← Dashboard

OSINT Threat Intelligence Report

2026-08-21 — Generated 2026-08-21 03:01:29 UTC — 3339 items

Daily Weekly Monthly Full JSON | Markdown

Total Items

349

By Source

cisa-kev8
nvd3068
cisa-advisories7
vendor-blogs87
malware-bazaar9
abuse-ipdb20
threatfox2
otx33
general-news112

By Category

vulnerability3073
advisory91
malware9
ip-reputation20
threat-intel35
news111

Fetch Errors

None

Top 10 Highlights

SeverityTitleSourceCVEsTags
critical CVE-2026-15706 — Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry… nvd CVE-2026-15706
critical CVE-2026-64960 — ATutor Gameme module allows users to upload files of any type and extension without restriction. Due… nvd CVE-2026-64960 rce
critical CVE-2026-64966 — ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker… nvd CVE-2026-64966 rce
critical CVE-2026-16926 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary f… nvd CVE-2026-16926
critical CVE-2026-15679 — Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution… nvd CVE-2026-15679 rce
critical CVE-2026-15686 — Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. Th… nvd CVE-2026-15686 rce
critical CVE-2026-18264 — NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows r… nvd CVE-2026-18264 rce
critical CVE-2026-18265 — OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability al… nvd CVE-2026-18265 rce
critical CVE-2026-18274 — Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This… nvd CVE-2026-18274 rce
critical CVE-2026-18279 — Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability. This vulnerability a… nvd CVE-2026-18279 rce

