# OSINT Threat Intelligence Report

**Date:** 2026-08-21 | **Generated:** 2026-08-21T03:01:29.634Z | **Items:** 317 | **Range:** daily

## Sources
| Source | Count |
|--------|-------|
| cisa-kev | 8 |
| nvd | 3068 |
| cisa-advisories | 7 |
| vendor-blogs | 87 |
| malware-bazaar | 9 |
| abuse-ipdb | 20 |
| threatfox | 2 |
| otx | 33 |
| general-news | 112 |

## Top 10 Highlights
| Severity | Title | Source | CVEs | Tags |
|----------|-------|--------|------|------|
| critical | CVE-2026-15706 — Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry… | nvd | CVE-2026-15706 |  |
| critical | CVE-2026-64960 — ATutor Gameme module allows users to upload files of any type and extension without restriction. Due… | nvd | CVE-2026-64960 | rce |
| critical | CVE-2026-64966 — ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker… | nvd | CVE-2026-64966 | rce |
| critical | CVE-2026-16926 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary f… | nvd | CVE-2026-16926 |  |
| critical | CVE-2026-15679 — Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution… | nvd | CVE-2026-15679 | rce |
| critical | CVE-2026-15686 — Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. Th… | nvd | CVE-2026-15686 | rce |
| critical | CVE-2026-18264 — NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows r… | nvd | CVE-2026-18264 | rce |
| critical | CVE-2026-18265 — OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability al… | nvd | CVE-2026-18265 | rce |
| critical | CVE-2026-18274 — Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This… | nvd | CVE-2026-18274 | rce |
| critical | CVE-2026-18279 — Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability. This vulnerability a… | nvd | CVE-2026-18279 | rce |

## All Items
| Severity | Title | Category | Source | Tags | Published |
|----------|-------|----------|--------|------|-----------|
| critical | CVE-2026-15706 — Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-64960 — ATutor Gameme module allows users to upload files of any type and extension without restriction. Due… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-64966 — ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-16926 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary f… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-15679 — Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-15686 — Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. Th… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18264 — NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows r… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18265 — OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability al… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18274 — Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18279 — Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability. This vulnerability a… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18281 — Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability. Th… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18282 — Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerabil… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18285 — Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability.… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18286 — Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability. T… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18287 — Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerability. Thi… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18288 — OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18289 — OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This v… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18290 — OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This v… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18291 — OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vul… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18292 — OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vul… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18293 — OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. Th… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18294 — OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18295 — GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerabili… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18296 — GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vuln… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18297 — GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vul… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18298 — GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vuln… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18299 — GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18300 — GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18301 — GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18302 — GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabi… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18303 — GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerab… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18304 — GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18306 — GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-18309 — GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allo… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-55642 — dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in c… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-71428 — The unstructured library provides open-source components for ingesting and pre-processing images and… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-77022 — A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the functi… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-2334 — An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-53424 — Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authent… | vulnerability | nvd | ransomware | 2026-08-20 |
| critical | CVE-2026-73256 — Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated atta… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-73257 — Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthentica… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-66785 — A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect ne… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-66788 — A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vu… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-77148 — A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the fi… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-67567 — A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a ten… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-69242 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-71485 — Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-62834 — Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attack… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-63509 — Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-65770 — Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-65801 — Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to e… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-65816 — Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevat… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-66309 — Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges ov… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-68782 — Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Da… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-69400 — Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps a… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-69555 — Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a ne… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-69836 — Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute c… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-69851 — Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevat… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-72843 — The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/m… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-77645 — A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC Flex… | vulnerability | nvd | rce | 2026-08-20 |
