9.4
CVE-2026-42810 - Apache Polaris: could broaden vended S3 credentials through wildcard-bearing namespace or table namβ¦
Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM resource patterns and `s3:prefix` conditions. In S3 IAM policy matching, `*` is β¦
8.1
CVE-2026-42075 - Evolver: Path Traversal via `--out` flag in `fetch` command allows Arbitrary File Write
Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in the skill download (fetch) command allows attackers to write files to arbitrary locations on the filesystem. The --out= flag accepts user-provided paths without validation, enabliβ¦
9.6
CVE-2026-25293 - Incorrect authorization in PLC FW
Buffer overflow due to incorrect authorization in PLC FW
5.5
CVE-2026-25266 - Exposed dangerous function in windows host
Memory corruption while processing IOCTL command when device is in power-save state.
7.8
CVE-2026-24082 - Use After Free in Automotive GPU
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
7.8
CVE-2025-47408 - Untrusted Pointer Dereference in Power Optimization Firmware
Memory corruption when another driver calls an IOCTL with invalid input/output buffer.
7.8
CVE-2025-47407 - Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service
Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.
6.1
CVE-2025-47406 - Buffer Over-read in DSP Service
Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
9.8
CVE-2026-42027 - Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader
Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 2.5.9, before 3.0.0-M3 Description:Β The ExtensionLoader.instantiateExtension(Class, String)Β method loads a class by its fully-qualified name via Class.forName()Β and invokes its nβ¦
7.8
CVE-2025-47405 - Untrusted Pointer Dereference in Camera
Memory corruption when processing camera sensor input/output control codes with invalid output buffers.