Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-47774

Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification_CVE-2026-47774

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vul...

envoyproxy envoy < 1.35.11 CVE
CRITICAL 9.2 CVE-2026-3894

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers._CVE-2026-3894

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from...

RTI Connext Professional 7.4.0 CVE
LOW 2.9 CVE-2026-39199

CVE-2026-39199_CVE-2026-39199

snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.

Snes9X team Snes9X 1.63 CVE
HIGH 8.8 CVE-2026-30803

Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers._CVE-2026-30803

Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connext Micro...

RTI Connext Micro 4.0.0 CVE
HIGH 8.8 CVE-2026-30802

Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers._CVE-2026-30802

Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connext Micro: from 4.0.0 before ...

RTI Connext Micro 4.0.0 CVE
MEDIUM 6.1 CVE-2026-30799

Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing._CVE-2026-30799

Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing.This issue affec...

RTI Connext Professional 7.4.0 CVE
MEDIUM 6 CVE-2026-2675

Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data._CVE-2026-2675

Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data.This issue...

RTI Connext Professional 7.4.0 CVE
MEDIUM 4.8 CVE-2026-2674

Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Service,Core Libraries,Persistence Service) allows Overflow Buffers._CVE-2026-2674

Out-of-bounds Write, Out-of-bounds Write, Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Service,Core Libraries,Persistenc...

RTI Connext Professional 7.4.0 CVE
CRITICAL 9.2 CVE-2026-2467

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags._CVE-2026-2467

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext...

RTI Connext Professional 7.4.0 CVE
CRITICAL 9.1 CVE-2026-20266

OS Command Injection in the btool Configuration Helper in Splunk AI Toolkit_CVE-2026-20266

In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Spl...

Splunk Splunk AI Toolkit 5.7 CVE