not Enforce Authentication on Node-RED API Endpoint10.0 CriticalUpdated
2026-08-28CVE-2026-20094Cisco UCS Command Injection Scores 8.88.8 HighUpdated
2026-08-26CVE-2026-71276Magistrala Message Reader API Interpolates Unvalidated HTTP Query Parameters Directly into Raw SQL Queries7.1 HighUpdated
2026-08-26CVE-2026-71235Magistrala Rules Engine Lua Script Engine Performs No Input Validation, Allowing Authenticated Users to Execute Arbitrary Server-Side Code8.8 HighUpdated
2026-08-25CVE-2026-9128Rockwell Automation Studio 5000 Logix Designer Unquoted Search Path in External Tools Configuration Allows Low-Privilege Code Execution7.5 HighUpdated
2026-08-25CVE-2026-9127Rockwell Automation Studio 5000 Logix Designer External Tool Config File Incorrect Authorization Allows Any Authenticated User to Modify Tool Paths7.5 HighUpdated
2026-08-25CVE-2026-9108Rockwell Automation Studio 5000 Logix Designer Path Traversal via Malicious ACD Project File Allows Arbitrary File Write7.5 HighUpdated
2026-08-24CVE-2026-46333Linux Kernel ptrace Dumpability Logic Flaw Risks Privilege Escalation via Memory Image Exposure on Siemens SIMATIC S7-1500 MFP7.1 HighUpdated
2026-08-24CVE-2026-21661Johnson Controls AC2000 Access Control System Uncontrolled Search Path Allows Authenticated Local Attacker to Leverage Configuration File Paths8.4 HighUpdated
2026-08-20CVE-2026-43038Linux Kernel IPv6 ICMP Error Generation Leaves skb2->cb[] Uncleared on Siemens SIMATIC S7-1500 MFP9.8 CriticalUpdated
2026-08-17CVE-2026-25193Gallagher Command Centre Service Installer Log File Exposes Service Account Credentials During Installation8.1 HighUpdated
2026-08-14CVE-2026-32153Use-After-Free in Windows Speech Component Allows Local Privilege Escalation7.8 HighUpdated
2026-08-13CVE-2026-64125Linux Kernel bcmgenet Driver Enabling RBUF EEE and PM Bits Stops RX Traffic When MAC EEE Activates, Causing a Denial-of-Service Condition on Broadcom GENET Hardware9.8 CriticalUpdated
2026-08-11CVE-2026-33390Nozomi Networks Guardian Arc Sensor Sync Incorrectly Grants CLI Permissions to Low-Privileged Authenticated Users8.1 HighUpdated
2026-08-11CVE-2026-31984Nozomi Networks Guardian Audit Logging Missing Input Size Limit Allows Unauthenticated Attacker to Cause Denial of Service7.5 HighUpdated
2026-08-11CVE-2026-31982Nozomi Networks Guardian SAML Single Sign-On Open Redirect via Unvalidated Redirection Parameter Allows Unauthenticated Phishing Attack7.1 HighUpdated
2026-08-11CVE-2026-3014Milestone XProtect Management Server API Allows Users with Edit Permission to Execute OS Commands via Crafted Requests9.1 CriticalUpdated
2026-08-11CVE-2026-0287Palo Alto Networks PAN-OS Multiple Denial-of-Service Vulnerabilities Allow Unauthenticated Network Attacker to Disrupt Firewall Service7.5 HighUpdated
2026-08-11CVE-2026-0286Palo Alto Networks PAN-OS Management Plane Command Injection Allows Authenticated Administrator to Execute Arbitrary Root-Level OS Commands7.2 HighUpdated
2026-08-11CVE-2026-0284Palo Alto Networks PAN-OS LSVPN XML Injection Allows Unauthenticated Network Attacker to Inject Malicious Content9.9 CriticalUpdated
2026-08-11CVE-2026-0283Palo Alto Networks PAN-OS Large Scale VPN Authentication Bypass Allows Network Attackers to Bypass Security Restrictions7.2 HighUpdated
2026-08-11CVE-2026-0281Palo Alto Networks PAN-OS Web Session Token Exposed to Unauthenticated Network Attacker via Management Interface7.1 HighUpdated
2026-08-11CVE-2026-0280Palo Alto Networks PAN-OS IPv6 Packet Processing Flaw Allows Unauthenticated Attackers to Bypass Firewall Security Policy7.2 HighUpdated
2026-08-11CVE-2025-40833Siemens IE/PB LINK Null Pointer Dereference on Specially Crafted IPv4 Requests Causes Denial of Service Requiring Manual Reset7.5 HighUpdated
2026-08-10CVE-2026-16443Red Hat Build of Keycloak Cryptographic Signature Verification Flaw Scores 7.47.4 HighUpdated
2026-07-31CVE-2026-44106Phoenix Contact CHARX SEC Init-Script for User Applications Allows Low-Privilege Local User to Execute Arbitrary Commands as Root7.8 HighUpdated
2026-07-31CVE-2026-44101Phoenix Contact CHARX OCPP Agent Service Missing Authentication Allows Unauthenticated Remote Attacker to Reconfigure Backend Connection9.8 CriticalUpdated
2026-07-31CVE-2026-44096Phoenix Contact CHARX SEC udhcpc Privilege Escalation Lets the charx-web User Execute Arbitrary Commands as Root7.8 HighUpdated
2026-07-31CVE-2026-44091Phoenix Contact CHARX SEC MQTT Broker Accepts Unauthenticated Malicious ID Injection That Creates Unauthorized Configuration Entries9.1 CriticalUpdated
2026-07-31CVE-2026-22620Eaton Tripp Lite PADM Authentication Component Input Validation Flaw Allows Unauthenticated Attackers to Gain Privileged Access8.6 HighUpdated
2026-07-30CVE-2026-7849Phoenix Contact CHARX SEC Unauthenticated Remote Attacker Can Inject System Configuration Commands Executed as Root9.8 CriticalUpdated
2026-07-30CVE-2026-44108Phoenix Contact CHARX SEC Firewall Terminated Prematurely During System Shutdown Creates Temporary Window Exposing Internal Services9.8 CriticalUpdated
2026-07-30CVE-2026-44107Phoenix Contact CHARX SEC Modbus TCP Reboot Command Requires No Authentication When Port Is Open7.5 HighUpdated
2026-07-30CVE-2026-44104Phoenix Contact CHARX SEC Firmware Update Process for Base Module Lacks Cryptographic Signature Verification, Allowing Unauthenticated Remote Firmware Replacement9.8 CriticalUpdated
2026-07-30CVE-2026-44100Phoenix Contact CHARX JupiCore Allows Unauthenticated Remote Attacker to Reconfigure Charging Points and Access Charging Point UIDs9.4 CriticalUpdated