All Items

Showing 349 items

Severity Title Category Source Indicators Tags Published
critical CVE-2026-15706 — Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry… vulnerability nvd CVE-2026-15706 2026-08-20
critical CVE-2026-64960 — ATutor Gameme module allows users to upload files of any type and extension without restriction. Due… vulnerability nvd CVE-2026-64960 rce 2026-08-20
critical CVE-2026-64966 — ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker… vulnerability nvd CVE-2026-64966 rce 2026-08-20
critical CVE-2026-16926 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary f… vulnerability nvd CVE-2026-16926 2026-08-20
critical CVE-2026-15679 — Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution… vulnerability nvd CVE-2026-15679 rce 2026-08-20
critical CVE-2026-15686 — Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. Th… vulnerability nvd CVE-2026-15686 rce 2026-08-20
critical CVE-2026-18264 — NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows r… vulnerability nvd CVE-2026-18264 rce 2026-08-20
critical CVE-2026-18265 — OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability al… vulnerability nvd CVE-2026-18265 rce 2026-08-20
critical CVE-2026-18274 — Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This… vulnerability nvd CVE-2026-18274 rce 2026-08-20
critical CVE-2026-18279 — Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability. This vulnerability a… vulnerability nvd CVE-2026-18279 rce 2026-08-20
critical CVE-2026-18281 — Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability. Th… vulnerability nvd CVE-2026-18281 rce 2026-08-20
critical CVE-2026-18282 — Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerabil… vulnerability nvd CVE-2026-18282 rce 2026-08-20
critical CVE-2026-18285 — Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability.… vulnerability nvd CVE-2026-18285 rce 2026-08-20
critical CVE-2026-18286 — Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability. T… vulnerability nvd CVE-2026-18286 rce 2026-08-20
critical CVE-2026-18287 — Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerability. Thi… vulnerability nvd CVE-2026-18287 rce 2026-08-20
critical CVE-2026-18288 — OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This… vulnerability nvd CVE-2026-18288 rce 2026-08-20
critical CVE-2026-18289 — OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This v… vulnerability nvd CVE-2026-18289 rce 2026-08-20
critical CVE-2026-18290 — OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This v… vulnerability nvd CVE-2026-18290 rce 2026-08-20
critical CVE-2026-18291 — OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vul… vulnerability nvd CVE-2026-18291 rce 2026-08-20
critical CVE-2026-18292 — OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vul… vulnerability nvd CVE-2026-18292 rce 2026-08-20
critical CVE-2026-18293 — OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. Th… vulnerability nvd CVE-2026-18293 rce 2026-08-20
critical CVE-2026-18294 — OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This… vulnerability nvd CVE-2026-18294 rce 2026-08-20
critical CVE-2026-18295 — GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerabili… vulnerability nvd CVE-2026-18295 rce 2026-08-20
critical CVE-2026-18296 — GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vuln… vulnerability nvd CVE-2026-18296 rce 2026-08-20
critical CVE-2026-18297 — GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vul… vulnerability nvd CVE-2026-18297 rce 2026-08-20
critical CVE-2026-18298 — GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vuln… vulnerability nvd CVE-2026-18298 rce 2026-08-20
critical CVE-2026-18299 — GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows… vulnerability nvd CVE-2026-18299 rce 2026-08-20
critical CVE-2026-18300 — GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow… vulnerability nvd CVE-2026-18300 rce 2026-08-20
critical CVE-2026-18301 — GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow… vulnerability nvd CVE-2026-18301 rce 2026-08-20
critical CVE-2026-18302 — GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabi… vulnerability nvd CVE-2026-18302, CVE-2026-18307 rce 2026-08-20
critical CVE-2026-18303 — GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerab… vulnerability nvd CVE-2026-18303 rce 2026-08-20
critical CVE-2026-18304 — GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow… vulnerability nvd CVE-2026-18304, CVE-2026-18305, CVE-2026-18308 rce 2026-08-20
critical CVE-2026-18306 — GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow… vulnerability nvd CVE-2026-18306 rce 2026-08-20
critical CVE-2026-18309 — GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allo… vulnerability nvd CVE-2026-18309 rce 2026-08-20
critical CVE-2026-55642 — dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in c… vulnerability nvd CVE-2026-55642 2026-08-20
critical CVE-2026-71428 — The unstructured library provides open-source components for ingesting and pre-processing images and… vulnerability nvd CVE-2026-71428 2026-08-20
critical CVE-2026-77022 — A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the functi… vulnerability nvd CVE-2026-77022 2026-08-20
critical CVE-2026-2334 — An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges… vulnerability nvd CVE-2026-2334 rce 2026-08-20
critical CVE-2026-53424 — Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authent… vulnerability nvd CVE-2026-53424 ransomware 2026-08-20
critical CVE-2026-73256 — Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated atta… vulnerability nvd CVE-2026-73256 2026-08-20
critical CVE-2026-73257 — Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthentica… vulnerability nvd CVE-2026-73257 2026-08-20
critical CVE-2026-66785 — A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect ne… vulnerability nvd CVE-2026-66785 2026-08-20
critical CVE-2026-66788 — A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vu… vulnerability nvd CVE-2026-66788 2026-08-20
critical CVE-2026-77148 — A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the fi… vulnerability nvd CVE-2026-77148 2026-08-20
critical CVE-2026-67567 — A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a ten… vulnerability nvd CVE-2026-67567 2026-08-20
critical CVE-2026-69242 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted… vulnerability nvd CVE-2026-69242 rce 2026-08-20
critical CVE-2026-71485 — Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies… vulnerability nvd CVE-2026-71485 2026-08-20
critical CVE-2026-62834 — Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attack… vulnerability nvd CVE-2026-62834 2026-08-20
critical CVE-2026-63509 — Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over… vulnerability nvd CVE-2026-63509 2026-08-20