| critical | CVE-2026-77647 — SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited i… | vulnerability | nvd |  | 2026-08-20 |
| critical | CVE-2026-77649 — The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project… | vulnerability | nvd | botnet | 2026-08-21 |
| critical | CVE-2026-77650 — The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a pr… | vulnerability | nvd | botnet | 2026-08-21 |
| critical | CVE-2026-77651 — The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project… | vulnerability | nvd | botnet | 2026-08-21 |
| critical | Malicious IP: 213.209.159.241 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 64.62.197.138 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 119.92.70.82 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 195.26.18.111 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 181.115.171.216 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 118.196.68.35 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 79.124.59.178 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 79.124.56.142 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 68.225.61.18 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 193.47.62.69 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 163.7.9.55 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 68.221.130.146 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 61.184.128.210 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 70.183.230.195 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 47.254.134.254 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 4.206.92.183 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 45.148.10.240 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 194.88.98.114 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 181.116.43.25 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | Malicious IP: 45.249.246.17 | ip-reputation | abuse-ipdb |  | 2026-08-21 |
| critical | payload_delivery: undefined | threat-intel | threatfox | ClearFake, mac-0xdcf2, macOS, Cloudflare, gif, PHP, webshell, WordPress, workers.dev, wp-admin, 21August2026, Commandline, mac-0x68dc, CobaltStrike, Vshell, 8560, asyncrat, c2, censys, compromised, etherhide, ClickFix, etherhiding, AISURU, elf, IoT, Mozi, Remus, mac-0x76c7, drb-ra, mac-0x0f14, 20August2026, ErrTraffic, Viper, Havoc, dcrat, PureHVNC, PureRAT, RAT, HypeAgent, Mythic, Supershell, 1xxbot, ArechClient, SectopRAT, CinaRAT, Quasar RAT, QuasarRAT, Yggdrasil, sliver, ResolverRAT, ConnectWise, ScreenConnect, 903ac24fcd9670b9ef2e674243d550d8, Loader, stealer, Vidar, RemusStealer, fake-plugin, nochain, SmartApeSG, win-0xa770, Windows, ValleyRAT, Kongtuke, AgentTesla, XWorm, Dropper, SocGholish, Pink, Adaptix, RevStealer, DomainShadowing, NEWTEST, Stealc, test_2, STRRAT, DanBot, CONTABO, CTFLoaderService, FakeAdobe, iso, LNK, pre-ransomware, velociraptor, cs-watermark-987654321, RemcosRAT, remcos, OffLoader, Socks5Systemz, Mirai, Vjw0rm, RedGuard, shodan, orcus, NetSupport, StarKillerC2, UNAM, AdaptixC2, PowerSploit, locust, GoPhish, phishing, cs-watermark-100000, Amos, nakedpages, Lud, 36903, MetaSploit, fake-copilot, RedLineStealer, 19August2026, njrat, Covenant, NeedleStealer, sliverfox, Gafgyt, rmm, 117ee8f56cb68a9f6a440e1b4329f856, SparkRAT, ExtRat, XTRAT, Xtreme RAT, Agentemis, Beacon, Cobalt Strike, cobeacon, clipboard, ACRStealer, Mac, Breut, darkcomet, Fynloski, klovbot, Lumma, NanoCore, SnappyClient, Diamotrix, URLscan, EvilGinx, EvilGoPhish, CHAOS, x4tte, PureLogsStealer, LxBaseRAT, ProRat, Panda, EpsteinClient, NetSupportManager, NetSupportRAT, 592a9e009f92c0e8eaea74a337b4f67c, capture-drop, honeypot, ssh-dropper, HTA, mexico, WhatsApp, sepolia, tofsee, web-inject, Spynote, HookBot, Byakugan, nc, gs-netcat, gsocket, moobot, nimplant, quasar, sectop, shadowpad, cs-watermark-1234567890, valleyrat_s2, 8395ea90eca49b3f66c2a339ab377348, 974b6b4ed30ddaa4b6f4ec27976e52d8, IRAHook, 40999, 45090, gated, poshc2, BianLian, PG, hook, Deimos, Magecart, userr, 4-72, card-theft, COLOMBIA, otp-relay, phishing-kit, telegram-exfil, tg.pe, BlakcSeeStealer, 726a8431d5d2ee941d0e6046b5948889, 17August2026, Loki, DinDoor, 16August2026, NetSupportManager RAT, Nancrat, NanoCore RAT, Remvio, Socmer, Bladabindi, Lime-Worm, Venom RAT, Farfli, Gh0st RAT, Ghost RAT, PCRat, Polygon, 6c0969259a3975582cd8a48f4c8913d7, UnamPanel, v1, 8075, 329556, 214961, kimwolf, 5fdb6df778631818165110294c620890, a6416186c7730e38c492792c820881c3, majinahanashi, Ransomware, whack.sh, 013c5d2d6312702c9bd8d7499170ed6b, aa462c8dcc4d1e29e6e35cbe1cd9ac85, build3, newbuild, 0f81469cc7638ba7c82eaddbd6b3c20a, cs-watermark-666666666, Cloudflare Inc., 15August2026, mac-0xfb64, mac-0xe447, be6f50208246a51977f7066c1ea613a0, e9bf104a963da535b0fb5aaebe6f06e1, 51c45d4bde39c5d7874e05e8c68314ca, 14August2026, cc382e7a75ab8441eee2f40142be37ed, AnimateClipper, LegionLoader, SheetRAT, MintsLoader, build1, L1, WilsonC2, panel, PhantomStrikeC2, EvilgnixC2, Tr4nsHack, ZygiskC2, AuraStealer, domain, DPRK, kimsuky, MoonPeak, Stella, golang, zimbra, zimbra-exfil, ZMBX, workes.dev, 14618, a77f04bc08864469eb801630c24264ba, AsynRAT, malware, d8b0m, ransomware, apt, botnet, infostealer | 2026-08-21 |
| critical | Critical Elementor Pro bug exposes WordPress sites to RCE attacks | news | general-news | rce | 2026-08-20 |
| critical | ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More | news | general-news | rce | 2026-08-20 |
| high | CVE-2026-76633 — WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that a… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-76635 — baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows au… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-76833 — @cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-76990 — A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-16925 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege esca… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-16927 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges d… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-49825 — lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attribute… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-61897 — An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-61898 — The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accounts… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-63490 — Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.g… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-76996 — A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impact… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-19611 — A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-75140 — jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnera… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-76998 — A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0.… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-77004 — A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-54449 — LangBot is a global IM bot platform designed for LLMs. In version 4.10.7 and earlier, any authentica… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-54616 — NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 un… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-61704 — Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in ind… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-65842 — Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-69183 — Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-77019 — A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-77020 — A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by thi… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-77176 — A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containe… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-54623 — django CMS is an easy-to-use and developer-friendly enterprise content management system powered by… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-63387 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-o… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-63388 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-63495 — Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebS… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-76641 — Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger me… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-77031 — A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreat… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-53583 — libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-66787 — A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes.… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-72852 — hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configur… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-18420 — Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards a… | vulnerability | nvd | rce | 2026-08-20 |
