Complete feed
No mitigation yet
No fix, workaround or mitigation extracted yet
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-67855] Denial of Service via heap use-after-free
Denial of Service via heap use-after-free. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825.
High [CVE-2026-67857] Denial of Service via out-of-bounds read in client-side function
Denial of Service via out-of-bounds read in client-side function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125.
High [CVE-2026-67858] Denial of Service via buffer overflow in Local Discovery Server
Denial of Service via buffer overflow in Local Discovery Server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-67859] Denial of Service via Discovery/LDS handling
Denial of Service via Discovery/LDS handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-67862] Denial of Service via buffer-overflow
Denial of Service via buffer-overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-64564] don't free the ASCONF's own transport in DEL-IP processing
don't free the ASCONF's own transport in DEL-IP processing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825.
High [CVE-2026-67861] Denial of Service via UA_Client_getRemoteDataTypes component
Denial of Service via UA_Client_getRemoteDataTypes component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-67860] Heap-based buffer overflow in HistoryRead path
Heap-based buffer overflow in HistoryRead path. Red Hat rates this important (CVSS 8.2). Weakness: CWE-120.
Medium [CVE-2026-18785] Use-after-free vulnerability via local manipulation
Use-after-free vulnerability via local manipulation. Red Hat rates this moderate. Weakness: CWE-825.
Medium [CVE-2026-18401] Denial of Service due to number length bypass in asynchronous JSON parser
Denial of Service due to number length bypass in asynchronous JSON parser. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770.
Medium [CVE-2026-8508] improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.
Medium [CVE-2026-51400] Arbitrary code execution via vms_fixfilename function
Arbitrary code execution via vms_fixfilename() function. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-94.
High [CVE-2026-68981] Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter
Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which relocates response compression to Jetty Server and disables decompression of gzip-encoded HTTP requests.
High [CVE-2026-62354] Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values
Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying Parameter Context configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, requiring write access to submit Parameter Context validation requests.
Low [CVE-2026-68980] Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which verifies Parameter Context ownership of the requested Asset before deletion using the same strategy applied to Asset read operations.