2026-07-30CVE-2026-44099Phoenix Contact CHARX SEC EV Charging Controller System Configuration Flaw Lets Local Low-Privilege User Execute Arbitrary Commands as Root7.8 HighUpdated
2026-07-30CVE-2026-44098Phoenix Contact CHARX SEC OCPP Backend Firewall Bypass Enables Unauthenticated Remote OS Command Execution8.6 HighUpdated
2026-07-30CVE-2026-44097Phoenix Contact CHARX SEC Firmware Update REST Endpoint Accepts Arbitrary File Uploads from Low-Privileged Operator Accounts7.1 HighUpdated
2026-07-30CVE-2026-44095Phoenix Contact CHARX SEC Network Configuration Script Allows Low-Privilege Local User to Execute Arbitrary Commands as Root7.8 HighUpdated
2026-07-30CVE-2026-44094Phoenix Contact CHARX SEC Unauthenticated Remote Attacker Can Force Fallback to Firmware Partition with Default Credentials8.6 HighUpdated
2026-07-30CVE-2026-44093Phoenix Contact CHARX SEC Charging Controller Init-Script Flaw Enables Low-Privilege Local User to Execute Arbitrary Commands as Root7.8 HighUpdated
2026-07-30CVE-2026-44092Phoenix Contact CHARX SEC ModbusServer Accepts Unvalidated MQTT Input, Letting Unauthenticated Backend-Control Attackers Inject Malicious Data9.1 CriticalUpdated
2026-07-30CVE-2026-44090Phoenix Contact CHARX SEC Unauthenticated MQTT Broker Accessible Behind Bypassed Firewall Risks Full Device Compromise9.8 CriticalUpdated
2026-07-30CVE-2026-14837Multiple Lenze Products Improper SSH Enable File Signature Verification Allows Low-Privilege Local Attacker to Bypass SSH Controls7.8 HighUpdated
2026-07-30CVE-2026-14354Schneider Electric EcoStruxure Cybersecurity Admin Expert Insufficient Credential Protection Allows Authentication Bypass and Unauthorized Credential Modification8.7 HighUpdated
2026-07-30CVE-2026-14169ads-tec Industrial IT DVG-IRF Incorrect Behavior Order Allows Low-Privilege Remote Attacker to Overwrite Existing User Passwords8.1 HighUpdated
2026-07-30CVE-2026-14168ads-tec Industrial IT DVG-IRF Missing Authorization at Configuration Table Insertion Path Grants Low-Privileged Users Full Administrator Access8.8 HighUpdated
2026-07-30CVE-2026-14167ads-tec Industrial IT DVG-IRF Router Incorrect Authorization Lets Low-Privileged Remote Users Make Administrator-Level Configuration Changes8.8 HighUpdated
2026-07-30CVE-2026-12927Schneider Electric IGSS Definition Out-of-Bounds Write in Malicious CGF File Import Risks Arbitrary Code Execution8.4 HighUpdated
2026-07-30CVE-2026-0667Schneider Electric SCADAPack Failure to Handle Unusual Communication Conditions Risks Arbitrary Code Execution and Full Data Loss9.3 CriticalUpdated
2026-07-24CVE-2026-5726Delta ASDA-Soft Stack-Based Buffer Overflow Allows Code Execution via Malicious File7.8 HighUpdated
2026-07-24CVE-2026-44469CODESYS Development System Administrative Installer Extracts Files to World-Writable Temp Directory, Enabling TOCTOU Privilege Escalation7.8 HighUpdated
2026-07-24CVE-2026-44468CODESYS Development System Administrative Installer Creates Directory with Insecure Default Permissions7.8 HighUpdated
2026-07-24CVE-2026-33105Critical Authorization Bypass in Microsoft Azure Kubernetes Service Allows Network Privilege Escalation10.0 CriticalUpdated
2026-07-24CVE-2026-31790Siemens SIMATIC CN 4100 OpenSSL RSASVE Key Encapsulation Sends Uninitialized Memory Contents to Peers7.5 HighUpdated
2026-07-24CVE-2026-31789Siemens SIMATIC CN 4100 OpenSSL 32-Bit Heap Buffer Overflow When Converting Excessively Large OCTET STRING to Hexadecimal9.8 CriticalUpdated
2026-07-24CVE-2026-31405Linux Kernel DVB-net ULE Extension Handler Uses a Network-Controlled Index into a 255-Entry Table Without Bounds Checking, Enabling Out-of-Bounds Reads and Writes9.8 CriticalUpdated
2026-07-24CVE-2026-31403Linux Kernel NFSD Network Reference Not Held for Full /proc/fs/nfs/exports Lifetime on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-24CVE-2026-31402Linux Kernel NFSv4.0 LOCK Replay Cache Heap Overflow Corrupts Memory on Siemens SIMATIC S7-1500 MFP9.8 CriticalUpdated
2026-07-24CVE-2026-31389Linux Kernel SPI Controller Registration Failure Use-After-Free on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-24CVE-2026-28387Siemens SIMATIC CN 4100 OpenSSL DANE TLSA Use-After-Free in Uncommon Server Authentication Configuration8.1 HighUpdated
2026-07-24CVE-2026-23458Linux kernel ctnetlink multi-round dump dereferences freed conntrack pointer in second callback invocation7.8 HighUpdated
2026-07-24CVE-2026-23457Linux Kernel SIP Content-Length Integer Truncation in nf_conntrack on Siemens SIMATIC S7-1500 MFP8.6 HighUpdated
2026-07-24CVE-2026-23456Linux Kernel netfilter H.323 Conntrack Out-of-Bounds Read in DecodeQ931 Integer Decode on Siemens SIMATIC S7-1500 MFP8.2 HighUpdated
2026-07-24CVE-2026-23455Linux Kernel H.323 Conntrack DecodeQ931 Reads Past Zero-Length UserUserIE Field on Siemens SIMATIC S7-1500 MFP9.1 CriticalUpdated
2026-07-24CVE-2026-23454Linux Kernel MANA Network Driver Use-After-Free in HWC Channel Teardown Reordering on Siemens SIMATIC S7-1500 MFP7.0 HighUpdated
2026-07-24CVE-2026-23450Linux Kernel SMC-over-TCP SYN Receive Path Calls sock_hold Then Schedules a tcp_close Work Item Without Synchronizing Against Concurrent Stack Cleanup, Enabling Use-After-Free and Null Dereference9.8 CriticalUpdated
2026-07-24CVE-2026-23434Linux Kernel NAND Flash Lock/Unlock Not Serialized Against Other NAND Operations on Siemens SIMATIC S7-1500 MFP7.1 HighUpdated
2026-07-24CVE-2026-23429Linux Kernel IOMMU SVA Use-After-Free in Unbind Path Scores 7.87.8 HighUpdated