critical CVE-2026-65770 — Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed… vulnerability nvd CVE-2026-65770 2026-08-20
critical CVE-2026-65801 — Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to e… vulnerability nvd CVE-2026-65801 2026-08-20
critical CVE-2026-65816 — Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevat… vulnerability nvd CVE-2026-65816 2026-08-20
critical CVE-2026-66309 — Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges ov… vulnerability nvd CVE-2026-66309 2026-08-20
critical CVE-2026-68782 — Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Da… vulnerability nvd CVE-2026-68782, CVE-2026-68789 2026-08-20
critical CVE-2026-69400 — Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps a… vulnerability nvd CVE-2026-69400 2026-08-20
critical CVE-2026-69555 — Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a ne… vulnerability nvd CVE-2026-69555 2026-08-20
critical CVE-2026-69836 — Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute c… vulnerability nvd CVE-2026-69836 2026-08-20
critical CVE-2026-69851 — Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevat… vulnerability nvd CVE-2026-69851 2026-08-20
critical CVE-2026-72843 — The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/m… vulnerability nvd CVE-2026-72843 2026-08-20
critical CVE-2026-77645 — A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC Flex… vulnerability nvd CVE-2026-77645 rce 2026-08-20
critical CVE-2026-77647 — SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited i… vulnerability nvd CVE-2026-77647 2026-08-20
critical CVE-2026-77649 — The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project… vulnerability nvd CVE-2026-77649 botnet 2026-08-21
critical CVE-2026-77650 — The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a pr… vulnerability nvd CVE-2026-77650 botnet 2026-08-21
critical CVE-2026-77651 — The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project… vulnerability nvd CVE-2026-77651 botnet 2026-08-21
critical CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-20
critical CVE-2026-61363 Remote Desktop Client Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-20
critical CVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-20
critical CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-20
critical CVE-2026-69419 Azure Data Manager for Energy Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-20
critical CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-20
critical CVE-2026-54118 Microsoft SQL Server Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-20
critical Malicious IP: 213.209.159.241 ip-reputation abuse-ipdb 213.209.159.241 2026-08-21
critical Malicious IP: 64.62.197.138 ip-reputation abuse-ipdb 64.62.197.138 2026-08-21
critical Malicious IP: 119.92.70.82 ip-reputation abuse-ipdb 119.92.70.82 2026-08-21
critical Malicious IP: 195.26.18.111 ip-reputation abuse-ipdb 195.26.18.111 2026-08-21
critical Malicious IP: 181.115.171.216 ip-reputation abuse-ipdb 181.115.171.216 2026-08-21
critical Malicious IP: 118.196.68.35 ip-reputation abuse-ipdb 118.196.68.35 2026-08-21
critical Malicious IP: 79.124.59.178 ip-reputation abuse-ipdb 79.124.59.178 2026-08-21
critical Malicious IP: 79.124.56.142 ip-reputation abuse-ipdb 79.124.56.142 2026-08-21
critical Malicious IP: 68.225.61.18 ip-reputation abuse-ipdb 68.225.61.18 2026-08-21
critical Malicious IP: 193.47.62.69 ip-reputation abuse-ipdb 193.47.62.69 2026-08-21
critical Malicious IP: 163.7.9.55 ip-reputation abuse-ipdb 163.7.9.55 2026-08-21
critical Malicious IP: 68.221.130.146 ip-reputation abuse-ipdb 68.221.130.146 2026-08-21
critical Malicious IP: 61.184.128.210 ip-reputation abuse-ipdb 61.184.128.210 2026-08-21
critical Malicious IP: 70.183.230.195 ip-reputation abuse-ipdb 70.183.230.195 2026-08-21
critical Malicious IP: 47.254.134.254 ip-reputation abuse-ipdb 47.254.134.254 2026-08-21
critical Malicious IP: 4.206.92.183 ip-reputation abuse-ipdb 4.206.92.183 2026-08-21
critical Malicious IP: 45.148.10.240 ip-reputation abuse-ipdb 45.148.10.240 2026-08-21
critical Malicious IP: 194.88.98.114 ip-reputation abuse-ipdb 194.88.98.114 2026-08-21
critical Malicious IP: 181.116.43.25 ip-reputation abuse-ipdb 181.116.43.25 2026-08-21
critical Malicious IP: 45.249.246.17 ip-reputation abuse-ipdb 45.249.246.17 2026-08-21
critical payload_delivery: undefined threat-intel threatfox ClearFake, mac-0xdcf2, macOS, Cloudflare, gif, PHP, webshell, WordPress, workers.dev, wp-admin, 21August2026, Commandline, mac-0x68dc, CobaltStrike, Vshell, 8560, asyncrat, c2, censys, compromised, etherhide, ClickFix, etherhiding, AISURU, elf, IoT, Mozi, Remus, mac-0x76c7, drb-ra, mac-0x0f14, 20August2026, ErrTraffic, Viper, Havoc, dcrat, PureHVNC, PureRAT, RAT, HypeAgent, Mythic, Supershell, 1xxbot, ArechClient, SectopRAT, CinaRAT, Quasar RAT, QuasarRAT, Yggdrasil, sliver, ResolverRAT, ConnectWise, ScreenConnect, 903ac24fcd9670b9ef2e674243d550d8, Loader, stealer, Vidar, RemusStealer, fake-plugin, nochain, SmartApeSG, win-0xa770, Windows, ValleyRAT, Kongtuke, AgentTesla, XWorm, Dropper, SocGholish, Pink, Adaptix, RevStealer, DomainShadowing, NEWTEST, Stealc, test_2, STRRAT, DanBot, CONTABO, CTFLoaderService, FakeAdobe, iso, LNK, pre-ransomware, velociraptor, cs-watermark-987654321, RemcosRAT, remcos, OffLoader, Socks5Systemz, Mirai, Vjw0rm, RedGuard, shodan, orcus, NetSupport, StarKillerC2, UNAM, AdaptixC2, PowerSploit, locust, GoPhish, phishing, cs-watermark-100000, Amos, nakedpages, Lud, 36903, MetaSploit, fake-copilot, RedLineStealer, 19August2026, njrat, Covenant, NeedleStealer, sliverfox, Gafgyt, rmm, 117ee8f56cb68a9f6a440e1b4329f856, SparkRAT, ExtRat, XTRAT, Xtreme RAT, Agentemis, Beacon, Cobalt Strike, cobeacon, clipboard, ACRStealer, Mac, Breut, darkcomet, Fynloski, klovbot, Lumma, NanoCore, SnappyClient, Diamotrix, URLscan, EvilGinx, EvilGoPhish, CHAOS, x4tte, PureLogsStealer, LxBaseRAT, ProRat, Panda, EpsteinClient, NetSupportManager, NetSupportRAT, 592a9e009f92c0e8eaea74a337b4f67c, capture-drop, honeypot, ssh-dropper, HTA, mexico, WhatsApp, sepolia, tofsee, web-inject, Spynote, HookBot, Byakugan, nc, gs-netcat, gsocket, moobot, nimplant, quasar, sectop, shadowpad, cs-watermark-1234567890, valleyrat_s2, 8395ea90eca49b3f66c2a339ab377348, 974b6b4ed30ddaa4b6f4ec27976e52d8, IRAHook, 40999, 45090, gated, poshc2, BianLian, PG, hook, Deimos, Magecart, userr, 4-72, card-theft, COLOMBIA, otp-relay, phishing-kit, telegram-exfil, tg.pe, BlakcSeeStealer, 726a8431d5d2ee941d0e6046b5948889, 17August2026, Loki, DinDoor, 16August2026, NetSupportManager RAT, Nancrat, NanoCore RAT, Remvio, Socmer, Bladabindi, Lime-Worm, Venom RAT, Farfli, Gh0st RAT, Ghost RAT, PCRat, Polygon, 6c0969259a3975582cd8a48f4c8913d7, UnamPanel, v1, 8075, 329556, 214961, kimwolf, 5fdb6df778631818165110294c620890, a6416186c7730e38c492792c820881c3, majinahanashi, Ransomware, whack.sh, 013c5d2d6312702c9bd8d7499170ed6b, aa462c8dcc4d1e29e6e35cbe1cd9ac85, build3, newbuild, 0f81469cc7638ba7c82eaddbd6b3c20a, cs-watermark-666666666, Cloudflare Inc., 15August2026, mac-0xfb64, mac-0xe447, be6f50208246a51977f7066c1ea613a0, e9bf104a963da535b0fb5aaebe6f06e1, 51c45d4bde39c5d7874e05e8c68314ca, 14August2026, cc382e7a75ab8441eee2f40142be37ed, AnimateClipper, LegionLoader, SheetRAT, MintsLoader, build1, L1, WilsonC2, panel, PhantomStrikeC2, EvilgnixC2, Tr4nsHack, ZygiskC2, AuraStealer, domain, DPRK, kimsuky, MoonPeak, Stella, golang, zimbra, zimbra-exfil, ZMBX, workes.dev, 14618, a77f04bc08864469eb801630c24264ba, AsynRAT, malware, d8b0m, ransomware, apt, botnet, infostealer 2026-08-21
