Common Vulnerabilities and Exposures (CVE)

CVE-2026-61893

Jul 30, 2026 22:58:32 UTC

A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.

CVE-2026-63033

Jul 30, 2026 22:54:25 UTC

A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer.

CVE-2026-10031

Jul 30, 2026 22:51:31 UTC

SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where downlo...

CVE-2026-66720

Jul 30, 2026 22:46:52 UTC

The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can tr...

CVE-2026-66369

Jul 30, 2026 22:45:29 UTC

The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its intern...

CVE-2026-63550

Jul 30, 2026 22:43:21 UTC

The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may a...

CVE-2026-65421

Jul 30, 2026 22:35:14 UTC

The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service proc...

CVE-2026-66364

Jul 30, 2026 22:33:28 UTC

The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length...

CVE-2026-66349

Jul 30, 2026 22:31:32 UTC

The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its intern...

CVE-2026-56758

Jul 30, 2026 22:29:20 UTC

The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read p...

CVE-2026-66360

Jul 30, 2026 22:25:54 UTC

The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero l...

CVE-2026-66421

Jul 30, 2026 22:16:58 UTC

OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messa...

CVE-2024-12718

Jul 30, 2026 22:16:39 UTC

Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar" of files outside the extraction directory. You are affected by this vulnerability if using the tarfile module to extra...

CVE-2025-0938

Jul 30, 2026 22:15:46 UTC

The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying...

CVE-2025-1795

Jul 30, 2026 22:15:07 UTC

During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. T...