| critical |
CVE-2026-72530 — TrueConf Server Code Injection Vulnerability |
vulnerability |
cisa-kev, nvd |
CVE-2026-72530 |
|
2026-08-20 |
| critical |
CVE-2026-72529 — TrueConf Server Missing Authentication for Critical Function Vulnerability |
vulnerability |
cisa-kev, nvd |
CVE-2026-72529 |
|
2026-08-20 |
| critical |
CVE-2026-64849 — MLflow Server-Side Request Forgery Vulnerability |
vulnerability |
cisa-kev, nvd |
CVE-2026-64849, CVE-2026-69146, CVE-2026-69148 |
|
2026-08-19 |
| critical |
Siemens Simcenter Nastran |
advisory |
cisa-advisories, vendor-blogs |
|
ics, rce |
2026-08-18 |
| critical |
CVE-2026-12949 — The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verifica… |
vulnerability |
nvd |
CVE-2026-12949 |
|
2026-08-14 |
| critical |
CVE-2026-72811 — SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query… |
vulnerability |
nvd |
CVE-2026-72811 |
|
2026-08-14 |
| critical |
CVE-2026-72822 — The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API… |
vulnerability |
nvd |
CVE-2026-72822 |
|
2026-08-14 |
| critical |
CVE-2026-72823 — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in… |
vulnerability |
nvd |
CVE-2026-72823, CVE-2026-72824, CVE-2026-72829 |
|
2026-08-14 |
| critical |
CVE-2026-72826 — The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly create… |
vulnerability |
nvd |
CVE-2026-72826 |
rce |
2026-08-14 |
| critical |
CVE-2026-72830 — Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-… |
vulnerability |
nvd |
CVE-2026-72830 |
rce |
2026-08-14 |
| critical |
CVE-2026-19626 — A remote code execution vulnerability exists in Tenable Security Center's report generation function… |
vulnerability |
nvd |
CVE-2026-19626 |
rce |
2026-08-14 |
| critical |
CVE-2026-47766 — crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's defau… |
vulnerability |
nvd |
CVE-2026-47766 |
ransomware |
2026-08-14 |
| critical |
CVE-2026-19681 — An authenticated command injection vulnerability exists in Security Center related to file upload pr… |
vulnerability |
nvd |
CVE-2026-19681 |
|
2026-08-14 |
| critical |
CVE-2026-19682 — A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker… |
vulnerability |
nvd |
CVE-2026-19682 |
|
2026-08-14 |
| critical |
CVE-2026-48528 — Metacat is data repository software that helps researchers preserve, share, and discover data. Metac… |
vulnerability |
nvd |
CVE-2026-48528 |
|
2026-08-14 |
| critical |
CVE-2026-73849 — Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=r… |
vulnerability |
nvd |
CVE-2026-73849 |
|
2026-08-14 |
| critical |
CVE-2026-19188 — A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gatew… |
vulnerability |
nvd |
CVE-2026-19188 |
|
2026-08-14 |
| critical |
CVE-2026-49457 — erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not au… |
vulnerability |
nvd |
CVE-2026-49457 |
|
2026-08-14 |
| critical |
CVE-2026-50027 — mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes… |
vulnerability |
nvd |
CVE-2026-50027 |
|
2026-08-14 |
| critical |
CVE-2026-73678 — MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution… |
vulnerability |
nvd |
CVE-2026-73678 |
rce |
2026-08-14 |
| critical |
CVE-2026-17181 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary loc… |
vulnerability |
nvd |
CVE-2026-17181 |
|
2026-08-14 |
| critical |
CVE-2026-17182 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and ob… |
vulnerability |
nvd |
CVE-2026-17182 |
|
2026-08-14 |
| critical |
CVE-2026-17184 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due t… |
vulnerability |
nvd |
CVE-2026-17184 |
|
2026-08-14 |
| critical |
CVE-2026-17186 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL command… |
vulnerability |
nvd |
CVE-2026-17186 |
|
2026-08-14 |
| critical |
CVE-2026-19909 — PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnera… |
vulnerability |
nvd |
CVE-2026-19909 |
rce |
2026-08-14 |
| critical |
CVE-2026-19910 — PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnera… |
vulnerability |
nvd |
CVE-2026-19910 |
rce |
2026-08-14 |
| critical |
CVE-2026-14484 — The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arb… |
vulnerability |
nvd |
CVE-2026-14484 |
rce |
2026-08-15 |
| critical |
CVE-2026-15303 — The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to,… |
vulnerability |
nvd |
CVE-2026-15303 |
|
2026-08-15 |
| critical |
CVE-2026-15341 — The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to… |
vulnerability |
nvd |
CVE-2026-15341 |
|
2026-08-15 |
| critical |
CVE-2026-68457 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials fo… |
vulnerability |
nvd |
CVE-2026-68457 |
|
2026-08-15 |
| critical |
CVE-2026-68476 — In the Linux kernel, the following vulnerability has been resolved: ipvs: reload ip header after hea… |
vulnerability |
nvd |
CVE-2026-68476 |
|
2026-08-15 |
| critical |
CVE-2026-68477 — In the Linux kernel, the following vulnerability has been resolved: ipvs: fix more places with wrong… |
vulnerability |
nvd |
CVE-2026-68477 |
|
2026-08-15 |
| critical |
CVE-2026-72014 — In the Linux kernel, the following vulnerability has been resolved: drbd: reject data replies with a… |
vulnerability |
nvd |
CVE-2026-72014 |
|
2026-08-15 |
| critical |
CVE-2026-72020 — In the Linux kernel, the following vulnerability has been resolved: ipvs: reset full ip_vs_seq struc… |
vulnerability |
nvd |
CVE-2026-72020 |
|
2026-08-15 |
| critical |
CVE-2026-72033 — In the Linux kernel, the following vulnerability has been resolved: orangefs: keep the readdir entry… |
vulnerability |
nvd |
CVE-2026-72033 |
|
2026-08-15 |
| critical |
CVE-2026-72041 — In the Linux kernel, the following vulnerability has been resolved: espintcp: use sk_msg_free_partia… |
vulnerability |
nvd |
CVE-2026-72041 |
|
2026-08-15 |
| critical |
CVE-2026-72046 — In the Linux kernel, the following vulnerability has been resolved: gve: fix header buffer corruptio… |
vulnerability |
nvd |
CVE-2026-72046 |
|
2026-08-15 |
| critical |
CVE-2026-72064 — In the Linux kernel, the following vulnerability has been resolved: net: mana: Sync page pool RX fra… |
vulnerability |
nvd |
CVE-2026-72064 |
|
2026-08-15 |
| critical |
CVE-2026-72065 — In the Linux kernel, the following vulnerability has been resolved: net: mana: Validate the packet l… |
vulnerability |
nvd |
CVE-2026-72065 |
|
2026-08-15 |
| critical |
CVE-2026-72069 — In the Linux kernel, the following vulnerability has been resolved: locking/rt: Fix the incorrect RC… |
vulnerability |
nvd |
CVE-2026-72069 |
|
2026-08-15 |
| critical |
CVE-2026-72083 — In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix iSCSI IS… |
vulnerability |
nvd |
CVE-2026-72083 |
|
2026-08-15 |
| critical |
CVE-2026-72084 — In the Linux kernel, the following vulnerability has been resolved: scsi: target: Bound PR-OUT Trans… |
vulnerability |
nvd |
CVE-2026-72084 |
|
2026-08-15 |
| critical |
CVE-2026-72085 — In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Free unsubm… |
vulnerability |
nvd |
CVE-2026-72085 |
|
2026-08-15 |
| critical |
CVE-2026-72098 — In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix buffer overflow i… |
vulnerability |
nvd |
CVE-2026-72098 |
|
2026-08-15 |
| critical |
CVE-2026-72129 — In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: handle inline data w… |
vulnerability |
nvd |
CVE-2026-72129 |
|
2026-08-15 |
| critical |
CVE-2026-72130 — In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: reject short AUTH_RE… |
vulnerability |
nvd |
CVE-2026-72130 |
|
2026-08-15 |
| critical |
CVE-2026-72137 — In the Linux kernel, the following vulnerability has been resolved: xfrm: nat_keepalive: avoid doubl… |
vulnerability |
nvd |
CVE-2026-72137 |
|
2026-08-15 |
| critical |
CVE-2026-72139 — In the Linux kernel, the following vulnerability has been resolved: tcp: defer md5sig_info kfree pas… |
vulnerability |
nvd |
CVE-2026-72139 |
|
2026-08-15 |
| critical |
CVE-2026-72185 — In the Linux kernel, the following vulnerability has been resolved: ntfs: fix WARN_ON for resident a… |
vulnerability |
nvd |
CVE-2026-72185 |
|
2026-08-15 |
| critical |
CVE-2026-72186 — In the Linux kernel, the following vulnerability has been resolved: ntfs: make system files immutabl… |
vulnerability |
nvd |
CVE-2026-72186 |
|
2026-08-15 |
| critical |
CVE-2026-72188 — In the Linux kernel, the following vulnerability has been resolved: ntfs: sanitize MFT references re… |
vulnerability |
nvd |
CVE-2026-72188 |
|
2026-08-15 |
| critical |
CVE-2026-72191 — In the Linux kernel, the following vulnerability has been resolved: ntfs3: validate split-point offs… |
vulnerability |
nvd |
CVE-2026-72191 |
|
2026-08-15 |
| critical |
CVE-2026-72192 — In the Linux kernel, the following vulnerability has been resolved: ntfs3: bound to_move in indx_ins… |
vulnerability |
nvd |
CVE-2026-72192 |
|
2026-08-15 |
| critical |
CVE-2026-72193 — In the Linux kernel, the following vulnerability has been resolved: ntfs3: cap RESTART_TABLE free-ch… |
vulnerability |
nvd |
CVE-2026-72193 |
ransomware |
2026-08-15 |
| critical |
CVE-2026-72194 — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: add depth limit to ind… |
vulnerability |
nvd |
CVE-2026-72194 |
|
2026-08-15 |
| critical |
CVE-2026-72199 — In the Linux kernel, the following vulnerability has been resolved: ntfs: validate resident index ro… |
vulnerability |
nvd |
CVE-2026-72199 |
|
2026-08-15 |
| critical |
CVE-2026-72200 — In the Linux kernel, the following vulnerability has been resolved: ntfs: detect mapping-pairs LCN a… |
vulnerability |
nvd |
CVE-2026-72200 |
|
2026-08-15 |
| critical |
CVE-2026-72201 — In the Linux kernel, the following vulnerability has been resolved: ntfs: validate index entries on… |
vulnerability |
nvd |
CVE-2026-72201 |
|
2026-08-15 |
| critical |
CVE-2026-72206 — In the Linux kernel, the following vulnerability has been resolved: ntfs: validate index block heade… |
vulnerability |
nvd |
CVE-2026-72206 |
|
2026-08-15 |
| critical |
CVE-2026-72207 — In the Linux kernel, the following vulnerability has been resolved: ntfs: not change 0-byte $DATA at… |
vulnerability |
nvd |
CVE-2026-72207 |
|
2026-08-15 |
| critical |
CVE-2026-72208 — In the Linux kernel, the following vulnerability has been resolved: ntfs: add bounds check before ac… |
vulnerability |
nvd |
CVE-2026-72208 |
|
2026-08-15 |
| critical |
CVE-2026-72209 — In the Linux kernel, the following vulnerability has been resolved: ntfs: validate attribute values… |
vulnerability |
nvd |
CVE-2026-72209 |
|
2026-08-15 |
| critical |
CVE-2026-72210 — In the Linux kernel, the following vulnerability has been resolved: ntfs: fix off-by-one in mapping… |
vulnerability |
nvd |
CVE-2026-72210 |
|
2026-08-15 |
| critical |
CVE-2026-72211 — In the Linux kernel, the following vulnerability has been resolved: ntfs: grow index root value befo… |
vulnerability |
nvd |
CVE-2026-72211 |
|
2026-08-15 |
| critical |
CVE-2026-72217 — In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Bound-check xdr_buf_to_b… |
vulnerability |
nvd |
CVE-2026-72217 |
|
2026-08-15 |
| critical |
CVE-2026-72220 — In the Linux kernel, the following vulnerability has been resolved: sunrpc: harden rq_procinfo lifec… |
vulnerability |
nvd |
CVE-2026-72220 |
|
2026-08-15 |
| critical |
CVE-2026-72221 — In the Linux kernel, the following vulnerability has been resolved: sunrpc: wait for in-flight TLS h… |
vulnerability |
nvd |
CVE-2026-72221 |
|
2026-08-15 |
| critical |
CVE-2026-72222 — In the Linux kernel, the following vulnerability has been resolved: sunrpc: pin svc_xprt across the… |
vulnerability |
nvd |
CVE-2026-72222 |
|
2026-08-15 |
| critical |
CVE-2026-72226 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: prevent TVLV OOB… |
vulnerability |
nvd |
CVE-2026-72226 |
|
2026-08-15 |
| critical |
CVE-2026-72234 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: access unicast_ttvn… |
vulnerability |
nvd |
CVE-2026-72234 |
|
2026-08-15 |
| critical |
CVE-2026-72239 — In the Linux kernel, the following vulnerability has been resolved: x86/virt/sev: Revert "Drop WBINV… |
vulnerability |
nvd |
CVE-2026-72239 |
|
2026-08-15 |
| critical |
CVE-2026-72248 — In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: support IP… |
vulnerability |
nvd |
CVE-2026-72248 |
|
2026-08-15 |
| critical |
CVE-2026-72249 — In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: use dst in… |
vulnerability |
nvd |
CVE-2026-72249 |
|
2026-08-15 |
| critical |
CVE-2026-72251 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: reload po… |
vulnerability |
nvd |
CVE-2026-72251 |
|
2026-08-15 |
| critical |
CVE-2026-72277 — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Inject SEA if gu… |
vulnerability |
nvd |
CVE-2026-72277 |
|
2026-08-15 |
| critical |
CVE-2026-72278 — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Re-translate VNC… |
vulnerability |
nvd |
CVE-2026-72278 |
|
2026-08-15 |
| critical |
CVE-2026-72279 — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Respect read-onl… |
vulnerability |
nvd |
CVE-2026-72279 |
|
2026-08-15 |
| critical |
CVE-2026-72288 — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Handle race be… |
vulnerability |
nvd |
CVE-2026-72288 |
|
2026-08-15 |
| critical |
CVE-2026-72289 — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Check the inte… |
vulnerability |
nvd |
CVE-2026-72289 |
|
2026-08-15 |
| critical |
CVE-2026-72291 — In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix unlikely race in… |
vulnerability |
nvd |
CVE-2026-72291 |
|
2026-08-15 |
| critical |
CVE-2026-72296 — In the Linux kernel, the following vulnerability has been resolved: net: ife: require ETH_HLEN to be… |
vulnerability |
nvd |
CVE-2026-72296 |
|
2026-08-15 |
| critical |
CVE-2026-72299 — In the Linux kernel, the following vulnerability has been resolved: tipc: restrict socket queue dump… |
vulnerability |
nvd |
CVE-2026-72299 |
botnet |
2026-08-15 |
| critical |
CVE-2026-72313 — In the Linux kernel, the following vulnerability has been resolved: drm/fb-helper: Only consider act… |
vulnerability |
nvd |
CVE-2026-72313 |
ransomware |
2026-08-15 |
| critical |
CVE-2026-72317 — In the Linux kernel, the following vulnerability has been resolved: SUNRPC: pin upper rpc_clnt acros… |
vulnerability |
nvd |
CVE-2026-72317 |
|
2026-08-15 |
| critical |
CVE-2026-72318 — In the Linux kernel, the following vulnerability has been resolved: cifs: validate DFS referral stri… |
vulnerability |
nvd |
CVE-2026-72318 |
|
2026-08-15 |
| critical |
CVE-2026-72319 — In the Linux kernel, the following vulnerability has been resolved: ipvs: ensure inner headers in IC… |
vulnerability |
nvd |
CVE-2026-72319 |
|
2026-08-15 |
| critical |
CVE-2026-72320 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_lookup: fix catch… |
vulnerability |
nvd |
CVE-2026-72320 |
|
2026-08-15 |
| critical |
CVE-2026-72322 — In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Fix potential UAF i… |
vulnerability |
nvd |
CVE-2026-72322 |
|
2026-08-15 |
| critical |
CVE-2026-72323 — In the Linux kernel, the following vulnerability has been resolved: ipv4: igmp: Fix potential UAF in… |
vulnerability |
nvd |
CVE-2026-72323 |
|
2026-08-15 |
| critical |
CVE-2026-72329 — In the Linux kernel, the following vulnerability has been resolved: net/liquidio: drop cached VF pci… |
vulnerability |
nvd |
CVE-2026-72329 |
|
2026-08-15 |
| critical |
CVE-2026-72339 — In the Linux kernel, the following vulnerability has been resolved: qede: fix off-by-one in BD ring… |
vulnerability |
nvd |
CVE-2026-72339 |
|
2026-08-15 |
| critical |
CVE-2026-72348 — In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6tables: mark malfo… |
vulnerability |
nvd |
CVE-2026-72348 |
|
2026-08-15 |
| critical |
CVE-2026-72351 — In the Linux kernel, the following vulnerability has been resolved: gue: validate REMCSUM private op… |
vulnerability |
nvd |
CVE-2026-72351 |
|
2026-08-15 |
| critical |
CVE-2026-72355 — In the Linux kernel, the following vulnerability has been resolved: netfs: Fix barriering when walki… |
vulnerability |
nvd |
CVE-2026-72355 |
|
2026-08-15 |
| critical |
CVE-2026-72366 — In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_create_write_re… |
vulnerability |
nvd |
CVE-2026-72366 |
|
2026-08-15 |
| critical |
CVE-2026-72381 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of fp-… |
vulnerability |
nvd |
CVE-2026-72381 |
|
2026-08-15 |
| critical |
CVE-2026-72393 — In the Linux kernel, the following vulnerability has been resolved: eth: fbnic: don't cache shinfo a… |
vulnerability |
nvd |
CVE-2026-72393 |
|
2026-08-15 |
| critical |
CVE-2026-72398 — In the Linux kernel, the following vulnerability has been resolved: sctp: add INIT verification afte… |
vulnerability |
nvd |
CVE-2026-72398 |
|
2026-08-15 |
| critical |
CVE-2026-72399 — In the Linux kernel, the following vulnerability has been resolved: net: enetc: check the number of… |
vulnerability |
nvd |
CVE-2026-72399 |
|
2026-08-15 |
| critical |
CVE-2026-72407 — In the Linux kernel, the following vulnerability has been resolved: geneve: validate inner network o… |
vulnerability |
nvd |
CVE-2026-72407 |
|
2026-08-15 |
| critical |
CVE-2026-72408 — In the Linux kernel, the following vulnerability has been resolved: geneve: gate GRO hint in geneve_… |
vulnerability |
nvd |
CVE-2026-72408 |
|
2026-08-15 |
| critical |
CVE-2026-72412 — In the Linux kernel, the following vulnerability has been resolved: s390/mm: Fix handling of _PAGE_U… |
vulnerability |
nvd |
CVE-2026-72412 |
|
2026-08-15 |
| critical |
CVE-2026-72417 — In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: Validate i… |
vulnerability |
nvd |
CVE-2026-72417 |
|
2026-08-15 |
| critical |
CVE-2026-72421 — In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: Don't ignore error ro… |
vulnerability |
nvd |
CVE-2026-72421 |
|
2026-08-15 |
| critical |
CVE-2026-72422 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of con… |
vulnerability |
nvd |
CVE-2026-72422 |
|
2026-08-15 |
| critical |
CVE-2026-72429 — In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix type confusion o… |
vulnerability |
nvd |
CVE-2026-72429 |
|
2026-08-15 |
| critical |
CVE-2026-72436 — In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Don't use test… |
vulnerability |
nvd |
CVE-2026-72436 |
|
2026-08-15 |
| critical |
CVE-2026-72442 — In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: fix and si… |
vulnerability |
nvd |
CVE-2026-72442 |
|
2026-08-15 |
| critical |
CVE-2026-72451 — In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix xfrm state cache inser… |
vulnerability |
nvd |
CVE-2026-72451 |
|
2026-08-15 |
| critical |
CVE-2026-72463 — In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix dev use-after-free in… |
vulnerability |
nvd |
CVE-2026-72463 |
|
2026-08-15 |
| critical |
CVE-2026-72466 — In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Fix bcall rep leak and… |
vulnerability |
nvd |
CVE-2026-72466 |
|
2026-08-15 |
| critical |
CVE-2026-72472 — In the Linux kernel, the following vulnerability has been resolved: nfs: use nfsi->rwsem to protect… |
vulnerability |
nvd |
CVE-2026-72472 |
|
2026-08-15 |
| critical |
CVE-2026-72473 — In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Decouple req recycling… |
vulnerability |
nvd |
CVE-2026-72473 |
|
2026-08-15 |
| critical |
CVE-2026-72477 — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: call _ntfs_bad_inode()… |
vulnerability |
nvd |
CVE-2026-72477 |
|
2026-08-15 |
| critical |
CVE-2026-72491 — In the Linux kernel, the following vulnerability has been resolved: net/9p: fix race condition on rd… |
vulnerability |
nvd |
CVE-2026-72491 |
|
2026-08-15 |
| critical |
CVE-2026-72493 — In the Linux kernel, the following vulnerability has been resolved: net: serialize netif_running() c… |
vulnerability |
nvd |
CVE-2026-72493 |
|
2026-08-15 |
| critical |
CVE-2026-72494 — In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Replace waitqueue an… |
vulnerability |
nvd |
CVE-2026-72494 |
|
2026-08-15 |
| critical |
CVE-2026-72495 — In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Avoid repeated req… |
vulnerability |
nvd |
CVE-2026-72495 |
|
2026-08-15 |
| critical |
CVE-2026-72496 — In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Proper rollback if… |
vulnerability |
nvd |
CVE-2026-72496 |
|
2026-08-15 |
| critical |
CVE-2026-72498 — In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Avoid displaying t… |
vulnerability |
nvd |
CVE-2026-72498 |
ransomware |
2026-08-15 |
| critical |
CVE-2026-74255 — In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in tipc_l2_send_ms… |
vulnerability |
nvd |
CVE-2026-74255 |
|
2026-08-15 |
| critical |
CVE-2026-74267 — In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_codel: Do not cal… |
vulnerability |
nvd |
CVE-2026-74267 |
|
2026-08-15 |
| critical |
CVE-2026-74268 — In the Linux kernel, the following vulnerability has been resolved: tcp: clear sock_ops cb flags bef… |
vulnerability |
nvd |
CVE-2026-74268 |
|
2026-08-15 |
| critical |
CVE-2026-74269 — In the Linux kernel, the following vulnerability has been resolved: bnxt: fix head underflow on XDP… |
vulnerability |
nvd |
CVE-2026-74269 |
|
2026-08-15 |
| critical |
CVE-2026-74279 — In the Linux kernel, the following vulnerability has been resolved: crypto: cavium/cpt - fix DMA cle… |
vulnerability |
nvd |
CVE-2026-74279 |
|
2026-08-15 |
| critical |
CVE-2026-74280 — In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/octeontx - fix D… |
vulnerability |
nvd |
CVE-2026-74280 |
|
2026-08-15 |
| critical |
CVE-2026-74287 — In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded address… |
vulnerability |
nvd |
CVE-2026-74287 |
|
2026-08-15 |
| critical |
CVE-2026-74309 — In the Linux kernel, the following vulnerability has been resolved: vdpa/octeon_ep: fix IRQ-to-ring… |
vulnerability |
nvd |
CVE-2026-74309 |
|
2026-08-15 |
| critical |
CVE-2026-74310 — In the Linux kernel, the following vulnerability has been resolved: vhost/net: complete zerocopy ubu… |
vulnerability |
nvd |
CVE-2026-74310 |
|
2026-08-15 |
| critical |
CVE-2026-74315 — In the Linux kernel, the following vulnerability has been resolved: lockd: Avoid hashing uninitializ… |
vulnerability |
nvd |
CVE-2026-74315 |
|
2026-08-15 |
| critical |
CVE-2026-74345 — In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix endpoint/socket as… |
vulnerability |
nvd |
CVE-2026-74345 |
|
2026-08-15 |
| critical |
CVE-2026-74350 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate fast symlink tar… |
vulnerability |
nvd |
CVE-2026-74350 |
|
2026-08-15 |
| critical |
CVE-2026-74361 — In the Linux kernel, the following vulnerability has been resolved: nvme: fix FDP fdpcidx bounds che… |
vulnerability |
nvd |