2026-07-24CVE-2026-23424Linux Kernel amdxdna Missing Command Buffer Validation Scores 7.17.1 HighUpdated
2026-07-24CVE-2026-23422Linux Kernel dpaa2-switch Out-of-Bounds Write from Malformed Interrupt Scores 7.87.8 HighUpdated
2026-07-24CVE-2026-23419Linux kernel rds_tcp_tune circular locking dependency causes deadlock via sk_net_refcnt_upgrade7.5 HighUpdated
2026-07-24CVE-2025-15620Belden HiOS Switch Platform Web Interface Denial of Service via Unauthenticated Request Allows Remote Attacker to Trigger Device Reboot8.6 HighUpdated
2026-07-24CVE-2025-14859Semtech LR11xx LoRa Transceiver Secure Boot Uses Non-Standard Hashing Algorithm That Weakens Firmware Authentication7.0 HighUpdated
2026-07-24CVE-2024-14034Belden Hirschmann HiEOS LRS11 HTTP Management Module Authentication Bypass Grants Unauthenticated Attackers Administrator Access9.8 CriticalUpdated
2026-07-24CVE-2024-14033Belden Hirschmann EagleSDV TLS Session Establishment Denial of Service via Protocol Downgrade Exploit7.5 HighUpdated
2026-07-24CVE-2023-7343Belden Hirschmann Industrial HiVision Arbitrary Code Execution Triggered When Administrator Opens Maliciously Crafted Project File7.8 HighUpdated
2026-07-24CVE-2023-7342Belden HiSecOS EAGLE Web Server Prior to 04.1.00 Privilege Escalation Allows Operator or Auditor to Gain Administrator Access8.8 HighUpdated
2026-07-24CVE-2022-4987Belden Hirschmann Industrial HiVision External Application Execution Flaw Allows Local Attacker to Escalate Privileges7.3 HighUpdated
2026-07-24CVE-2022-4986Belden Hirschmann EagleSDV Denial of Service During TLS 1.0/1.1 Session Establishment via Crafted Handshake7.5 HighUpdated
2026-07-24CVE-2021-4477Belden Hirschmann HiLCOS OpenBAT IPv6 IPsec Firewall Bypass Allows Traffic from VPN Connections to Evade Configured Rules9.1 CriticalUpdated
2026-07-24CVE-2020-37216Belden Hirschmann HiOS Devices Prior to 08.1.00 Crash on Improper EtherNet/IP Packet Length Handling7.5 HighUpdated
2026-07-23CVE-2026-8047CODESYS Runtime HTTP Request Length Check Flaw Enables Unauthenticated Remote Out-of-Bounds Write and Denial of Service7.5 HighUpdated
2026-07-23CVE-2026-8046CODESYS Runtime Insufficient Authorization on User Account Deletion Allows Low-Privilege Remote User to Delete Any User8.1 HighUpdated
2026-07-23CVE-2026-46749Siemens SINEC INS Hardcoded Static Salt in Password Hashing Shared Across All Users Weakens Stored Credential Security7.5 HighUpdated
2026-07-23CVE-2026-46748Siemens SINEC INS Binary with cap_dac_override Capability Set Allows Low-Privilege User to Read or Write Arbitrary Files8.8 HighUpdated
2026-07-23CVE-2026-46746Siemens SINEC INS sftp Upload API Unsanitized Input Allows Authenticated Remote Users to Inject OS Commands8.8 HighUpdated
2026-07-23CVE-2026-42542TDengine taosd Integer Underflow in RPC Handler Lets Unauthenticated Attackers Crash the Server With One Packet7.5 HighUpdated
2026-07-23CVE-2026-24349Siemens SIMATIC WinCC Unified PC Runtime Stores Sensitive Information in Cleartext in Configuration Files7.1 HighUpdated
2026-07-22CVE-2026-41032Phoenix Contact CHARX SEC Controller Log Files Downloadable by Adjacent Unauthenticated Attacker, Disclosing Restricted Information7.5 HighUpdated
2026-07-22CVE-2026-35085MBS Universal Gateway User-Privilege Remote Stack Buffer Overflow in gdv-serverconfig Allows Root-Level Code Execution8.8 HighUpdated
2026-07-22CVE-2026-35084MBS Universal Gateway User-Privilege Remote Stack Buffer Overflow in dali-devconfig Allows Root-Level Code Execution8.8 HighUpdated
2026-07-22CVE-2026-35083MBS Universal Gateway User-Privilege Remote Stack Buffer Overflow in bac-serverconfig Allows Root-Level Code Execution8.8 HighUpdated
2026-07-22CVE-2026-35082MBS Universal Gateway ugw-logread Method Allows Authenticated Remote Users to Read Arbitrary Local Files8.8 HighUpdated
2026-07-22CVE-2026-35081MBS Universal Gateway ugw-logstop Method Allows Authenticated Remote Users to Terminate Arbitrary System Processes8.1 HighUpdated
2026-07-22CVE-2026-35080MBS Universal Gateway ugw-restoreinfo Method Allows Authenticated Remote Users to Delete Arbitrary Local Files8.1 HighUpdated
2026-07-22CVE-2026-35079MBS Universal Gateway ugw-restore Method Allows Authenticated Remote Users to Delete Arbitrary Local Files8.1 HighUpdated
2026-07-22CVE-2026-35078MBS Universal Gateway ugw-logstop Method Allows Authenticated Remote Users to Delete Arbitrary Local Files8.1 HighUpdated
2026-07-22CVE-2026-35077MBS Universal Gateway ugw-delete-file Method Allows Authenticated Remote Users to Delete Arbitrary Local Files8.1 HighUpdated
2026-07-22CVE-2026-35076MBS Universal Gateway bac-scanresult Method Allows Authenticated Remote Users to Delete Arbitrary Local Files8.1 HighUpdated
2026-07-22CVE-2026-35075MBS Universal Gateway Default Hard-Coded Password Recoverable from Firmware Image Allows Full Unauthenticated Access9.8 CriticalUpdated
2026-07-22CVE-2026-14448MB Connect Line Remote Portal OS Command Injection in Certificate Management View Exploitable by High-Privilege Remote Attacker7.2 HighUpdated
2026-07-22CVE-2025-14774ABB T-MAC Plus Incorrect Authorization Allows Adjacent Unauthenticated Attacker to Cause Denial of Service7.4 HighUpdated
2026-07-22CVE-2025-14773ABB T-MAC Plus Cross-Site Scripting Vulnerability Allows Authenticated Low-Privilege Attacker to Execute Malicious Scripts8.0 HighUpdated
2026-07-22CVE-2025-14772ABB T-MAC Plus Authorization Bypass via User-Controlled Key Allows Authenticated Users to Access Other Users' Resources8.8 HighUpdated
2026-07-22CVE-2025-14771ABB T-MAC Plus Exposes Sensitive Files and Directories to External Network Access9.9 CriticalUpdated
