1w ago
2026-09-03 23:17Z
CRIT

CVE-2026-85440 — MOOS: core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85440

MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that allows remote attackers to write arbitrary data by declaring a negative packet length. Attackers can exploit the signed integer check in InflateTo() and negative size conversion in recv() to overflow a four-byte heap buffer during the HandShake phase before authentication. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDMoosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 23:17Z
CRIT

CVE-2026-85438 — MOOS: MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85438

MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used as allocation sizes and loop bounds without validation. Attackers can supply crafted payloads with mismatched dimension values to write attacker-controlled doubles past the end of the IvPBox weight array, causing memory corruption and potential code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 190VNDMoosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 23:17Z
CRIT

CVE-2026-85437 — MOOS: MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85437

MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled length fields without validation. Attackers can craft malicious encoded strings with mismatched declared and actual field lengths to overflow heap and stack buffers, potentially achieving remote code execution through MOOS variables or alog files. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDMoosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 23:17Z
CRIT

CVE-2026-85435 — MOOS: MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85435

MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including sensor data and control information. CVSSv3.1 9.1 (CRITICAL)

CWECWE 345VNDMoosTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 23:17Z
CRIT

CVE-2026-85434 — MOOS: MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85434

MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses. CVSSv3.1 9.1 (CRITICAL)

CWECWE 345VNDMoosTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 23:17Z
CRIT

CVE-2026-85433 — MOOS: essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85433

MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners on arbitrary addresses and redirect or duplicate bus traffic to attacker-controlled destinations. CVSSv3.1 9.8 (CRITICAL)

CWECWE 862VNDMoosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 23:17Z
HIGH

CVE-2026-85432 — MOOS: core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85432

MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by supplying arbitrary source identifiers in serialized messages. Attackers can forge message origins and cancel third-party subscriptions by exploiting the disconnect between authenticated connection identity and wire-supplied source attribution. CVSSv3.1 8.2 (HIGH)

CWECWE 290VNDMoosTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
1w ago
2026-09-03 23:17Z
CRIT

CVE-2026-85430 — MOOS: essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85430

MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact. Attackers can send crafted UDP datagrams to pShare input routes to inject messages into the local MOOS community under spoofed identities, or send malformed datagrams to crash the pShare process. CVSSv3.1 9.1 (CRITICAL)

CWECWE 345VNDMoosTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 23:17Z
CRIT

CVE-2026-85428 — MOOS: core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85428

MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS variables including actuator and override commands without authentication. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDMoosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 23:17Z
HIGH

CVE-2026-85427 — MOOS: essential-moos pAntler through 10.0.1 contains a remote code execution vulnerability that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85427

MOOS essential-moos pAntler through 10.0.1 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary programs by publishing a crafted MISSION_FILE message to the MOOSDB. Attackers can publish a mission file containing malicious Run entries that pAntler parses and executes via execvp() without authentication validation. CVSSv3.1 8.1 (HIGH)

CWECWE 494VNDMoosTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 23:17Z
CRIT

CVE-2026-85426 — MOOS: MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85426

MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into client names to execute arbitrary commands as the uMemWatch process user through unquoted redirection targets in system calls. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDMoosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 23:17Z
CRIT

CVE-2026-85425 — MOOS: MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85425

MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. Attackers can publish SAY_MOOS messages containing backticks or command substitution syntax to execute arbitrary commands as the iSay process user. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDMoosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 23:17Z
CRIT

CVE-2026-85424 — MOOS: Attackers can bypass the compile-time protocol string check and connect with arbitrary client names

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85424

MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations including DB_CLEAR which resets all variables and clears client mail queues. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDMoosTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 23:17Z
CRIT

CVE-2026-83711 — Authorization: bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83711

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 10.0 (CRITICAL)

CWECWE 639TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1w ago
2026-09-03 23:17Z
CRIT

CVE-2026-80098 — Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80098

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 9.3 (CRITICAL)

CWECWE 347TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
1w ago
2026-09-03 23:17Z
CRIT

CVE-2026-70352 — Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70352

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 10.0 (CRITICAL)

CWECWE 306TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1w ago
2026-09-03 23:17Z
HIGH

CVE-2026-70178 — Microsoft: Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70178

Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.5 (HIGH)

CWECWE 862VNDMicrosoftTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
1w ago
2026-09-03 23:17Z
HIGH

CVE-2026-69857 — Authorization: bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69857

Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network. CVSSv3.1 8.5 (HIGH)

CWECWE 639TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
1w ago
2026-09-03 23:17Z
HIGH

CVE-2026-65818 — Server: Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65818

Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.5 (HIGH)

CWECWE 918TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
1w ago
2026-09-03 23:17Z
CRIT

CVE-2026-62916 — Authentication: bypass using an alternate path or channel in Microsoft Entra ID allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62916

Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 9.1 (CRITICAL)

CWECWE 288TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 22:18Z
CRIT

CVE-2026-85224 — Executing a manipulation of the argument fileurl can lead to os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85224

A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. CVSSv3.1 9.1 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 22:18Z
CRIT

CVE-2026-85223 — Performing a manipulation of the argument callback_url/sync_interval results in os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85223

A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used. CVSSv3.1 9.9 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1w ago
2026-09-03 21:17Z
CRIT

CVE-2026-85222 — Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85222

A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. CVSSv3.1 9.1 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 21:17Z
CRIT

CVE-2026-85061 — MapLibre: GL JS is an interactive vector tile map library for web browsers.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85061

MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an adjacent dangerous attribute. An attacker who controls untrusted third-party style attribution strings or user-supplied custom attributions can supply consecutive dangerous attributes, causing an attribut CVSSv3.1 10.0 (CRITICAL)

CWECWE 79VNDMaplibreTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1w ago
2026-09-03 21:17Z
HIGH

CVE-2026-63376 — TOML: Injected properties become visible throughout the Node.js process and can cause denial of service

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63376

toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Object.prototype. The currentPath tracking value uses both arrays and strings, so valueAssignments records a comma-joined path such as a,b.y while deepRef checks the dot-joined path a.b.y, allowing the duplicate-key guard to miss and attacker-co CVSSv3.1 8.2 (HIGH)

CWECWE 1321VNDTomlTYPVulnerability
8.2
CVSS v3.1
91
Edit Score