Common Vulnerabilities and Exposures (CVE)

CVE-2024-9355

Aug 21, 2026 17:39:12 UTC

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positiv...

CVE-2026-17252

Aug 21, 2026 17:38:36 UTC

A stack-based out-of-bounds write vulnerability exists in the login request handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability by se...

CVE-2026-41451

Aug 21, 2026 17:36:02 UTC

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories from /etc/passwd are substituted directly int...

CVE-2026-72848

Aug 21, 2026 17:35:18 UTC

SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nes...

CVE-2026-41449

Aug 21, 2026 17:33:50 UTC

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attackers to execute arbitrary commands by injecting shell metacharacters into untrusted data suc...

CVE-2026-77814

Aug 21, 2026 17:33:29 UTC

is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without appending a path separator. A directory whose name merely begins with an allowed path therefo...

CVE-2026-77768

Aug 21, 2026 17:31:03 UTC

The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAccess middleware in packages/trpc/src/trpc.ts evaluates membership only when the input carri...

CVE-2026-53804

Aug 21, 2026 17:29:18 UTC

OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path a...

CVE-2026-61400

Aug 21, 2026 17:28:17 UTC

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics functionality for the system VMs and virtual routers. An authenticated user holding the permis...

CVE-2026-73570

Aug 21, 2026 17:27:32 UTC

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP not...

CVE-2026-69836

Aug 21, 2026 17:27:32 UTC

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

CVE-2026-54789

Aug 21, 2026 17:24:15 UTC

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bo...

CVE-2026-77710

Aug 21, 2026 17:19:40 UTC

A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between the internal MISP parser and the external STIX par...

CVE-2026-5419

Aug 21, 2026 17:14:39 UTC

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through obser...

CVE-2025-9820

Aug 21, 2026 17:14:37 UTC

A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-siz...