2026-07-22CVE-2024-14036Dräger Core 1.0.5 and M540 Converter Service Denial of Service via Specially Crafted Unencrypted Network Packets7.5 HighUpdated
2026-07-22CVE-2022-4992Dräger Infinity Acute Care System and M540 Patient Monitors Network Message Handling Flaw Risks Data Integrity Across Multiple Software Versions8.6 HighUpdated
2026-07-22CVE-2021-4481Dräger Protector Software Insecure File System Permissions Allow Local Attacker to Execute Arbitrary Code with System-Level Privileges8.2 HighUpdated
2026-07-22CVE-2021-4480Dräger Protector Software Insecure File System Permissions Allow Local Attacker to Execute Arbitrary Code with Elevated Privileges8.2 HighUpdated
2026-07-22CVE-2021-4478Dräger CC-Vision Basic and E-Cal Out-of-Bounds Write on Loading Crafted GDT File Can Cause Buffer Overflow8.2 HighUpdated
2026-07-22CVE-2019-25722Dräger SC Patient Monitoring Devices Contain Hard-Coded Plaintext Credentials and Local Denial-of-Service Vulnerability in Source Code7.6 HighUpdated
2026-07-22CVE-2019-25719Dräger Infinity Acute Care System and M540 Patient Monitors Contain Network Message Handling Vulnerabilities Affecting Confidentiality and Integrity8.6 HighUpdated
2026-07-22CVE-2019-25718Dräger Infinity Explorer C700 Kiosk Mode Escape Allows Privilege Escalation to Underlying Operating System8.4 HighUpdated
2026-07-21CVE-2026-23425Linux Kernel KVM arm64 ID Register Initialization Flaw Scores 8.88.8 HighUpdated
2026-07-21CVE-2018-25237Belden Hirschmann HiSecOS Classic Firewall HTTPS Login Buffer Overflow with RADIUS Authentication Allows Remote Crash9.8 CriticalUpdated
2026-07-21CVE-2018-25236Belden Hirschmann HiOS and HiSecOS Products HTTP Management Module Authentication Bypass Allows Unauthenticated Remote Access9.8 CriticalUpdated
2026-07-21CVE-2017-20238Belden Hirschmann Industrial HiVision 06.0.00/07.0.00 Improper Authorization Allows Read-Only Users to Gain Write Access to Managed Devices7.1 HighUpdated
2026-07-21CVE-2017-20237Belden Hirschmann Industrial HiVision Prior to 06.0.07 Authentication Bypass in Master Service Allows Unauthenticated Remote Code Execution9.8 CriticalUpdated
2026-07-21CVE-2017-20236ProSoft Technology ICX35-HWC Cellular Gateway Web Interface Input Validation Flaw Allows Unauthenticated Remote OS Command Injection9.8 CriticalUpdated
2026-07-21CVE-2017-20235ProSoft Technology ICX35-HWC Cellular Gateway Web Interface Authentication Bypass Grants Unauthenticated Attackers Administrator Access9.1 CriticalUpdated
2026-07-21CVE-2017-20234Belden GarrettCom Magnum 6K/10K Managed Switches Hard-Coded Authentication String Allows Unauthenticated Admin Access9.8 CriticalUpdated
2026-07-21CVE-2016-15058Belden Hirschmann HiLCOS Classic Platform Stores User Passwords in Recoverable Format, Exposing Credentials to Adjacent Unauthenticated Attackers8.1 HighUpdated
2026-07-21CVE-2015-10148Belden Hirschmann HiLCOS Devices Shipped with Hardcoded SSH and SSL Keys That Cannot Be Changed8.2 HighUpdated
2026-07-15CVE-2026-8314Rockwell Automation Arena Simulation Memory Corruption in siman.exe Component via Malformed File Data7.3 HighUpdated
2026-07-15CVE-2026-8313Rockwell Automation Arena Simulation Memory Corruption in linker.exe Siman Component via Malformed File Data7.3 HighUpdated
2026-07-15CVE-2026-8312Rockwell Automation Arena Simulation Memory Corruption in expmt.exe Siman Component via Malformed File Data7.3 HighUpdated
2026-07-15CVE-2026-8085Rockwell Automation Arena Simulation Memory Corruption in model.exe Component via Malformed File Data7.3 HighUpdated
2026-07-15CVE-2026-56451Siemens Opcenter X Skips JWT Algorithm Validation, Letting Unauthenticated Attackers Forge Arbitrary Tokens and Bypass Authentication; CVSS 10.010.0 CriticalUpdated
2026-07-15CVE-2026-54429Siemens SIMATIC S7-PLCSIM Advanced High-Volume Multicast Traffic Exhausts Device Memory, Causing Denial of Service7.4 HighUpdated
2026-07-15CVE-2026-39304Apache ActiveMQ NIO SSL Transports Vulnerable to Denial-of-Service via Memory Exhaustion7.5 HighUpdated
2026-07-14CVE-2026-9653Rockwell Automation 1756-EN2 and EN3 CIP Implicit Connection Validation Flaw Allows Network Attacker to Cause Denial of Service8.7 HighUpdated
2026-07-14CVE-2026-9650Schneider Electric EasyLogic T150/Saitel DR Credentials Stored in Filesystem Accessible to Unauthenticated Attackers7.5 HighUpdated
2026-07-14CVE-2026-9636Rockwell Automation ControlLogix and CompactLogix CIP Security Certificate Revocation Check Flaw Allows Revoked Certificates to Authenticate8.2 HighUpdated
2026-07-14CVE-2026-9292Rockwell Automation FactoryTalk DataMosaix Private Cloud Stored Cross-Site Scripting in Workflows Configuration Requires Admin Interaction8.4 HighUpdated
2026-07-14CVE-2026-9140Rockwell Automation 1718/1719-AENTR I/O Module UDP Unicast Network Storm Causes Device to Lose Communication8.7 HighUpdated
2026-07-14CVE-2026-5928GNU C Library ungetwc Multibyte Encoding Overlap Flaw Affects Siemens SIMATIC S7-1500 MFP and Multiple Vendor Products7.5 HighUpdated
2026-07-14CVE-2026-5450GNU C Library scanf Heap Buffer Overflow on Wide Character Match with Large Format Width Affects Siemens SIMATIC S7-1500 MFP and Other Products9.8 CriticalUpdated
2026-07-14CVE-2026-5435GNU C Library Deprecated DNS Print Functions Ignore Caller Buffer Length, Affecting Siemens SIMATIC S7-1500 MFP and Related Vendor Products7.3 HighUpdated
2026-07-14CVE-2026-46174Linux Kernel AMD Zen2 Op Cache Improper Resource Isolation on Siemens SIMATIC S7-1500 MFP Enables Cross-Process Leakage8.8 HighUpdated
