8.2

CVSS4.0

CVE-2026-22026 - CryptoLib Unbounded Memory Allocation in KMC HTTP Response Handler Allows Resource Exhaustion

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the libcurl write_callback function in the K…

πŸ“… Published: Jan. 10, 2026, 12:22 a.m. πŸ”„ Last Modified: April 18, 2026, 7:30 a.m.

6.3

CVSS4.0

CVE-2026-22025 - CryptoLib Memory Leak on HTTP Error Response in KMC Client

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, when the KMC server returns a non-200 HTTP s…

πŸ“… Published: Jan. 10, 2026, 12:20 a.m. πŸ”„ Last Modified: April 18, 2026, 7:30 p.m.

6.3

CVSS4.0

CVE-2026-22024 - CryptoLib Memory Leak in KMC Encrypt Function Leads to Resource Exhaustion

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the cryptography_encrypt() function allocate…

πŸ“… Published: Jan. 10, 2026, 12:19 a.m. πŸ”„ Last Modified: April 18, 2026, 7:30 a.m.

8.2

CVSS4.0

CVE-2026-22023 - CryptoLib Has Out-of-Bounds Read in KMC AEAD Encrypt Metadata Parsing via Flawed strtok Pattern

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, there is an out-of-bounds heap read vulnerab…

πŸ“… Published: Jan. 10, 2026, 12:17 a.m. πŸ”„ Last Modified: April 18, 2026, 4:45 p.m.

8.2

CVSS4.0

CVE-2026-21900 - CryptoLib Has Out-of-Bounds Read in KMC Encrypt Metadata Parsing via Flawed strtok Pattern

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, an out-of-bounds heap read vulnerability in …

πŸ“… Published: Jan. 10, 2026, 12:14 a.m. πŸ”„ Last Modified: April 18, 2026, 4:45 p.m.

4.7

CVSS3.1

CVE-2026-21899 - CryptoLib has an out-of-bounds read and crash vulnerability when decoding an empty Base64url string

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, in base64urlDecode, padding-stripping derefe…

πŸ“… Published: Jan. 10, 2026, 12:11 a.m. πŸ”„ Last Modified: April 18, 2026, 7:30 a.m.

8.2

CVSS3.1

CVE-2026-21898 - CryptoLib Has Out-of-bounds Read in Crypto_AOS_ProcessSecurity

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the Crypto_AOS_ProcessSecurity function read…

πŸ“… Published: Jan. 10, 2026, 12:10 a.m. πŸ”„ Last Modified: April 18, 2026, 7:30 a.m.

7.3

CVSS3.1

CVE-2026-21897 - CryptoLib Has Out-of-Bounds Write in Crypto_Config_Add_Gvcid_Managed_Parameters

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the Crypto_Config_Add_Gvcid_Managed_Paramete…

πŸ“… Published: Jan. 10, 2026, 12:07 a.m. πŸ”„ Last Modified: April 18, 2026, 7:30 a.m.

9.3

CVSS4.0

CVE-2025-15501 - Sangfor Operation and Maintenance Management System getCmd WriterHandle.getCmd os command injection

A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the file /isomp-protocol/protocol/getCmd. This manipulation of the argument sessionPath causes os command injection. Remote exploitation of the attack i…

πŸ“… Published: Jan. 9, 2026, 10:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:27 a.m.

9.8

CVSS3.1

CVE-2026-22584 - Code Injection Allows Execution of Code from Non-Executable Files in Salesforce Uni2TS

Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code in Non-Executable Files.This issue affects Uni2TS: through 1.2.0.

πŸ“… Published: Jan. 9, 2026, 10:10 p.m. πŸ”„ Last Modified: April 18, 2026, 7:30 a.m.
Total resulsts: 346515
Page 1940 of 34,652
Β« previous page Β» next page
Filters