critical Critical Elementor Pro bug exposes WordPress sites to RCE attacks news general-news rce 2026-08-20
critical ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More news general-news rce 2026-08-20
critical Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE news general-news rce 2026-08-20
high CVE-2026-76633 — WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that a… vulnerability nvd CVE-2026-76633 2026-08-20
high CVE-2026-76635 — baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows au… vulnerability nvd CVE-2026-76635 2026-08-20
high CVE-2026-76833 — @cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to… vulnerability nvd CVE-2026-76833 2026-08-20
high CVE-2026-76990 — A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue… vulnerability nvd CVE-2026-76990 2026-08-20
high CVE-2026-16925 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege esca… vulnerability nvd CVE-2026-16925 2026-08-20
high CVE-2026-16927 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges d… vulnerability nvd CVE-2026-16927 2026-08-20
high CVE-2026-49825 — lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attribute… vulnerability nvd CVE-2026-49825 2026-08-20
high CVE-2026-61897 — An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges… vulnerability nvd CVE-2026-61897 2026-08-20
high CVE-2026-61898 — The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accounts… vulnerability nvd CVE-2026-61898 2026-08-20
high CVE-2026-63490 — Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.g… vulnerability nvd CVE-2026-63490 2026-08-20
high CVE-2026-76996 — A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impact… vulnerability nvd CVE-2026-76996 2026-08-20
high CVE-2026-19611 — A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode… vulnerability nvd CVE-2026-19611 2026-08-20
high CVE-2026-75140 — jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnera… vulnerability nvd CVE-2026-75140 2026-08-20
high CVE-2026-76998 — A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0.… vulnerability nvd CVE-2026-76998 2026-08-20
high CVE-2026-77004 — A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi… vulnerability nvd CVE-2026-77004 2026-08-20
high CVE-2026-54449 — LangBot is a global IM bot platform designed for LLMs. In version 4.10.7 and earlier, any authentica… vulnerability nvd CVE-2026-54449 2026-08-20
high CVE-2026-54616 — NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 un… vulnerability nvd CVE-2026-54616 2026-08-20
high CVE-2026-61704 — Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in ind… vulnerability nvd CVE-2026-61704 2026-08-20
high CVE-2026-65842 — Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote… vulnerability nvd CVE-2026-65842 2026-08-20
high CVE-2026-69183 — Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-… vulnerability nvd CVE-2026-69183 2026-08-20
high CVE-2026-77019 — A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an… vulnerability nvd CVE-2026-77019 2026-08-20
high CVE-2026-77020 — A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by thi… vulnerability nvd CVE-2026-77020 2026-08-20
high CVE-2026-77176 — A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containe… vulnerability nvd CVE-2026-77176 2026-08-20
high CVE-2026-54623 — django CMS is an easy-to-use and developer-friendly enterprise content management system powered by… vulnerability nvd CVE-2026-54623, CVE-2026-54622, CVE-2026-54624, CVE-2026-61663, CVE-2026-63003, CVE-2026-75526 2026-08-20
high CVE-2026-63387 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-o… vulnerability nvd CVE-2026-63387 2026-08-20
high CVE-2026-63388 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-… vulnerability nvd CVE-2026-63388 2026-08-20
high CVE-2026-63495 — Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebS… vulnerability nvd CVE-2026-63495 2026-08-20
high CVE-2026-76641 — Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger me… vulnerability nvd CVE-2026-76641 2026-08-20
high CVE-2026-77031 — A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreat… vulnerability nvd CVE-2026-77031 2026-08-20
high CVE-2026-53583 — libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a… vulnerability nvd CVE-2026-53583, CVE-2026-53584, CVE-2026-53585, CVE-2026-53586, CVE-2026-53587 2026-08-20
high CVE-2026-66787 — A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes.… vulnerability nvd CVE-2026-66787 2026-08-20
high CVE-2026-72852 — hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configur… vulnerability nvd CVE-2026-72852 2026-08-20
high CVE-2026-18420 — Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards a… vulnerability nvd CVE-2026-18420 rce 2026-08-20
high CVE-2026-53804 — OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encry… vulnerability nvd CVE-2026-53804 2026-08-20
high CVE-2026-73040 — Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in va… vulnerability nvd CVE-2026-73040 2026-08-20
high CVE-2026-73137 — A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Mana… vulnerability nvd CVE-2026-73137 2026-08-20
high CVE-2026-77584 — Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has a… vulnerability nvd CVE-2026-77584 2026-08-20
high CVE-2026-77638 — Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous… vulnerability nvd CVE-2026-77638 2026-08-20
high CVE-2026-17003 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confid… vulnerability nvd CVE-2026-17003 2026-08-20
high CVE-2026-17171 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary fi… vulnerability nvd CVE-2026-17171 2026-08-20
high CVE-2026-19442 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtua… vulnerability nvd CVE-2026-19442 2026-08-20
high CVE-2026-19446 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a cr… vulnerability nvd CVE-2026-19446 2026-08-20
high CVE-2026-19449 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unpriv… vulnerability nvd CVE-2026-19449 2026-08-20
high CVE-2026-46355 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebu… vulnerability nvd CVE-2026-46355 2026-08-20
high CVE-2026-46682 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authentica… vulnerability nvd CVE-2026-46682 2026-08-20