2026-07-14CVE-2026-43057Linux Kernel IPv6 Tunneled Traffic Checksum GSO Fallback Incorrectly Handled on Siemens SIMATIC S7-1500 MFP7.5 HighUpdated
2026-07-14CVE-2026-43040Linux Kernel IPv6 NDISC Router Advertisement User Option Leaves Padding Fields Uninitialized on Siemens SIMATIC S7-1500 MFP7.1 HighUpdated
2026-07-14CVE-2026-43033Linux Kernel authencesn Out-of-Place Decryption Writes hiseq at Wrong Destination on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-14CVE-2026-43030Linux Kernel BPF Verifier Incorrect Packet Pointer Safety Check on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-14CVE-2026-43028Linux Kernel netfilter x_tables Name Null-Termination Gap Risks Out-of-Bounds Read on Siemens SIMATIC S7-1500 MFP7.1 HighUpdated
2026-07-14CVE-2026-43027Linux Kernel netfilter CT Helper Pass-Through on Expect Cleanup on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-14CVE-2026-43025Linux Kernel netfilter ctnetlink Helper Out-of-Bounds Read on New Expectations on Siemens SIMATIC S7-1500 MFP7.3 HighUpdated
2026-07-14CVE-2026-43011Linux Kernel X.25 Socket Double-Free of skb on Memory Allocation Failure on Siemens SIMATIC S7-1500 MFP9.8 CriticalUpdated
2026-07-14CVE-2026-31768Linux Kernel TI ADC SPI Read Uses Non-DMA-Safe Stack Buffer on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-14CVE-2026-31761Linux Kernel IIO Gyro MPU3050 Device Registration Race Condition on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-14CVE-2026-31682Linux Kernel Bridge Neighbor Discovery Sends ND Options Parsing Without Linearizing skb First on Siemens SIMATIC S7-1500 MFP9.1 CriticalUpdated
2026-07-14CVE-2026-31680Linux Kernel IPv6 Flow Label Exclusive Option Freed Before RCU Teardown on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-14CVE-2026-31674Linux Kernel IPv6 Routing Match addrnr Exceeding IP6T_RT_HOPS Causes Out-of-Bounds Read on Siemens SIMATIC S7-1500 MFP7.1 HighUpdated
2026-07-14CVE-2026-31669Linux Kernel MPTCP slab-use-after-free in __inet_lookup_established via Lockless ehash Table Walk on Siemens SIMATIC S7-1500 MFP9.8 CriticalUpdated
2026-07-14CVE-2026-31665Linux Kernel nftables CT Timeout Object Use-After-Free on Destroy on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-14CVE-2026-31649Linux Kernel stmmac Ethernet Chain Mode Integer Underflow on Jumbo Frame Transmission on Siemens SIMATIC S7-1500 MFP9.8 CriticalUpdated
2026-07-14CVE-2026-31563Linux Kernel MACB Network Driver Frees TX sk_buff in IRQ-Disabled Context Using Wrong Function on Siemens SIMATIC S7-1500 MFP7.5 HighUpdated
2026-07-14CVE-2026-31533Linux Kernel TLS Encryption EBUSY Error Path Use-After-Free on Siemens SIMATIC S7-1500 MFP9.8 CriticalUpdated
2026-07-14CVE-2026-31508Linux Kernel Open vSwitch Teardown Releases Network Device Before Completion on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-14CVE-2026-31507Linux Kernel SMC double-free of smc_spd_priv When tee() Duplicates Splice Pipe Buffer on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-14CVE-2026-31504Linux Kernel PACKET Socket Fanout Use-After-Free via NETDEV_UP Race in packet_release on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-14CVE-2026-31494Linux Kernel MACB Ethernet Driver Queue Statistics Array Size Mismatch on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-14CVE-2026-31485Linux Kernel SPI FSL LPSPI Teardown Order Use-After-Free on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-14CVE-2026-31469Linux Kernel virtio_net Use-After-Free in Destination Route on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-14CVE-2026-31452Linux Kernel ext4 Inline-to-Extents Conversion Missing When Truncation Exceeds Inline Data Size on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-14CVE-2026-31450Linux Kernel ext4 jinode Published Before Initialization Completes on Siemens SIMATIC S7-1500 MFP8.8 HighUpdated
2026-07-14CVE-2026-31448Linux Kernel ext4 mkdir/mknod Logical to Physical Block Mapping Infinite Loop via Residual Data on Siemens SIMATIC S7-1500 MFP9.4 CriticalUpdated
2026-07-14CVE-2026-31447Linux Kernel ext4 Rejects Mount of bigalloc Filesystems with s_first_data_block Not Zero on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-14CVE-2026-31446Linux kernel ext4 use-after-free in update_super_work races with unmount after sysfs unregistration7.8 HighUpdated
2026-07-14CVE-2026-31417Linux Kernel X.25 Packet Fragment Length Integer Overflow on Siemens SIMATIC S7-1500 MFP7.5 HighUpdated
2026-07-14CVE-2026-31414Linux Kernel netfilter Conntrack Expectation Helper Name Resolved from Wrong Source on Siemens SIMATIC S7-1500 MFP9.8 CriticalUpdated
2026-07-14CVE-2026-31396Linux Kernel MACB Network Driver PTP Clock Use-After-Free on Interface Open and Close on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-14CVE-2026-25789Siemens SIMATIC S7-1500 MFP Web Interface Filename Validation Gap on Firmware Update Page Enables Social Engineering Attack7.1 HighUpdated
2026-07-14CVE-2026-25787Siemens SIMATIC S7-1500 MFP Web Interface Stored Cross-Site Scripting in Technology Object Name Field Exploitable by Authenticated Attacker9.1 CriticalUpdated
2026-07-14CVE-2026-25786Siemens SIMATIC S7-1500 MFP Web Interface Stored Cross-Site Scripting in PLC Name Field Exploitable by Authenticated Attacker9.1 CriticalUpdated
2026-07-14CVE-2026-23449Linux Kernel Network Scheduler TEQL Double-Free with Lockless Qdisc Root on Siemens SIMATIC S7-1500 MFP7.8 HighUpdated
2026-07-14CVE-2026-23414Linux Kernel TLS Memory Leak in Async Decrypt Wait Scores 7.57.5 HighUpdated
