Common Vulnerabilities and Exposures (CVE)

CVE-2026-11812

Aug 10, 2026 23:09:17 UTC

The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single file-scope ctx structure that holds the CoAP block context, payload buffer, status code, socket, and a one-element poll-fd...

CVE-2026-56852

Aug 10, 2026 22:57:54 UTC

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

CVE-2026-42504

Aug 10, 2026 22:57:54 UTC

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

CVE-2026-11811

Aug 10, 2026 22:55:17 UTC

The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure paths. The shared error: cleanup gated socket closing on a ret > 0 fla...

CVE-2026-1498

Aug 10, 2026 22:43:30 UTC

An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interfac...

CVE-2026-8718

Aug 10, 2026 22:40:26 UTC

tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the ...

CVE-2026-48161

Aug 10, 2026 22:27:35 UTC

react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d1495a2505f9277da295a98cf176f4496 through 7b79148d1495a2505f9277da295a98cf176f4496 that exec...

CVE-2025-30241

Aug 10, 2026 22:26:08 UTC

Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions.  An authenticated adjacent attacker may inject spec...

CVE-2025-30240

Aug 10, 2026 22:25:41 UTC

The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic link on supported storage media, an attacker may cause the system to resolve the link. ...

CVE-2025-30239

Aug 10, 2026 22:25:03 UTC

In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device storage to recover the keys and decrypt stored data. ...

CVE-2025-30238

Aug 10, 2026 22:24:20 UTC

In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged operations. An attacker may perform administrative actions such as creating privileged acc...

CVE-2025-30237

Aug 10, 2026 22:23:41 UTC

The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker can send specially crafted requests to bypass authentication and ...

CVE-2025-32736

Aug 10, 2026 21:54:21 UTC

Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered by administrators with active sessions.

CVE-2024-0775

Aug 10, 2026 21:49:46 UTC

A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an information leak problem while freeing the old quota file names before a potential failure, lead...

CVE-2024-0565

Aug 10, 2026 21:49:42 UTC

An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to integer underflow on the memcpy length, leading to a denial o...