high CVE-2026-49217 — Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorizati… vulnerability nvd CVE-2026-49217 2026-08-20
high CVE-2026-49436 — LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API… vulnerability nvd CVE-2026-49436 2026-08-20
high CVE-2026-55013 — Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to per… vulnerability nvd CVE-2026-55013 2026-08-20
high CVE-2026-55765 — CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments.… vulnerability nvd CVE-2026-55765, CVE-2026-55769 2026-08-20
high CVE-2026-66800 — Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose… vulnerability nvd CVE-2026-66800 2026-08-20
high CVE-2026-69419 — Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to exe… vulnerability nvd CVE-2026-69419 2026-08-20
high CVE-2026-69519 — Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose infor… vulnerability nvd CVE-2026-69519 2026-08-20
high CVE-2026-69543 — Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevat… vulnerability nvd CVE-2026-69543 2026-08-20
high CVE-2026-69558 — Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized… vulnerability nvd CVE-2026-69558 2026-08-20
high CVE-2026-69855 — Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to di… vulnerability nvd CVE-2026-69855 2026-08-20
high CVE-2026-72818 — The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and app… vulnerability nvd CVE-2026-72818 2026-08-20
high CVE-2026-72848 — SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documente… vulnerability nvd CVE-2026-72848 2026-08-20
high CVE-2026-72860 — The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues se… vulnerability nvd CVE-2026-72860 2026-08-20
high CVE-2026-77642 — tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signatur… vulnerability nvd CVE-2026-77642 2026-08-20
high CISA, NSA, FBI warn of Siemens S7 PLC exploitation using AI-generated scripts to disrupt critical industrial processes advisory vendor-blogs ics 2026-08-20
high b93f2842c5ede1d48659eebbba629082787a8ccd17edd2571f5ada14c1252341.elf malware malware-bazaar b93f2842c5ede1d4…, 1c4345de3e48f3e3… elf, exe, whack.sh 2026-08-21
high 611fa15a339dabc3efdfdde36db072b7cddb2b70f37dd092abf0496f3fad74c7.exe malware malware-bazaar 611fa15a339dabc3…, 2a4721f8805f3e2b… ConnectWise, exe, whack.sh 2026-08-21
high wr.php malware malware-bazaar 3fb78a20a4cd6939…, 9d90aadfd3b64533… sh 2026-08-21
high ok malware malware-bazaar b59075c2da6a7f8e…, d48beea3c242577e… sh 2026-08-21
high flutter.mipsel malware malware-bazaar 12dd079eab15afe1…, c9e08297a9f9d908… elf, Mirai, upx-dec, upx, botnet 2026-08-21
high 377339da9394e4590baa1a2aa8e433cf676718bb83a50a37fb9399eb6c8f62c7.exe malware malware-bazaar 377339da9394e459…, eb3815f639e96df5… exe, signed, whack.sh 2026-08-21
high f4b330adc3e1cb5d4ba6f1c506d0e4d6821b83d9b033f6e0f21cfdb94c35d2c2.bin malware malware-bazaar f4b330adc3e1cb5d…, 61118b7b4e83504d… exe, signed, Vidar, botnet, infostealer 2026-08-21
high wr.php malware malware-bazaar a38e5b31a0472067…, fdf04b0361e5fcb9… sh 2026-08-21
high k.php malware malware-bazaar d59aa853fe50e2c4…, 1c44f812710050f6… sh 2026-08-21
high Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia threat-intel otx b9ad79eaf7a4133f…, f6f7a94c11ea0ee0… spear phishing, chrome remote desktop, powershell, gmail exfiltration, onedrive, northeast asia, keylogger, lnk malware, anydesk, chrome extension, apt, phishing, botnet, infostealer 2026-08-20
high Distinct Clusters Target Individuals of Interest to Russia threat-intel otx ca3be5885afb3eb3…, 5484009071ea96c7… russian cyber espionage, oauth phishing, vidar, device code phishing, headrush, app password phishing, unc6293, atomic, cherrypie, unc7005, enginelight, hospitality captive portal, unc5976, whatsapp device linking, authentication abuse, phishing, infostealer 2026-08-20
high Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads news general-news supply-chain 2026-08-20
high JFrog Artifactory Flaws Enable Software Supply Chain Attacks news general-news supply-chain 2026-08-20
medium CVE-2026-76634 — WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profil… vulnerability nvd CVE-2026-76634 2026-08-20
medium CVE-2026-44725 — EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to vers… vulnerability nvd CVE-2026-44725 transport 2026-08-20
medium CVE-2026-55558 — aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_t… vulnerability nvd CVE-2026-55558 2026-08-20
medium CVE-2026-76991 — A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown pa… vulnerability nvd CVE-2026-76991 2026-08-20
medium CVE-2026-76993 — A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown… vulnerability nvd CVE-2026-76993 2026-08-20
medium CVE-2026-76995 — A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue… vulnerability nvd CVE-2026-76995 2026-08-20
medium CVE-2026-63015 — Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons c… vulnerability nvd CVE-2026-63015 2026-08-20
medium CVE-2026-63016 — Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational con… vulnerability nvd CVE-2026-63016 2026-08-20
medium CVE-2026-76997 — A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affecte… vulnerability nvd CVE-2026-76997 2026-08-20
medium CVE-2026-76999 — A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analy… vulnerability nvd CVE-2026-76999 2026-08-20
medium CVE-2026-54770 — WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_abs… vulnerability nvd CVE-2026-54770 phishing 2026-08-20
medium CVE-2026-55586 — SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, a crafted CHM file can supply… vulnerability nvd CVE-2026-55586 2026-08-20
medium CVE-2026-61625 — VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.… vulnerability nvd CVE-2026-61625 2026-08-20
medium CVE-2026-77025 — A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unkno… vulnerability nvd CVE-2026-77025 2026-08-20
medium CVE-2026-54625 — django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the djan… vulnerability nvd CVE-2026-54625 2026-08-20
medium CVE-2026-72844 — The Lean 4 kernel does not verify that the structure named in a projection expression matches the ty… vulnerability nvd CVE-2026-72844 2026-08-20
medium CVE-2026-72847 — broot renders each file and directory name in its interactive tree view exactly as read from the fil… vulnerability nvd CVE-2026-72847 2026-08-20
medium CVE-2026-73254 — Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a… vulnerability nvd CVE-2026-73254 2026-08-20
medium CVE-2026-73255 — Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control a… vulnerability nvd CVE-2026-73255 2026-08-20
medium CVE-2026-73258 — Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a… vulnerability nvd CVE-2026-73258 2026-08-20