2026-07-14CVE-2026-12659Rockwell Automation FLEX 5000 EtherNet/IP Adapter Improper CIP Packet Exception Handling Causes Denial of Service Requiring Manual Restart8.7 HighUpdated
2026-07-14CVE-2026-10714Rockwell Automation FactoryTalk Services Platform JWT Signature Bypass in Okta Web Authentication Allows Attacker to Impersonate Users8.8 HighUpdated
2026-07-14CVE-2026-0265Palo Alto Networks PAN-OS Authentication Bypass Affects Siemens RUGGEDCOM APE1808, Scores 8.18.1 HighUpdated
2026-07-14CVE-2026-0264Critical Palo Alto Networks PAN-OS DNS Heap Overflow Affects Siemens RUGGEDCOM APE1808, Scores 9.89.8 CriticalUpdated
2026-07-14CVE-2026-0262Palo Alto Networks PAN-OS Multiple Denial-of-Service Flaws Affect Siemens RUGGEDCOM APE18087.5 HighUpdated
2026-07-14CVE-2026-0261Palo Alto Networks PAN-OS Command Injection Affects Siemens RUGGEDCOM APE1808, Scores 7.27.2 HighUpdated
2026-07-14CVE-2026-0258Palo Alto Networks PAN-OS IKEv2 SSRF Affects Siemens RUGGEDCOM APE1808, Scores 9.19.1 CriticalUpdated
2026-07-09CVE-2026-54801Siemens CPCI85 and SICORE Password Change Accepts New Password Without Verifying Current One7.2 HighUpdated
2026-07-08CVE-2026-46279Linux Kernel Page Extension Initialization Leaves Codetag Uninitialized for Pages Allocated Before page_ext Is Ready7.8 HighUpdated
2026-07-08CVE-2026-20151Cisco Smart Software Manager On-Prem Leaks Sensitive Data in Transmitted Requests7.3 HighUpdated
2026-07-07CVE-2026-40141A critical query-injection flaw in BeyondTrust Remote Support lets low-privileged users reach unauthorized resources, CVSS 9.99.9 CriticalUpdated
2026-07-07CVE-2026-40140Unauthenticated attackers can crash BeyondTrust Remote Support appliances via a network-communication flaw7.5 HighUpdated
2026-07-07CVE-2026-40139Critical Pre-Authentication Bypass in BeyondTrust Remote Support Allows Unauthorized Access9.8 CriticalUpdated
2026-07-07CVE-2026-40138BeyondTrust Privileged Remote Access Shares Pre-Authentication Bypass Flaw with Remote Support8.1 HighUpdated
2026-07-02CVE-2026-53225Linux Kernel SCTP ASCONF Lookup Reads Past the Validated Header Boundary, Exposing Uninitialized Memory to Downstream Address Parameter Processing9.1 CriticalUpdated
2026-07-02CVE-2026-20155Cisco Evolved Programmable Network Manager Missing Authorization Scores 8.08.0 HighUpdated
2026-07-01CVE-2026-9717Schneider Electric PowerLogic P7 OS Command Injection in Admin-Privileged Context Allows Unauthorized Command Execution7.2 HighUpdated
2026-07-01CVE-2026-9716Schneider Electric PowerLogic P7 NULL Pointer Dereference Renders HMI and Configuration Interface Unavailable via Malformed Requests7.5 HighUpdated
2026-07-01CVE-2026-20160Critical Cisco Smart Software Manager On-Prem Resource Exposure Scores 9.89.8 CriticalUpdated
2026-07-01CVE-2026-14193Delta DVP80ES300T PLC Improper Array Index Validation Creates Remote Denial-of-Service Exposure7.5 HighUpdated
2026-07-01CVE-2026-12579Delta AS228T Authentication Bypass Vulnerability Allows Unauthenticated Access Without Valid Credentials7.4 HighUpdated
2026-07-01CVE-2026-12577Delta DVP80ES3 PLC Improperly Implemented Security Check Allows Bypassing Standard Protocol Verification8.7 HighUpdated
2026-07-01CVE-2026-12576Delta DVP80ES3 PLC Communication Channel Message Integrity Not Enforced, Allowing Message Substitution7.5 HighUpdated
2026-07-01CVE-2026-12575Delta DVP80ES3 PLC Improper Resource Release Creates Remote Denial-of-Service Exposure7.5 HighUpdated
2026-06-30CVE-2026-12578Delta DTMSoft Deserialization of Untrusted Data Allows Attacker to Execute Arbitrary Code8.4 HighUpdated
2026-06-30CVE-2026-10763Hitachi Energy PROMOD V Uses Unencrypted HTTP for Digipede Server Communication, Exposing Data to Interception7.0 HighUpdated
2026-06-29CVE-2026-22925Siemens SIMATIC CN 4100 TCP SYN Flood Exhausts Available Resources and Causes Denial of Service7.5 HighUpdated
2026-06-29CVE-2026-22924Siemens SIMATIC CN 4100 Accepts Unlimited Unauthenticated Connections, Enabling Remote Resource Exhaustion and Denial of Service9.1 CriticalUpdated
2026-06-29CVE-2025-40949Siemens RUGGEDCOM ROX OS Command Injection Lets Authenticated Administrators Execute Root-Level Commands Across Multiple Platform Generations9.1 CriticalUpdated
2026-06-29CVE-2025-40947Siemens RUGGEDCOM ROX Authenticated OS Command Injection Requires Low Privilege and Network Access Across Multiple Platform Generations7.5 HighUpdated
2026-06-27CVE-2024-54013Hanwha Vision Network Camera Web Server Request Handling Flaw Exposes Protected Functions to Adjacent Unauthenticated Attackers8.8 HighUpdated
2026-06-24CVE-2026-6866Schneider Electric EcoStruxure Panel Server Credentials Revert to Insecure Initial Settings After Rare Event, Disclosing Sensitive Information7.5 HighUpdated
2026-06-23CVE-2026-10521MB Connect Line mbconnect24 Hidden Configuration Method Accessible to High-Privilege Attackers Allows Critical Parameter Modification7.2 HighUpdated
2026-06-22CVE-2026-8024iba ibaPDA and ibaDatCoordinator Deserialization of Untrusted Data Allows Unauthenticated Remote Attacker to Gain Full System Access9.8 CriticalUpdated
2026-06-17CVE-2026-6888Advantech SaaS Composer Authenticated Admin SQL Injection Allows Remote Command Execution via Specific API Interface7.2 HighUpdated
2026-06-17CVE-2026-6865Schneider Electric EasyLogic T150 Path Traversal in User-Supplied Input Allows Unauthorized Access to Sensitive Files7.1 HighUpdated
2026-06-17CVE-2026-6332Schneider Electric EcoStruxure Machine Expert HVAC Stores Sensitive Source Code in Cleartext, Risking Disclosure of Protected Intellectual Property7.5 HighUpdated
2026-06-17CVE-2026-5416Turck Managed Ethernet Switch OS Command Injection via Name Parameter Exploitable by Low-Privilege Remote Attacker8.8 HighUpdated
2026-06-17CVE-2026-5387AVEVA Pipeline Simulation 2025 Allows Unauthenticated Access to Instructor and Simulator Developer Administrative Operations9.3 CriticalUpdated
2026-06-17CVE-2026-4827Schneider Electric Easergy MiCOM C264 Insufficient Session Token Entropy Allows Network Attacker to Compromise Sessions8.7 HighUpdated
2026-06-17CVE-2026-43296Linux Kernel octeontx2-af NIC SQ Manager Sticky Mode Causes Stalls and Potential PSE Deadlock When Multiple Queues Share an SMQ7.5 HighUpdated
2026-06-17CVE-2026-41551Siemens ROS# Path Traversal in User-Supplied Input Allows Unauthenticated Remote Attacker to Read or Write Arbitrary Files9.1 CriticalUpdated
2026-06-17CVE-2026-4116SonicWall SMA1000 Mishandles Unicode Encoding in TOTP Validation, Allowing an Authenticated SSLVPN User to Bypass Two-Factor Authentication7.2 HighUpdated
2026-06-17CVE-2026-4113SonicWall SMA1000 Distinguishable Authentication Error Responses Allow a Remote Attacker to Enumerate SSL VPN User Accounts7.2 HighUpdated
2026-06-17CVE-2026-4112SonicWall SMA1000 SQL Injection in the SSLVPN Component Allows a Read-Only Administrator to Escalate to Primary Administrator7.2 HighUpdated
2026-06-17CVE-2026-40852MB Connect Line mbNET/mbNET.rokey High-Privilege Config Generator OS Command Injection via Unsanitized Config Value7.2 HighUpdated
2026-06-17CVE-2026-40851MB Connect Line mbNET/mbNET.rokey USB Config File Parser Confusion Attack Allows Local Attacker to Achieve Code Execution8.4 HighUpdated
2026-06-17CVE-2026-40850MB Connect Line Remote Portal Unauthenticated SQL Injection in getAccountData Function Exposes Full Database Contents7.5 HighUpdated
2026-06-17CVE-2026-40836MB Connect Line and Helmholz Remote Portal SQL Injection in inmessage Model DELETE Command Allows Low-Privilege Database Access7.1 HighUpdated
2026-06-17CVE-2026-40834MB Connect Line and Helmholz Remote Portal SQL Injection in dash_layout.php Dashboard Layout Function Exposes Database to Low-Privileged Attackers7.1 HighUpdated
2026-06-17CVE-2026-40833MB Connect Line and Helmholz Remote Portal SQL Injection in Dashboard Layout Function Exposes Database to Low-Privileged Remote Users7.1 HighUpdated
2026-06-17CVE-2026-40819MB Connect Line Remote Portal Unauthenticated SQL Injection in sync_data24 Task Exposes Full Database Contents7.5 HighUpdated
2026-06-17CVE-2026-40818MB Connect Line Remote Portal Unauthenticated SQL Injection in _mb24confi_getDevice Function Exposes Database Contents7.5 HighUpdated
2026-06-17CVE-2026-40817MB Connect Line Remote Portal Unauthenticated SQL Injection in getAlarmProfiles Function Exposes Database Contents7.5 HighUpdated
2026-06-17CVE-2026-40816MB Connect Line Remote Portal Unauthenticated SQL Injection in Alarm Configuration Function Exposes Database Contents7.5 HighUpdated
2026-06-17CVE-2026-40815MB Connect Line Remote Portal Unauthenticated SQL Injection in _mb24api_getUserAccount Function Exposes Database Contents7.5 HighUpdated
2026-06-17CVE-2026-40814MB Connect Line Remote Portal Unauthenticated SQL Injection in dataapi.php _mb24confi_getTagAlarm Function Exposes Database7.5 HighUpdated
2026-06-17CVE-2026-40813MB Connect Line Remote Portal Unauthenticated SQL Injection in getLiveValues tagid Parameter Exposes Database Contents7.5 HighUpdated
2026-06-17CVE-2026-40812MB Connect Line Remote Portal Unauthenticated SQL Injection in getLiveValues sn Parameter Exposes Database Contents7.5 HighUpdated
2026-06-17CVE-2026-40811MB Connect Line Remote Portal Unauthenticated SQL Injection in ssoabstractservice SELECT Command Exposes Database Contents7.5 HighUpdated
2026-06-17CVE-2026-40810MB Connect Line Remote Portal Unauthenticated SQL Injection in userinfo Endpoint Exposes Full Database Contents7.5 HighUpdated
2026-06-17CVE-2026-33893Siemens Teamcenter Hard-Coded Credentials in Multiple Versions Allow Unauthenticated Remote Access to Sensitive Data7.5 HighUpdated
2026-06-17CVE-2026-33892Siemens Industrial Edge Management Authentication Sequence Weakness Allows Unauthorized Actions via Phishing in Affected Versions7.1 HighUpdated
2026-06-17CVE-2026-33862Siemens Teamcenter Cross-Site Scripting Requires Low-Privilege Attacker and User Interaction, Risks Full Session Compromise7.3 HighUpdated
2026-06-17CVE-2026-33616MB Connect Line mbconnect24 Blind SQL Injection in mb24api Endpoint Gives Unauthenticated Attackers Full Database Read Access7.5 HighUpdated
2026-06-17CVE-2026-33615MB Connect Line mbconnect24 Unauthenticated SQL Injection in setinfo Endpoint Allows Arbitrary Data Write via UPDATE Command9.1 CriticalUpdated
2026-06-17CVE-2026-33614MB Connect Line mbconnect24 Unauthenticated SQL Injection in getinfo Endpoint Exposes Full Database via SELECT Command7.5 HighUpdated
2026-06-17CVE-2026-33613MB Connect Line mbconnect24 Admin-Authenticated OS Command Injection in generateSrpArray Function Allows Full System Compromise7.2 HighUpdated
2026-06-17CVE-2026-3323Vega vegapuls Level Sensor Unsecured Configuration Interface Exposes Hashed Credentials and Access Codes to Unauthenticated Remote Attackers7.5 HighUpdated
2026-06-17CVE-2026-32091Race Condition in Microsoft Brokering File System Allows Unauthorized Privilege Escalation8.4 HighUpdated
2026-06-17CVE-2026-31693Linux kernel CIFS replay path missing variable reinitializations causes undefined behavior on request retry7.8 HighUpdated
