CVE ID :CVE-2026-90651 Published : Sept. 13, 2026, 12:17 a.m. | 51 minutes ago Description :Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the…
CVE-2026-90647 – Kalkitech ASE2000 Improper Certificate Validation Vulnerability
CVE ID :CVE-2026-90647 Published : Sept. 12, 2026, 10:38 p.m. | 29 minutes ago Description :ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in…
CVE-2026-90560 – zstd-jni 1.2.0 through 1.5.7-13 Out-of-Bounds Read via ZstdDictDecompress
CVE ID :CVE-2026-90560 Published : Sept. 12, 2026, 6:16 p.m. | 4 hours, 51 minutes ago Description :zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and…
CVE-2026-90559 – snappy-java through 1.1.10.8 Out-of-Bounds Write via uncompress
CVE ID :CVE-2026-90559 Published : Sept. 12, 2026, 6:16 p.m. | 4 hours, 51 minutes ago Description :snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never…
CVE-2026-90558 – sngrep through 1.8.4 Stack Buffer Overflow via SIP Headers
CVE ID :CVE-2026-90558 Published : Sept. 12, 2026, 6:16 p.m. | 4 hours, 51 minutes ago Description :sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed…
CVE-2026-90556 – Freeciv before 3.2.6 Heap Buffer Overflow via worklist_load
CVE ID :CVE-2026-90556 Published : Sept. 12, 2026, 6:16 p.m. | 4 hours, 51 minutes ago Description :Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared…
CVE-2026-89266 – stb_vorbis through 1.22 heap buffer overflow via codebook multiplicands
CVE ID :CVE-2026-89266 Published : Sept. 12, 2026, 12:17 a.m. | 43 minutes ago Description :stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated…
CVE-2026-90456 – Inventory Management Component Default Administrative Credential Vulnerability
CVE ID :CVE-2026-90456 Published : Sept. 11, 2026, 10:16 p.m. | 2 hours, 44 minutes ago Description :An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A…
CVE-2026-90451 – Packet-Analysis Component Authentication Cookie Forgery via Hardcoded Secret
CVE ID :CVE-2026-90451 Published : Sept. 11, 2026, 10:16 p.m. | 2 hours, 44 minutes ago Description :An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for…
CVE-2026-90444 – Product Name OS Command Injection via Filename Validation Bypass
CVE ID :CVE-2026-90444 Published : Sept. 11, 2026, 10:16 p.m. | 2 hours, 44 minutes ago Description :A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process…