medium CVE-2026-73259 — Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a… vulnerability nvd CVE-2026-73259 2026-08-20
medium CVE-2026-77036 — A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailCon… vulnerability nvd CVE-2026-77036 2026-08-20
medium CVE-2026-43678 — An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingb… vulnerability nvd CVE-2026-43678 2026-08-20
medium CVE-2026-64777 — A malicious builder peer may be able to request an in-context file by name from the host and receive… vulnerability nvd CVE-2026-64777 2026-08-20
medium CVE-2026-72854 — msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_… vulnerability nvd CVE-2026-72854 2026-08-20
medium CVE-2026-75514 — BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklis… vulnerability nvd CVE-2026-75514 2026-08-20
medium CVE-2026-72861 — The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inv… vulnerability nvd CVE-2026-72861 2026-08-20
medium CVE-2026-75910 — Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Fede… vulnerability nvd CVE-2026-75910 2026-08-20
medium CVE-2026-67445 — Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP command… vulnerability nvd CVE-2026-67445 2026-08-20
medium CVE-2026-67446 — Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-s… vulnerability nvd CVE-2026-67446 2026-08-20
medium CVE-2026-68921 — DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpola… vulnerability nvd CVE-2026-68921 2026-08-20
medium CVE-2026-76018 — Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker lev… vulnerability nvd CVE-2026-76018 phishing 2026-08-20
medium CVE-2026-76019 — Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacke… vulnerability nvd CVE-2026-76019 phishing 2026-08-20
medium CVE-2026-77506 — Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS. vulnerability nvd CVE-2026-77506 2026-08-20
medium CVE-2026-77587 — Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object whe… vulnerability nvd CVE-2026-77587 2026-08-20
medium CVE-2026-77639 — Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many g… vulnerability nvd CVE-2026-77639 2026-08-20
medium CVE-2026-77641 — tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. Th… vulnerability nvd CVE-2026-77641 2026-08-20
medium CVE-2026-16951 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute… vulnerability nvd CVE-2026-16951 2026-08-20
medium CVE-2026-16964 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages an… vulnerability nvd CVE-2026-16964 2026-08-20
medium CVE-2026-16973 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to disclose sensitive ker… vulnerability nvd CVE-2026-16973 2026-08-20
medium CVE-2026-17424 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restr… vulnerability nvd CVE-2026-17424 2026-08-20
medium CVE-2026-19448 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the… vulnerability nvd CVE-2026-19448 2026-08-20
medium CVE-2026-19783 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory co… vulnerability nvd CVE-2026-19783 2026-08-20
medium CVE-2026-49244 — SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public we… vulnerability nvd CVE-2026-49244 2026-08-20
medium CVE-2026-54389 — Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser t… vulnerability nvd CVE-2026-54389 2026-08-20
medium CVE-2026-54509 — TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link… vulnerability nvd CVE-2026-54509 2026-08-20
medium CVE-2026-55015 — Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny servic… vulnerability nvd CVE-2026-55015 2026-08-20
medium CVE-2026-55489 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could s… vulnerability nvd CVE-2026-55489 2026-08-20
medium CVE-2026-55491 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape m… vulnerability nvd CVE-2026-55491 ransomware 2026-08-20
medium CVE-2026-62945 — TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions a… vulnerability nvd CVE-2026-62945 2026-08-20
medium CVE-2026-67447 — Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's interna… vulnerability nvd CVE-2026-67447 2026-08-20
medium CVE-2026-67448 — Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/… vulnerability nvd CVE-2026-67448 2026-08-20
medium CVE-2026-70105 — Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose infor… vulnerability nvd CVE-2026-70105 2026-08-20
medium CVE-2026-72846 — Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendW… vulnerability nvd CVE-2026-72846 2026-08-20
medium CVE-2026-77643 — A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core… vulnerability nvd CVE-2026-77643 2026-08-20
medium CVE-2026-77391 — A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS,… vulnerability nvd CVE-2026-77391 2026-08-21
medium CVE-2026-77392 — A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and… vulnerability nvd CVE-2026-77392 2026-08-21
medium BRIDGEHEAD: An npm typosquatting campaign that crosses from WSL into Windows to plant a crypto-wallet stealer threat-intel otx 6888d4c54ef2b5bf… rust, github-hosted-payload, browser-credentials, wsl, telegram, npm, cryptocurrency-stealer, typosquatting, in-memory-execution, supply-chain, botnet 2026-08-20
medium How Peer2Profit and Astroproxy Turn Your Bandwidth Into Someone Else's Product threat-intel otx c85c7436fdb71cf5… backconnect infrastructure, bandwidth-sharing, internal network exposure, privateloader, sdk analysis, proxy enumeration, peer2profit, residential proxies, astroproxy 2026-08-20
medium N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it threat-intel otx CVE-2023-48022, CVE-2026-26220, CVE-2026-27944, CVE-2026-33032, CVE-2026-39987 | e09ac5e8c23a768a…, b8e66803519f9376… n4d mesh controller, cve-2023-48022, cve-2026-26220, linux malware, go-titan, cve-2026-27944, ray dashboard, cve-2026-33032, n4d, cve-2026-39987, mcp exploitation, lateral movement, ai infrastructure targeting, cloudflare tunnels, credential theft, lightllm, botnet 2026-08-20
medium Hackers poison arrayref Rust crate to push infostealer malware news general-news infostealer 2026-08-20
medium How MSPs can catch phishing attacks email filters miss news general-news phishing 2026-08-20
low CVE-2026-64846 — Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation e… vulnerability nvd CVE-2026-64846 2026-08-20
low CVE-2026-49996 — SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle s… vulnerability nvd CVE-2026-49996 2026-08-20
low CVE-2026-77151 — A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the func… vulnerability nvd CVE-2026-77151 2026-08-20
low CVE-2026-77640 — tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream wit… vulnerability nvd CVE-2026-77640 2026-08-20
low CVE-2026-49245 — SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline qu… vulnerability nvd CVE-2026-49245 phishing 2026-08-20
low CVE-2026-77648 — In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_f… vulnerability nvd CVE-2026-77648 2026-08-20