CVE-2026-74361 |
|
2026-08-15 |
| critical |
CVE-2026-74376 — In the Linux kernel, the following vulnerability has been resolved: md/raid10: reset read_slot when… |
vulnerability |
nvd |
CVE-2026-74376 |
|
2026-08-15 |
| critical |
CVE-2026-74384 — In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: fix flex array s… |
vulnerability |
nvd |
CVE-2026-74384 |
botnet |
2026-08-15 |
| critical |
CVE-2026-74394 — In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: fix integer overflow… |
vulnerability |
nvd |
CVE-2026-74394 |
|
2026-08-15 |
| critical |
CVE-2026-74398 — In the Linux kernel, the following vulnerability has been resolved: ipv6: addrconf: bail out of dad_… |
vulnerability |
nvd |
CVE-2026-74398 |
|
2026-08-15 |
| critical |
CVE-2026-74401 — In the Linux kernel, the following vulnerability has been resolved: dlm: fix add msg handle in send_… |
vulnerability |
nvd |
CVE-2026-74401 |
|
2026-08-15 |
| critical |
CVE-2026-74406 — In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix potential null-ptr-de… |
vulnerability |
nvd |
CVE-2026-74406 |
|
2026-08-15 |
| critical |
CVE-2026-74424 — In the Linux kernel, the following vulnerability has been resolved: fbcon: fix NULL pointer derefere… |
vulnerability |
nvd |
CVE-2026-74424 |
ransomware |
2026-08-15 |
| critical |
CVE-2026-74427 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix netns teardown to cance… |
vulnerability |
nvd |
CVE-2026-74427 |
|
2026-08-15 |
| critical |
CVE-2026-74428 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix double unlock in rxrp… |
vulnerability |
nvd |
CVE-2026-74428 |
|
2026-08-15 |
| critical |
CVE-2026-74433 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix UAF in rxgk_issue_cha… |
vulnerability |
nvd |
CVE-2026-74433 |
|
2026-08-15 |
| critical |
CVE-2026-74434 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: Don't move a peeked OOB m… |
vulnerability |
nvd |
CVE-2026-74434 |
|
2026-08-15 |
| critical |
CVE-2026-74436 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: serialize kernel accept p… |
vulnerability |
nvd |
CVE-2026-74436 |
|
2026-08-15 |
| critical |
CVE-2026-74439 — In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit be… |
vulnerability |
nvd |
CVE-2026-74439 |
|
2026-08-15 |
| critical |
CVE-2026-15826 — The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confus… |
vulnerability |
nvd |
CVE-2026-15826 |
|
2026-08-15 |
| critical |
CVE-2026-16142 — The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and inc… |
vulnerability |
nvd |
CVE-2026-16142 |
|
2026-08-15 |
| critical |
CVE-2026-73193 — DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wr… |
vulnerability |
nvd |
CVE-2026-73193 |
|
2026-08-15 |
| critical |
CVE-2026-73194 — DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric place… |
vulnerability |
nvd |
CVE-2026-73194 |
|
2026-08-15 |
| critical |
CVE-2026-74473 — In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull… |
vulnerability |
nvd |
CVE-2026-74473, CVE-2026-74474 |
|
2026-08-15 |
| critical |
CVE-2026-74475 — In the Linux kernel, the following vulnerability has been resolved: vxlan: use neigh_ha_snapshot() i… |
vulnerability |
nvd |
CVE-2026-74475 |
|
2026-08-15 |
| critical |
CVE-2026-74476 — In the Linux kernel, the following vulnerability has been resolved: veth: convert frag_list skbs bef… |
vulnerability |
nvd |
CVE-2026-74476 |
|
2026-08-15 |
| critical |
CVE-2026-74478 — In the Linux kernel, the following vulnerability has been resolved: um: vector: fix use-after-free i… |
vulnerability |
nvd |
CVE-2026-74478 |
|
2026-08-15 |
| critical |
CVE-2026-74480 — In the Linux kernel, the following vulnerability has been resolved: net: bridge: stop fast-leave aft… |
vulnerability |
nvd |
CVE-2026-74480 |
|
2026-08-15 |
| critical |
CVE-2026-74486 — In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: use exe_file_deny_w… |
vulnerability |
nvd |
CVE-2026-74486 |
ransomware |
2026-08-15 |
| critical |
CVE-2026-74493 — In the Linux kernel, the following vulnerability has been resolved: net/smc: fix socket use-after-fr… |
vulnerability |
nvd |
CVE-2026-74493 |
|
2026-08-15 |
| critical |
CVE-2026-74495 — In the Linux kernel, the following vulnerability has been resolved: igbvf: Fix leak in TX DMA error… |
vulnerability |
nvd |
CVE-2026-74495 |
|
2026-08-15 |
| critical |
CVE-2026-74517 — In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Cancel delayed I/O API… |
vulnerability |
nvd |
CVE-2026-74517 |
|
2026-08-15 |
| critical |
CVE-2026-74521 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: use memcmp() to compare C… |
vulnerability |
nvd |
CVE-2026-74521 |
|
2026-08-15 |
| critical |
CVE-2026-74545 — In the Linux kernel, the following vulnerability has been resolved: rtase: fix double free of multi-… |
vulnerability |
nvd |
CVE-2026-74545 |
|
2026-08-15 |
| critical |
CVE-2026-74556 — In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi_tcp: Bound SCSI R… |
vulnerability |
nvd |
CVE-2026-74556 |
|
2026-08-15 |
| critical |
CVE-2026-74568 — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Fix race betwe… |
vulnerability |
nvd |
CVE-2026-74568 |
|
2026-08-15 |
| critical |
CVE-2026-74569 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: wid… |
vulnerability |
nvd |
CVE-2026-74569 |
|
2026-08-15 |
| critical |
CVE-2026-74570 — In the Linux kernel, the following vulnerability has been resolved: ntfs: harden runlist realloc siz… |
vulnerability |
nvd |
CVE-2026-74570 |
|
2026-08-15 |
| critical |
CVE-2026-74573 — In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3-iommufd: Requi… |
vulnerability |
nvd |
CVE-2026-74573 |
|
2026-08-15 |
| critical |
CVE-2026-15689 — Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisonin… |
vulnerability |
nvd |
CVE-2026-15689 |
|
2026-08-15 |
| critical |
CVE-2026-19598 — The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalatio… |
vulnerability |
nvd |
CVE-2026-19598 |
|
2026-08-15 |
| critical |
CVE-2026-18855 — The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f… |
vulnerability |
nvd |
CVE-2026-18855 |
rce |
2026-08-15 |
| critical |
CVE-2026-73041 — SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the se… |
vulnerability |
nvd |
CVE-2026-73041 |
|
2026-08-15 |
| critical |
CVE-2026-73042 — SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing… |
vulnerability |
nvd |
CVE-2026-73042 |
|
2026-08-15 |
| critical |
CVE-2026-73043 — SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculat… |
vulnerability |
nvd |
CVE-2026-73043 |
rce |
2026-08-15 |
| critical |
CVE-2026-73044 — SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored… |
vulnerability |
nvd |
CVE-2026-73044 |
|
2026-08-15 |
| critical |
CVE-2026-73046 — SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middl… |
vulnerability |
nvd |
CVE-2026-73046 |
|
2026-08-15 |
| critical |
CVE-2026-73050 — SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select op… |
vulnerability |
nvd |
CVE-2026-73050 |
|
2026-08-15 |
| critical |
CVE-2026-73052 — SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them d… |
vulnerability |
nvd |
CVE-2026-73052 |
|
2026-08-15 |
| critical |
CVE-2026-73053 — SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji func… |
vulnerability |
nvd |
CVE-2026-73053 |
|
2026-08-15 |
| critical |
CVE-2026-19924 — A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability… |
vulnerability |
nvd |
CVE-2026-19924 |
|
2026-08-16 |
| critical |
CVE-2026-14524 — The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insuf… |
vulnerability |
nvd |
CVE-2026-14524 |
rce |
2026-08-16 |
| critical |
CVE-2026-16098 — The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all version… |
vulnerability |
nvd |
CVE-2026-16098 |
rce |
2026-08-16 |
| critical |
CVE-2026-18432 — The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all v… |
vulnerability |
nvd |
CVE-2026-18432 |
|
2026-08-16 |
| critical |
CVE-2026-18316 — The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data du… |
vulnerability |
nvd |
CVE-2026-18316 |
|
2026-08-16 |
| critical |
CVE-2026-19714 — The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google iden… |
vulnerability |
nvd |
CVE-2026-19714 |
|
2026-08-16 |
| critical |
CVE-2026-19725 — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value… |
vulnerability |
nvd |
CVE-2026-19725 |
|
2026-08-16 |
| critical |
CVE-2026-19349 — Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 befo… |
vulnerability |
nvd |
CVE-2026-19349 |
ransomware |
2026-08-16 |
| critical |
CVE-2026-72887 — Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OA… |
vulnerability |
nvd |
CVE-2026-72887 |
|
2026-08-16 |
| critical |
CVE-2026-73056 — SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication atte… |
vulnerability |
nvd |
CVE-2026-73056 |
|
2026-08-16 |
| critical |
CVE-2026-73061 — Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that al… |
vulnerability |
nvd |
CVE-2026-73061 |
|
2026-08-16 |
| critical |
CVE-2026-74790 — Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter change… |
vulnerability |
nvd |
CVE-2026-74790 |
|
2026-08-16 |
| critical |
CVE-2026-19959 — A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetu… |
vulnerability |
nvd |
CVE-2026-19959 |
|
2026-08-16 |
| critical |
CVE-2026-19961 — A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of… |
vulnerability |
nvd |
CVE-2026-19961 |
|
2026-08-16 |
| critical |
CVE-2026-19977 — A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function http… |
vulnerability |
nvd |
CVE-2026-19977 |
|
2026-08-17 |
| critical |
CVE-2026-74799 — SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps w… |
vulnerability |
nvd |
CVE-2026-74799 |
|
2026-08-17 |
| critical |
CVE-2026-74800 — SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when servin… |
vulnerability |
nvd |
CVE-2026-74800 |
|
2026-08-17 |
| critical |
CVE-2026-74872 — openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirl… |
vulnerability |
nvd |
CVE-2026-74872 |
|
2026-08-17 |
| critical |
CVE-2026-74875 — openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema libra… |
vulnerability |
nvd |
CVE-2026-74875 |
|
2026-08-17 |
| critical |
CVE-2026-74876 — openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that cr… |
vulnerability |
nvd |
CVE-2026-74876 |
|
2026-08-17 |
| critical |
CVE-2026-74878 — openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection… |
vulnerability |
nvd |
CVE-2026-74878 |
|
2026-08-17 |
| critical |
CVE-2026-74880 — openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and… |
vulnerability |
nvd |
CVE-2026-74880 |
|
2026-08-17 |
| critical |
CVE-2026-74886 — openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the Plugin… |
vulnerability |
nvd |
CVE-2026-74886 |
|
2026-08-17 |
| critical |
CVE-2026-74889 — openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normali… |
vulnerability |
nvd |
CVE-2026-74889 |
|
2026-08-17 |
| critical |
CVE-2026-74891 — openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server co… |
vulnerability |
nvd |
CVE-2026-74891 |
|
2026-08-17 |
| critical |
CVE-2026-74894 — openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token… |
vulnerability |
nvd |
CVE-2026-74894 |
|
2026-08-17 |
| critical |
CVE-2026-74895 — openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isol… |
vulnerability |
nvd |
CVE-2026-74895 |
|
2026-08-17 |
| critical |
CVE-2026-74896 — openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPattern… |
vulnerability |
nvd |
CVE-2026-74896 |
|
2026-08-17 |
| critical |
CVE-2026-74899 — openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecut… |
vulnerability |
nvd |
CVE-2026-74899 |
|
2026-08-17 |
| critical |
CVE-2026-74900 — openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsula… |
vulnerability |
nvd |
CVE-2026-74900 |
|
2026-08-17 |
| critical |
CVE-2026-74901 — openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where… |
vulnerability |
nvd |
CVE-2026-74901 |
|
2026-08-17 |
| critical |
CVE-2026-74843 — A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerabilit… |
vulnerability |
nvd |
CVE-2026-74843 |
|
2026-08-17 |
| critical |
CVE-2026-14564 — Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consul… |
vulnerability |
nvd |
CVE-2026-14564 |
|
2026-08-17 |
| critical |
CVE-2026-71566 — FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware… |
vulnerability |
nvd |
CVE-2026-71566 |
|
2026-08-17 |
| critical |
CVE-2026-53960 — Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0… |
vulnerability |
nvd |
CVE-2026-53960, CVE-2026-55674 |
|
2026-08-17 |
| critical |
CVE-2026-64859 — New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management sys… |
vulnerability |
nvd |
CVE-2026-64859, CVE-2026-64865, CVE-2026-64866, CVE-2026-64868, CVE-2026-71479 |
|
2026-08-17 |
| critical |
CVE-2026-75045 — In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker c… |
vulnerability |
nvd |
CVE-2026-75045 |
|
2026-08-17 |
| critical |
CVE-2026-50768 — File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a r… |
vulnerability |
nvd |
CVE-2026-50768 |
|
2026-08-17 |
| critical |
CVE-2026-50769 — The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Inj… |
vulnerability |
nvd |
CVE-2026-50769 |
|
2026-08-17 |
| critical |
CVE-2026-50770 — An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges… |
vulnerability |
nvd |
CVE-2026-50770 |
|
2026-08-17 |
| critical |
CVE-2026-50772 — An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via… |
vulnerability |
nvd |
CVE-2026-50772 |
|
2026-08-17 |
| critical |
CVE-2026-51346 — SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote att… |
vulnerability |
nvd |
CVE-2026-51346 |
|
2026-08-17 |
| critical |
CVE-2026-74253 — Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in… |
vulnerability |
nvd |
CVE-2026-74253 |
rce |
2026-08-17 |
| critical |
CVE-2026-50774 — An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Ma… |
vulnerability |
nvd |
CVE-2026-50774 |
|
2026-08-17 |
| critical |
CVE-2026-50775 — A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the… |
vulnerability |
nvd |
CVE-2026-50775 |
|
2026-08-17 |
| critical |
CVE-2026-66792 — A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a use… |
vulnerability |
nvd |
CVE-2026-66792 |
|
2026-08-17 |
| critical |
CVE-2026-19478 — GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.… |
vulnerability |
nvd |
CVE-2026-19478, CVE-2026-19650 |
|
2026-08-17 |
| critical |
CVE-2026-67678 — File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute ar… |
vulnerability |
nvd |
CVE-2026-67678 |
|
2026-08-17 |
| critical |
CVE-2026-68004 — An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitra… |
vulnerability |
nvd |
CVE-2026-68004 |
|
2026-08-17 |
| critical |
CVE-2026-71472 — A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such a… |
vulnerability |
nvd |
CVE-2026-71472 |
|
2026-08-17 |
| critical |
CVE-2026-39254 — Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execut… |
vulnerability |
nvd |
CVE-2026-39254, CVE-2026-39255 |
|
2026-08-17 |
| critical |
CVE-2026-47686 — vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbo… |
vulnerability |
nvd |
CVE-2026-47686 |
|
2026-08-17 |
| critical |
CVE-2026-47698 — vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.j… |
vulnerability |
nvd |
CVE-2026-47698 |
|
2026-08-17 |
| critical |
CVE-2026-65640 — WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file uploa… |
vulnerability |
nvd |
CVE-2026-65640 |
rce |
2026-08-17 |
| critical |
CVE-2026-65974 — ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0,… |
vulnerability |
nvd |
CVE-2026-65974 |
rce |
2026-08-17 |
| critical |
CVE-2026-66795 — A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto… |
vulnerability |
nvd |
CVE-2026-66795 |
|
2026-08-17 |
| critical |
CVE-2026-67917 — zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup res… |
vulnerability |
nvd |
CVE-2026-67917 |
|
2026-08-17 |
| critical |
CVE-2026-67926 — An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Param… |
vulnerability |
nvd |
CVE-2026-67926 |
|
2026-08-17 |
| critical |
CVE-2026-67965 — An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the… |
vulnerability |
nvd |
CVE-2026-67965 |
|
2026-08-17 |
| critical |
CVE-2026-67966 — Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activ… |
vulnerability |
nvd |
CVE-2026-67966 |
|
2026-08-17 |
| critical |
CVE-2026-67967 — Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary… |
vulnerability |
nvd |
CVE-2026-67967 |
|
2026-08-17 |
| critical |
CVE-2026-75106 — OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an em… |
vulnerability |
nvd |
CVE-2026-75106 |
|
2026-08-17 |
| critical |
CVE-2026-75110 — MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is en… |
vulnerability |
nvd |
CVE-2026-75110 |
|
2026-08-17 |
| critical |
CVE-2026-42163 — Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Lear… |
vulnerability |
nvd |
CVE-2026-42163 |
|
2026-08-17 |
| critical |
CVE-2026-51977 — An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically… |
vulnerability |
nvd |
CVE-2026-51977 |
|
2026-08-17 |
| critical |
CVE-2026-67854 — SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code |
vulnerability |
nvd |
CVE-2026-67854 |
|
2026-08-17 |
| critical |
CVE-2026-67868 — A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter hand… |
vulnerability |
nvd |
CVE-2026-67868 |
|
2026-08-17 |
| critical |
CVE-2026-67960 — An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.… |
vulnerability |
nvd |
CVE-2026-67960 |
|
2026-08-17 |
| critical |
CVE-2026-71424 — Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers… |
vulnerability |
nvd |
CVE-2026-71424 |
|
2026-08-17 |
| critical |
CVE-2026-38165 — A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration… |
vulnerability |
nvd |
CVE-2026-38165 |
|
2026-08-17 |
| critical |
CVE-2026-42162 — Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certai… |
vulnerability |
nvd |
CVE-2026-42162 |
|
2026-08-17 |
| critical |
CVE-2026-42164 — Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call… |
vulnerability |
nvd |
CVE-2026-42164 |
|
2026-08-17 |
| critical |
CVE-2026-67919 — An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.ja… |
vulnerability |
nvd |
CVE-2026-67919 |
|
2026-08-17 |
| critical |
CVE-2026-75094 — A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /… |
vulnerability |
nvd |
CVE-2026-75094 |
|
2026-08-18 |
| critical |
CVE-2026-15748 — The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up… |
vulnerability |
nvd |
CVE-2026-15748 |
rce |
2026-08-18 |
| critical |
CVE-2026-34884 — SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking… |
vulnerability |
nvd |
CVE-2026-34884 |
|
2026-08-18 |
| critical |
CVE-2026-75626 — SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including s… |
vulnerability |
nvd |
CVE-2026-75626 |
|
2026-08-18 |
| critical |
CVE-2026-75627 — Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unaut… |
vulnerability |
nvd |
CVE-2026-75627 |
|
2026-08-18 |
| critical |
CVE-2026-75837 — Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required sec… |
vulnerability |
nvd |
CVE-2026-75837 |
|
2026-08-18 |
| critical |
CVE-2026-75843 — ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor th… |
vulnerability |
nvd |
CVE-2026-75843 |
|
2026-08-18 |
| critical |
CVE-2026-75851 — ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the… |
vulnerability |
nvd |
CVE-2026-75851 |
|
2026-08-18 |
| critical |
CVE-2026-75852 — ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB… |
vulnerability |
nvd |
CVE-2026-75852 |
|
2026-08-18 |
| critical |
CVE-2026-75854 — ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-pro… |
vulnerability |
nvd |
CVE-2026-75854 |
|
2026-08-18 |
| critical |
CVE-2026-74936 — Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154… |
vulnerability |
nvd |
CVE-2026-74936 |
|
2026-08-18 |
| critical |
CVE-2026-74938 — Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Fire… |
vulnerability |
nvd |
CVE-2026-74938 |
|
2026-08-18 |
| critical |
CVE-2026-74940 — Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox… |
vulnerability |
nvd |
CVE-2026-74940 |
|
2026-08-18 |
| critical |
CVE-2026-74943 — Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Fir… |
vulnerability |
nvd |
CVE-2026-74943 |
|
2026-08-18 |
| critical |
CVE-2026-74944 — Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firef… |
vulnerability |
nvd |
CVE-2026-74944 |
|
2026-08-18 |
| critical |
CVE-2026-74956 — Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Fir… |
vulnerability |
nvd |
CVE-2026-74956 |
|
2026-08-18 |
| critical |
CVE-2026-74961 — Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 15… |
vulnerability |
nvd |
CVE-2026-74961 |
|
2026-08-18 |
| critical |
CVE-2026-74964 — Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR… |
vulnerability |
nvd |
CVE-2026-74964, CVE-2026-74977 |
|
2026-08-18 |
| critical |
CVE-2026-74979 — Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Fir… |
vulnerability |
nvd |
CVE-2026-74979 |
|
2026-08-18 |
| critical |
CVE-2026-74985 — Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 1… |
vulnerability |
nvd |
CVE-2026-74985 |
|
2026-08-18 |
| critical |
CVE-2026-74986 — Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in F… |
vulnerability |
nvd |
CVE-2026-74986 |
|
2026-08-18 |
| critical |
CVE-2026-74987 — Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153.… |
vulnerability |
nvd |
CVE-2026-74987, CVE-2026-74990 |
|
2026-08-18 |
| critical |
CVE-2026-74988 — Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showe… |
vulnerability |
nvd |
CVE-2026-74988 |
|
2026-08-18 |
| critical |
CVE-2026-74989 — Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corru… |
vulnerability |
nvd |
CVE-2026-74989 |
|
2026-08-18 |
| critical |
CVE-2026-75783 — A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulner… |
vulnerability |
nvd |
CVE-2026-75783 |
|
2026-08-18 |
| critical |
CVE-2026-75874 — Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154… |
vulnerability |
nvd |
CVE-2026-75874 |
|
2026-08-18 |
| critical |
CVE-2026-28192 — Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. |
vulnerability |
nvd |
CVE-2026-28192 |
|
2026-08-18 |
| critical |
CVE-2026-32444 — Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. |
vulnerability |
nvd |
CVE-2026-32444 |
rce |
2026-08-18 |
| critical |
CVE-2026-32463 — Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. |
vulnerability |
nvd |
CVE-2026-32463 |
|
2026-08-18 |
| critical |
CVE-2026-32470 — Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. |
vulnerability |
nvd |
CVE-2026-32470, CVE-2026-73993 |
|
2026-08-18 |
| critical |
CVE-2026-32474 — Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. |
vulnerability |
