CVE-2026-67863 - open62541 Use-After-Free Vulnerability
CVE ID :CVE-2026-67863
Published : Aug. 5, 2026, 11:16 p.m. | 48 minutes ago
Description :In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem for the current local MonitoredItem. This allows a remote attacker to cause a denial of service.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-67863
Published : Aug. 5, 2026, 11:16 p.m. | 48 minutes ago
Description :In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem for the current local MonitoredItem. This allows a remote attacker to cause a denial of service.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67866 - Systerel S2OPC Buffer Overflow Vulnerability
CVE ID :CVE-2026-67866
Published : Aug. 5, 2026, 11:16 p.m. | 48 minutes ago
Description :Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse and SOPC_StaMac_NewDeleteMonitoredItems in the client wrapper DeleteMonitoredItems path
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-67866
Published : Aug. 5, 2026, 11:16 p.m. | 48 minutes ago
Description :Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse and SOPC_StaMac_NewDeleteMonitoredItems in the client wrapper DeleteMonitoredItems path
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67867 - Systerel S2OPC Buffer Overflow
CVE ID :CVE-2026-67867
Published : Aug. 5, 2026, 11:16 p.m. | 48 minutes ago
Description :Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Alarm/Conditions wrapper when processing PublishResponse EventNotificationList data
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-67867
Published : Aug. 5, 2026, 11:16 p.m. | 48 minutes ago
Description :Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Alarm/Conditions wrapper when processing PublishResponse EventNotificationList data
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18969 - Rongzhitong Visual Integrated Command and Dispatch Platform upload unrestricted upload
CVE ID :CVE-2026-18969
Published : Aug. 5, 2026, 11:30 p.m. | 34 minutes ago
Description :A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the file /dm/dispatch/userinfo/upload. Performing a manipulation of the argument File results in unrestricted upload. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18969
Published : Aug. 5, 2026, 11:30 p.m. | 34 minutes ago
Description :A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the file /dm/dispatch/userinfo/upload. Performing a manipulation of the argument File results in unrestricted upload. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54383 - Rejected reason: Erroneously reserved under wrong
CVE ID :CVE-2023-54383
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2023-54383
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54384 - Rejected reason: Erroneously reserved under wrong
CVE ID :CVE-2023-54384
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2023-54384
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54385 - Rejected reason: Erroneously reserved under wrong
CVE ID :CVE-2023-54385
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2023-54385
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54386 - Rejected reason: Erroneously reserved under wrong
CVE ID :CVE-2023-54386
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2023-54386
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54387 - Rejected reason: Erroneously reserved under wrong
CVE ID :CVE-2023-54387
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2023-54387
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54388 - Rejected reason: Erroneously reserved under wrong
CVE ID :CVE-2023-54388
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2023-54388
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54389 - Rejected reason: Erroneously reserved under wrong
CVE ID :CVE-2023-54389
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2023-54389
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18970 - Rongzhitong Visual Integrated Command and Dispatch Platform findAll sql injection
CVE ID :CVE-2026-18970
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of the file /dm/dispatch/user/findAll. Executing a manipulation of the argument Name can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18970
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of the file /dm/dispatch/user/findAll. Executing a manipulation of the argument Name can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-52466 - VuFind Incorrect Access Control Vulnerability
CVE ID :CVE-2026-52466
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not allow access to the requested function. The requester receives a response indicating that access was denied, but the actual function is executed regardless of that.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-52466
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not allow access to the requested function. The requester receives a response indicating that access was denied, but the actual function is executed regardless of that.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67869 - open62541 Buffer Overflow Vulnerability
CVE ID :CVE-2026-67869
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-67869
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67870 - open62541 Null Pointer Dereference Vulnerability
CVE ID :CVE-2026-67870
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-67870
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67871 - Systerel S2OPC Buffer Overflow
CVE ID :CVE-2026-67871
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-67871
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67872 - Systerel S2OPC Denial of Service Vulnerability
CVE ID :CVE-2026-67872
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queue resize handling
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-67872
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queue resize handling
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67873 - lib60870-C Heap-Based Buffer Overflow
CVE ID :CVE-2026-67873
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the current ASDU frame before encoding object fields and segment data
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-67873
Published : Aug. 6, 2026, 12:16 a.m. | 3 hours, 49 minutes ago
Description :A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the current ASDU frame before encoding object fields and segment data
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18973 - heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgery
CVE ID :CVE-2026-18973
Published : Aug. 6, 2026, 1:16 a.m. | 2 hours, 49 minutes ago
Description :A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component extension_proxy Route. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18973
Published : Aug. 6, 2026, 1:16 a.m. | 2 hours, 49 minutes ago
Description :A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component extension_proxy Route. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18974 - heshengtao super-agent-party execute_tool_manually Endpoint server.py get_file_content information disclosure
CVE ID :CVE-2026-18974
Published : Aug. 6, 2026, 1:16 a.m. | 2 hours, 49 minutes ago
Description :A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the component execute_tool_manually Endpoint. The manipulation of the argument tool_name/tool_params results in information disclosure. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18974
Published : Aug. 6, 2026, 1:16 a.m. | 2 hours, 49 minutes ago
Description :A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the component execute_tool_manually Endpoint. The manipulation of the argument tool_name/tool_params results in information disclosure. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18976 - NousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definitions privileges assignment
CVE ID :CVE-2026-18976
Published : Aug. 6, 2026, 2:16 a.m. | 1 hour, 49 minutes ago
Description :A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This manipulation causes incorrect privilege assignment. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18976
Published : Aug. 6, 2026, 2:16 a.m. | 1 hour, 49 minutes ago
Description :A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This manipulation causes incorrect privilege assignment. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...