2026-06-17CVE-2026-31568Linux kernel s390/mm missing secure storage access fixups for donated pages causes kernel context exceptions7.1 HighUpdated
2026-06-17CVE-2026-31426Linux kernel ACPI EC address space handler persists after probe failure leaves dangling pointer7.0 HighUpdated
2026-06-17CVE-2026-27914Improper Access Control in Microsoft Management Console Allows Local Privilege Escalation7.8 HighUpdated
2026-06-17CVE-2026-27909Use-After-Free in Windows Search Component Allows Authorized Attacker to Escalate Privileges7.8 HighUpdated
2026-06-17CVE-2026-27668Siemens RUGGEDCOM CROSSBOW Secure Access Manager User Administrators Can Administer Groups They Belong To, Enabling Privilege Escalation8.8 HighUpdated
2026-06-17CVE-2026-27662Siemens SIMATIC HMI Unified Comfort Panel Web Browser Accessible Without Authentication When No Security Mechanism Is Configured7.7 HighUpdated
2026-06-17CVE-2026-26181Use-After-Free in Microsoft Brokering File System Lets Authorized User Escalate Privileges7.8 HighUpdated
2026-06-17CVE-2026-26170Input Validation Flaw in Microsoft PowerShell Allows Local Privilege Escalation7.8 HighUpdated
2026-06-17CVE-2026-25654Siemens SINEC NMS Password Reset Request Authorization Not Validated, Allowing Authenticated User to Reset Any Account Password8.8 HighUpdated
2026-06-17CVE-2026-24032Siemens SINEC NMS UMC Authentication Weakness Allows Forged User Identity Due to Insufficient Validation7.3 HighUpdated
2026-06-17CVE-2026-23428Critical Linux Kernel ksmbd Use-After-Free in Compound Request Handling Scores 9.89.8 CriticalUpdated
2026-06-17CVE-2026-23427Critical Linux Kernel ksmbd Use-After-Free in Durable Handle Replay Scores 9.89.8 CriticalUpdated
2026-06-17CVE-2026-23415Linux Kernel Futex Use-After-Free between Key Lookup and VMA Policy Scores 7.87.8 HighUpdated
2026-06-17CVE-2026-23413Linux Kernel clsact Use-After-Free in Init/Destroy Rollback Scores 7.87.8 HighUpdated
2026-06-17CVE-2026-23412Linux Kernel Netfilter BPF Use-After-Free in Hook Memory Release Scores 7.87.8 HighUpdated
2026-06-17CVE-2026-23411Linux Kernel AppArmor Race Condition Frees i_private Data Early Scores 7.87.8 HighUpdated
2026-06-17CVE-2026-23410Linux Kernel AppArmor Race on Rawdata Dereference Scores 7.87.8 HighUpdated
2026-06-17CVE-2026-23408Linux Kernel AppArmor Double Free of Namespace Name Scores 7.87.8 HighUpdated
2026-06-17CVE-2026-23407Linux Kernel AppArmor Out-of-Bounds Read in DFA Verification Scores 7.87.8 HighUpdated
2026-06-17CVE-2026-23406Linux kernel AppArmor match_char macro evaluates pointer multiple times and skips input characters during DFA traversal7.8 HighUpdated
2026-06-17CVE-2026-1952Delta Electronics AS320T Denial of Service via Undocumented Subfunction Call, Exploitable Remotely Without Authentication9.8 CriticalUpdated
2026-06-17CVE-2026-1951Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing Directory Name Length Check, Enabling Unauthenticated Remote Code Execution9.8 CriticalUpdated
2026-06-17CVE-2026-1950Delta Electronics AS320T Stack-Based Buffer Overflow Due to Missing File Name Length Check, Enabling Unauthenticated Remote Code Execution9.8 CriticalUpdated
2026-06-17CVE-2026-1949Delta Electronics AS320T GET/PUT Request Handler Incorrectly Calculates Stack Buffer Size, Enabling Unauthenticated Remote Code Execution via the Web Service9.8 CriticalUpdated
2026-06-17CVE-2026-11317Rockwell Automation CompactLogix and ControlLogix Crafted CIP Message Fault Causes Denial of Service Requiring Device Restart8.7 HighUpdated
2026-06-17CVE-2026-10829Moxa NPort W2150A-W4/W2250A-W4 Series Stack-Based Buffer Overflow from Insufficient Input Validation Allows Unauthenticated Remote Exploitation8.6 HighUpdated
2026-06-17CVE-2026-10825Moxa NPort 6000-G2 Series WebSocket API JSON Request Handling Flaw Allows Low-Privilege Authenticated Attacker to Cause Denial of Service7.1 HighUpdated
2026-06-17CVE-2026-0647Rockwell Automation FLEX I/O 1794-AENTR Adapter Web Server Missing Authentication Allows Unauthenticated Attacker to Change Web Interface Password8.8 HighUpdated
2026-06-17CVE-2026-0646Rockwell Automation FLEX I/O 1794-AENTR Adapter Improper CIP Protocol Memory Handling Causes Adapter Fault and Communication Loss8.7 HighUpdated
2026-06-17CVE-2025-41670Phoenix Contact AXC F PLC Runtime User-Writable Configuration Files Allow Low-Privilege Local User to Influence Privileged Service Behavior7.8 HighUpdated
2026-06-17CVE-2025-41669Phoenix Contact AXC F PLC PLCnext Store App Installation Lacks Data Verification, Allowing Low-Privilege Remote Engineer to Install Unsigned Applications8.8 HighUpdated
2026-06-17CVE-2025-40946Siemens blueplanet Solar Inverter Hard-Coded Credentials Allow Adjacent Unauthenticated Attacker to Compromise Device8.3 HighUpdated
2026-06-17CVE-2025-40899Nozomi Networks Guardian Stored Cross-Site Scripting in Assets/Nodes Custom Fields Allows Low-Privilege Authenticated Attacker to Execute Scripts8.9 HighUpdated
2026-06-17CVE-2025-40897Nozomi Networks Guardian Threat Intelligence Access Control Flaw Lets View-Only Authenticated Users Modify Records8.1 HighUpdated
2026-06-17CVE-2024-43384Phoenix Contact mGuard Firewall Improper Removal of Sensitive Information Before Storage Exposes Root Password to Low-Privilege Remote User8.0 HighUpdated
2026-06-17CVE-2024-1490WAGO PLC OpenVPN Configuration via Web Management Allows Authenticated High-Privilege Attacker to Execute Arbitrary Code7.2 HighUpdated
2026-06-17CVE-2023-3634Festo MSE6 Undocumented Test Mode Functions Exploitable by Authenticated Low-Privilege Remote Attacker for Full Data Loss8.8 HighUpdated

No advisories match this filter.