nvd |
CVE-2026-32474 |
|
2026-08-18 |
| critical |
CVE-2026-59940 — Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify cap… |
vulnerability |
nvd |
CVE-2026-59940 |
rce |
2026-08-18 |
| critical |
CVE-2026-66627 — Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. |
vulnerability |
nvd |
CVE-2026-66627 |
|
2026-08-18 |
| critical |
CVE-2026-73187 — Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. |
vulnerability |
nvd |
CVE-2026-73187 |
|
2026-08-18 |
| critical |
CVE-2026-73339 — Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. |
vulnerability |
nvd |
CVE-2026-73339 |
|
2026-08-18 |
| critical |
CVE-2026-73341 — Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. |
vulnerability |
nvd |
CVE-2026-73341 |
|
2026-08-18 |
| critical |
CVE-2026-73343 — Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. |
vulnerability |
nvd |
CVE-2026-73343 |
rce |
2026-08-18 |
| critical |
CVE-2026-73355 — Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions. |
vulnerability |
nvd |
CVE-2026-73355 |
|
2026-08-18 |
| critical |
CVE-2026-73365 — Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. |
vulnerability |
nvd |
CVE-2026-73365 |
|
2026-08-18 |
| critical |
CVE-2026-73366 — Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. |
vulnerability |
nvd |
CVE-2026-73366 |
|
2026-08-18 |
| critical |
CVE-2026-73376 — Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. |
vulnerability |
nvd |
CVE-2026-73376 |
|
2026-08-18 |
| critical |
CVE-2026-73380 — Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. |
vulnerability |
nvd |
CVE-2026-73380 |
|
2026-08-18 |
| critical |
CVE-2026-73381 — Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. |
vulnerability |
nvd |
CVE-2026-73381 |
|
2026-08-18 |
| critical |
CVE-2026-73392 — Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions. |
vulnerability |
nvd |
CVE-2026-73392 |
|
2026-08-18 |
| critical |
CVE-2026-73397 — Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. |
vulnerability |
nvd |
CVE-2026-73397 |
|
2026-08-18 |
| critical |
CVE-2026-73996 — Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. |
vulnerability |
nvd |
CVE-2026-73996 |
|
2026-08-18 |
| critical |
CVE-2026-74015 — Unauthenticated SQL Injection in Readabler < 2.0.18 versions. |
vulnerability |
nvd |
CVE-2026-74015 |
|
2026-08-18 |
| critical |
CVE-2026-75784 — A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the functio… |
vulnerability |
nvd |
CVE-2026-75784 |
|
2026-08-18 |
| critical |
CVE-2026-12564 — A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() fu… |
vulnerability |
nvd |
CVE-2026-12564 |
|
2026-08-18 |
| critical |
CVE-2026-45117 — MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not… |
vulnerability |
nvd |
CVE-2026-45117 |
rce |
2026-08-18 |
| critical |
CVE-2026-45118 — MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a… |
vulnerability |
nvd |
CVE-2026-45118 |
|
2026-08-18 |
| critical |
CVE-2026-75913 — CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection… |
vulnerability |
nvd |
CVE-2026-75913 |
|
2026-08-18 |
| critical |
CVE-2026-18963 — A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core… |
vulnerability |
nvd |
CVE-2026-18963 |
|
2026-08-18 |
| critical |
CVE-2026-50576 — ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to… |
vulnerability |
nvd |
CVE-2026-50576, CVE-2026-50577, CVE-2026-50578, CVE-2026-52723 |
|
2026-08-18 |
| critical |
CVE-2026-67271 — Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthentic… |
vulnerability |
nvd |
CVE-2026-67271 |
rce |
2026-08-18 |
| critical |
CVE-2026-52608 — An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attack… |
vulnerability |
nvd |
CVE-2026-52608 |
rce |
2026-08-18 |
| critical |
CVE-2026-52610 — An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote at… |
vulnerability |
nvd |
CVE-2026-52610 |
|
2026-08-18 |
| critical |
CVE-2026-66780 — A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, whi… |
vulnerability |
nvd |
CVE-2026-66780 |
|
2026-08-18 |
| critical |
CVE-2026-67921 — Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the Cor… |
vulnerability |
nvd |
CVE-2026-67921 |
|
2026-08-18 |
| critical |
CVE-2026-75130 — Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute ma… |
vulnerability |
nvd |
CVE-2026-75130 |
|
2026-08-18 |
| critical |
CVE-2026-75625 — Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest be… |
vulnerability |
nvd |
CVE-2026-75625 |
|
2026-08-18 |
| critical |
CVE-2026-47627 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path… |
vulnerability |
nvd |
CVE-2026-47627 |
|
2026-08-18 |
| critical |
CVE-2026-55166 — Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME… |
vulnerability |
nvd |
CVE-2026-55166 |
|
2026-08-18 |
| critical |
CVE-2026-57826 — An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certificate chain verificatio… |
vulnerability |
nvd |
CVE-2026-57826 |
|
2026-08-18 |
| critical |
CVE-2026-75877 — A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function Syst… |
vulnerability |
nvd |
CVE-2026-75877 |
|
2026-08-18 |
| critical |
CVE-2026-60391 — Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv… |
vulnerability |
nvd |
CVE-2026-60391, CVE-2026-70739, CVE-2026-70740, CVE-2026-70741, CVE-2026-70742, CVE-2026-70743, CVE-2026-70744, CVE-2026-70745, CVE-2026-70746, CVE-2026-70749, CVE-2026-70750, CVE-2026-70751, CVE-2026-70752, CVE-2026-70753, CVE-2026-70754, CVE-2026-70758, CVE-2026-70759, CVE-2026-70765, CVE-2026-70766, CVE-2026-70767, CVE-2026-70768, CVE-2026-70769, CVE-2026-70776, CVE-2026-70780, CVE-2026-70784, CVE-2026-70785, CVE-2026-70787, CVE-2026-70788, CVE-2026-70789, CVE-2026-70793, CVE-2026-70794 |
|
2026-08-18 |
| critical |
CVE-2026-60393 — Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component… |
vulnerability |
nvd |
CVE-2026-60393, CVE-2026-62457, CVE-2026-62463, CVE-2026-62467, CVE-2026-62471, CVE-2026-62477, CVE-2026-62481, CVE-2026-62485, CVE-2026-62492, CVE-2026-62499, CVE-2026-62500, CVE-2026-62501, CVE-2026-62502, CVE-2026-62506, CVE-2026-62509, CVE-2026-62510, CVE-2026-62511, CVE-2026-62520, CVE-2026-62522, CVE-2026-62523, CVE-2026-62526, CVE-2026-62531, CVE-2026-62535, CVE-2026-62536, CVE-2026-62537, CVE-2026-62538, CVE-2026-62539, CVE-2026-62541, CVE-2026-62543, CVE-2026-62544, CVE-2026-62545, CVE-2026-62550, CVE-2026-62551, CVE-2026-62552, CVE-2026-62553, CVE-2026-62554, CVE-2026-62555, CVE-2026-62558, CVE-2026-62564, CVE-2026-62566, CVE-2026-62568, CVE-2026-62569, CVE-2026-62570, CVE-2026-62572, CVE-2026-62573, CVE-2026-62575, CVE-2026-62576, CVE-2026-62577, CVE-2026-62579, CVE-2026-62581, CVE-2026-62583, CVE-2026-62584, CVE-2026-70956, CVE-2026-70957, CVE-2026-70958, CVE-2026-70959, CVE-2026-70961, CVE-2026-70962, CVE-2026-70963, CVE-2026-70964, CVE-2026-70965, CVE-2026-70966, CVE-2026-70967, CVE-2026-70968, CVE-2026-70971, CVE-2026-70972, CVE-2026-70973 |
|
2026-08-18 |
| critical |
CVE-2026-60415 — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S… |
vulnerability |
nvd |
CVE-2026-60415, CVE-2026-60672, CVE-2026-60679, CVE-2026-60680, CVE-2026-60696, CVE-2026-60698, CVE-2026-60699, CVE-2026-60702 |
|
2026-08-18 |
| critical |
CVE-2026-60590 — Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (c… |
vulnerability |
nvd |
CVE-2026-60590, CVE-2026-60591 |
|
2026-08-18 |
| critical |
CVE-2026-60715 — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Leg… |
vulnerability |
nvd |
CVE-2026-60715, CVE-2026-60716, CVE-2026-60720, CVE-2026-60721, CVE-2026-60722, CVE-2026-60727, CVE-2026-61066, CVE-2026-61118 |
|
2026-08-18 |
| critical |
CVE-2026-60728 — Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet… |
vulnerability |
nvd |
CVE-2026-60728 |
|
2026-08-18 |
| critical |
CVE-2026-60729 — Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Compose… |
vulnerability |
nvd |
CVE-2026-60729, CVE-2026-60730, CVE-2026-60731, CVE-2026-60733 |
|
2026-08-18 |
| critical |
CVE-2026-60737 — Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web… |
vulnerability |
nvd |
CVE-2026-60737, CVE-2026-61001, CVE-2026-70924 |
|
2026-08-18 |
| critical |
CVE-2026-60751 — Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Su… |
vulnerability |
nvd |
CVE-2026-60751, CVE-2026-60752, CVE-2026-60754, CVE-2026-60765, CVE-2026-60767, CVE-2026-60779, CVE-2026-60803 |
|
2026-08-18 |
| critical |
CVE-2026-60781 — Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmissio… |
vulnerability |
nvd |
CVE-2026-60781, CVE-2026-60782, CVE-2026-70694, CVE-2026-70695, CVE-2026-70696, CVE-2026-70699, CVE-2026-70702 |
|
2026-08-18 |
| critical |
CVE-2026-60821 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Busi… |
vulnerability |
nvd |
CVE-2026-60821 |
|
2026-08-18 |
| critical |
CVE-2026-60853 — Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).… |
vulnerability |
nvd |
CVE-2026-60853, CVE-2026-60915, CVE-2026-70716, CVE-2026-70727, CVE-2026-70908, CVE-2026-70923, CVE-2026-71029, CVE-2026-71065, CVE-2026-71074, CVE-2026-71110, CVE-2026-71152, CVE-2026-71153, CVE-2026-71154, CVE-2026-71155, CVE-2026-71156, CVE-2026-71157, CVE-2026-71158, CVE-2026-71159, CVE-2026-71160, CVE-2026-71161, CVE-2026-71162, CVE-2026-71164, CVE-2026-71165, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73867, CVE-2026-73868, CVE-2026-73869, CVE-2026-73870, CVE-2026-73871, CVE-2026-73872, CVE-2026-73873, CVE-2026-73874, CVE-2026-73875, CVE-2026-73876, CVE-2026-73877, CVE-2026-73878, CVE-2026-73879, CVE-2026-73880, CVE-2026-73881, CVE-2026-73882, CVE-2026-73883, CVE-2026-73884, CVE-2026-73885, CVE-2026-73886, CVE-2026-73887, CVE-2026-73888, CVE-2026-73889, CVE-2026-73890, CVE-2026-73891, CVE-2026-73892, CVE-2026-73893, CVE-2026-73894, CVE-2026-73895, CVE-2026-73896, CVE-2026-73897, CVE-2026-73898, CVE-2026-73899, CVE-2026-73900, CVE-2026-73901, CVE-2026-73902, CVE-2026-73903, CVE-2026-73904, CVE-2026-73905, CVE-2026-73906, CVE-2026-73907, CVE-2026-73908, CVE-2026-73909, CVE-2026-73910, CVE-2026-73911, CVE-2026-73912, CVE-2026-73913, CVE-2026-73914, CVE-2026-73915, CVE-2026-73916, CVE-2026-73917, CVE-2026-73918, CVE-2026-73919, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73923, CVE-2026-73924, CVE-2026-73925, CVE-2026-73927, CVE-2026-73928, CVE-2026-73929, CVE-2026-73930, CVE-2026-73931, CVE-2026-73932, CVE-2026-73933, CVE-2026-73934, CVE-2026-73935, CVE-2026-73936, CVE-2026-73937, CVE-2026-73938, CVE-2026-73939 |
|
2026-08-18 |
| critical |
CVE-2026-60858 — Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Secu… |
vulnerability |
nvd |
CVE-2026-60858, CVE-2026-61206, CVE-2026-61259, CVE-2026-61276, CVE-2026-61281, CVE-2026-61293, CVE-2026-61313, CVE-2026-61342, CVE-2026-62441, CVE-2026-62446, CVE-2026-62459, CVE-2026-62460, CVE-2026-62461, CVE-2026-62529, CVE-2026-62532, CVE-2026-62533, CVE-2026-62571, CVE-2026-62578, CVE-2026-62580, CVE-2026-62582, CVE-2026-62598, CVE-2026-62602, CVE-2026-62603, CVE-2026-62604, CVE-2026-62606, CVE-2026-70676, CVE-2026-70677, CVE-2026-70678, CVE-2026-70679, CVE-2026-70682, CVE-2026-70683, CVE-2026-70685, CVE-2026-70705, CVE-2026-70711, CVE-2026-70714, CVE-2026-70719 |
|
2026-08-18 |
| critical |
CVE-2026-60860 — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messa… |
vulnerability |
nvd |
CVE-2026-60860, CVE-2026-60861, CVE-2026-60865, CVE-2026-60866 |
|
2026-08-18 |
| critical |
CVE-2026-60903 — Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Conten… |
vulnerability |
nvd |
CVE-2026-60903, CVE-2026-60905, CVE-2026-60906, CVE-2026-60909, CVE-2026-60928, CVE-2026-60933, CVE-2026-60934, CVE-2026-60935, CVE-2026-60944, CVE-2026-60949, CVE-2026-60954, CVE-2026-60955, CVE-2026-60961, CVE-2026-60980, CVE-2026-60981, CVE-2026-60983, CVE-2026-61288, CVE-2026-61290, CVE-2026-61291, CVE-2026-61295, CVE-2026-70858 |
|
2026-08-18 |
| critical |
CVE-2026-60916 — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (compon… |
vulnerability |
nvd |
CVE-2026-60916, CVE-2026-60921, CVE-2026-60946, CVE-2026-60947, CVE-2026-60958, CVE-2026-60970, CVE-2026-60971 |
|
2026-08-18 |
| critical |
CVE-2026-60977 — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core… |
vulnerability |
nvd |
CVE-2026-60977 |
|
2026-08-18 |
| critical |
CVE-2026-60990 — Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (componen… |
vulnerability |
nvd |
CVE-2026-60990, CVE-2026-60991, CVE-2026-60992, CVE-2026-60993, CVE-2026-60994, CVE-2026-60995, CVE-2026-60996, CVE-2026-60998 |
|
2026-08-18 |
| critical |
CVE-2026-61003 — Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MF… |
vulnerability |
nvd |
CVE-2026-61003 |
|
2026-08-18 |
| critical |
CVE-2026-61007 — Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCente… |
vulnerability |
nvd |
CVE-2026-61007, CVE-2026-61008, CVE-2026-61011, CVE-2026-61016, CVE-2026-61017, CVE-2026-61018, CVE-2026-61021, CVE-2026-61022, CVE-2026-61029, CVE-2026-61032, CVE-2026-61033, CVE-2026-61034, CVE-2026-61038, CVE-2026-61040, CVE-2026-61042, CVE-2026-61045, CVE-2026-61054, CVE-2026-61058 |
|
2026-08-18 |
| critical |
CVE-2026-61124 — Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime… |
vulnerability |
nvd |
CVE-2026-61124, CVE-2026-61177, CVE-2026-61193, CVE-2026-61199, CVE-2026-61208, CVE-2026-61212, CVE-2026-61213, CVE-2026-61215, CVE-2026-61219, CVE-2026-61222, CVE-2026-61227, CVE-2026-61228, CVE-2026-61229, CVE-2026-61230, CVE-2026-70970 |
|
2026-08-18 |
| critical |
CVE-2026-61241 — Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID L… |
vulnerability |
nvd |
CVE-2026-61241, CVE-2026-61248, CVE-2026-61258 |
|
2026-08-18 |
| critical |
CVE-2026-61272 — Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run… |
vulnerability |
nvd |
CVE-2026-61272 |
|
2026-08-18 |
| critical |
CVE-2026-61317 — Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel C… |
vulnerability |
nvd |
CVE-2026-61317, CVE-2026-61318, CVE-2026-61321, CVE-2026-61326, CVE-2026-61330, CVE-2026-61332, CVE-2026-61339, CVE-2026-61341, CVE-2026-62442, CVE-2026-62452, CVE-2026-62454, CVE-2026-62455, CVE-2026-62512 |
|
2026-08-18 |
| critical |
CVE-2026-62585 — Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archiva… |
vulnerability |
nvd |
CVE-2026-62585, CVE-2026-62586, CVE-2026-62587 |
|
2026-08-18 |
| critical |
CVE-2026-62588 — Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integratio… |
vulnerability |
nvd |
CVE-2026-62588, CVE-2026-62589, CVE-2026-62590, CVE-2026-62591, CVE-2026-62592, CVE-2026-62593, CVE-2026-62594, CVE-2026-62595, CVE-2026-62596 |
|
2026-08-18 |
| critical |
CVE-2026-62608 — Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Securi… |
vulnerability |
nvd |
CVE-2026-62608, CVE-2026-62609, CVE-2026-62610, CVE-2026-62611, CVE-2026-62612, CVE-2026-62613, CVE-2026-62614, CVE-2026-62615, CVE-2026-62616, CVE-2026-62617, CVE-2026-62618, CVE-2026-62619, CVE-2026-62620, CVE-2026-62621, CVE-2026-62622, CVE-2026-62623, CVE-2026-62624, CVE-2026-62625, CVE-2026-62626, CVE-2026-62627, CVE-2026-62628, CVE-2026-62629, CVE-2026-62630, CVE-2026-62631, CVE-2026-62632, CVE-2026-62633, CVE-2026-62634, CVE-2026-62635, CVE-2026-62636, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70670, CVE-2026-70671, CVE-2026-70672, CVE-2026-70673, CVE-2026-70674, CVE-2026-70675 |
|
2026-08-18 |
| critical |
CVE-2026-62988 — Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Cu… |
vulnerability |
nvd |
CVE-2026-62988 |
|
2026-08-18 |
| critical |
CVE-2026-70689 — Vulnerability in Oracle Essbase (component: Infrastructure). The supported version that is affected… |
vulnerability |
nvd |
CVE-2026-70689 |
|
2026-08-18 |
| critical |
CVE-2026-70721 — Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (c… |
vulnerability |
nvd |
CVE-2026-70721, CVE-2026-70723, CVE-2026-70730, CVE-2026-70733, CVE-2026-70735, CVE-2026-70736, CVE-2026-70738 |
|
2026-08-18 |
| critical |
CVE-2026-70817 — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Sec… |
vulnerability |
nvd |
CVE-2026-70817, CVE-2026-70818, CVE-2026-70819, CVE-2026-70821, CVE-2026-70822, CVE-2026-70823, CVE-2026-70824, CVE-2026-70825, CVE-2026-70826, CVE-2026-70828, CVE-2026-70831, CVE-2026-70832, CVE-2026-70834, CVE-2026-70836, CVE-2026-70838, CVE-2026-70840, CVE-2026-70841, CVE-2026-70842, CVE-2026-70843, CVE-2026-70847, CVE-2026-70848, CVE-2026-70849, CVE-2026-70850, CVE-2026-70851, CVE-2026-70853, CVE-2026-70854, CVE-2026-70909, CVE-2026-70911, CVE-2026-70912, CVE-2026-70914, CVE-2026-70916, CVE-2026-70917, CVE-2026-70919, CVE-2026-70920, CVE-2026-70921, CVE-2026-70925, CVE-2026-70928, CVE-2026-70929, CVE-2026-70933, CVE-2026-70934, CVE-2026-70935, CVE-2026-70936, CVE-2026-70937, CVE-2026-70938, CVE-2026-70939, CVE-2026-70940, CVE-2026-70942, CVE-2026-70943, CVE-2026-70944, CVE-2026-70946, CVE-2026-70950, CVE-2026-70952, CVE-2026-70960, CVE-2026-70969, CVE-2026-70974, CVE-2026-70975, CVE-2026-71013, CVE-2026-71060, CVE-2026-71085, CVE-2026-71090, CVE-2026-71091, CVE-2026-71103, CVE-2026-71105, CVE-2026-71108, CVE-2026-71109, CVE-2026-71117, CVE-2026-71118, CVE-2026-71119, CVE-2026-71120, CVE-2026-71121, CVE-2026-71123, CVE-2026-71144, CVE-2026-71145, CVE-2026-71146, CVE-2026-71147, CVE-2026-71148, CVE-2026-71149, CVE-2026-71150 |
|
2026-08-18 |
| critical |
CVE-2026-70846 — Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Oper… |
vulnerability |
nvd |
CVE-2026-70846, CVE-2026-70852 |
supply-chain |
2026-08-18 |
| critical |
CVE-2026-70855 — Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Tr… |
vulnerability |
nvd |
CVE-2026-70855 |
|
2026-08-18 |
| critical |
CVE-2026-70862 — Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.… |
vulnerability |
nvd |
CVE-2026-70862, CVE-2026-70863, CVE-2026-70864, CVE-2026-70865, CVE-2026-70866, CVE-2026-70867, CVE-2026-70868 |
|
2026-08-18 |
| critical |
CVE-2026-70870 — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (compon… |
vulnerability |
nvd |
CVE-2026-70870, CVE-2026-70871, CVE-2026-70872, CVE-2026-70873, CVE-2026-70874, CVE-2026-70875, CVE-2026-70876, CVE-2026-70877, CVE-2026-70878, CVE-2026-70879, CVE-2026-70880, CVE-2026-70881, CVE-2026-70882, CVE-2026-70883, CVE-2026-70884, CVE-2026-70885, CVE-2026-70886, CVE-2026-70887, CVE-2026-70888, CVE-2026-70889, CVE-2026-70890, CVE-2026-70891, CVE-2026-70892, CVE-2026-70893, CVE-2026-70894, CVE-2026-70895, CVE-2026-70896, CVE-2026-70897, CVE-2026-70898, CVE-2026-70899, CVE-2026-70900, CVE-2026-70901, CVE-2026-70902, CVE-2026-70903, CVE-2026-70904 |
|
2026-08-18 |
| critical |
CVE-2026-70905 — Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Agent inf… |
vulnerability |
nvd |
CVE-2026-70905 |
|
2026-08-18 |
| critical |
CVE-2026-70926 — Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notific… |
vulnerability |
nvd |
CVE-2026-70926, CVE-2026-70927, CVE-2026-70931 |
|
2026-08-18 |
| critical |
CVE-2026-70953 — Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Applicat… |
vulnerability |
nvd |
CVE-2026-70953, CVE-2026-70954, CVE-2026-70955 |
|
2026-08-18 |
| critical |
CVE-2026-70976 — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O… |
vulnerability |
nvd |
CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70982, CVE-2026-70983, CVE-2026-70984, CVE-2026-70985, CVE-2026-70986, CVE-2026-70987, CVE-2026-70988, CVE-2026-70989, CVE-2026-70990, CVE-2026-70991, CVE-2026-70992, CVE-2026-70993, CVE-2026-70994, CVE-2026-70995, CVE-2026-70996, CVE-2026-70997, CVE-2026-70998, CVE-2026-70999, CVE-2026-71000, CVE-2026-71001, CVE-2026-71002, CVE-2026-71003, CVE-2026-71004, CVE-2026-71005, CVE-2026-71006, CVE-2026-71007, CVE-2026-71008, CVE-2026-71009, CVE-2026-71010, CVE-2026-71011, CVE-2026-71012, CVE-2026-71014, CVE-2026-71015, CVE-2026-71016, CVE-2026-71017, CVE-2026-71018, CVE-2026-71019, CVE-2026-71020, CVE-2026-71021, CVE-2026-71022, CVE-2026-71023, CVE-2026-71024, CVE-2026-71025, CVE-2026-71026, CVE-2026-71027, CVE-2026-71028, CVE-2026-71030, CVE-2026-71031, CVE-2026-71032, CVE-2026-71033, CVE-2026-71034, CVE-2026-71035, CVE-2026-71036, CVE-2026-71037, CVE-2026-71038 |
|
2026-08-18 |
| critical |
CVE-2026-71040 — Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supp… |
vulnerability |
nvd |
CVE-2026-71040, CVE-2026-71043, CVE-2026-71045, CVE-2026-71046 |
supply-chain |
2026-08-18 |
| critical |
CVE-2026-71058 — Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). S… |
vulnerability |
nvd |
CVE-2026-71058, CVE-2026-71059 |
|
2026-08-18 |
| critical |
CVE-2026-71063 — Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions th… |
vulnerability |
nvd |
CVE-2026-71063, CVE-2026-71064, CVE-2026-71102 |
|
2026-08-18 |
| critical |
CVE-2026-76035 — Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a r… |
vulnerability |
nvd |
CVE-2026-76035 |
|
2026-08-18 |
| critical |
CVE-2026-76036 — Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote atta… |
vulnerability |
nvd |
CVE-2026-76036 |
|
2026-08-18 |
| critical |
CVE-2026-75976 — A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of… |
vulnerability |
nvd |
CVE-2026-75976 |
|
2026-08-19 |
| critical |
CVE-2026-76003 — A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strc… |
vulnerability |
nvd |
CVE-2026-76003 |
|
2026-08-19 |
| critical |
CVE-2026-76004 — A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected b… |
vulnerability |
nvd |
CVE-2026-76004 |
|
2026-08-19 |
| critical |
CVE-2026-76008 — A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the… |
vulnerability |
nvd |
CVE-2026-76008 |
|
2026-08-19 |
| critical |
CVE-2026-18031 — The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before est… |
vulnerability |
nvd |
CVE-2026-18031 |
|
2026-08-19 |
| critical |
CVE-2026-18051 — The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it use… |
vulnerability |
nvd |
CVE-2026-18051 |
|
2026-08-19 |
| critical |
CVE-2026-18776 — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of it… |
vulnerability |
nvd |
CVE-2026-18776, CVE-2026-18778 |
|
2026-08-19 |
| critical |
CVE-2026-18937 — The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accep… |
vulnerability |
nvd |
CVE-2026-18937 |
|
2026-08-19 |
| critical |
CVE-2026-58085 — After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to ch… |
vulnerability |
nvd |
CVE-2026-58085 |
ransomware |
2026-08-19 |
| critical |
CVE-2026-18371 — HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to… |
vulnerability |
nvd |
CVE-2026-18371 |
ransomware |
2026-08-19 |
| critical |
CVE-2026-18372 — CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault adminis… |
vulnerability |
nvd |
CVE-2026-18372 |
ransomware |
2026-08-19 |
| critical |
CVE-2026-66613 — Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions. |
vulnerability |
nvd |
CVE-2026-66613 |
rce |
2026-08-19 |
| critical |
CVE-2026-73183 — Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. |
vulnerability |
nvd |
CVE-2026-73183 |
|
2026-08-19 |
| critical |
