Common Vulnerabilities and Exposures (CVE)

CVE-2026-19594

Aug 12, 2026 05:22:07 UTC

Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segm...

CVE-2026-12235

Aug 12, 2026 04:55:15 UTC

The Linkable Loadable Extensions (llext) subsystem mis-handles PLT/RELA relocation entries when linking a relocatable (partially-linked) ELF extension. In llext_link_plt() (subsys/llext/llext_link.c), the relocatable branch (tgt != NULL, th...

CVE-2026-12234

Aug 12, 2026 04:39:23 UTC

The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c snapshot the caller-supplied struct net_msghdr into a kernel-side copy with k_usermode_from_copy(), but then re-read the s...

CVE-2026-64954

Aug 12, 2026 04:26:32 UTC

Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets t...

CVE-2026-19588

Aug 12, 2026 04:02:08 UTC

Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.

CVE-2026-66145

Aug 12, 2026 04:00:44 UTC

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.

CVE-2026-66147

Aug 12, 2026 04:00:42 UTC

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

CVE-2026-66149

Aug 12, 2026 04:00:41 UTC

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands t...

CVE-2026-66150

Aug 12, 2026 04:00:40 UTC

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands t...

CVE-2025-31936

Aug 12, 2026 04:00:39 UTC

Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexit...

CVE-2026-70339

Aug 12, 2026 04:00:38 UTC

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-18634

Aug 12, 2026 04:00:37 UTC

An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to interact with the service could exploit this ...

CVE-2026-66154

Aug 12, 2026 04:00:36 UTC

An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could p...

CVE-2026-11739

Aug 12, 2026 04:00:35 UTC

A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality ...

CVE-2026-12571

Aug 12, 2026 04:00:34 UTC

An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.