| high | CVE-2026-53804 — OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encry… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-73040 — Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in va… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-73137 — A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Mana… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-77584 — Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has a… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-77638 — Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-17003 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confid… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-17171 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary fi… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-19442 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtua… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-19446 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a cr… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-19449 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unpriv… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-46355 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebu… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-46682 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authentica… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-49217 — Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorizati… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-49436 — LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-55013 — Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to per… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-55765 — CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments.… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-66800 — Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-69419 — Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to exe… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-69519 — Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose infor… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-69543 — Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevat… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-69558 — Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-69855 — Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to di… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-72818 — The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and app… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-72848 — SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documente… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-72860 — The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues se… | vulnerability | nvd |  | 2026-08-20 |
| high | CVE-2026-77642 — tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signatur… | vulnerability | nvd |  | 2026-08-20 |
| high | CISA, NSA, FBI warn of Siemens S7 PLC exploitation using AI-generated scripts to disrupt critical industrial processes | advisory | vendor-blogs | ics | 2026-08-20 |
| high | b93f2842c5ede1d48659eebbba629082787a8ccd17edd2571f5ada14c1252341.elf | malware | malware-bazaar | elf, exe, whack.sh | 2026-08-21 |
| high | 611fa15a339dabc3efdfdde36db072b7cddb2b70f37dd092abf0496f3fad74c7.exe | malware | malware-bazaar | ConnectWise, exe, whack.sh | 2026-08-21 |
| high | wr.php | malware | malware-bazaar | sh | 2026-08-21 |
| high | ok | malware | malware-bazaar | sh | 2026-08-21 |
| high | flutter.mipsel | malware | malware-bazaar | elf, Mirai, upx-dec, upx, botnet | 2026-08-21 |
| high | 377339da9394e4590baa1a2aa8e433cf676718bb83a50a37fb9399eb6c8f62c7.exe | malware | malware-bazaar | exe, signed, whack.sh | 2026-08-21 |
| high | f4b330adc3e1cb5d4ba6f1c506d0e4d6821b83d9b033f6e0f21cfdb94c35d2c2.bin | malware | malware-bazaar | exe, signed, Vidar, botnet, infostealer | 2026-08-21 |
| high | wr.php | malware | malware-bazaar | sh | 2026-08-21 |
| high | k.php | malware | malware-bazaar | sh | 2026-08-21 |
| high | Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia | threat-intel | otx | spear phishing, chrome remote desktop, powershell, gmail exfiltration, onedrive, northeast asia, keylogger, lnk malware, anydesk, chrome extension, apt, phishing, botnet, infostealer | 2026-08-20 |
| high | Distinct Clusters Target Individuals of Interest to Russia | threat-intel | otx | russian cyber espionage, oauth phishing, vidar, device code phishing, headrush, app password phishing, unc6293, atomic, cherrypie, unc7005, enginelight, hospitality captive portal, unc5976, whatsapp device linking, authentication abuse, phishing, infostealer | 2026-08-20 |
| high | Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads | news | general-news | supply-chain | 2026-08-20 |
| high | JFrog Artifactory Flaws Enable Software Supply Chain Attacks | news | general-news | supply-chain | 2026-08-20 |
| medium | CVE-2026-76634 — WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profil… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-44725 — EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to vers… | vulnerability | nvd | transport | 2026-08-20 |
| medium | CVE-2026-55558 — aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_t… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-76991 — A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown pa… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-76993 — A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-76995 — A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-63015 — Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons c… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-63016 — Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational con… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-76997 — A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affecte… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-76999 — A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analy… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-54770 — WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_abs… | vulnerability | nvd | phishing | 2026-08-20 |