CVE-2026-73185 — Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. |
vulnerability |
nvd |
CVE-2026-73185 |
|
2026-08-19 |
| critical |
CVE-2026-73347 — Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. |
vulnerability |
nvd |
CVE-2026-73347 |
|
2026-08-19 |
| critical |
CVE-2026-73364 — Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. |
vulnerability |
nvd |
CVE-2026-73364 |
|
2026-08-19 |
| critical |
CVE-2026-73388 — Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. |
vulnerability |
nvd |
CVE-2026-73388 |
|
2026-08-19 |
| critical |
CVE-2026-73389 — Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. |
vulnerability |
nvd |
CVE-2026-73389 |
|
2026-08-19 |
| critical |
CVE-2026-73390 — Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. |
vulnerability |
nvd |
CVE-2026-73390 |
|
2026-08-19 |
| critical |
CVE-2026-73391 — Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. |
vulnerability |
nvd |
CVE-2026-73391 |
|
2026-08-19 |
| critical |
CVE-2026-16019 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i… |
vulnerability |
nvd |
CVE-2026-16019, CVE-2026-74011, CVE-2026-63037, CVE-2026-63038, CVE-2026-63039 |
|
2026-08-19 |
| critical |
CVE-2026-15065 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security r… |
vulnerability |
nvd |
CVE-2026-15065 |
|
2026-08-19 |
| critical |
CVE-2026-15068 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to exe… |
vulnerability |
nvd |
CVE-2026-15068 |
|
2026-08-19 |
| critical |
CVE-2026-16656 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges… |
vulnerability |
nvd |
CVE-2026-16656 |
|
2026-08-19 |
| critical |
CVE-2026-16690 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser… |
vulnerability |
nvd |
CVE-2026-16690, CVE-2026-16706, CVE-2026-16817, CVE-2026-16818, CVE-2026-16824, CVE-2026-16827, CVE-2026-16829, CVE-2026-16831, CVE-2026-16834, CVE-2026-16836, CVE-2026-16837, CVE-2026-16846, CVE-2026-16849, CVE-2026-16851, CVE-2026-16852, CVE-2026-16866, CVE-2026-16886, CVE-2026-16924, CVE-2026-16928, CVE-2026-16958, CVE-2026-17120, CVE-2026-17121, CVE-2026-17159, CVE-2026-17163, CVE-2026-17165, CVE-2026-17170, CVE-2026-17425, CVE-2026-18670, CVE-2026-18828 |
|
2026-08-19 |
| critical |
CVE-2026-16814 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod… |
vulnerability |
nvd |
CVE-2026-16814, CVE-2026-16840, CVE-2026-16841, CVE-2026-16845, CVE-2026-16847, CVE-2026-16850, CVE-2026-16862, CVE-2026-16864, CVE-2026-16865, CVE-2026-16872, CVE-2026-16885, CVE-2026-16894, CVE-2026-16901, CVE-2026-16903, CVE-2026-16909, CVE-2026-16913, CVE-2026-16917, CVE-2026-16919, CVE-2026-17000, CVE-2026-17006, CVE-2026-17024, CVE-2026-17040, CVE-2026-17118, CVE-2026-17122, CVE-2026-17136, CVE-2026-17138, CVE-2026-17141, CVE-2026-17145, CVE-2026-17152, CVE-2026-17157, CVE-2026-17160, CVE-2026-17436, CVE-2026-18832, CVE-2026-19437 |
|
2026-08-19 |
| critical |
CVE-2026-16816 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute… |
vulnerability |
nvd |
CVE-2026-16816, CVE-2026-16877, CVE-2026-16911, CVE-2026-17168, CVE-2026-18824, CVE-2026-18835 |
|
2026-08-19 |
| critical |
CVE-2026-47187 — SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue… |
vulnerability |
nvd |
CVE-2026-47187 |
|
2026-08-19 |
| critical |
CVE-2026-52889 — Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hi… |
vulnerability |
nvd |
CVE-2026-52889 |
rce |
2026-08-19 |
| critical |
CVE-2026-53451 — Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and… |
vulnerability |
nvd |
CVE-2026-53451, CVE-2026-53452 |
|
2026-08-19 |
| critical |
CVE-2026-71960 — Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnera… |
vulnerability |
nvd |
CVE-2026-71960 |
|
2026-08-19 |
| critical |
CVE-2026-44252 — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4… |
vulnerability |
nvd |
CVE-2026-44252, CVE-2026-46343, CVE-2026-41424, CVE-2026-44255, CVE-2026-44256, CVE-2026-44901, CVE-2026-45798, CVE-2026-48024, CVE-2026-48162, CVE-2026-49392, CVE-2026-49441 |
|
2026-08-19 |
| critical |
CVE-2026-20030 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork… |
vulnerability |
nvd |
CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, CVE-2026-20359 |
|
2026-08-19 |
| critical |
CVE-2026-20231 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Wo… |
vulnerability |
nvd |
CVE-2026-20231, CVE-2026-20315, CVE-2026-20317, CVE-2026-20318, CVE-2026-20319 |
|
2026-08-19 |
| critical |
CVE-2026-71470 — A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specificall… |
vulnerability |
nvd |
CVE-2026-71470 |
|
2026-08-19 |
| critical |
CVE-2026-75143 — FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavforma… |
vulnerability |
nvd |
CVE-2026-75143 |
|
2026-08-19 |
| critical |
CVE-2026-32475 — Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Usin… |
vulnerability |
nvd |
CVE-2026-32475 |
|
2026-08-19 |
| critical |
CVE-2026-66794 — A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This… |
vulnerability |
nvd |
CVE-2026-66794 |
|
2026-08-19 |
| critical |
CVE-2026-67581 — Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to ob… |
vulnerability |
nvd |
CVE-2026-67581 |
ransomware |
2026-08-19 |
| critical |
CVE-2026-73136 — Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obta… |
vulnerability |
nvd |
CVE-2026-73136 |
ransomware |
2026-08-19 |
| critical |
CVE-2026-73829 — Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote cl… |
vulnerability |
nvd |
CVE-2026-73829 |
ransomware |
2026-08-19 |
| critical |
CVE-2026-16687 — IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and… |
vulnerability |
nvd |
CVE-2026-16687, CVE-2026-16828, CVE-2026-16832, CVE-2026-16835, CVE-2026-16938, CVE-2026-18848 |
|
2026-08-19 |
| critical |
CVE-2026-18315 — The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Auth… |
vulnerability |
nvd |
CVE-2026-18315 |
|
2026-08-19 |
| critical |
CVE-2026-70496 — A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a c… |
vulnerability |
nvd |
CVE-2026-70496 |
|
2026-08-19 |
| critical |
CVE-2026-16822 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC p… |
vulnerability |
nvd |
CVE-2026-16822 |
|
2026-08-19 |
| critical |
CVE-2026-16839 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive info… |
vulnerability |
nvd |
CVE-2026-16839, CVE-2026-16888, CVE-2026-16972, CVE-2026-17060, CVE-2026-17423 |
|
2026-08-19 |
| critical |
CVE-2026-16842 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary com… |
vulnerability |
nvd |
CVE-2026-16842, CVE-2026-16844, CVE-2026-16848, CVE-2026-16882, CVE-2026-17142 |
|
2026-08-19 |
| critical |
CVE-2026-16869 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code… |
vulnerability |
nvd |
CVE-2026-16869, CVE-2026-16914, CVE-2026-16922, CVE-2026-16936, CVE-2026-16943, CVE-2026-16944, CVE-2026-16945, CVE-2026-16996, CVE-2026-17124, CVE-2026-17422, CVE-2026-18840 |
|
2026-08-19 |
| critical |
CVE-2026-22306 — Download of code without integrity check, inclusion of functionality from untrusted control sphere,… |
vulnerability |
nvd |
CVE-2026-22306 |
|
2026-08-19 |
| critical |
CVE-2026-55085 — Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/dom… |
vulnerability |
nvd |
CVE-2026-55085 |
|
2026-08-19 |
| critical |
CVE-2026-55089 — Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/AP… |
vulnerability |
nvd |
CVE-2026-55089 |
|
2026-08-19 |
| critical |
CVE-2026-63722 — ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthentic… |
vulnerability |
nvd |
CVE-2026-63722 |
rce |
2026-08-19 |
| critical |
CVE-2026-53542 — Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa… |
vulnerability |
nvd |
CVE-2026-53542, CVE-2026-53545, CVE-2026-53546, CVE-2026-53547, CVE-2026-53548, CVE-2026-53549 |
|
2026-08-19 |
| critical |
CVE-2026-54494 — Koel is a free, open-source music streaming solution. Prior to 9.7.1, App\Helpers\Network::isPublicH… |
vulnerability |
nvd |
CVE-2026-54494 |
ransomware |
2026-08-19 |
| critical |
CVE-2026-76584 — A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some… |
vulnerability |
nvd |
CVE-2026-76584 |
|
2026-08-19 |
| critical |
CVE-2026-76310 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who… |
vulnerability |
nvd |
CVE-2026-76310, CVE-2026-76311, CVE-2026-76338 |
|
2026-08-19 |
| critical |
CVE-2026-76312 — In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who… |
vulnerability |
nvd |
CVE-2026-76312 |
|
2026-08-19 |
| critical |
CVE-2026-76404 — In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execut… |
vulnerability |
nvd |
CVE-2026-76404 |
|
2026-08-19 |
| critical |
CVE-2026-76589 — A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000… |
vulnerability |
nvd |
CVE-2026-76589 |
|
2026-08-19 |
| critical |
CVE-2026-76590 — A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some… |
vulnerability |
nvd |
CVE-2026-76590 |
|
2026-08-19 |
| critical |
CVE-2026-76850 — LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine… |
vulnerability |
nvd |
CVE-2026-76850 |
|
2026-08-19 |
| critical |
CVE-2026-75860 — The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verifica… |
vulnerability |
nvd |
CVE-2026-75860 |
|
2026-08-20 |
| critical |
CVE-2026-14950 — An unauthenticated remote attacker in possession of a valid session identifier is able to continue u… |
vulnerability |
nvd |
CVE-2026-14950 |
|
2026-08-20 |
| critical |
CVE-2026-11861 — A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Dire… |
vulnerability |
nvd |
CVE-2026-11861 |
|
2026-08-20 |
| critical |
CVE-2026-13097 — A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos pri… |
vulnerability |
nvd |
CVE-2026-13097 |
|
2026-08-20 |
| critical |
CVE-2025-15688 — Unauthenticated SQL Injection in Capella <= 2.5.5 versions. |
vulnerability |
nvd |
CVE-2025-15688 |
|
2026-08-20 |
| critical |
CVE-2025-15689 — Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. |
vulnerability |
nvd |
CVE-2025-15689 |
|
2026-08-20 |
| critical |
CVE-2026-66583 — Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. |
vulnerability |
nvd |
CVE-2026-66583 |
|
2026-08-20 |
| critical |
CVE-2026-66592 — Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. |
vulnerability |
nvd |
CVE-2026-66592 |
|
2026-08-20 |
| critical |
CVE-2026-66593 — Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. |
vulnerability |
nvd |
CVE-2026-66593 |
|
2026-08-20 |
| critical |
CVE-2026-66600 — Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. |
vulnerability |
nvd |
CVE-2026-66600 |
|
2026-08-20 |
| critical |
CVE-2026-66609 — Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. |
vulnerability |
nvd |
CVE-2026-66609 |
|
2026-08-20 |
| critical |
CVE-2026-66649 — Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. |
vulnerability |
nvd |
CVE-2026-66649 |
|
2026-08-20 |
| critical |
CVE-2026-66672 — Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. |
vulnerability |
nvd |
CVE-2026-66672 |
|
2026-08-20 |
| critical |
CVE-2026-66680 — Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions. |
vulnerability |
nvd |
CVE-2026-66680 |
|
2026-08-20 |
| critical |
CVE-2026-66682 — Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. |
vulnerability |
nvd |
CVE-2026-66682 |
|
2026-08-20 |
| critical |
CVE-2026-68566 — Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. |
vulnerability |
nvd |
CVE-2026-68566 |
|
2026-08-20 |
| critical |
CVE-2026-73992 — Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions. |
vulnerability |
nvd |
CVE-2026-73992 |
rce |
2026-08-20 |
| critical |
CVE-2026-74001 — Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. |
vulnerability |
nvd |
CVE-2026-74001 |
|
2026-08-20 |
| critical |
CVE-2026-74014 — Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions. |
vulnerability |
nvd |
CVE-2026-74014 |
|
2026-08-20 |
| critical |
CVE-2026-74016 — Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions. |
vulnerability |
nvd |
CVE-2026-74016 |
|
2026-08-20 |
| critical |
CVE-2026-74018 — Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. |
vulnerability |
nvd |
CVE-2026-74018 |
|
2026-08-20 |
| critical |
CVE-2026-77068 — n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n… |
vulnerability |
nvd |
CVE-2026-77068 |
rce |
2026-08-20 |
| critical |
CVE-2026-18482 — Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the… |
vulnerability |
nvd |
CVE-2026-18482 |
ransomware |
2026-08-20 |
| critical |
CVE-2026-28164 — Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Sit… |
vulnerability |
nvd |
CVE-2026-28164 |
|
2026-08-20 |
| critical |
CVE-2026-15706 — Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry… |
vulnerability |
nvd |
CVE-2026-15706 |
|
2026-08-20 |
| critical |
CVE-2026-64960 — ATutor Gameme module allows users to upload files of any type and extension without restriction. Due… |
vulnerability |
nvd |
CVE-2026-64960 |
rce |
2026-08-20 |
| critical |
CVE-2026-64966 — ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker… |
vulnerability |
nvd |
CVE-2026-64966 |
rce |
2026-08-20 |
| critical |
CVE-2026-16926 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary f… |
vulnerability |
nvd |
CVE-2026-16926 |
|
2026-08-20 |
| critical |
CVE-2026-15679 — Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution… |
vulnerability |
nvd |
CVE-2026-15679 |
rce |
2026-08-20 |
| critical |
CVE-2026-15686 — Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. Th… |
vulnerability |
nvd |
CVE-2026-15686 |
rce |
2026-08-20 |
| critical |
CVE-2026-18264 — NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows r… |
vulnerability |
nvd |
CVE-2026-18264 |
rce |
2026-08-20 |
| critical |
CVE-2026-18265 — OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability al… |
vulnerability |
nvd |
CVE-2026-18265 |
rce |
2026-08-20 |
| critical |
CVE-2026-18274 — Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This… |
vulnerability |
nvd |
CVE-2026-18274 |
rce |
2026-08-20 |
| critical |
CVE-2026-18279 — Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability. This vulnerability a… |
vulnerability |
nvd |
CVE-2026-18279 |
rce |
2026-08-20 |
| critical |
CVE-2026-18281 — Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability. Th… |
vulnerability |
nvd |
CVE-2026-18281 |
rce |
2026-08-20 |
| critical |
CVE-2026-18282 — Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerabil… |
vulnerability |
nvd |
CVE-2026-18282 |
rce |
2026-08-20 |
| critical |
CVE-2026-18285 — Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability.… |
vulnerability |
nvd |
CVE-2026-18285 |
rce |
2026-08-20 |
| critical |
CVE-2026-18286 — Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability. T… |
vulnerability |
nvd |
CVE-2026-18286 |
rce |
2026-08-20 |
| critical |
CVE-2026-18287 — Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerability. Thi… |
vulnerability |
nvd |
CVE-2026-18287 |
rce |
2026-08-20 |
| critical |
CVE-2026-18288 — OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This… |
vulnerability |
nvd |
CVE-2026-18288 |
rce |
2026-08-20 |
| critical |
CVE-2026-18289 — OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This v… |
vulnerability |
nvd |
CVE-2026-18289 |
rce |
2026-08-20 |
| critical |
CVE-2026-18290 — OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This v… |
vulnerability |
nvd |
CVE-2026-18290 |
rce |
2026-08-20 |
| critical |
CVE-2026-18291 — OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vul… |
vulnerability |
nvd |
CVE-2026-18291 |
rce |
2026-08-20 |
| critical |
CVE-2026-18292 — OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vul… |
vulnerability |
nvd |
CVE-2026-18292 |
rce |
2026-08-20 |
| critical |
CVE-2026-18293 — OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. Th… |
vulnerability |
nvd |
CVE-2026-18293 |
rce |
2026-08-20 |
| critical |
CVE-2026-18294 — OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This… |
vulnerability |
nvd |
CVE-2026-18294 |
rce |
2026-08-20 |
| critical |
CVE-2026-18295 — GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerabili… |
vulnerability |
nvd |
CVE-2026-18295 |
rce |
2026-08-20 |
| critical |
CVE-2026-18296 — GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vuln… |
vulnerability |
nvd |
CVE-2026-18296 |
rce |
2026-08-20 |
| critical |
CVE-2026-18297 — GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vul… |
vulnerability |
nvd |
CVE-2026-18297 |
rce |
2026-08-20 |
| critical |
CVE-2026-18298 — GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vuln… |
vulnerability |
nvd |
CVE-2026-18298 |
rce |
2026-08-20 |
| critical |
CVE-2026-18299 — GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows… |
vulnerability |
nvd |
CVE-2026-18299 |
rce |
2026-08-20 |
| critical |
CVE-2026-18300 — GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow… |
vulnerability |
nvd |
CVE-2026-18300 |
rce |
2026-08-20 |
| critical |
CVE-2026-18301 — GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow… |
vulnerability |
nvd |
CVE-2026-18301 |
rce |
2026-08-20 |
| critical |
CVE-2026-18302 — GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabi… |
vulnerability |
nvd |
CVE-2026-18302, CVE-2026-18307 |
rce |
2026-08-20 |
| critical |
CVE-2026-18303 — GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerab… |
vulnerability |
nvd |
CVE-2026-18303 |
rce |
2026-08-20 |
| critical |
CVE-2026-18304 — GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow… |
vulnerability |
nvd |
CVE-2026-18304, CVE-2026-18305, CVE-2026-18308 |
rce |
2026-08-20 |
| critical |
CVE-2026-18306 — GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow… |
vulnerability |
nvd |
CVE-2026-18306 |
rce |
2026-08-20 |
| critical |
CVE-2026-18309 — GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allo… |
vulnerability |
nvd |
CVE-2026-18309 |
rce |
2026-08-20 |
| critical |
CVE-2026-55642 — dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in c… |
vulnerability |
nvd |
CVE-2026-55642 |
|
2026-08-20 |
| critical |
CVE-2026-71428 — The unstructured library provides open-source components for ingesting and pre-processing images and… |
vulnerability |
nvd |
CVE-2026-71428 |
|
2026-08-20 |
| critical |
CVE-2026-77022 — A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the functi… |
vulnerability |
nvd |
CVE-2026-77022 |
|
2026-08-20 |
| critical |
CVE-2026-2334 — An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges… |
vulnerability |
nvd |
CVE-2026-2334 |
rce |
2026-08-20 |
| critical |
CVE-2026-53424 — Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authent… |
vulnerability |
nvd |
CVE-2026-53424 |
ransomware |
2026-08-20 |
| critical |
CVE-2026-73256 — Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated atta… |
vulnerability |
nvd |
CVE-2026-73256 |
|
2026-08-20 |
| critical |
CVE-2026-73257 — Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthentica… |
vulnerability |
nvd |
CVE-2026-73257 |
|
2026-08-20 |
| critical |
CVE-2026-66785 — A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect ne… |
vulnerability |
nvd |
CVE-2026-66785 |
|
2026-08-20 |
| critical |
CVE-2026-66788 — A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vu… |
vulnerability |
nvd |
CVE-2026-66788 |
|
2026-08-20 |
| critical |
CVE-2026-77148 — A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the fi… |
vulnerability |
nvd |
CVE-2026-77148 |
|
2026-08-20 |
| critical |
CVE-2026-67567 — A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a ten… |
vulnerability |
nvd |
CVE-2026-67567 |
|
2026-08-20 |
| critical |
CVE-2026-69242 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted… |
vulnerability |
nvd |
CVE-2026-69242 |
rce |
2026-08-20 |
| critical |
CVE-2026-71485 — Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies… |
vulnerability |
nvd |
CVE-2026-71485 |
|
2026-08-20 |
| critical |
CVE-2026-62834 — Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attack… |
vulnerability |
nvd |
CVE-2026-62834 |
|
2026-08-20 |
| critical |
CVE-2026-63509 — Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over… |
vulnerability |
nvd |
CVE-2026-63509 |
|
2026-08-20 |
| critical |
CVE-2026-65770 — Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed… |
vulnerability |
nvd |
CVE-2026-65770 |
|
2026-08-20 |
| critical |
CVE-2026-65801 — Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to e… |
vulnerability |
nvd |
CVE-2026-65801 |
|
2026-08-20 |
| critical |
CVE-2026-65816 — Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevat… |
vulnerability |
nvd |
CVE-2026-65816 |
|
2026-08-20 |
| critical |
CVE-2026-66309 — Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges ov… |
vulnerability |
nvd |
CVE-2026-66309 |
|
2026-08-20 |
| critical |
CVE-2026-68782 — Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Da… |
vulnerability |
nvd |
CVE-2026-68782, CVE-2026-68789 |
|
2026-08-20 |
| critical |
CVE-2026-69400 — Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps a… |
vulnerability |
nvd |
CVE-2026-69400 |
|
2026-08-20 |
| critical |
CVE-2026-69555 — Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a ne… |
vulnerability |
nvd |
CVE-2026-69555 |
|
2026-08-20 |
| critical |
CVE-2026-69836 — Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute c… |
vulnerability |
nvd |
CVE-2026-69836 |
|
2026-08-20 |
| critical |
CVE-2026-69851 — Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevat… |
vulnerability |
nvd |
CVE-2026-69851 |
|
2026-08-20 |
| critical |
CVE-2026-72843 — The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/m… |
vulnerability |
nvd |
CVE-2026-72843 |
|
2026-08-20 |
| critical |
CVE-2026-77645 — A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC Flex… |
vulnerability |
nvd |
CVE-2026-77645 |
rce |
2026-08-20 |
| critical |
CVE-2026-77647 — SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited i… |
vulnerability |
nvd |
CVE-2026-77647 |
|
2026-08-20 |
| critical |
CVE-2026-77649 — The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project… |
vulnerability |
nvd |
CVE-2026-77649 |
botnet |
2026-08-21 |
| critical |
CVE-2026-77650 — The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a pr… |
vulnerability |
nvd |
CVE-2026-77650 |
botnet |
2026-08-21 |
| critical |
CVE-2026-77651 — The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project… |
vulnerability |
nvd |
CVE-2026-77651 |
botnet |
2026-08-21 |
| critical |
CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-20 |
| critical |
CVE-2026-61363 Remote Desktop Client Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-20 |
| critical |
CVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-20 |
| critical |
CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-20 |
| critical |
CVE-2026-69419 Azure Data Manager for Energy Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-20 |
| critical |
CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-20 |
| critical |
CVE-2026-54118 Microsoft SQL Server Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-20 |