unknown CVE-2026-64961 — ATutor is vulnerable to authentication bypass . Although a token validation check is present in the… vulnerability nvd CVE-2026-64961 2026-08-20
unknown CVE-2026-64962 — ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attack… vulnerability nvd CVE-2026-64962 2026-08-20
unknown CVE-2026-64963 — A path traversal vulnerability in ATutor allows an authenticated user to access files from other cou… vulnerability nvd CVE-2026-64963 2026-08-20
unknown CVE-2026-64964 — ATutor generates predictable email confirmation tokens due to the use of insufficiently random value… vulnerability nvd CVE-2026-64964 2026-08-20
unknown CVE-2026-64965 — ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints. A low-pri… vulnerability nvd CVE-2026-64965 2026-08-20
unknown CVE-2026-64967 — A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative p… vulnerability nvd CVE-2026-64967 2026-08-20
unknown CVE-2026-64968 — ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated admi… vulnerability nvd CVE-2026-64968 2026-08-20
unknown CVE-2026-64969 — ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related en… vulnerability nvd CVE-2026-64969 2026-08-20
unknown CVE-2026-64970 — ATutor is vulnerable to Stored Cross Site Scripting in registration functionality. An attacker can r… vulnerability nvd CVE-2026-64970 2026-08-20
unknown CVE-2026-64971 — ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially… vulnerability nvd CVE-2026-64971 2026-08-20
unknown CVE-2026-64972 — ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker… vulnerability nvd CVE-2026-64972 2026-08-20
unknown CVE-2026-70383 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Esto… vulnerability nvd CVE-2026-70383 2026-08-20
unknown CVE-2026-73220 — CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0… vulnerability nvd CVE-2026-73220 2026-08-20
unknown CVE-2026-63040 — Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource per… vulnerability nvd CVE-2026-63040 2026-08-20
unknown CVE-2026-63042 — Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can… vulnerability nvd CVE-2026-63042 2026-08-20
unknown CVE-2026-63043 — Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host file… vulnerability nvd CVE-2026-63043 2026-08-20
unknown CVE-2026-63044 — Server-Side Request Forgery (SSRF) vulnerability in Apache InLong. Any authenticated user (no admin… vulnerability nvd CVE-2026-63044 2026-08-20
unknown CVE-2026-13121 — Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulne… vulnerability nvd CVE-2026-13121, CVE-2026-18262, CVE-2026-18263 2026-08-20
unknown CVE-2026-18267 — Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability. This vulnerability al… vulnerability nvd CVE-2026-18267 2026-08-20
unknown CVE-2026-18268 — Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability. This vuln… vulnerability nvd CVE-2026-18268 2026-08-20
unknown CVE-2026-18269 — Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution Vulnerability. This vulne… vulnerability nvd CVE-2026-18269 2026-08-20
unknown CVE-2026-18270 — Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability. T… vulnerability nvd CVE-2026-18270 2026-08-20
unknown CVE-2026-18271 — Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerab… vulnerability nvd CVE-2026-18271 2026-08-20
unknown CVE-2026-18272 — Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability. This vulnerability allows phys… vulnerability nvd CVE-2026-18272 2026-08-20
unknown CVE-2026-18273 — Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability. This v… vulnerability nvd CVE-2026-18273 2026-08-20
unknown CVE-2026-18278 — Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability. This v… vulnerability nvd CVE-2026-18278 2026-08-20
unknown CVE-2026-18280 — Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allo… vulnerability nvd CVE-2026-18280 2026-08-20
unknown CVE-2026-18283 — Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physica… vulnerability nvd CVE-2026-18283 2026-08-20
unknown CVE-2026-18284 — Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerability. This… vulnerability nvd CVE-2026-18284 2026-08-20
unknown CVE-2026-40345 — deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects.… vulnerability nvd CVE-2026-40345 2026-08-20
unknown CVE-2026-54136 — Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows an… vulnerability nvd CVE-2026-54136 2026-08-20
unknown CVE-2026-55095 — OpenProject is open-source, web-based project management software. In version 17.5.1 and earlier, an… vulnerability nvd CVE-2026-55095 2026-08-20
unknown CVE-2026-63481 — Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In versio… vulnerability nvd CVE-2026-63481 2026-08-20
unknown CVE-2026-71492 — Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, Dir… vulnerability nvd CVE-2026-71492 2026-08-20
unknown CVE-2026-53425 — Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to… vulnerability nvd CVE-2026-53425 2026-08-20
unknown CVE-2026-63379 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunk… vulnerability nvd CVE-2026-63379 2026-08-20
unknown CVE-2026-63380 — Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid li… vulnerability nvd CVE-2026-63380 2026-08-20
unknown CVE-2026-63381 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after… vulnerability nvd CVE-2026-63381 2026-08-20
unknown CVE-2026-63382 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp pars… vulnerability nvd CVE-2026-63382 2026-08-20
unknown CVE-2026-63383 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond… vulnerability nvd CVE-2026-63383 2026-08-20
unknown CVE-2026-63384 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrec… vulnerability nvd CVE-2026-63384 2026-08-20
unknown CVE-2026-63385 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP pa… vulnerability nvd CVE-2026-63385 2026-08-20
unknown CVE-2026-73251 — Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impers… vulnerability nvd CVE-2026-73251 2026-08-20
unknown CVE-2026-73253 — Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network at… vulnerability nvd CVE-2026-73253 2026-08-20
unknown CVE-2026-15743 — Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable… vulnerability nvd CVE-2026-15743 2026-08-20
unknown CVE-2026-19586 — A pre-authentication OS command injection vulnerability has been identified in Omada gateways config… vulnerability nvd CVE-2026-19586 2026-08-20
unknown CVE-2026-19683 — A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During com… vulnerability nvd CVE-2026-19683 2026-08-20
unknown CVE-2026-50190 — Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in… vulnerability nvd CVE-2026-50190 2026-08-20
unknown CVE-2026-53569 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted to… vulnerability nvd CVE-2026-53569 2026-08-20
