25 results//sorted by published//last sync 2026-09-15 12:20Z
1w ago
2026-09-04 05:17Z
CRIT
CVE-2026-85508 — FreeIPMI: ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).
CVSSv3.1 9.8 (CRITICAL)
CWECWE 121VNDFreeipmiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 05:17Z
CRIT
CVE-2026-85507 — FreeIPMI: ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).
CVSSv3.1 9.8 (CRITICAL)
CWECWE 121VNDFreeipmiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 05:17Z
CRIT
CVE-2026-85506 — FreeIPMI: ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
CVSSv3.1 9.8 (CRITICAL)
CWECWE 121VNDFreeipmiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 05:17Z
CRIT
CVE-2026-85504 — FreeIPMI: before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 121VNDFreeipmiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 05:17Z
CRIT
CVE-2026-11613 — Divi: The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in
The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be upload
CVSSv3.1 9.8 (CRITICAL)
CWECWE 98VNDDiviTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 03:17Z
CRIT
CVE-2026-85148 — SmartIT: Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability.
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 798VNDSmartitTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-04 03:17Z
CRIT
CVE-2026-85146 — SmartIT: Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability.
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 798VNDSmartitTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
1w ago
2026-09-04 00:00Z
HIGH
Data access: the hidden cost of security vendor lock-in
Elastic Security Labs·elastic.co
Elastic Security Labs publishes a comparative analysis of data export capabilities across six major SIEM vendors (CrowdStrike, Palo Alto Networks, Microsoft, Google, Splunk, and Elastic), revealing significant differences in cost, latency, and fidelity. The research demonstrates that most vendors impose licensing fees, batch delays, or data restrictions on egress—creating artificial lock-in that fragments security investigations and delays incident response. The article argues that true data openness requires three conditions: no additional cost, full-fidelity access, and real-time availability.
MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted short packet to read memory before authentication.
CVSSv3.1 8.2 (HIGH)
CWECWE 125VNDMoosTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 23:17Z
HIGH
CVE-2026-85452 — MOOS: ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where
MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply arbitrarily long MOOS identifiers that overflow the buffers when an operator selects process list entries or pokes variables, enabling code execution.
CVSSv3.1 8.8 (HIGH)
CWECWE 787VNDMoosTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-03 23:17Z
CRIT
CVE-2026-85440 — MOOS: core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling
MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that allows remote attackers to write arbitrary data by declaring a negative packet length. Attackers can exploit the signed integer check in InflateTo() and negative size conversion in recv() to overflow a four-byte heap buffer during the HandShake phase before authentication.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 787VNDMoosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 23:17Z
CRIT
CVE-2026-85438 — MOOS: MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and
MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used as allocation sizes and loop bounds without validation. Attackers can supply crafted payloads with mismatched dimension values to write attacker-controlled doubles past the end of the IvPBox weight array, causing memory corruption and potential code execution.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 190VNDMoosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 23:17Z
CRIT
CVE-2026-85437 — MOOS: MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that
MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled length fields without validation. Attackers can craft malicious encoded strings with mismatched declared and actual field lengths to overflow heap and stack buffers, potentially achieving remote code execution through MOOS variables or alog files.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 787VNDMoosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 23:17Z
CRIT
CVE-2026-85435 — MOOS: MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the
MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including sensor data and control information.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 345VNDMoosTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 23:17Z
CRIT
CVE-2026-85434 — MOOS: MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge
MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 345VNDMoosTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 23:17Z
CRIT
CVE-2026-85433 — MOOS: essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher
MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners on arbitrary addresses and redirect or duplicate bus traffic to attacker-controlled destinations.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 862VNDMoosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 23:17Z
HIGH
CVE-2026-85432 — MOOS: core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing
MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by supplying arbitrary source identifiers in serialized messages. Attackers can forge message origins and cancel third-party subscriptions by exploiting the disconnect between authenticated connection identity and wire-supplied source attribution.
CVSSv3.1 8.2 (HIGH)
CWECWE 290VNDMoosTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 23:17Z
CRIT
CVE-2026-85430 — MOOS: essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP
MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact. Attackers can send crafted UDP datagrams to pShare input routes to inject messages into the local MOOS community under spoofed identities, or send malformed datagrams to crash the pShare process.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 345VNDMoosTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 23:17Z
CRIT
CVE-2026-85428 — MOOS: core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP
MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS variables including actuator and override commands without authentication.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 306VNDMoosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 23:17Z
HIGH
CVE-2026-85427 — MOOS: essential-moos pAntler through 10.0.1 contains a remote code execution vulnerability that allows unauthenticated
MOOS essential-moos pAntler through 10.0.1 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary programs by publishing a crafted MISSION_FILE message to the MOOSDB. Attackers can publish a mission file containing malicious Run entries that pAntler parses and executes via execvp() without authentication validation.
CVSSv3.1 8.1 (HIGH)
CWECWE 494VNDMoosTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 23:17Z
CRIT
CVE-2026-85426 — MOOS: MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization.
MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into client names to execute arbitrary commands as the uMemWatch process user through unquoted redirection targets in system calls.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 78VNDMoosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 23:17Z
CRIT
CVE-2026-85425 — MOOS: MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable
MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. Attackers can publish SAY_MOOS messages containing backticks or command substitution syntax to execute arbitrary commands as the iSay process user.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 78VNDMoosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 23:17Z
CRIT
CVE-2026-85424 — MOOS: Attackers can bypass the compile-time protocol string check and connect with arbitrary client names
MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations including DB_CLEAR which resets all variables and clears client mail queues.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 306VNDMoosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 23:17Z
CRIT
CVE-2026-83711 — Authorization: bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
CVSSv3.1 10.0 (CRITICAL)
CWECWE 639TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1w ago
2026-09-03 23:17Z
CRIT
CVE-2026-80098 — Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
CVSSv3.1 9.3 (CRITICAL)