| critical |
CVE-2026-65811 Power BI Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-19 |
| critical |
CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-18 |
| critical |
CVE-2026-56642 Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-18 |
| critical |
CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-17 |
| critical |
CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-17 |
| critical |
CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-17 |
| critical |
CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-17 |
| critical |
CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-17 |
| critical |
CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-16 |
| critical |
CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-16 |
| critical |
CVE-2026-72970 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-14 |
| critical |
CVE-2026-50313 Windows NTFS Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-14 |
| critical |
FBI, CISA, HHS update Medusa ransomware advisory, detail RaaS affiliate model, exploited flaws and attack tools |
advisory |
vendor-blogs |
|
ransomware |
2026-08-19 |
| critical |
Black Kite report finds 73% of ransomware incidents hit mid-market companies amid growing third-party and AI risks |
advisory |
vendor-blogs |
|
ransomware |
2026-08-19 |
| critical |
Malicious IP: 213.209.159.241 |
ip-reputation |
abuse-ipdb |
213.209.159.241 |
|
2026-08-21 |
| critical |
Malicious IP: 64.62.197.138 |
ip-reputation |
abuse-ipdb |
64.62.197.138 |
|
2026-08-21 |
| critical |
Malicious IP: 119.92.70.82 |
ip-reputation |
abuse-ipdb |
119.92.70.82 |
|
2026-08-21 |
| critical |
Malicious IP: 195.26.18.111 |
ip-reputation |
abuse-ipdb |
195.26.18.111 |
|
2026-08-21 |
| critical |
Malicious IP: 181.115.171.216 |
ip-reputation |
abuse-ipdb |
181.115.171.216 |
|
2026-08-21 |
| critical |
Malicious IP: 118.196.68.35 |
ip-reputation |
abuse-ipdb |
118.196.68.35 |
|
2026-08-21 |
| critical |
Malicious IP: 79.124.59.178 |
ip-reputation |
abuse-ipdb |
79.124.59.178 |
|
2026-08-21 |
| critical |
Malicious IP: 79.124.56.142 |
ip-reputation |
abuse-ipdb |
79.124.56.142 |
|
2026-08-21 |
| critical |
Malicious IP: 68.225.61.18 |
ip-reputation |
abuse-ipdb |
68.225.61.18 |
|
2026-08-21 |
| critical |
Malicious IP: 193.47.62.69 |
ip-reputation |
abuse-ipdb |
193.47.62.69 |
|
2026-08-21 |
| critical |
Malicious IP: 163.7.9.55 |
ip-reputation |
abuse-ipdb |
163.7.9.55 |
|
2026-08-21 |
| critical |
Malicious IP: 68.221.130.146 |
ip-reputation |
abuse-ipdb |
68.221.130.146 |
|
2026-08-21 |
| critical |
Malicious IP: 61.184.128.210 |
ip-reputation |
abuse-ipdb |
61.184.128.210 |
|
2026-08-21 |
| critical |
Malicious IP: 70.183.230.195 |
ip-reputation |
abuse-ipdb |
70.183.230.195 |
|
2026-08-21 |
| critical |
Malicious IP: 47.254.134.254 |
ip-reputation |
abuse-ipdb |
47.254.134.254 |
|
2026-08-21 |
| critical |
Malicious IP: 4.206.92.183 |
ip-reputation |
abuse-ipdb |
4.206.92.183 |
|
2026-08-21 |
| critical |
Malicious IP: 45.148.10.240 |
ip-reputation |
abuse-ipdb |
45.148.10.240 |
|
2026-08-21 |
| critical |
Malicious IP: 194.88.98.114 |
ip-reputation |
abuse-ipdb |
194.88.98.114 |
|
2026-08-21 |
| critical |
Malicious IP: 181.116.43.25 |
ip-reputation |
abuse-ipdb |
181.116.43.25 |
|
2026-08-21 |
| critical |
Malicious IP: 45.249.246.17 |
ip-reputation |
abuse-ipdb |
45.249.246.17 |
|
2026-08-21 |
| critical |
payload_delivery: undefined |
threat-intel |
threatfox |
|
ClearFake, mac-0xdcf2, macOS, Cloudflare, gif, PHP, webshell, WordPress, workers.dev, wp-admin, 21August2026, Commandline, mac-0x68dc, CobaltStrike, Vshell, 8560, asyncrat, c2, censys, compromised, etherhide, ClickFix, etherhiding, AISURU, elf, IoT, Mozi, Remus, mac-0x76c7, drb-ra, mac-0x0f14, 20August2026, ErrTraffic, Viper, Havoc, dcrat, PureHVNC, PureRAT, RAT, HypeAgent, Mythic, Supershell, 1xxbot, ArechClient, SectopRAT, CinaRAT, Quasar RAT, QuasarRAT, Yggdrasil, sliver, ResolverRAT, ConnectWise, ScreenConnect, 903ac24fcd9670b9ef2e674243d550d8, Loader, stealer, Vidar, RemusStealer, fake-plugin, nochain, SmartApeSG, win-0xa770, Windows, ValleyRAT, Kongtuke, AgentTesla, XWorm, Dropper, SocGholish, Pink, Adaptix, RevStealer, DomainShadowing, NEWTEST, Stealc, test_2, STRRAT, DanBot, CONTABO, CTFLoaderService, FakeAdobe, iso, LNK, pre-ransomware, velociraptor, cs-watermark-987654321, RemcosRAT, remcos, OffLoader, Socks5Systemz, Mirai, Vjw0rm, RedGuard, shodan, orcus, NetSupport, StarKillerC2, UNAM, AdaptixC2, PowerSploit, locust, GoPhish, phishing, cs-watermark-100000, Amos, nakedpages, Lud, 36903, MetaSploit, fake-copilot, RedLineStealer, 19August2026, njrat, Covenant, NeedleStealer, sliverfox, Gafgyt, rmm, 117ee8f56cb68a9f6a440e1b4329f856, SparkRAT, ExtRat, XTRAT, Xtreme RAT, Agentemis, Beacon, Cobalt Strike, cobeacon, clipboard, ACRStealer, Mac, Breut, darkcomet, Fynloski, klovbot, Lumma, NanoCore, SnappyClient, Diamotrix, URLscan, EvilGinx, EvilGoPhish, CHAOS, x4tte, PureLogsStealer, LxBaseRAT, ProRat, Panda, EpsteinClient, NetSupportManager, NetSupportRAT, 592a9e009f92c0e8eaea74a337b4f67c, capture-drop, honeypot, ssh-dropper, HTA, mexico, WhatsApp, sepolia, tofsee, web-inject, Spynote, HookBot, Byakugan, nc, gs-netcat, gsocket, moobot, nimplant, quasar, sectop, shadowpad, cs-watermark-1234567890, valleyrat_s2, 8395ea90eca49b3f66c2a339ab377348, 974b6b4ed30ddaa4b6f4ec27976e52d8, IRAHook, 40999, 45090, gated, poshc2, BianLian, PG, hook, Deimos, Magecart, userr, 4-72, card-theft, COLOMBIA, otp-relay, phishing-kit, telegram-exfil, tg.pe, BlakcSeeStealer, 726a8431d5d2ee941d0e6046b5948889, 17August2026, Loki, DinDoor, 16August2026, NetSupportManager RAT, Nancrat, NanoCore RAT, Remvio, Socmer, Bladabindi, Lime-Worm, Venom RAT, Farfli, Gh0st RAT, Ghost RAT, PCRat, Polygon, 6c0969259a3975582cd8a48f4c8913d7, UnamPanel, v1, 8075, 329556, 214961, kimwolf, 5fdb6df778631818165110294c620890, a6416186c7730e38c492792c820881c3, majinahanashi, Ransomware, whack.sh, 013c5d2d6312702c9bd8d7499170ed6b, aa462c8dcc4d1e29e6e35cbe1cd9ac85, build3, newbuild, 0f81469cc7638ba7c82eaddbd6b3c20a, cs-watermark-666666666, Cloudflare Inc., 15August2026, mac-0xfb64, mac-0xe447, be6f50208246a51977f7066c1ea613a0, e9bf104a963da535b0fb5aaebe6f06e1, 51c45d4bde39c5d7874e05e8c68314ca, 14August2026, cc382e7a75ab8441eee2f40142be37ed, AnimateClipper, LegionLoader, SheetRAT, MintsLoader, build1, L1, WilsonC2, panel, PhantomStrikeC2, EvilgnixC2, Tr4nsHack, ZygiskC2, AuraStealer, domain, DPRK, kimsuky, MoonPeak, Stella, golang, zimbra, zimbra-exfil, ZMBX, workes.dev, 14618, a77f04bc08864469eb801630c24264ba, AsynRAT, malware, d8b0m, ransomware, apt, botnet, infostealer |
2026-08-21 |
| critical |
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2 |
threat-intel |
otx |
45.158.196.184, 45.158.196.23 | 20675a659c338f72… |
github c2, backdoor, clickfix, oyster, initial access broker, lactrodectus, rust-based, dll sideloading, c2looper, ransomware, botnet |
2026-08-17 |
| critical |
Projextor: Abusing Electron in Trojanized Productivity Applications |
threat-intel |
otx |
e7bc36c7345b3894…, b648ec0880e9f542… |
javascript execution, trojanized software, impersonation websites, desktop capture, projextor, productivity applications, tamperedchef, electron framework |
2026-08-17 |
| critical |
Critical Elementor Pro bug exposes WordPress sites to RCE attacks |
news |
general-news |
|
rce |
2026-08-20 |
| critical |
Critical Zimbra RCE flaw now actively exploited in attacks |
news |
general-news |
|
rce |
2026-08-20 |
| critical |
Rogue ransomware affiliate poses as recovery firm to steal payments |
news |
general-news |
|
ransomware |
2026-08-19 |
| critical |
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More |
news |
general-news |
|
rce |
2026-08-20 |
| critical |
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE |
news |
general-news |
|
rce |
2026-08-20 |
| critical |
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution |
news |
general-news |
|
rce |
2026-08-20 |
| critical |
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code |
news |
general-news |
|
rce |
2026-08-20 |
| critical |
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data |
news |
general-news |
|
ransomware |
2026-08-19 |
| critical |
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000 |
news |
general-news |
|
ransomware |
2026-08-18 |
| critical |
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE |
news |
general-news |
|
rce |
2026-08-18 |
| critical |
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads |
news |
general-news |
|
rce |
2026-08-17 |
| critical |
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More |
news |
general-news |
|
zeroday, supply-chain |
2026-08-17 |
| critical |
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access |
news |
general-news |
|
rce |
2026-08-17 |
| critical |
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware |
news |
general-news |
|
ransomware, apt |
2026-08-17 |
| critical |
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth |
news |
general-news |
|
apt, botnet |
2026-08-14 |
| critical |
'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service |
news |
general-news |
|
ransomware |
2026-08-18 |
| critical |
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities |
news |
general-news |
|
rce |
2026-08-20 |
| critical |
Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware |
news |
general-news |
|
ransomware |
2026-08-19 |
| critical |
Three-quarters of Ransomware Attacks Target Mid-Market Firms |
news |
general-news |
|
ransomware |
2026-08-18 |
| critical |
Researchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations |
news |
general-news |
|
apt |
2026-08-14 |
| critical |
The long tail of Clop’s PTC hack is just beginning to emerge |
news |
general-news |
|
ransomware |
2026-08-19 |
| critical |
Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics |
news |
general-news |
|
ransomware |
2026-08-18 |
| high |
CVE-2026-33824 — Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability |
vulnerability |
cisa-kev |
CVE-2026-33824 |
rce |
2026-08-18 |
| high |
CVE-2026-59310 — Broadcom VMware vCenter Path Traversal Vulnerability |
vulnerability |
cisa-kev |
CVE-2026-59310 |
|
2026-08-18 |
| high |
CVE-2026-55040 — Microsoft SharePoint Weak Authentication Vulnerability |
vulnerability |
cisa-kev |
CVE-2026-55040 |
|
2026-08-18 |
| high |
CVE-2026-65400 — Apple macOS Improper Authentication Vulnerability |
vulnerability |
cisa-kev |
CVE-2026-65400 |
|
2026-08-18 |
| high |
CVE-2025-62593 — Ray-Project Ray Code Injection Vulnerability |
vulnerability |
cisa-kev |
CVE-2025-62593 |
rce |
2026-08-17 |
| high |
Johnson Controls Simplex Incident Manager |
advisory |
cisa-advisories, vendor-blogs |
|
phishing, ics |
2026-08-20 |
| high |
Defending Against an Active Threat to Siemens S7 Series PLCs |
advisory |
cisa-advisories |
|
ics, supply-chain |
2026-08-19 |
| high |
CISA Malcolm |
advisory |
cisa-advisories, vendor-blogs |
|
phishing, ics |
2026-08-18 |
| high |
CVE-2026-19757 — A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown cod… |
vulnerability |
nvd |
CVE-2026-19757 |
|
2026-08-14 |
| high |
CVE-2026-19758 — A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown p… |
vulnerability |
nvd |
CVE-2026-19758 |
|
2026-08-14 |
| high |
CVE-2026-19762 — A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Pat… |
vulnerability |
nvd |
CVE-2026-19762 |
|
2026-08-14 |
| high |
CVE-2026-19764 — A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up… |
vulnerability |
nvd |
CVE-2026-19764 |
|
2026-08-14 |
| high |
CVE-2026-19771 — A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown fun… |
vulnerability |
nvd |
CVE-2026-19771 |
|
2026-08-14 |
| high |
CVE-2026-18109 — The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Aut… |
vulnerability |
nvd |
CVE-2026-18109 |
|
2026-08-14 |
| high |
CVE-2026-19788 — A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_devi… |
vulnerability |
nvd |
CVE-2026-19788 |
|
2026-08-14 |
| high |
CVE-2026-19789 — A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects th… |
vulnerability |
nvd |
CVE-2026-19789 |
|
2026-08-14 |
| high |
CVE-2026-19790 — A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPo… |
vulnerability |
nvd |
CVE-2026-19790 |
|
2026-08-14 |
| high |
CVE-2026-19791 — A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addS… |
vulnerability |
nvd |
CVE-2026-19791 |
|
2026-08-14 |
| high |
CVE-2026-19792 — A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapp… |
vulnerability |
nvd |
CVE-2026-19792 |
|
2026-08-14 |
| high |
CVE-2026-15205 — The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplie… |
vulnerability |
nvd |
CVE-2026-15205 |
|
2026-08-14 |
| high |
CVE-2026-18039 — The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied regi… |
vulnerability |
nvd |
CVE-2026-18039 |
|
2026-08-14 |
| high |
CVE-2026-19811 — A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element i… |
vulnerability |
nvd |
CVE-2026-19811 |
|
2026-08-14 |
| high |
CVE-2026-19794 — The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to… |
vulnerability |
nvd |
CVE-2026-19794 |
|
2026-08-14 |
| high |
CVE-2026-19812 — A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function U… |
vulnerability |
nvd |
CVE-2026-19812 |
|
2026-08-14 |
| high |
CVE-2026-19813 — A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts th… |
vulnerability |
nvd |
CVE-2026-19813 |
|
2026-08-14 |
| high |
CVE-2026-19814 — A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setM… |
vulnerability |
nvd |
CVE-2026-19814 |
|
2026-08-14 |
| high |
CVE-2026-19815 — A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is th… |
vulnerability |
nvd |
CVE-2026-19815 |
|
2026-08-14 |
| high |
CVE-2026-19821 — A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the… |
vulnerability |
nvd |
CVE-2026-19821 |
|
2026-08-14 |
| high |
CVE-2026-19822 — A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the… |
vulnerability |
nvd |
CVE-2026-19822 |
|
2026-08-14 |
| high |
CVE-2026-72810 — SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast… |
vulnerability |
nvd |
CVE-2026-72810 |
|
2026-08-14 |
| high |
CVE-2026-72819 — Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin set… |
vulnerability |
nvd |
CVE-2026-72819 |
rce |
2026-08-14 |
| high |
CVE-2026-72825 — The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /r… |
vulnerability |
nvd |
CVE-2026-72825 |
rce |
2026-08-14 |
| high |
CVE-2026-72827 — Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action param… |
vulnerability |
nvd |
CVE-2026-72827 |
rce |
2026-08-14 |
| high |
CVE-2026-72828 — Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in Invit… |
vulnerability |
nvd |
CVE-2026-72828 |
|
2026-08-14 |
| high |
CVE-2026-72831 — The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization… |
vulnerability |
nvd |
CVE-2026-72831 |
|
2026-08-14 |
| high |
CVE-2026-72833 — The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege es… |
vulnerability |
nvd |
CVE-2026-72833 |
|
2026-08-14 |
| high |
CVE-2026-72836 — FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home dire… |
vulnerability |
nvd |
CVE-2026-72836 |
|
2026-08-14 |
| high |
CVE-2026-72837 — File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook aut… |
vulnerability |
nvd |
CVE-2026-72837 |
|
2026-08-14 |
| high |
CVE-2026-72859 — Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment uplo… |
vulnerability |
nvd |
CVE-2026-72859 |
|
2026-08-14 |
| high |
CVE-2026-19823 — A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. Impacted is the f… |
vulnerability |
nvd |
CVE-2026-19823 |
|
2026-08-14 |
| high |
CVE-2026-19824 — A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element i… |
vulnerability |
nvd |
CVE-2026-19824 |
|
2026-08-14 |
| high |
CVE-2026-19825 — A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. Th… |
vulnerability |
nvd |
CVE-2026-19825 |
|
2026-08-14 |
| high |
CVE-2026-19826 — A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian… |
vulnerability |
nvd |
CVE-2026-19826 |
|
2026-08-14 |
| high |
CVE-2026-73673 — Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability tha… |
vulnerability |
nvd |
CVE-2026-73673 |
|
2026-08-14 |
| high |
CVE-2026-19768 — Improper control of generation of code ('Code Injection') in the settings feature in Devolutions Pow… |
vulnerability |
nvd |
CVE-2026-19768 |
|
2026-08-14 |
| high |
CVE-2026-73633 — Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an applica… |
vulnerability |
nvd |
CVE-2026-73633 |
|
2026-08-14 |
| high |
CVE-2026-69101 — Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authen… |
vulnerability |
nvd |
CVE-2026-69101 |
|
2026-08-14 |
| high |
CVE-2026-16772 — In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to… |
vulnerability |
nvd |
CVE-2026-16772 |
|
2026-08-14 |
| high |
CVE-2026-53970 — ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby… |
vulnerability |
nvd |
CVE-2026-53970 |
|
2026-08-14 |
| high |
CVE-2026-63700 — Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permissio… |
vulnerability |
nvd |
CVE-2026-63700 |
|
2026-08-14 |
| high |
CVE-2026-66270 — Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File… |
vulnerability |
nvd |
CVE-2026-66270, CVE-2026-66271 |
rce |
2026-08-14 |
| high |
CVE-2026-19628 — A command injection vulnerability exists in Tenable Security Center. An authenticated administrator… |
vulnerability |
nvd |
CVE-2026-19628 |
|
2026-08-14 |
| high |
CVE-2026-19844 — A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the func… |
vulnerability |
nvd |
CVE-2026-19844 |
|
2026-08-14 |
| high |
CVE-2026-19845 — A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function s… |
vulnerability |
nvd |
CVE-2026-19845 |
|
2026-08-14 |
| high |
CVE-2026-46380 — compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 a… |
vulnerability |
nvd |
CVE-2026-46380, CVE-2026-46345 |
|
2026-08-14 |
| high |
CVE-2026-46439 — compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 a… |
vulnerability |
nvd |
CVE-2026-46439 |
|
2026-08-14 |
| high |
CVE-2026-46603 — VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing… |
vulnerability |
nvd |
CVE-2026-46603 |
|
2026-08-14 |
| high |
CVE-2026-12364 — The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was… |
vulnerability |
nvd |
CVE-2026-12364 |
|
2026-08-14 |
| high |
CVE-2026-12366 — Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an… |
vulnerability |
nvd |
CVE-2026-12366 |
|
2026-08-14 |
| high |
CVE-2026-19629 — A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Secu… |
vulnerability |
nvd |
CVE-2026-19629 |
|
2026-08-14 |
| high |
CVE-2026-19635 — A local privilege escalation vulnerability exists in Security Center. An attacker with write access… |
vulnerability |
nvd |
CVE-2026-19635 |
|
2026-08-14 |
| high |
CVE-2026-19679 — An input validation vulnerability exists in Security Center's file upload handling, where insufficie… |
vulnerability |
nvd |
CVE-2026-19679 |
|
2026-08-14 |
| high |
CVE-2026-19680 — A SQL injection vulnerability exists in Security Center that could allow an attacker to access unaut… |
vulnerability |
nvd |
CVE-2026-19680 |
|
2026-08-14 |
| high |
CVE-2026-19846 — A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function s… |
vulnerability |
nvd |
CVE-2026-19846 |
|
2026-08-14 |
| high |
CVE-2026-19847 — A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the functi… |
vulnerability |
nvd |
CVE-2026-19847 |
|
2026-08-14 |
| high |
CVE-2026-72970 — Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to exe… |
vulnerability |
nvd |
CVE-2026-72970 |
|
2026-08-14 |
| high |
CVE-2025-7639 — The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operat… |
vulnerability |
nvd |
CVE-2025-7639 |
ics |
2026-08-14 |
| high |
CVE-2026-45699 — Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.… |
vulnerability |
nvd |
CVE-2026-45699, CVE-2026-45698 |
|
2026-08-14 |
| high |
CVE-2026-73679 — ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module th… |
vulnerability |
nvd |
CVE-2026-73679 |
rce |
2026-08-14 |
| high |
CVE-2026-16708 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information… |
vulnerability |
nvd |
CVE-2026-16708 |
|
2026-08-14 |
| high |
CVE-2026-16879 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass securit… |
vulnerability |
nvd |
CVE-2026-16879, CVE-2026-17079, CVE-2026-17227 |
|
2026-08-14 |
| high |
CVE-2026-16905 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti… |
vulnerability |
nvd |
CVE-2026-16905, CVE-2026-16915, CVE-2026-17173, CVE-2026-17175, CVE-2026-18554 |
|
2026-08-14 |
| high |
CVE-2026-17081 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to… |
vulnerability |
nvd |
CVE-2026-17081 |
|
2026-08-14 |
| high |
CVE-2026-17177 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service du… |
vulnerability |
nvd |
CVE-2026-17177 |
|
2026-08-14 |
| high |
CVE-2026-17179 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial… |
vulnerability |
nvd |
CVE-2026-17179 |
|
2026-08-14 |
| high |
CVE-2026-73680 — Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration th… |
vulnerability |
nvd |
CVE-2026-73680 |
|
2026-08-14 |
| high |
CVE-2026-50523 — Improper neutralization of special elements used in a command ('command injection') in Microsoft Pow… |
vulnerability |
nvd |
CVE-2026-50523 |
|
2026-08-14 |
| high |
CVE-2026-69414 — Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Micros… |
vulnerability |
nvd |
CVE-2026-69414 |
|
2026-08-14 |
| high |
CVE-2026-73683 — Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows un… |
vulnerability |
nvd |
CVE-2026-73683 |
ransomware |
2026-08-14 |
| high |
CVE-2026-14433 — The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable t… |
vulnerability |
nvd |
CVE-2026-14433 |
|
2026-08-15 |
| high |
CVE-2026-15001 — The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalatio… |
vulnerability |
nvd |
CVE-2026-15001 |
|
2026-08-15 |
| high |
CVE-2026-15162 — The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpre… |
vulnerability |
nvd |
CVE-2026-15162 |
|
2026-08-15 |
| high |
CVE-2026-15312 — The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege… |
vulnerability |
nvd |
CVE-2026-15312 |
|
2026-08-15 |
| high |
CVE-2026-15965 — The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnera… |
vulnerability |
nvd |
CVE-2026-15965 |
rce |
2026-08-15 |
| high |
CVE-2026-13360 — The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored… |
vulnerability |
nvd |
CVE-2026-13360 |
|
2026-08-15 |
| high |
CVE-2026-16094 — The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vuln… |
vulnerability |
nvd |
CVE-2026-16094, CVE-2026-16145, CVE-2026-16146 |
|
2026-08-15 |
| high |