unknown CVE-2026-62315 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_… vulnerability nvd CVE-2026-62315 2026-08-20
unknown CVE-2026-63654 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted fr… vulnerability nvd CVE-2026-63654 2026-08-20
unknown CVE-2026-66001 — Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and aut… vulnerability nvd CVE-2026-66001 2026-08-20
unknown CVE-2026-66002 — Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-… vulnerability nvd CVE-2026-66002 2026-08-20
unknown CVE-2026-9033 — An unauthenticated attacker with network access to the captive portal service of an affected device… vulnerability nvd CVE-2026-9033 2026-08-20
unknown CVE-2026-19755 — NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing a… vulnerability nvd CVE-2026-19755 2026-08-20
unknown CVE-2026-43798 — A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write… vulnerability nvd CVE-2026-43798 2026-08-20
unknown CVE-2026-52021 — An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remote attacker to obtain sensitiv… vulnerability nvd CVE-2026-52021 2026-08-20
unknown CVE-2026-70651 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips b… vulnerability nvd CVE-2026-70651, CVE-2026-70652 2026-08-20
unknown CVE-2026-70653 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-s… vulnerability nvd CVE-2026-70653 2026-08-20
unknown CVE-2026-70654 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applicati… vulnerability nvd CVE-2026-70654 2026-08-20
unknown CVE-2026-74836 — Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unaut… vulnerability nvd CVE-2026-74836 2026-08-20
unknown CVE-2026-75484 — Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows… vulnerability nvd CVE-2026-75484 2026-08-20
unknown CVE-2026-76017 — Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to e… vulnerability nvd CVE-2026-76017 2026-08-20
unknown CVE-2026-76020 — Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute a… vulnerability nvd CVE-2026-76020 2026-08-20
unknown CVE-2026-76021 — Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute… vulnerability nvd CVE-2026-76021 2026-08-20
unknown CVE-2026-76022 — Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to exe… vulnerability nvd CVE-2026-76022 2026-08-20
unknown CVE-2026-76023 — Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed… vulnerability nvd CVE-2026-76023 2026-08-20
unknown CVE-2025-52182 — The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure… vulnerability nvd CVE-2025-52182 2026-08-20
unknown CVE-2026-50192 — Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the… vulnerability nvd CVE-2026-50192 2026-08-20
unknown CVE-2026-54505 — TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK int… vulnerability nvd CVE-2026-54505 2026-08-20
unknown CVE-2026-54508 — TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before n… vulnerability nvd CVE-2026-54508 2026-08-20
unknown CVE-2026-55893 — Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.… vulnerability nvd CVE-2026-55893, CVE-2026-55894 2026-08-20
unknown CVE-2026-64773 — An attacker that can reach a container's published TCP port may be able to force the host's forwardi… vulnerability nvd CVE-2026-64773 2026-08-20
unknown CVE-2026-77644 — A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliabili… vulnerability nvd CVE-2026-77644 2026-08-20
unknown CVE-2026-77646 — A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PT… vulnerability nvd CVE-2026-77646 2026-08-20
unknown CVE-2026-77113 — Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allow… vulnerability nvd CVE-2026-77113 2026-08-20
unknown CVE-2026-16520 — Improper input validation and Exposure of sensitive information through data queries vulnerability i… vulnerability nvd CVE-2026-16520 2026-08-21
unknown CVE-2026-20679 — The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Son… vulnerability nvd CVE-2026-20679 2026-08-21
unknown CVE-2026-43679 — This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An… vulnerability nvd CVE-2026-43679 2026-08-21
unknown CVE-2026-76155 — Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a rem… vulnerability nvd CVE-2026-76155 2026-08-21
unknown CVE-2026-76156 — OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.… vulnerability nvd CVE-2026-76156 2026-08-21
unknown CVE-2026-76157 — Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management… vulnerability nvd CVE-2026-76157 2026-08-21
unknown CVE-2026-62834 Azure Data Factory Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-68789 Azure SQL Database Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-69519 Azure Stack HCI Information Disclosure Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-69851 Microsoft Entra ID Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-62703 Windows DWM Core Library Information Disclosure Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-62754 Windows Kerberos Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-65786 Desktop Window Manager Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-55015 Microsoft Remote Help Denial of Service Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-55013 Windows Remote Help Defense Spoofing Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-70105 Microsoft Word Information Disclosure Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-63509 Microsoft Fabric Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-65816 Azure Arc Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-66800 Azure Data Factory Information Disclosure Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-69400 Azure Logic Apps Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-69558 Microsoft Partner Center Information Disclosure Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-69543 Azure Virtual Machines Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-69855 Microsoft Copilot in Azure Information Disclosure Vulnerability advisory vendor-blogs 2026-08-20
unknown Is Cyber missing the Marque? advisory vendor-blogs 2026-08-20
unknown AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure news general-news 2026-08-20
unknown New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data news general-news 2026-08-20
unknown Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers news general-news 2026-08-20
unknown New CUSTODY Framework Constrains AI Agents Inside the Network news general-news 2026-08-20
unknown N-able Bug Exposes Password Vault Master Keys news general-news 2026-08-20
unknown Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks news general-news 2026-08-20
unknown Hackers Target Zimbra Servers in Active Exploitation Campaign news general-news 2026-08-20
unknown China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware news general-news 2026-08-20
unknown The push to designate AI as the next critical infrastructure sector news general-news 2026-08-20