| medium | CVE-2026-55586 — SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, a crafted CHM file can supply… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-61625 — VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-77025 — A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unkno… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-54625 — django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the djan… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-72844 — The Lean 4 kernel does not verify that the structure named in a projection expression matches the ty… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-72847 — broot renders each file and directory name in its interactive tree view exactly as read from the fil… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-73254 — Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-73255 — Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control a… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-73258 — Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-73259 — Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-77036 — A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailCon… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-43678 — An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingb… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-64777 — A malicious builder peer may be able to request an in-context file by name from the host and receive… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-72854 — msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-75514 — BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklis… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-72861 — The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inv… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-75910 — Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Fede… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-67445 — Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP command… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-67446 — Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-s… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-68921 — DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpola… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-76018 — Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker lev… | vulnerability | nvd | phishing | 2026-08-20 |
| medium | CVE-2026-76019 — Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacke… | vulnerability | nvd | phishing | 2026-08-20 |
| medium | CVE-2026-77506 — Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS. | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-77587 — Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object whe… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-77639 — Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many g… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-77641 — tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. Th… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-16951 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-16964 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages an… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-16973 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to disclose sensitive ker… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-17424 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restr… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-19448 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-19783 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory co… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-49244 — SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public we… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-54389 — Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser t… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-54509 — TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-55015 — Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny servic… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-55489 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could s… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-55491 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape m… | vulnerability | nvd | ransomware | 2026-08-20 |
| medium | CVE-2026-62945 — TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions a… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-67447 — Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's interna… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-67448 — Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-70105 — Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose infor… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-72846 — Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendW… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-77643 — A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core… | vulnerability | nvd |  | 2026-08-20 |
| medium | CVE-2026-77391 — A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS,… | vulnerability | nvd |  | 2026-08-21 |
| medium | CVE-2026-77392 — A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and… | vulnerability | nvd |  | 2026-08-21 |
| medium | BRIDGEHEAD: An npm typosquatting campaign that crosses from WSL into Windows to plant a crypto-wallet stealer | threat-intel | otx | rust, github-hosted-payload, browser-credentials, wsl, telegram, npm, cryptocurrency-stealer, typosquatting, in-memory-execution, supply-chain, botnet | 2026-08-20 |
| medium | How Peer2Profit and Astroproxy Turn Your Bandwidth Into Someone Else's Product | threat-intel | otx | backconnect infrastructure, bandwidth-sharing, internal network exposure, privateloader, sdk analysis, proxy enumeration, peer2profit, residential proxies, astroproxy | 2026-08-20 |
| medium | N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it | threat-intel | otx | n4d mesh controller, cve-2023-48022, cve-2026-26220, linux malware, go-titan, cve-2026-27944, ray dashboard, cve-2026-33032, n4d, cve-2026-39987, mcp exploitation, lateral movement, ai infrastructure targeting, cloudflare tunnels, credential theft, lightllm, botnet | 2026-08-20 |
| medium | Hackers poison arrayref Rust crate to push infostealer malware | news | general-news | infostealer | 2026-08-20 |
| low | CVE-2026-64846 — Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation e… | vulnerability | nvd |  | 2026-08-20 |
| low | CVE-2026-49996 — SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle s… | vulnerability | nvd |  | 2026-08-20 |
| low | CVE-2026-77151 — A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the func… | vulnerability | nvd |  | 2026-08-20 |
| low | CVE-2026-77640 — tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream wit… | vulnerability | nvd |  | 2026-08-20 |
| low | CVE-2026-49245 — SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline qu… | vulnerability | nvd | phishing | 2026-08-20 |
| low | CVE-2026-77648 — In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_f… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-64961 — ATutor is vulnerable to authentication bypass . Although a token validation check is present in the… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-64962 — ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attack… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-64963 — A path traversal vulnerability in ATutor allows an authenticated user to access files from other cou… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-64964 — ATutor generates predictable email confirmation tokens due to the use of insufficiently random value… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-64965 — ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints. A low-pri… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-64967 — A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative p… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-64968 — ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated admi… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-64969 — ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related en… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-64970 — ATutor is vulnerable to Stored Cross Site Scripting in registration functionality. An attacker can r… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-64971 — ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-64972 — ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-70383 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Esto… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-73220 — CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-63040 — Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource per… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-63042 — Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-63043 — Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host file… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-63044 — Server-Side Request Forgery (SSRF) vulnerability in Apache InLong. Any authenticated user (no admin… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-13121 — Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulne… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-18267 — Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability. This vulnerability al… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-18268 — Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability. This vuln… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-18269 — Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution Vulnerability. This vulne… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-18270 — Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability. T… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-18271 — Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerab… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-18272 — Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability. This vulnerability allows phys… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-18273 — Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability. This v… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-18278 — Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability. This v… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-18280 — Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allo… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-18283 — Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physica… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-18284 — Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerability. This… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-40345 — deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects.… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-54136 — Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows an… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-55095 — OpenProject is open-source, web-based project management software. In version 17.5.1 and earlier, an… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-63481 — Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In versio… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-71492 — Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, Dir… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-53425 — Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-63379 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunk… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-63380 — Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid li… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-63381 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-63382 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp pars… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-63383 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-63384 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrec… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-63385 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP pa… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-73251 — Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impers… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-73253 — Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network at… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-15743 — Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-19586 — A pre-authentication OS command injection vulnerability has been identified in Omada gateways config… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-19683 — A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During com… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-50190 — Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-53569 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted to… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-62315 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-63654 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted fr… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-66001 — Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and aut… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-66002 — Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-9033 — An unauthenticated attacker with network access to the captive portal service of an affected device… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-19755 — NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing a… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-43798 — A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-52021 — An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remote attacker to obtain sensitiv… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-70651 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips b… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-70653 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-s… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-70654 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applicati… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-74836 — Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unaut… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-75484 — Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-76017 — Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to e… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-76020 — Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute a… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-76021 — Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-76022 — Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to exe… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-76023 — Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2025-52182 — The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-50192 — Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-54505 — TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK int… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-54508 — TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before n… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-55893 — Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-64773 — An attacker that can reach a container's published TCP port may be able to force the host's forwardi… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-77644 — A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliabili… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-77646 — A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PT… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-77113 — Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allow… | vulnerability | nvd |  | 2026-08-20 |
| unknown | CVE-2026-16520 — Improper input validation and Exposure of sensitive information through data queries vulnerability i… | vulnerability | nvd |  | 2026-08-21 |
| unknown | CVE-2026-20679 — The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Son… | vulnerability | nvd |  | 2026-08-21 |
| unknown | CVE-2026-43679 — This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An… | vulnerability | nvd |  | 2026-08-21 |
| unknown | CVE-2026-76155 — Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a rem… | vulnerability | nvd |  | 2026-08-21 |
| unknown | CVE-2026-76156 — OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.… | vulnerability | nvd |  | 2026-08-21 |
| unknown | CVE-2026-76157 — Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management… | vulnerability | nvd |  | 2026-08-21 |
| unknown | Is Cyber missing the Marque? | advisory | vendor-blogs |  | 2026-08-20 |
| unknown | AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure | news | general-news |  | 2026-08-20 |
| unknown | New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data | news | general-news |  | 2026-08-20 |
| unknown | New CUSTODY Framework Constrains AI Agents Inside the Network | news | general-news |  | 2026-08-20 |
| unknown | N-able Bug Exposes Password Vault Master Keys | news | general-news |  | 2026-08-20 |
| unknown | Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks | news | general-news |  | 2026-08-20 |
| unknown | Hackers Target Zimbra Servers in Active Exploitation Campaign | news | general-news |  | 2026-08-20 |
| unknown | China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware | news | general-news |  | 2026-08-20 |