CVE-2026-16611 — The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an… |
vulnerability |
nvd |
CVE-2026-16611 |
|
2026-08-15 |
| high |
CVE-2026-68458 — In the Linux kernel, the following vulnerability has been resolved: binder: cache secctx size before… |
vulnerability |
nvd |
CVE-2026-68458 |
|
2026-08-15 |
| high |
CVE-2026-68461 — In the Linux kernel, the following vulnerability has been resolved: device property: initialize the… |
vulnerability |
nvd |
CVE-2026-68461 |
|
2026-08-15 |
| high |
CVE-2026-68462 — In the Linux kernel, the following vulnerability has been resolved: bpf: Reject negative const offse… |
vulnerability |
nvd |
CVE-2026-68462 |
|
2026-08-15 |
| high |
CVE-2026-68466 — In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: lpc32xx_slc: fail… |
vulnerability |
nvd |
CVE-2026-68466 |
|
2026-08-15 |
| high |
CVE-2026-68467 — In the Linux kernel, the following vulnerability has been resolved: mtd: mchp23k256: use SPI match d… |
vulnerability |
nvd |
CVE-2026-68467 |
|
2026-08-15 |
| high |
CVE-2026-68470 — In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate extensi… |
vulnerability |
nvd |
CVE-2026-68470 |
|
2026-08-15 |
| high |
CVE-2026-68471 — In the Linux kernel, the following vulnerability has been resolved: wifi: ieee80211: validate MLE co… |
vulnerability |
nvd |
CVE-2026-68471 |
|
2026-08-15 |
| high |
CVE-2026-68472 — In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate EHT MLE… |
vulnerability |
nvd |
CVE-2026-68472 |
|
2026-08-15 |
| high |
CVE-2026-68473 — In the Linux kernel, the following vulnerability has been resolved: powerpc/uaccess: correct check f… |
vulnerability |
nvd |
CVE-2026-68473 |
|
2026-08-15 |
| high |
CVE-2026-68474 — In the Linux kernel, the following vulnerability has been resolved: powerpc/spufs: fix out-of-bounds… |
vulnerability |
nvd |
CVE-2026-68474 |
|
2026-08-15 |
| high |
CVE-2026-68479 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: validate firmw… |
vulnerability |
nvd |
CVE-2026-68479 |
|
2026-08-15 |
| high |
CVE-2026-72003 — In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: cyw: fix heap ov… |
vulnerability |
nvd |
CVE-2026-72003 |
|
2026-08-15 |
| high |
CVE-2026-72005 — In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00: avoid full teardow… |
vulnerability |
nvd |
CVE-2026-72005 |
|
2026-08-15 |
| high |
CVE-2026-72009 — In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx93-blk-ctrl: Extrac… |
vulnerability |
nvd |
CVE-2026-72009 |
|
2026-08-15 |
| high |
CVE-2026-72012 — In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Call synchroniz… |
vulnerability |
nvd |
CVE-2026-72012 |
|
2026-08-15 |
| high |
CVE-2026-72018 — In the Linux kernel, the following vulnerability has been resolved: dibs: loopback: validate offset… |
vulnerability |
nvd |
CVE-2026-72018 |
|
2026-08-15 |
| high |
CVE-2026-72019 — In the Linux kernel, the following vulnerability has been resolved: macsec: don't read an unset MAC… |
vulnerability |
nvd |
CVE-2026-72019 |
|
2026-08-15 |
| high |
CVE-2026-72021 — In the Linux kernel, the following vulnerability has been resolved: ipvs: use parsed transport offse… |
vulnerability |
nvd |
CVE-2026-72021 |
|
2026-08-15 |
| high |
CVE-2026-72024 — In the Linux kernel, the following vulnerability has been resolved: mac802154: remove interfaces wit… |
vulnerability |
nvd |
CVE-2026-72024 |
|
2026-08-15 |
| high |
CVE-2026-72027 — In the Linux kernel, the following vulnerability has been resolved: mm/compaction: handle free_pages… |
vulnerability |
nvd |
CVE-2026-72027 |
|
2026-08-15 |
| high |
CVE-2026-72029 — In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: bound device of… |
vulnerability |
nvd |
CVE-2026-72029 |
|
2026-08-15 |
| high |
CVE-2026-72034 — In the Linux kernel, the following vulnerability has been resolved: fhandle: reject detached mounts… |
vulnerability |
nvd |
CVE-2026-72034 |
|
2026-08-15 |
| high |
CVE-2026-72035 — In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_taprio: Replace d… |
vulnerability |
nvd |
CVE-2026-72035 |
|
2026-08-15 |
| high |
CVE-2026-72036 — In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_multiq: Replace d… |
vulnerability |
nvd |
CVE-2026-72036 |
|
2026-08-15 |
| high |
CVE-2026-72042 — In the Linux kernel, the following vulnerability has been resolved: ipmi: Fix user refcount underflo… |
vulnerability |
nvd |
CVE-2026-72042 |
|
2026-08-15 |
| high |
CVE-2026-72043 — In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix missing dirty pag… |
vulnerability |
nvd |
CVE-2026-72043 |
|
2026-08-15 |
| high |
CVE-2026-72045 — In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: cn10k: restrict VF… |
vulnerability |
nvd |
CVE-2026-72045 |
|
2026-08-15 |
| high |
CVE-2026-72049 — In the Linux kernel, the following vulnerability has been resolved: ieee802154: admin-gate legacy LL… |
vulnerability |
nvd |
CVE-2026-72049 |
|
2026-08-15 |
| high |
CVE-2026-72051 — In the Linux kernel, the following vulnerability has been resolved: net: ip6_tunnel: require CAP_NET… |
vulnerability |
nvd |
CVE-2026-72051 |
|
2026-08-15 |
| high |
CVE-2026-72052 — In the Linux kernel, the following vulnerability has been resolved: net: ip6_gre: require CAP_NET_AD… |
vulnerability |
nvd |
CVE-2026-72052 |
|
2026-08-15 |
| high |
CVE-2026-72053 — In the Linux kernel, the following vulnerability has been resolved: net: ipip: require CAP_NET_ADMIN… |
vulnerability |
nvd |
CVE-2026-72053 |
|
2026-08-15 |
| high |
CVE-2026-72054 — In the Linux kernel, the following vulnerability has been resolved: net: ip_vti: require CAP_NET_ADM… |
vulnerability |
nvd |
CVE-2026-72054 |
|
2026-08-15 |
| high |
CVE-2026-72055 — In the Linux kernel, the following vulnerability has been resolved: net: ip6_vti: require CAP_NET_AD… |
vulnerability |
nvd |
CVE-2026-72055 |
|
2026-08-15 |
| high |
CVE-2026-72057 — In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: preserve tc_s… |
vulnerability |
nvd |
CVE-2026-72057 |
|
2026-08-15 |
| high |
CVE-2026-72061 — In the Linux kernel, the following vulnerability has been resolved: net: sit: require CAP_NET_ADMIN… |
vulnerability |
nvd |
CVE-2026-72061 |
|
2026-08-15 |
| high |
CVE-2026-72066 — In the Linux kernel, the following vulnerability has been resolved: cpu: hotplug: Bound hotplug stat… |
vulnerability |
nvd |
CVE-2026-72066 |
|
2026-08-15 |
| high |
CVE-2026-72067 — In the Linux kernel, the following vulnerability has been resolved: cpu: hotplug: Preserve per insta… |
vulnerability |
nvd |
CVE-2026-72067 |
|
2026-08-15 |
| high |
CVE-2026-72071 — In the Linux kernel, the following vulnerability has been resolved: tracing/user_events: Fix use-aft… |
vulnerability |
nvd |
CVE-2026-72071 |
|
2026-08-15 |
| high |
CVE-2026-72072 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: macsec: fix use-after… |
vulnerability |
nvd |
CVE-2026-72072 |
|
2026-08-15 |
| high |
CVE-2026-72080 — In the Linux kernel, the following vulnerability has been resolved: fs/resctrl: Fix use-after-free d… |
vulnerability |
nvd |
CVE-2026-72080 |
|
2026-08-15 |
| high |
CVE-2026-72089 — In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Reject firmware log… |
vulnerability |
nvd |
CVE-2026-72089 |
|
2026-08-15 |
| high |
CVE-2026-72090 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Use caller client… |
vulnerability |
nvd |
CVE-2026-72090 |
|
2026-08-15 |
| high |
CVE-2026-72093 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix use-after-fre… |
vulnerability |
nvd |
CVE-2026-72093 |
|
2026-08-15 |
| high |
CVE-2026-72095 — In the Linux kernel, the following vulnerability has been resolved: dma-fence: Make dma_fence_dedup_… |
vulnerability |
nvd |
CVE-2026-72095 |
|
2026-08-15 |
| high |
CVE-2026-72099 — In the Linux kernel, the following vulnerability has been resolved: dm-integrity: don't increment ha… |
vulnerability |
nvd |
CVE-2026-72099 |
|
2026-08-15 |
| high |
CVE-2026-72100 — In the Linux kernel, the following vulnerability has been resolved: dm-integrity: fix a bug if the b… |
vulnerability |
nvd |
CVE-2026-72100 |
|
2026-08-15 |
| high |
CVE-2026-72102 — In the Linux kernel, the following vulnerability has been resolved: dm_early_create: fix freeing use… |
vulnerability |
nvd |
CVE-2026-72102 |
|
2026-08-15 |
| high |
CVE-2026-72103 — In the Linux kernel, the following vulnerability has been resolved: dm: avoid leaking the caller's t… |
vulnerability |
nvd |
CVE-2026-72103 |
|
2026-08-15 |
| high |
CVE-2026-72105 — In the Linux kernel, the following vulnerability has been resolved: dm-log: fix a bitset_size overfl… |
vulnerability |
nvd |
CVE-2026-72105 |
botnet |
2026-08-15 |
| high |
CVE-2026-72107 — In the Linux kernel, the following vulnerability has been resolved: dm era: fix out-of-bounds memory… |
vulnerability |
nvd |
CVE-2026-72107 |
|
2026-08-15 |
| high |
CVE-2026-72108 — In the Linux kernel, the following vulnerability has been resolved: dm thin metadata: fix metadata s… |
vulnerability |
nvd |
CVE-2026-72108 |
|
2026-08-15 |
| high |
CVE-2026-72109 — In the Linux kernel, the following vulnerability has been resolved: net: sparx5: unregister blocking… |
vulnerability |
nvd |
CVE-2026-72109 |
|
2026-08-15 |
| high |
CVE-2026-72110 — In the Linux kernel, the following vulnerability has been resolved: bpf,fork: wipe ->bpf_storage bef… |
vulnerability |
nvd |
CVE-2026-72110 |
|
2026-08-15 |
| high |
CVE-2026-72111 — In the Linux kernel, the following vulnerability has been resolved: bpf: Reset register bounds befor… |
vulnerability |
nvd |
CVE-2026-72111 |
|
2026-08-15 |
| high |
CVE-2026-72112 — In the Linux kernel, the following vulnerability has been resolved: io_uring/bpf-ops: reject re-regi… |
vulnerability |
nvd |
CVE-2026-72112 |
|
2026-08-15 |
| high |
CVE-2026-72113 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing device ref… |
vulnerability |
nvd |
CVE-2026-72113 |
botnet |
2026-08-15 |
| high |
CVE-2026-72114 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: validate frame length… |
vulnerability |
nvd |
CVE-2026-72114 |
|
2026-08-15 |
| high |
CVE-2026-72115 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: track a single source… |
vulnerability |
nvd |
CVE-2026-72115 |
|
2026-08-15 |
| high |
CVE-2026-72116 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix stale rx/tx ops af… |
vulnerability |
nvd |
CVE-2026-72116 |
|
2026-08-15 |
| high |
CVE-2026-72119 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: extend bcm_tx_lock usa… |
vulnerability |
nvd |
CVE-2026-72119 |
|
2026-08-15 |
| high |
CVE-2026-72120 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu list a… |
vulnerability |
nvd |
CVE-2026-72120 |
|
2026-08-15 |
| high |
CVE-2026-72121 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking when updat… |
vulnerability |
nvd |
CVE-2026-72121 |
|
2026-08-15 |
| high |
CVE-2026-72122 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix lockless bound/ifi… |
vulnerability |
nvd |
CVE-2026-72122 |
|
2026-08-15 |
| high |
CVE-2026-72123 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: defer rx_op deallocati… |
vulnerability |
nvd |
CVE-2026-72123 |
|
2026-08-15 |
| high |
CVE-2026-72124 — In the Linux kernel, the following vulnerability has been resolved: can: isotp: serialize TX state t… |
vulnerability |
nvd |
CVE-2026-72124 |
|
2026-08-15 |
| high |
CVE-2026-72125 — In the Linux kernel, the following vulnerability has been resolved: can: isotp: fix use-after-free r… |
vulnerability |
nvd |
CVE-2026-72125 |
|
2026-08-15 |
| high |
CVE-2026-72126 — In the Linux kernel, the following vulnerability has been resolved: can: isotp: use unconditional sy… |
vulnerability |
nvd |
CVE-2026-72126 |
|
2026-08-15 |
| high |
CVE-2026-72127 — In the Linux kernel, the following vulnerability has been resolved: netdev-genl: report NAPI thread… |
vulnerability |
nvd |
CVE-2026-72127 |
botnet |
2026-08-15 |
| high |
CVE-2026-72133 — In the Linux kernel, the following vulnerability has been resolved: spi: uniphier: Fix completion in… |
vulnerability |
nvd |
CVE-2026-72133 |
|
2026-08-15 |
| high |
CVE-2026-72134 — In the Linux kernel, the following vulnerability has been resolved: spi: imx: reconfigure for PIO wh… |
vulnerability |
nvd |
CVE-2026-72134 |
|
2026-08-15 |
| high |
CVE-2026-72135 — In the Linux kernel, the following vulnerability has been resolved: tpm: Make the TPM character devi… |
vulnerability |
nvd |
CVE-2026-72135 |
|
2026-08-15 |
| high |
CVE-2026-72136 — In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_interface: require CA… |
vulnerability |
nvd |
CVE-2026-72136 |
|
2026-08-15 |
| high |
CVE-2026-72141 — In the Linux kernel, the following vulnerability has been resolved: i2c: imx: fix locked bus on SMBu… |
vulnerability |
nvd |
CVE-2026-72141, CVE-2026-72142 |
|
2026-08-15 |
| high |
CVE-2026-72143 — In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Restore SST-… |
vulnerability |
nvd |
CVE-2026-72143 |
|
2026-08-15 |
| high |
CVE-2026-72144 — In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-laptop: fix m… |
vulnerability |
nvd |
CVE-2026-72144 |
|
2026-08-15 |
| high |
CVE-2026-72146 — In the Linux kernel, the following vulnerability has been resolved: dmaengine: sh: rz-dmac: Move int… |
vulnerability |
nvd |
CVE-2026-72146 |
|
2026-08-15 |
| high |
CVE-2026-72148 — In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Add spinlock… |
vulnerability |
nvd |
CVE-2026-72148 |
|
2026-08-15 |
| high |
CVE-2026-72149 — In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra: Fix burst size… |
vulnerability |
nvd |
CVE-2026-72149 |
|
2026-08-15 |
| high |
CVE-2026-72151 — In the Linux kernel, the following vulnerability has been resolved: tpm: tpm2-sessions: wait for asy… |
vulnerability |
nvd |
CVE-2026-72151 |
|
2026-08-15 |
| high |
CVE-2026-72154 — In the Linux kernel, the following vulnerability has been resolved: openrisc: Fix jump_label smp syn… |
vulnerability |
nvd |
CVE-2026-72154 |
|
2026-08-15 |
| high |
CVE-2026-72157 — In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Fix frags[] ov… |
vulnerability |
nvd |
CVE-2026-72157 |
|
2026-08-15 |
| high |
CVE-2026-72160 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject dinodes with non-c… |
vulnerability |
nvd |
CVE-2026-72160 |
|
2026-08-15 |
| high |
CVE-2026-72162 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix UBSAN array-index-out… |
vulnerability |
nvd |
CVE-2026-72162 |
|
2026-08-15 |
| high |
CVE-2026-72164 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: avoid moving extents to o… |
vulnerability |
nvd |
CVE-2026-72164 |
|
2026-08-15 |
| high |
CVE-2026-72165 — In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: fix condition in '… |
vulnerability |
nvd |
CVE-2026-72165 |
|
2026-08-15 |
| high |
CVE-2026-72170 — In the Linux kernel, the following vulnerability has been resolved: 9p: skip nlink update in cachele… |
vulnerability |
nvd |
CVE-2026-72170 |
|
2026-08-15 |
| high |
CVE-2026-72171 — In the Linux kernel, the following vulnerability has been resolved: mtd: slram: remove failed entrie… |
vulnerability |
nvd |
CVE-2026-72171 |
|
2026-08-15 |
| high |
CVE-2026-72172 — In the Linux kernel, the following vulnerability has been resolved: mm/mm_init: fix uninitialized st… |
vulnerability |
nvd |
CVE-2026-72172 |
|
2026-08-15 |
| high |
CVE-2026-72175 — In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: fix make_uffd_… |
vulnerability |
nvd |
CVE-2026-72175 |
|
2026-08-15 |
| high |
CVE-2026-72181 — In the Linux kernel, the following vulnerability has been resolved: mips: sched: Fix CPUMASK_OFFSTAC… |
vulnerability |
nvd |
CVE-2026-72181 |
|
2026-08-15 |
| high |
CVE-2026-72183 — In the Linux kernel, the following vulnerability has been resolved: landlock: Fix LANDLOCK_SCOPE_SIG… |
vulnerability |
nvd |
CVE-2026-72183 |
|
2026-08-15 |
| high |
CVE-2026-72195 — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound attr_off in Upda… |
vulnerability |
nvd |
CVE-2026-72195 |
|
2026-08-15 |
| high |
CVE-2026-72196 — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound copy_lcns dp->pa… |
vulnerability |
nvd |
CVE-2026-72196 |
ransomware |
2026-08-15 |
| high |
CVE-2026-72197 — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound DeleteIndexEntry… |
vulnerability |
nvd |
CVE-2026-72197 |
|
2026-08-15 |
| high |
CVE-2026-72198 — In the Linux kernel, the following vulnerability has been resolved: ntfs: reject non-resident record… |
vulnerability |
nvd |
CVE-2026-72198 |
|
2026-08-15 |
| high |
CVE-2026-72202 — In the Linux kernel, the following vulnerability has been resolved: ntfs: avoid heap allocation for… |
vulnerability |
nvd |
CVE-2026-72202 |
|
2026-08-15 |
| high |
CVE-2026-72203 — In the Linux kernel, the following vulnerability has been resolved: ntfs: skip extent mft records in… |
vulnerability |
nvd |
CVE-2026-72203 |
|
2026-08-15 |
| high |
CVE-2026-72204 — In the Linux kernel, the following vulnerability has been resolved: ntfs: centalize $INDEX_ROOT head… |
vulnerability |
nvd |
CVE-2026-72204 |
|
2026-08-15 |
| high |
CVE-2026-72213 — In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb cgroup r… |
vulnerability |
nvd |
CVE-2026-72213 |
|
2026-08-15 |
| high |
CVE-2026-72225 — In the Linux kernel, the following vulnerability has been resolved: jbd2: fix integer underflow in j… |
vulnerability |
nvd |
CVE-2026-72225 |
|
2026-08-15 |
| high |
CVE-2026-72227 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: avoid OOB rea… |
vulnerability |
nvd |
CVE-2026-72227 |
|
2026-08-15 |
| high |
CVE-2026-72231 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: avoid request st… |
vulnerability |
nvd |
CVE-2026-72231 |
|
2026-08-15 |
| high |
CVE-2026-72232 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: ensure minimal ether… |
vulnerability |
nvd |
CVE-2026-72232 |
|
2026-08-15 |
| high |
CVE-2026-72233 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: reacquire gw ad… |
vulnerability |
nvd |
CVE-2026-72233 |
|
2026-08-15 |
| high |
CVE-2026-72235 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: retrieve ethhdr afte… |
vulnerability |
nvd |
CVE-2026-72235 |
|
2026-08-15 |
| high |
CVE-2026-72242 — In the Linux kernel, the following vulnerability has been resolved: selinux: avoid sk_socket derefer… |
vulnerability |
nvd |
CVE-2026-72242 |
|
2026-08-15 |
| high |
CVE-2026-72243 — In the Linux kernel, the following vulnerability has been resolved: selinux: check connect-related p… |
vulnerability |
nvd |
CVE-2026-72243 |
|
2026-08-15 |
| high |
CVE-2026-72244 — In the Linux kernel, the following vulnerability has been resolved: gpu/buddy: bail out of try_harde… |
vulnerability |
nvd |
CVE-2026-72244 |
|
2026-08-15 |
| high |
CVE-2026-72247 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: fix zon… |
vulnerability |
nvd |
CVE-2026-72247 |
|
2026-08-15 |
| high |
CVE-2026-72250 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_reasm: g… |
vulnerability |
nvd |
CVE-2026-72250 |
|
2026-08-15 |
| high |
CVE-2026-72252 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: don't… |
vulnerability |
nvd |
CVE-2026-72252 |
|
2026-08-15 |
| high |
CVE-2026-72253 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: val… |
vulnerability |
nvd |
CVE-2026-72253 |
|
2026-08-15 |
| high |
CVE-2026-72254 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_fib: reject fib e… |
vulnerability |
nvd |
CVE-2026-72254 |
|
2026-08-15 |
| high |
CVE-2026-72255 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: pin bridge… |
vulnerability |
nvd |
CVE-2026-72255 |
|
2026-08-15 |
| high |
CVE-2026-72261 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Validat… |
vulnerability |
nvd |
CVE-2026-72261 |
|
2026-08-15 |
| high |
CVE-2026-72262 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Fix hea… |
vulnerability |
nvd |
CVE-2026-72262 |
|
2026-08-15 |
| high |
CVE-2026-72280 — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Drop bogus WARN… |
vulnerability |
nvd |
CVE-2026-72280 |
|
2026-08-15 |
| high |
CVE-2026-72282 — In the Linux kernel, the following vulnerability has been resolved: KVM: Move kvm_io_bus_get_dev() l… |
vulnerability |
nvd |
CVE-2026-72282 |
|
2026-08-15 |
| high |
CVE-2026-72283 — In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Nullify irqfd->produce… |
vulnerability |
nvd |
CVE-2026-72283 |
|
2026-08-15 |
| high |
CVE-2026-72284 — In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ignore pending PV EOI… |
vulnerability |
nvd |
CVE-2026-72284 |
|
2026-08-15 |
| high |
CVE-2026-72285 — In the Linux kernel, the following vulnerability has been resolved: KVM: TDX: Reject concurrent chan… |
vulnerability |
nvd |
CVE-2026-72285 |
|
2026-08-15 |
| high |
CVE-2026-72286 — In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Do not allow intra-hos… |
vulnerability |
nvd |
CVE-2026-72286 |
|
2026-08-15 |
| high |
CVE-2026-72287 — In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Move vTPR vs. TPR Thr… |
vulnerability |
nvd |
CVE-2026-72287 |
|
2026-08-15 |
| high |
CVE-2026-72294 — In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Check irq validi… |
vulnerability |
nvd |
CVE-2026-72294 |
|
2026-08-15 |
| high |
CVE-2026-72295 — In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Validate irqchip… |
vulnerability |
nvd |
CVE-2026-72295 |
|
2026-08-15 |
| high |
CVE-2026-72297 — In the Linux kernel, the following vulnerability has been resolved: net: atm: reject out-of-range tr… |
vulnerability |
nvd |
CVE-2026-72297 |
|
2026-08-15 |
| high |
CVE-2026-72298 — In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix 32-bit integer ov… |
vulnerability |
nvd |
CVE-2026-72298 |
|
2026-08-15 |
| high |
CVE-2026-72301 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Fix TOC… |
vulnerability |
nvd |
CVE-2026-72301 |
|
2026-08-15 |
| high |
CVE-2026-72302 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Use ove… |
vulnerability |
nvd |
CVE-2026-72302 |
|
2026-08-15 |
| high |
CVE-2026-72303 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-control: Validat… |
vulnerability |
nvd |
CVE-2026-72303 |
|
2026-08-15 |
| high |
CVE-2026-72304 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-control: Fix TOC… |
vulnerability |
nvd |
CVE-2026-72304 |
|
2026-08-15 |
| high |
CVE-2026-72310 — In the Linux kernel, the following vulnerability has been resolved: smb: client: fix overflow in pas… |
vulnerability |
nvd |
CVE-2026-72310 |
|
2026-08-15 |
| high |
CVE-2026-72312 — In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: fix VF bringup aff… |
vulnerability |
nvd |
CVE-2026-72312 |
|
2026-08-15 |
| high |
CVE-2026-72314 — In the Linux kernel, the following vulnerability has been resolved: regulator: core: regulator_lock_… |
