NVD CVEs — 本日公開 (31 件)
CVE-2026-11835
Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mode allows a compromised local attacker to silently bypass secure boot by supplying an AXI staging address that is not validated against the strap-confi
CVE-2026-11836
Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to the integrator's debug unlock signing service to unlock production debug on an unintended device by presenting a valid token issue
CVE-2026-18685 9.8 CRITICAL
A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly an
CVE-2026-18686 9.8 CRITICAL
A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public
CVE-2026-62870 8.8 HIGH
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
CVE-2026-65802 7.4 HIGH
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
CVE-2026-65804 6.1 MEDIUM
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66310 7.7 HIGH
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
CVE-2026-66311 6.2 MEDIUM
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
CVE-2026-66312 6.5 MEDIUM
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
GitHub Security Advisories — 本日公開 (20 件)
GHSA-mv6j-rvc6-f296
MEDIUM
A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code...
GHSA-hq2r-whw2-gr82
MEDIUM
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S...
GHSA-62xj-w627-m337
MEDIUM
A path traversal flaw was found in WildFly's domain mode
implementation. The...
GHSA-fq66-x242-gfpv
HIGH
A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel...
GHSA-pgf6-87r4-94vm
MEDIUM
A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response...
GHSA-4j79-vxj3-vjvm
MEDIUM
A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in...
GHSA-qgrj-5wc5-7xvc
MEDIUM
A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync...
GHSA-6c37-9jgq-mgm8
HIGH
An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when...
GHSA-gxcj-787f-7pq4
LOW
A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file...
GHSA-6hff-9f4h-85xm
LOW
A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding...