Aggregator
CVE-2026-15690 | open62541 up to 1.5.5 Shared Client Library ua_client_connect.c responseReadNamespacesArray Server_NamespaceArray null pointer dereference (Issue 8104)
1 week 2 days ago
A vulnerability described as problematic has been identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesArray of the file src/client/ua_client_connect.c of the component Shared Client Library. Such manipulation of the argument Server_NamespaceArray leads to null pointer dereference.
This vulnerability is documented as CVE-2026-15690. The attack can be executed remotely. Additionally, an exploit exists.
The project closed the issue report, stating that this is not the official way to report a security vulnerability.
vuldb.com
ZDI-CAN-31759: NVIDIA
1 week 2 days ago
A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'YJK(@YJK0805) of ZUSO ART' was reported to the affected vendor on: 2026-07-14, 8 days ago. The vendor is given until 2026-11-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
ZDI-CAN-31905: NVIDIA
1 week 2 days ago
A CVSS score 8.8 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Brandon Evans of TrendAI Zero Day Initiative' was reported to the affected vendor on: 2026-07-14, 8 days ago. The vendor is given until 2026-11-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
ZDI-CAN-30268: Parallels
1 week 2 days ago
A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Aled Mehta (@x_delfino) of Dolphin Labs' was reported to the affected vendor on: 2026-07-14, 8 days ago. The vendor is given until 2026-11-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
ZDI-CAN-32123: Open Robotics
1 week 2 days ago
A CVSS score 6.5 AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H severity vulnerability discovered by 'Aaron Luo of VicOne LAB R7' was reported to the affected vendor on: 2026-07-14, 8 days ago. The vendor is given until 2026-11-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
ZDI-CAN-31524: Linux
1 week 2 days ago
A CVSS score 7.8 AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'elden, Bryan Mbeumo' was reported to the affected vendor on: 2026-07-14, 8 days ago. The vendor is given until 2026-11-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
ZDI-CAN-32122: Open Robotics
1 week 2 days ago
A CVSS score 6.5 AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H severity vulnerability discovered by 'Aaron Luo of VicOne LAB R7' was reported to the affected vendor on: 2026-07-14, 8 days ago. The vendor is given until 2026-11-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
ZDI-CAN-30931: Linux
1 week 2 days ago
A CVSS score 7.8 AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'GangMin Kim' was reported to the affected vendor on: 2026-07-14, 8 days ago. The vendor is given until 2026-11-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
ZDI-CAN-32121: Open Robotics
1 week 2 days ago
A CVSS score 5.5 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N severity vulnerability discovered by 'Aaron Luo of VicOne LAB R7' was reported to the affected vendor on: 2026-07-14, 8 days ago. The vendor is given until 2026-11-11 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
Submit #856019: Tenda BE12 Pro V16.03.66.23 Stack-based Buffer Overflow [Accepted]
1 week 2 days ago
Submit #856019 / VDB-378243
dexingzhiqing
Submit #856017: Tenda BE12 Pro V16.03.66.23 Stack-based Buffer Overflow [Accepted]
1 week 2 days ago
Submit #856017 / VDB-378242
dexingzhiqing
Submit #856015: Tenda BE12 Pro V16.03.66.23 Stack-based Buffer Overflow [Accepted]
1 week 2 days ago
Submit #856015 / VDB-378241
dexingzhiqing
Submit #856011: Tenda BE12 Pro V16.03.66.23 Stack-based Buffer Overflow [Accepted]
1 week 2 days ago
Submit #856011 / VDB-378240
dexingzhiqing
Submit #856010: Tenda BE12 Pro V16.03.66.23 Stack-based Buffer Overflow [Accepted]
1 week 2 days ago
Submit #856010 / VDB-378239
dexingzhiqing
Submit #855999: Tenda BE12 Pro V16.03.66.23 Stack-based Buffer Overflow [Accepted]
1 week 2 days ago
Submit #855999 / VDB-378238
dexingzhiqing
Submit #855996: open62541 Project open62541 master (commit ca356b088ada7dee824d1b4acd07c1ff07ce242b) out-of-bounds read [Accepted]
1 week 2 days ago
Submit #855996 / VDB-378237
VULL
CVE-2026-43288 | Linux Kernel up to 6.6.127/6.12.74/6.18.15/6.19.5 ext4 ext4_percpu_param_init memory corruption (WID-SEC-2026-1454)
1 week 2 days ago
A vulnerability described as critical has been identified in Linux Kernel up to 6.6.127/6.12.74/6.18.15/6.19.5. Affected by this issue is the function ext4_percpu_param_init of the component ext4. Such manipulation leads to memory corruption.
This vulnerability is documented as CVE-2026-43288. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-43290 | Linux Kernel up to 6.18.15/6.19.5 media /dev/video0 start_streaming buffer overflow (WID-SEC-2026-1454)
1 week 2 days ago
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.18.15/6.19.5. This affects the function start_streaming of the file /dev/video0 of the component media. Executing a manipulation can lead to buffer overflow.
This vulnerability is tracked as CVE-2026-43290. The attack is only possible within the local network. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-43289 | Linux Kernel up to 6.19.5 kernel/kexec_file.c kexec_load_purgatory privilege escalation (Nessus ID 318589 / WID-SEC-2026-1454)
1 week 2 days ago
A vulnerability was found in Linux Kernel up to 6.19.5 and classified as critical. The impacted element is the function kexec_load_purgatory of the file kernel/kexec_file.c. Such manipulation leads to privilege escalation.
This vulnerability is uniquely identified as CVE-2026-43289. The attack can only be initiated within the local network. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com