vulnerability |
nvd |
CVE-2026-72314 |
|
2026-08-15 |
| high |
CVE-2026-72315 — In the Linux kernel, the following vulnerability has been resolved: smb: client: fix busy dentry war… |
vulnerability |
nvd |
CVE-2026-72315 |
|
2026-08-15 |
| high |
CVE-2026-72328 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix potential amd… |
vulnerability |
nvd |
CVE-2026-72328 |
|
2026-08-15 |
| high |
CVE-2026-72330 — In the Linux kernel, the following vulnerability has been resolved: net/tls: Consume empty data reco… |
vulnerability |
nvd |
CVE-2026-72330 |
|
2026-08-15 |
| high |
CVE-2026-72331 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix VMA access ra… |
vulnerability |
nvd |
CVE-2026-72331 |
|
2026-08-15 |
| high |
CVE-2026-72334 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix malformed IS… |
vulnerability |
nvd |
CVE-2026-72334 |
|
2026-08-15 |
| high |
CVE-2026-72335 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix adv monitor… |
vulnerability |
nvd |
CVE-2026-72335 |
|
2026-08-15 |
| high |
CVE-2026-72338 — In the Linux kernel, the following vulnerability has been resolved: net/sched: act_pedit: fix TOCTOU… |
vulnerability |
nvd |
CVE-2026-72338 |
|
2026-08-15 |
| high |
CVE-2026-72340 — In the Linux kernel, the following vulnerability has been resolved: net: microchip: vcap: fix races… |
vulnerability |
nvd |
CVE-2026-72340 |
|
2026-08-15 |
| high |
CVE-2026-72342 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix HV VHCA stats age… |
vulnerability |
nvd |
CVE-2026-72342 |
|
2026-08-15 |
| high |
CVE-2026-72343 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix HV VHCA stats zer… |
vulnerability |
nvd |
CVE-2026-72343 |
|
2026-08-15 |
| high |
CVE-2026-72344 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: TC, skip peer flow cl… |
vulnerability |
nvd |
CVE-2026-72344 |
|
2026-08-15 |
| high |
CVE-2026-72345 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5: LAG, Fix off-by-one in… |
vulnerability |
nvd |
CVE-2026-72345 |
|
2026-08-15 |
| high |
CVE-2026-72347 — In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_connmark: reject i… |
vulnerability |
nvd |
CVE-2026-72347 |
|
2026-08-15 |
| high |
CVE-2026-72350 — In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_u32: reject invali… |
vulnerability |
nvd |
CVE-2026-72350 |
|
2026-08-15 |
| high |
CVE-2026-72352 — In the Linux kernel, the following vulnerability has been resolved: HID: bpf: Fix hid_bpf_get_data()… |
vulnerability |
nvd |
CVE-2026-72352 |
|
2026-08-15 |
| high |
CVE-2026-72353 — In the Linux kernel, the following vulnerability has been resolved: ntfs: avoid stale runlist elemen… |
vulnerability |
nvd |
CVE-2026-72353, CVE-2026-72354 |
|
2026-08-15 |
| high |
CVE-2026-72356 — In the Linux kernel, the following vulnerability has been resolved: cifs: Fix missing credit release… |
vulnerability |
nvd |
CVE-2026-72356 |
|
2026-08-15 |
| high |
CVE-2026-72357 — In the Linux kernel, the following vulnerability has been resolved: uprobes/x86: Use proper mm_struc… |
vulnerability |
nvd |
CVE-2026-72357 |
|
2026-08-15 |
| high |
CVE-2026-72358 — In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: prevent invalid curso… |
vulnerability |
nvd |
CVE-2026-72358 |
|
2026-08-15 |
| high |
CVE-2026-72360 — In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Don't attempt to proc… |
vulnerability |
nvd |
CVE-2026-72360 |
|
2026-08-15 |
| high |
CVE-2026-72364 — In the Linux kernel, the following vulnerability has been resolved: netfs: Fix writeback error handl… |
vulnerability |
nvd |
CVE-2026-72364 |
|
2026-08-15 |
| high |
CVE-2026-72367 — In the Linux kernel, the following vulnerability has been resolved: iomap: guard io_size EOF trim ag… |
vulnerability |
nvd |
CVE-2026-72367 |
|
2026-08-15 |
| high |
CVE-2026-72368 — In the Linux kernel, the following vulnerability has been resolved: cachefiles: Fix double unlock in… |
vulnerability |
nvd |
CVE-2026-72368 |
|
2026-08-15 |
| high |
CVE-2026-72369 — In the Linux kernel, the following vulnerability has been resolved: minix: avoid overflow in bitmap… |
vulnerability |
nvd |
CVE-2026-72369 |
|
2026-08-15 |
| high |
CVE-2026-72371 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix the volume AFS_VOLUME_R… |
vulnerability |
nvd |
CVE-2026-72371 |
|
2026-08-15 |
| high |
CVE-2026-72372 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix lack of locking around… |
vulnerability |
nvd |
CVE-2026-72372 |
|
2026-08-15 |
| high |
CVE-2026-72373 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix missing NULL pointer ch… |
vulnerability |
nvd |
CVE-2026-72373 |
|
2026-08-15 |
| high |
CVE-2026-72374 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix callback service messag… |
vulnerability |
nvd |
CVE-2026-72374 |
|
2026-08-15 |
| high |
CVE-2026-72375 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix reinitialisation of the… |
vulnerability |
nvd |
CVE-2026-72375 |
|
2026-08-15 |
| high |
CVE-2026-72378 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix error code in afs_extra… |
vulnerability |
nvd |
CVE-2026-72378 |
|
2026-08-15 |
| high |
CVE-2026-72380 — In the Linux kernel, the following vulnerability has been resolved: xen/pvcalls: bound backend respo… |
vulnerability |
nvd |
CVE-2026-72380 |
|
2026-08-15 |
| high |
CVE-2026-72382 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject undersized DACLs b… |
vulnerability |
nvd |
CVE-2026-72382 |
|
2026-08-15 |
| high |
CVE-2026-72383 — In the Linux kernel, the following vulnerability has been resolved: sctp: fix addr_wq_timer race in… |
vulnerability |
nvd |
CVE-2026-72383 |
|
2026-08-15 |
| high |
CVE-2026-72389 — In the Linux kernel, the following vulnerability has been resolved: bridge: stp: Fix a potential use… |
vulnerability |
nvd |
CVE-2026-72389 |
|
2026-08-15 |
| high |
CVE-2026-72390 — In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_teql: Introduce s… |
vulnerability |
nvd |
CVE-2026-72390 |
|
2026-08-15 |
| high |
CVE-2026-72395 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus) Fix passing event… |
vulnerability |
nvd |
CVE-2026-72395 |
|
2026-08-15 |
| high |
CVE-2026-72397 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/core) honor vrm_ve… |
vulnerability |
nvd |
CVE-2026-72397 |
|
2026-08-15 |
| high |
CVE-2026-72400 — In the Linux kernel, the following vulnerability has been resolved: seg6: validate SRH length before… |
vulnerability |
nvd |
CVE-2026-72400 |
|
2026-08-15 |
| high |
CVE-2026-72404 — In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in cleanup_bearer(… |
vulnerability |
nvd |
CVE-2026-72404 |
|
2026-08-15 |
| high |
CVE-2026-72405 — In the Linux kernel, the following vulnerability has been resolved: net: udp_tunnel: prevent double… |
vulnerability |
nvd |
CVE-2026-72405 |
|
2026-08-15 |
| high |
CVE-2026-72406 — In the Linux kernel, the following vulnerability has been resolved: net: sungem: fix probe error cle… |
vulnerability |
nvd |
CVE-2026-72406 |
|
2026-08-15 |
| high |
CVE-2026-72409 — In the Linux kernel, the following vulnerability has been resolved: net: mvneta: re-enable percpu in… |
vulnerability |
nvd |
CVE-2026-72409 |
|
2026-08-15 |
| high |
CVE-2026-72410 — In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Validate NIX maxim… |
vulnerability |
nvd |
CVE-2026-72410 |
|
2026-08-15 |
| high |
CVE-2026-72411 — In the Linux kernel, the following vulnerability has been resolved: net: dsa: mxl862xx: fix use-afte… |
vulnerability |
nvd |
CVE-2026-72411 |
|
2026-08-15 |
| high |
CVE-2026-72415 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: Validate written enu… |
vulnerability |
nvd |
CVE-2026-72415 |
|
2026-08-15 |
| high |
CVE-2026-72416 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_compat: ebtables… |
vulnerability |
nvd |
CVE-2026-72416 |
|
2026-08-15 |
| high |
CVE-2026-72418 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: prevent… |
vulnerability |
nvd |
CVE-2026-72418 |
|
2026-08-15 |
| high |
CVE-2026-72419 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat: avoid invalid… |
vulnerability |
nvd |
CVE-2026-72419 |
botnet |
2026-08-15 |
| high |
CVE-2026-72420 — In the Linux kernel, the following vulnerability has been resolved: md/raid5: avoid R5_Overlap races… |
vulnerability |
nvd |
CVE-2026-72420 |
botnet |
2026-08-15 |
| high |
CVE-2026-72423 — In the Linux kernel, the following vulnerability has been resolved: bpf: Guard conntrack opts error… |
vulnerability |
nvd |
CVE-2026-72423 |
|
2026-08-15 |
| high |
CVE-2026-72425 — In the Linux kernel, the following vulnerability has been resolved: ice: fix FDIR CTRL VSI resource… |
vulnerability |
nvd |
CVE-2026-72425 |
|
2026-08-15 |
| high |
CVE-2026-72426 — In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve pointer spill meta… |
vulnerability |
nvd |
CVE-2026-72426 |
|
2026-08-15 |
| high |
CVE-2026-72427 — In the Linux kernel, the following vulnerability has been resolved: bpf: Fix effective prog array in… |
vulnerability |
nvd |
CVE-2026-72427 |
ransomware |
2026-08-15 |
| high |
CVE-2026-72434 — In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: make sure gc i… |
vulnerability |
nvd |
CVE-2026-72434 |
|
2026-08-15 |
| high |
CVE-2026-72435 — In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix order of k… |
vulnerability |
nvd |
CVE-2026-72435 |
|
2026-08-15 |
| high |
CVE-2026-72438 — In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix writes_pending an… |
vulnerability |
nvd |
CVE-2026-72438 |
|
2026-08-15 |
| high |
CVE-2026-72440 — In the Linux kernel, the following vulnerability has been resolved: md/raid1: fix writes_pending and… |
vulnerability |
nvd |
CVE-2026-72440 |
|
2026-08-15 |
| high |
CVE-2026-72444 — In the Linux kernel, the following vulnerability has been resolved: flow_dissector: check device typ… |
vulnerability |
nvd |
CVE-2026-72444 |
|
2026-08-15 |
| high |
CVE-2026-72446 — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: qcom: reject st… |
vulnerability |
nvd |
CVE-2026-72446 |
|
2026-08-15 |
| high |
CVE-2026-72449 — In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix list_del corrupt… |
vulnerability |
nvd |
CVE-2026-72449 |
|
2026-08-15 |
| high |
CVE-2026-72450 — In the Linux kernel, the following vulnerability has been resolved: xfrm: validate selector family a… |
vulnerability |
nvd |
CVE-2026-72450 |
|
2026-08-15 |
| high |
CVE-2026-72452 — In the Linux kernel, the following vulnerability has been resolved: drm/i915: clear CRTC color blob… |
vulnerability |
nvd |
CVE-2026-72452 |
|
2026-08-15 |
| high |
CVE-2026-72454 — In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Fix race in i… |
vulnerability |
nvd |
CVE-2026-72454 |
|
2026-08-15 |
| high |
CVE-2026-72455 — In the Linux kernel, the following vulnerability has been resolved: apparmor: fix uninitialised poin… |
vulnerability |
nvd |
CVE-2026-72455 |
|
2026-08-15 |
| high |
CVE-2026-72459 — In the Linux kernel, the following vulnerability has been resolved: apparmor: aa_label_alloc use aa_… |
vulnerability |
nvd |
CVE-2026-72459 |
|
2026-08-15 |
| high |
CVE-2026-72460 — In the Linux kernel, the following vulnerability has been resolved: apparmor: check label build befo… |
vulnerability |
nvd |
CVE-2026-72460 |
|
2026-08-15 |
| high |
CVE-2026-72461 — In the Linux kernel, the following vulnerability has been resolved: apparmor: fix refcount leak when… |
vulnerability |
nvd |
CVE-2026-72461 |
|
2026-08-15 |
| high |
CVE-2026-72462 — In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race in unix socke… |
vulnerability |
nvd |
CVE-2026-72462 |
|
2026-08-15 |
| high |
CVE-2026-72464 — In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Repost Receive buffers… |
vulnerability |
nvd |
CVE-2026-72464 |
|
2026-08-15 |
| high |
CVE-2026-72465 — In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Sanitize the reply cre… |
vulnerability |
nvd |
CVE-2026-72465 |
|
2026-08-15 |
| high |
CVE-2026-72469 — In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Fix ep kref imbalance… |
vulnerability |
nvd |
CVE-2026-72469 |
|
2026-08-15 |
| high |
CVE-2026-72470 — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: resize log->one_page_b… |
vulnerability |
nvd |
CVE-2026-72470 |
ransomware |
2026-08-15 |
| high |
CVE-2026-72471 — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: prevent potential lcn… |
vulnerability |
nvd |
CVE-2026-72471 |
|
2026-08-15 |
| high |
CVE-2026-72476 — In the Linux kernel, the following vulnerability has been resolved: dmaengine: Fix possible use afte… |
vulnerability |
nvd |
CVE-2026-72476 |
|
2026-08-15 |
| high |
CVE-2026-72478 — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: add bounds check to ru… |
vulnerability |
nvd |
CVE-2026-72478 |
ransomware |
2026-08-15 |
| high |
CVE-2026-72480 — In the Linux kernel, the following vulnerability has been resolved: iio: adc: xilinx-ams: fix out-of… |
vulnerability |
nvd |
CVE-2026-72480 |
|
2026-08-15 |
| high |
CVE-2026-72482 — In the Linux kernel, the following vulnerability has been resolved: gpib: fix double decrement of de… |
vulnerability |
nvd |
CVE-2026-72482 |
|
2026-08-15 |
| high |
CVE-2026-72483 — In the Linux kernel, the following vulnerability has been resolved: usb: host: max3421: Fix shift-ou… |
vulnerability |
nvd |
CVE-2026-72483 |
|
2026-08-15 |
| high |
CVE-2026-72485 — In the Linux kernel, the following vulnerability has been resolved: coresight: platform: defer conne… |
vulnerability |
nvd |
CVE-2026-72485 |
|
2026-08-15 |
| high |
CVE-2026-72487 — In the Linux kernel, the following vulnerability has been resolved: PCI: Check ROM header and data s… |
vulnerability |
nvd |
CVE-2026-72487 |
|
2026-08-15 |
| high |
CVE-2026-72488 — In the Linux kernel, the following vulnerability has been resolved: soundwire: fix bug in sdw_add_el… |
vulnerability |
nvd |
CVE-2026-72488 |
|
2026-08-15 |
| high |
CVE-2026-72489 — In the Linux kernel, the following vulnerability has been resolved: staging: nvec: fix use-after-fre… |
vulnerability |
nvd |
CVE-2026-72489 |
|
2026-08-15 |
| high |
CVE-2026-72492 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in sam… |
vulnerability |
nvd |
CVE-2026-72492 |
|
2026-08-15 |
| high |
CVE-2026-72497 — In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Add a max slot che… |
vulnerability |
nvd |
CVE-2026-72497 |
|
2026-08-15 |
| high |
CVE-2026-72499 — In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Free CQ toggle pag… |
vulnerability |
nvd |
CVE-2026-72499 |
|
2026-08-15 |
| high |
CVE-2026-72500 — In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Free SRQ toggle pa… |
vulnerability |
nvd |
CVE-2026-72500 |
|
2026-08-15 |
| high |
CVE-2026-72502 — In the Linux kernel, the following vulnerability has been resolved: tcp: ipv6: clamp default adverti… |
vulnerability |
nvd |
CVE-2026-72502 |
|
2026-08-15 |
| high |
CVE-2026-74256 — In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: fix integer overfl… |
vulnerability |
nvd |
CVE-2026-74256 |
botnet |
2026-08-15 |
| high |
CVE-2026-74257 — In the Linux kernel, the following vulnerability has been resolved: sockmap: Fix use-after-free in u… |
vulnerability |
nvd |
CVE-2026-74257 |
botnet |
2026-08-15 |
| high |
CVE-2026-74258 — In the Linux kernel, the following vulnerability has been resolved: bpf: Guard __get_user acesss wit… |
vulnerability |
nvd |
CVE-2026-74258 |
|
2026-08-15 |
| high |
CVE-2026-74259 — In the Linux kernel, the following vulnerability has been resolved: cifs: remove all cifs files befo… |
vulnerability |
nvd |
CVE-2026-74259 |
|
2026-08-15 |
| high |
CVE-2026-74260 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_dup_netdev: add nf… |
vulnerability |
nvd |
CVE-2026-74260 |
|
2026-08-15 |
| high |
CVE-2026-74262 — In the Linux kernel, the following vulnerability has been resolved: kcm: use WRITE_ONCE() when chang… |
vulnerability |
nvd |
CVE-2026-74262 |
|
2026-08-15 |
| high |
CVE-2026-74264 — In the Linux kernel, the following vulnerability has been resolved: net: watchdog: fix refcount trac… |
vulnerability |
nvd |
CVE-2026-74264 |
|
2026-08-15 |
| high |
CVE-2026-74266 — In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_dualpi2: Do not c… |
vulnerability |
nvd |
CVE-2026-74266 |
botnet |
2026-08-15 |
| high |
CVE-2026-74270 — In the Linux kernel, the following vulnerability has been resolved: handshake: Require admin permiss… |
vulnerability |
nvd |
CVE-2026-74270 |
|
2026-08-15 |
| high |
CVE-2026-74275 — In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix out-of-bounds ac… |
vulnerability |
nvd |
CVE-2026-74275 |
|
2026-08-15 |
| high |
CVE-2026-74277 — In the Linux kernel, the following vulnerability has been resolved: iommu/dma-iommu: Fix wrong scatt… |
vulnerability |
nvd |
CVE-2026-74277 |
|
2026-08-15 |
| high |
CVE-2026-74281 — In the Linux kernel, the following vulnerability has been resolved: tipc: reject inverted service ra… |
vulnerability |
nvd |
CVE-2026-74281 |
|
2026-08-15 |
| high |
CVE-2026-74282 — In the Linux kernel, the following vulnerability has been resolved: tipc: prevent snt_unacked underf… |
vulnerability |
nvd |
CVE-2026-74282 |
|
2026-08-15 |
| high |
CVE-2026-74283 — In the Linux kernel, the following vulnerability has been resolved: tipc: require net admin for TIPC… |
vulnerability |
nvd |
CVE-2026-74283 |
|
2026-08-15 |
| high |
CVE-2026-74285 — In the Linux kernel, the following vulnerability has been resolved: net: Stop leased rxq before unin… |
vulnerability |
nvd |
CVE-2026-74285 |
|
2026-08-15 |
| high |
CVE-2026-74288 — In the Linux kernel, the following vulnerability has been resolved: net: fib_rules: Don't dump dying… |
vulnerability |
nvd |
CVE-2026-74288 |
|
2026-08-15 |
| high |
CVE-2026-74289 — In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: Don't dump dying fib_… |
vulnerability |
nvd |
CVE-2026-74289 |
|
2026-08-15 |
| high |
CVE-2026-74292 — In the Linux kernel, the following vulnerability has been resolved: ASoC: tegra: tegra210_ahub: Vali… |
vulnerability |
nvd |
CVE-2026-74292 |
|
2026-08-15 |
| high |
CVE-2026-74293 — In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl: fsl_audmix: Validate… |
vulnerability |
nvd |
CVE-2026-74293 |
|
2026-08-15 |
| high |
CVE-2026-74294 — In the Linux kernel, the following vulnerability has been resolved: ASoC: meson: aiu: Validate writt… |
vulnerability |
nvd |
CVE-2026-74294 |
|
2026-08-15 |
| high |
CVE-2026-74295 — In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: hdac_hdmi: Validat… |
vulnerability |
nvd |
CVE-2026-74295 |
|
2026-08-15 |
| high |
CVE-2026-74296 — In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Release the HW‑provid… |
vulnerability |
nvd |
CVE-2026-74296 |
|
2026-08-15 |
| high |
CVE-2026-74297 — In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix undefined shift o… |
vulnerability |
nvd |
CVE-2026-74297 |
|
2026-08-15 |
| high |
CVE-2026-74300 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci: validate codec c… |
vulnerability |
nvd |
CVE-2026-74300 |
|
2026-08-15 |
| high |
CVE-2026-74302 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix UAF in… |
vulnerability |
nvd |
CVE-2026-74302 |
|
2026-08-15 |
| high |
CVE-2026-74305 — In the Linux kernel, the following vulnerability has been resolved: bpf: Tighten cgroup storage cook… |
vulnerability |
nvd |
CVE-2026-74305 |
|
2026-08-15 |
| high |
CVE-2026-74306 — In the Linux kernel, the following vulnerability has been resolved: vfio/qat: fix f_pos race in qat_… |
vulnerability |
nvd |
CVE-2026-74306 |
|
2026-08-15 |
| high |
CVE-2026-74311 — In the Linux kernel, the following vulnerability has been resolved: virtio: rtc: tear down old virtq… |
vulnerability |
nvd |
CVE-2026-74311 |
|
2026-08-15 |
| high |
CVE-2026-74312 — In the Linux kernel, the following vulnerability has been resolved: vhost/vdpa: validate virtqueue i… |
vulnerability |
nvd |
CVE-2026-74312 |
|
2026-08-15 |
| high |
CVE-2026-74313 — In the Linux kernel, the following vulnerability has been resolved: vduse: hold vduse_lock across ID… |
vulnerability |
nvd |
CVE-2026-74313 |
|
2026-08-15 |
| high |
CVE-2026-74314 — In the Linux kernel, the following vulnerability has been resolved: bpf: Cancel special fields on ma… |
vulnerability |
nvd |
CVE-2026-74314 |
|
2026-08-15 |
| high |
CVE-2026-74316 — In the Linux kernel, the following vulnerability has been resolved: NFSD: Handle layout stid in nfsd… |
vulnerability |
nvd |
CVE-2026-74316 |
|
2026-08-15 |
| high |
CVE-2026-74317 — In the Linux kernel, the following vulnerability has been resolved: ixgbe: do not configure xps for… |
vulnerability |
nvd |
CVE-2026-74317 |
|
2026-08-15 |
| high |
CVE-2026-74321 — In the Linux kernel, the following vulnerability has been resolved: btrfs: fix invalid pointer deref… |
vulnerability |
nvd |
CVE-2026-74321 |
|
2026-08-15 |
| high |
CVE-2026-74322 — In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: Fix possible… |
vulnerability |
nvd |
CVE-2026-74322, CVE-2026-74323 |
|
2026-08-15 |
| high |
CVE-2026-74325 — In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: use kfree_rcu for of… |
vulnerability |
nvd |
CVE-2026-74325 |
|
2026-08-15 |
| high |
CVE-2026-74328 — In the Linux kernel, the following vulnerability has been resolved: iommufd: Destroy the pages conte… |
vulnerability |
nvd |
CVE-2026-74328 |
|
2026-08-15 |
| high |
CVE-2026-74330 — In the Linux kernel, the following vulnerability has been resolved: configfs: fix lockless traversal… |
vulnerability |
nvd |
CVE-2026-74330 |
|
2026-08-15 |
| high |
CVE-2026-74332 — In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp-sdw-sof: Bound DA… |
vulnerability |
nvd |
CVE-2026-74332 |
|
2026-08-15 |
| high |
CVE-2026-74333 — In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp-sdw-legacy: Bound… |
vulnerability |
nvd |
CVE-2026-74333 |
|
2026-08-15 |
| high |
CVE-2026-74334 — In the Linux kernel, the following vulnerability has been resolved: RDMA/nldev: Fix locking when acc… |
vulnerability |
nvd |
CVE-2026-74334 |
|
2026-08-15 |
| high |
CVE-2026-74338 — In the Linux kernel, the following vulnerability has been resolved: bpf: Reject sleepable BPF_LSM_CG… |
vulnerability |
nvd |
CVE-2026-74338 |
|
2026-08-15 |
| high |
CVE-2026-74340 — In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix OOB read from… |
vulnerability |
nvd |
CVE-2026-74340 |
|
2026-08-15 |
| high |
CVE-2026-74341 — In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix heap overflow… |
vulnerability |
nvd |
CVE-2026-74341 |
|
2026-08-15 |
| high |
CVE-2026-74343 — In the Linux kernel, the following vulnerability has been resolved: kernfs: fix xattr race condition… |
vulnerability |
nvd |
CVE-2026-74343 |
|
2026-08-15 |
| high |
CVE-2026-74344 — In the Linux kernel, the following vulnerability has been resolved: bpf: Clear rb node linkage when… |
vulnerability |
nvd |
CVE-2026-74344 |
|
2026-08-15 |
| high |
CVE-2026-74347 — In the Linux kernel, the following vulnerability has been resolved: netfilter: cttimeout: detach dat… |
vulnerability |
nvd |
CVE-2026-74347 |
|
2026-08-15 |
| high |
CVE-2026-74349 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject FITRIM ranges shor… |
vulnerability |
nvd |
CVE-2026-74349 |
|
2026-08-15 |
| high |
CVE-2026-74354 — In the Linux kernel, the following vulnerability has been resolved: bpf: Take mmap_lock in zap_pages… |
vulnerability |
nvd |
CVE-2026-74354 |
|
2026-08-15 |
| high |
CVE-2026-74355 — In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix RB-tree corrupti… |
vulnerability |
nvd |
CVE-2026-74355 |
|
2026-08-15 |
| high |
CVE-2026-74356 — In the Linux kernel, the following vulnerability has been resolved: vhost: fix vhost_get_avail_idx f… |
vulnerability |
nvd |
CVE-2026-74356 |
|
2026-08-15 |
| high |
CVE-2026-74357 — In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix KASAN slab-out-o… |
vulnerability |
nvd |
CVE-2026-74357 |
|
2026-08-15 |
| high |
CVE-2026-74359 — In the Linux kernel, the following vulnerability has been resolved: configfs_lookup(): don't leave -… |
vulnerability |
nvd |
CVE-2026-74359 |
|
2026-08-15 |
| high |
CVE-2026-74363 — In the Linux kernel, the following vulnerability has been resolved: bpf: fix UAF by restoring RCU-de… |
vulnerability |
nvd |
CVE-2026-74363 |
|
2026-08-15 |
| high |
CVE-2026-74364 — In the Linux kernel, the following vulnerability has been resolved: bpf: Reject exclusive maps as in… |
vulnerability |
nvd |
CVE-2026-74364 |
|
2026-08-15 |
| high |
CVE-2026-74365 — In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: Handle preemption in… |
vulnerability |
nvd |
CVE-2026-74365 |
|
2026-08-15 |
| high |
CVE-2026-74367 — In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix inconsistent a… |
vulnerability |
nvd |
CVE-2026-74367 |
|
2026-08-15 |
| high |
CVE-2026-74371 — In the Linux kernel, the following vulnerability has been resolved: bpf: fix BPF_PROG_QUERY OOB writ… |
vulnerability |
nvd |
CVE-2026-74371 |
|
2026-08-15 |
| high |
CVE-2026-74374 — In the Linux kernel, the following vulnerability has been resolved: md/raid1,raid10: fix error-path… |
vulnerability |
nvd |
CVE-2026-74374 |
|
2026-08-15 |
| high |
CVE-2026-74377 — In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Copy WQE to local buff… |
vulnerability |
nvd |
CVE-2026-74377 |
|
2026-08-15 |
| high |
CVE-2026-74378 — In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix TOCTOU heap overfl… |
vulnerability |
nvd |
CVE-2026-74378 |
|
2026-08-15 |
| high |
CVE-2026-74380 — In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix iommu_map_sgtab… |
vulnerability |
nvd |
CVE-2026-74380 |
|
2026-08-15 |
| high |
CVE-2026-74383 — In the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix out-of-bounds acce… |
vulnerability |
nvd |
CVE-2026-74383 |
|
2026-08-15 |
| high |
CVE-2026-74385 — In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check return value of… |
vulnerability |
nvd |
CVE-2026-74385 |
|
2026-08-15 |
| high |
CVE-2026-74387 — In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: midi: Serialize outpu… |
vulnerability |
nvd |
CVE-2026-74387 |
|
2026-08-15 |
| high |
CVE-2026-74388 — In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: oss: Fix UAF at handl… |
vulnerability |
nvd |
CVE-2026-74388 |
|
2026-08-15 |
| high |
CVE-2026-74390 — In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix out-of-bounds wr… |
vulnerability |
nvd |
CVE-2026-74390 |
|
2026-08-15 |
| high |
CVE-2026-74396 — In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix UMR XLT cleanup o… |
vulnerability |
nvd |
CVE-2026-74396 |
|
2026-08-15 |
| high |
CVE-2026-74397 — In the Linux kernel, the following vulnerability has been resolved: IB/mlx5: Fix transport-domain ro… |
vulnerability |
nvd |
CVE-2026-74397 |
|
2026-08-15 |
| high |
CVE-2026-74403 — In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Check for page all… |
vulnerability |
nvd |
CVE-2026-74403 |
|
2026-08-15 |
| high |
CVE-2026-74404 — In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix snp_filter_res… |
vulnerability |
nvd |
CVE-2026-74404 |
|
2026-08-15 |
| high |
CVE-2026-74405 — In the Linux kernel, the following vulnerability has been resolved: OPP: Fix race between OPP additi… |
vulnerability |
nvd |
CVE-2026-74405 |
|
2026-08-15 |
| high |
CVE-2026-74407 — In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: cancel SSR work it… |
vulnerability |
nvd |
CVE-2026-74407 |
|
2026-08-15 |
| high |
CVE-2026-74408 — In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: fix OOB access from… |
vulnerability |
nvd |
CVE-2026-74408 |
|
2026-08-15 |
| high |
CVE-2026-74409 — In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: add bounds check on… |
vulnerability |
nvd |
CVE-2026-74409 |
|
2026-08-15 |
| high |
CVE-2026-74410 — In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: fix OOB read from f… |
vulnerability |
nvd |
CVE-2026-74410 |
|
2026-08-15 |
| high |
CVE-2026-74411 — In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: Correct data type f… |
vulnerability |
nvd |
CVE-2026-74411 |
|
2026-08-15 |
| high |
CVE-2026-74412 — In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: fix wrong pci_get_d… |
vulnerability |
nvd |
CVE-2026-74412 |
|
2026-08-15 |
| high |
CVE-2026-74413 — In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix wrong pci_get_d… |
vulnerability |
nvd |
CVE-2026-74413 |
|
2026-08-15 |
| high |
CVE-2026-74417 — In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix integer overflow… |
vulnerability |
nvd |
CVE-2026-74417 |
|
2026-08-15 |
| high |
CVE-2026-74419 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Adjust size for c… |
vulnerability |
nvd |
CVE-2026-74419 |
|
2026-08-15 |
| high |
CVE-2026-74425 — In the Linux kernel, the following vulnerability has been resolved: afs: handle CB.InitCallBackState… |
vulnerability |
nvd |
CVE-2026-74425 |
|
2026-08-15 |
| high |
CVE-2026-74429 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the reception of a re… |
vulnerability |
nvd |
CVE-2026-74429 |
|
2026-08-15 |
| high |
CVE-2026-74430 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix ACKALL packet handlin… |
vulnerability |
nvd |
CVE-2026-74430 |
|
2026-08-15 |
| high |
CVE-2026-74431 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix potential infinite lo… |
vulnerability |
nvd |
CVE-2026-74431 |
|
2026-08-15 |
| high |
CVE-2026-74435 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: rxrpc_verify_data ensure… |
vulnerability |
nvd |
CVE-2026-74435 |
|
2026-08-15 |
| high |
CVE-2026-74438 — In the Linux kernel, the following vulnerability has been resolved: crypto: sun4i-ss - Remove insecu… |
vulnerability |
nvd |
CVE-2026-74438 |
|
2026-08-15 |
| high |
CVE-2026-14279 — The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, a… |
vulnerability |
nvd |
CVE-2026-14279 |
|
2026-08-15 |
| high |
CVE-2026-15142 — The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versio… |
vulnerability |
nvd |
CVE-2026-15142 |
|
2026-08-15 |
| high |
CVE-2026-18438 — The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud!… |
vulnerability |
nvd |
CVE-2026-18438 |
rce |
2026-08-15 |
| high |
CVE-2026-73634 — Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an end… |
vulnerability |
nvd |
CVE-2026-73634 |
|
2026-08-15 |
| high |
CVE-2026-73635 — Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed l… |
vulnerability |
nvd |
CVE-2026-73635 |
|
2026-08-15 |
| high |
CVE-2026-74440 — In the Linux kernel, the following vulnerability has been resolved: drm/xe: Wait on external BO kern… |
vulnerability |
nvd |
CVE-2026-74440 |
|
2026-08-15 |
| high |
CVE-2026-74443 — In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: bound DMA command bo… |
vulnerability |
nvd |
CVE-2026-74443 |
|
2026-08-15 |
| high |
CVE-2026-74444 — In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: validate DRAW_PRIMIT… |
vulnerability |
nvd |
CVE-2026-74444 |
|
2026-08-15 |
| high |
CVE-2026-74446 — In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: hold event_mutex whi… |
vulnerability |
nvd |
CVE-2026-74446 |
|
2026-08-15 |
| high |
CVE-2026-74447 — In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix uint32_t overflo… |
vulnerability |
nvd |
CVE-2026-74447 |
|
2026-08-15 |
| high |
CVE-2026-74449 — In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix divide-by-z… |
vulnerability |
nvd |
CVE-2026-74449 |
ransomware |
2026-08-15 |
| high |
CVE-2026-74450 — In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: fix pptable use-afte… |
vulnerability |
nvd |
CVE-2026-74450 |
|
2026-08-15 |
| high |
CVE-2026-74451 — In the Linux kernel, the following vulnerability has been resolved: drm/panthor: validate firmware i… |
vulnerability |
nvd |
CVE-2026-74451 |
|
2026-08-15 |
| high |
CVE-2026-74452 — In the Linux kernel, the following vulnerability has been resolved: drm/panthor: reject firmware sec… |
vulnerability |
nvd |
CVE-2026-74452 |
|
2026-08-15 |
| high |
CVE-2026-74453 — In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Zero the tile state dat… |
vulnerability |
nvd |
CVE-2026-74453 |
|
2026-08-15 |
| high |
CVE-2026-74454 — In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Supply the overflow slo… |
vulnerability |
nvd |
CVE-2026-74454 |
|
2026-08-15 |
| high |
CVE-2026-74456 — In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: peak_usb_start():… |
vulnerability |
nvd |
CVE-2026-74456 |
|
2026-08-15 |
| high |
CVE-2026-74461 — In the Linux kernel, the following vulnerability has been resolved: i2c: imx: Cancel hrtimer before… |
vulnerability |
nvd |
CVE-2026-74461 |
|
2026-08-15 |
| high |
CVE-2026-74465 — In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix potential… |
vulnerability |
nvd |
CVE-2026-74465 |
zeroday |
2026-08-15 |
| high |
CVE-2026-74467 — In the Linux kernel, the following vulnerability has been resolved: s390/qeth: Check CAP_NET_ADMIN f… |
vulnerability |
nvd |
CVE-2026-74467 |
|
2026-08-15 |
| high |
CVE-2026-74469 — In the Linux kernel, the following vulnerability has been resolved: sctp: prevent peer transport cou… |
vulnerability |
nvd |
CVE-2026-74469 |
|
2026-08-15 |
| high |
CVE-2026-74470 — In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_debug: Fix REPORT ZON… |
vulnerability |
nvd |
CVE-2026-74470 |
|
2026-08-15 |
| high |
CVE-2026-74471 — In the Linux kernel, the following vulnerability has been resolved: tracing: Check return value of _… |
vulnerability |
nvd |
CVE-2026-74471 |
|
2026-08-15 |
| high |
CVE-2026-74479 — In the Linux kernel, the following vulnerability has been resolved: net: pktgen: fix proc entry use-… |
vulnerability |
nvd |
CVE-2026-74479 |
|
2026-08-15 |
| high |
CVE-2026-74481 — In the Linux kernel, the following vulnerability has been resolved: mm/page_reporting: use system_fr… |
vulnerability |
nvd |
CVE-2026-74481 |
|
2026-08-15 |
| high |
CVE-2026-74482 — In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: unlock i_mmap_rw… |
vulnerability |
nvd |
CVE-2026-74482 |
|
2026-08-15 |
| high |
CVE-2026-74485 — In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: reject a flag chara… |
vulnerability |
nvd |
CVE-2026-74485 |
|
2026-08-15 |
| high |
CVE-2026-74488 — In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: use the subframe… |
vulnerability |
nvd |
CVE-2026-74488 |
|
2026-08-15 |
| high |
CVE-2026-74489 — In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix tid_tx use-a… |
vulnerability |
nvd |
CVE-2026-74489 |
|
2026-08-15 |
| high |
CVE-2026-74490 — In the Linux kernel, the following vulnerability has been resolved: tipc: avoid use-after-free in po… |
vulnerability |
nvd |
CVE-2026-74490 |
|
2026-08-15 |
| high |
CVE-2026-74492 — In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: do not update… |
vulnerability |
nvd |
CVE-2026-74492 |
ransomware |
2026-08-15 |
| high |
CVE-2026-74496 — In the Linux kernel, the following vulnerability has been resolved: fou: Fix use-after-free in fou_c… |
vulnerability |
nvd |
CVE-2026-74496 |
|
2026-08-15 |
| high |
CVE-2026-74497 — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Clamp frame siz… |
vulnerability |
nvd |
CVE-2026-74497 |
ransomware |
2026-08-15 |
| high |
CVE-2026-74503 — In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Clear SNDRV_TIMER_I… |
vulnerability |
nvd |
CVE-2026-74503 |
|
2026-08-15 |
| high |
CVE-2026-74506 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix UAF when sending a mess… |
vulnerability |
nvd |
CVE-2026-74506 |
ransomware |
2026-08-15 |
| high |
CVE-2026-74507 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: validate number… |
vulnerability |
nvd |
CVE-2026-74507 |
|
2026-08-15 |
| high |
CVE-2026-74508 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: reject frames w… |
vulnerability |
nvd |
CVE-2026-74508 |
|
2026-08-15 |
| high |
CVE-2026-74509 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix adverti… |
vulnerability |
nvd |
CVE-2026-74509 |
|
2026-08-15 |
| high |
CVE-2026-74510 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix UAF in pair… |
vulnerability |
nvd |
CVE-2026-74510 |
|
2026-08-15 |
| high |
CVE-2026-74512 — In the Linux kernel, the following vulnerability has been resolved: audit: fix potential use-after-f… |
vulnerability |
nvd |
CVE-2026-74512 |
|
2026-08-15 |
| high |
CVE-2026-74513 — In the Linux kernel, the following vulnerability has been resolved: dibs: fix use-after-free of dmb_… |
vulnerability |
nvd |
CVE-2026-74513 |
botnet |
2026-08-15 |
| high |
CVE-2026-74515 — In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Reject adapter i… |
vulnerability |
nvd |
CVE-2026-74515 |
|
2026-08-15 |
| high |
CVE-2026-74516 — In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Update x2APIC MSR inte… |
vulnerability |
nvd |
CVE-2026-74516 |
|
2026-08-15 |
| high |
CVE-2026-74518 — In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix list corruption… |
vulnerability |
nvd |
CVE-2026-74518 |
botnet |
2026-08-15 |
| high |
CVE-2026-74519 — In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: don't free… |
vulnerability |
nvd |
CVE-2026-74519 |
|
2026-08-15 |
| high |
CVE-2026-74520 — In the Linux kernel, the following vulnerability has been resolved: iommu/iommufd: Fix IOPF group ow… |
vulnerability |
nvd |
CVE-2026-74520 |
|
2026-08-15 |
| high |
CVE-2026-74522 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __c… |
vulnerability |
nvd |
CVE-2026-74522 |
|
2026-08-15 |
| high |
CVE-2026-74523 — In the Linux kernel, the following vulnerability has been resolved: qede: sync udp_tunnel ports outs… |
vulnerability |
nvd |
CVE-2026-74523 |
|
2026-08-15 |
| high |
CVE-2026-74527 — In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Block VFs from clo… |
vulnerability |
nvd |
CVE-2026-74527 |
|
2026-08-15 |
| high |
CVE-2026-74528 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn i… |
vulnerability |
nvd |
CVE-2026-74528, CVE-2026-74529, CVE-2026-74530 |
|
2026-08-15 |
| high |
CVE-2026-74531 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: hold conn r… |
vulnerability |
nvd |
CVE-2026-74531 |
|
2026-08-15 |
| high |
CVE-2026-74533 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix race of kfre… |
vulnerability |
nvd |
CVE-2026-74533 |
|
2026-08-15 |
| high |
CVE-2026-74534 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix refcounting… |
vulnerability |
nvd |
CVE-2026-74534 |
|
2026-08-15 |
| high |
CVE-2026-74535 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: avoid deadlocks… |
vulnerability |
nvd |
CVE-2026-74535 |
|
2026-08-15 |
| high |
CVE-2026-74537 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: hold sk properly… |
vulnerability |
nvd |
CVE-2026-74537 |
|
2026-08-15 |
| high |
CVE-2026-74538 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: lock sk in iso_c… |
vulnerability |
nvd |
CVE-2026-74538 |
|
2026-08-15 |
| high |
CVE-2026-74539 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: lock sk in iso_s… |
vulnerability |
nvd |
CVE-2026-74539 |
|
2026-08-15 |
| high |
CVE-2026-74540 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix UAF in l2c… |
vulnerability |
nvd |
CVE-2026-74540 |
|
2026-08-15 |
| high |
CVE-2026-74541 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: clear iso_data a… |
vulnerability |
nvd |
CVE-2026-74541 |
|
2026-08-15 |
| high |
CVE-2026-74544 — In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_u32: validate off… |
vulnerability |
nvd |
CVE-2026-74544 |
|
2026-08-15 |
| high |
CVE-2026-74548 — In the Linux kernel, the following vulnerability has been resolved: forcedeth: fix UAF of txrx_stats… |
vulnerability |
nvd |
CVE-2026-74548 |
|
2026-08-15 |
| high |
CVE-2026-74549 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct6775-core) Prevent ac… |
vulnerability |
nvd |
CVE-2026-74549 |
|
2026-08-15 |
| high |
CVE-2026-74550 — In the Linux kernel, the following vulnerability has been resolved: net: do not send ICMP/NDISC Redi… |
vulnerability |
nvd |
CVE-2026-74550 |
|
2026-08-15 |
| high |
CVE-2026-74551 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (nzxt-smart2) DMA-align o… |
vulnerability |
nvd |
CVE-2026-74551 |
|
2026-08-15 |
| high |
CVE-2026-74554 — In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix out-of-bounds… |
vulnerability |
nvd |
CVE-2026-74554 |
|
2026-08-15 |
| high |
CVE-2026-74557 — In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi: Fix stale-data l… |
vulnerability |
nvd |
CVE-2026-74557 |
|
2026-08-15 |
| high |
CVE-2026-74560 — In the Linux kernel, the following vulnerability has been resolved: xsk: fix buffer leak in xsk_drop… |
vulnerability |
nvd |
CVE-2026-74560 |
botnet |
2026-08-15 |
| high |
CVE-2026-74561 — In the Linux kernel, the following vulnerability has been resolved: nexthop: avoid unlocked f6i_list… |
vulnerability |
nvd |
CVE-2026-74561 |
|
2026-08-15 |
| high |
CVE-2026-74562 — In the Linux kernel, the following vulnerability has been resolved: nexthop: take nh->lock for f6i_l… |
vulnerability |
nvd |
CVE-2026-74562 |
|
2026-08-15 |
| high |
CVE-2026-74563 — In the Linux kernel, the following vulnerability has been resolved: rds: tcp: hold the RCU lock acro… |
vulnerability |
nvd |
CVE-2026-74563 |
|
2026-08-15 |
| high |
CVE-2026-74564 — In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_hashlimit: validat… |
vulnerability |
nvd |
CVE-2026-74564 |
|
2026-08-15 |
| high |
CVE-2026-74565 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: make nft_o… |
vulnerability |
nvd |
CVE-2026-74565 |
|
2026-08-15 |
| high |
CVE-2026-74567 — In the Linux kernel, the following vulnerability has been resolved: keys: fix out-of-bounds read in… |
vulnerability |
nvd |
CVE-2026-74567 |
|
2026-08-15 |
| high |
CVE-2026-74572 — In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix deadlock betwe… |
vulnerability |
nvd |
CVE-2026-74572 |
|
2026-08-15 |
| high |
CVE-2026-74574 — In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix fdev setup… |
vulnerability |
nvd |
CVE-2026-74574 |
|
2026-08-15 |
| high |
CVE-2026-74575 — In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Prevent XDomain del… |
vulnerability |
nvd |
CVE-2026-74575 |
|
2026-08-15 |
| high |
CVE-2026-74576 — In the Linux kernel, the following vulnerability has been resolved: mm/slab: prevent unbounded recur… |
vulnerability |
nvd |
CVE-2026-74576 |
|
2026-08-15 |
| high |
CVE-2026-18500 — @fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verifi… |
vulnerability |
nvd |
CVE-2026-18500 |
|
2026-08-15 |
| high |
CVE-2026-18549 — @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not… |
vulnerability |
nvd |
CVE-2026-18549 |
|
2026-08-15 |
| high |
CVE-2026-19474 — @fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not… |
vulnerability |
nvd |
CVE-2026-19474 |
|
2026-08-15 |
| high |
CVE-2026-19899 — A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected… |
vulnerability |
nvd |
CVE-2026-19899 |
|
2026-08-15 |
| high |
CVE-2026-19900 — A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown… |
vulnerability |
nvd |
CVE-2026-19900 |
|
2026-08-15 |
| high |
CVE-2026-19901 — A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown functi… |
vulnerability |
nvd |
CVE-2026-19901 |
|
2026-08-15 |
| high |
CVE-2026-19905 — A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHS… |
vulnerability |
nvd |
CVE-2026-19905 |
|
2026-08-15 |
| high |
CVE-2026-73045 — SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerabil… |
vulnerability |
nvd |
CVE-2026-73045 |
|
2026-08-15 |
| high |
CVE-2026-73054 — SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoi… |
vulnerability |
nvd |
CVE-2026-73054 |
|
2026-08-15 |
| high |
CVE-2026-19919 — A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown funct… |
vulnerability |
nvd |
CVE-2026-19919 |
|
2026-08-16 |
| high |
CVE-2026-19926 — A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected el… |
vulnerability |
nvd |
CVE-2026-19926 |
|
2026-08-16 |
| high |
CVE-2026-14498 — The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to… |
vulnerability |
nvd |
CVE-2026-14498 |
rce |
2026-08-16 |
| high |
CVE-2026-15002 — The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Sc… |
vulnerability |
nvd |
CVE-2026-15002 |
|
2026-08-16 |
| high |
CVE-2026-16099 — The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to i… |
vulnerability |
nvd |
CVE-2026-16099 |
rce |
2026-08-16 |
| high |
CVE-2026-17123 — The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in vers… |
vulnerability |
nvd |
CVE-2026-17123 |
ransomware |
2026-08-16 |
| high |
CVE-2026-17533 — The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration… |
vulnerability |
nvd |
CVE-2026-17533 |
|
2026-08-16 |
| high |
CVE-2026-17581 — The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code In… |
vulnerability |
nvd |
CVE-2026-17581 |
rce |
2026-08-16 |
| high |
CVE-2026-18653 — The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before u… |
vulnerability |
nvd |
CVE-2026-18653 |
|
2026-08-16 |
| high |
CVE-2026-19717 — The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisat… |
vulnerability |
nvd |
CVE-2026-19717 |
|
2026-08-16 |
| high |
CVE-2026-19728 — The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify th… |
vulnerability |
nvd |
CVE-2026-19728 |
|
2026-08-16 |
| high |
CVE-2026-10734 — The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_recor… |
vulnerability |
nvd |
CVE-2026-10734 |
|
2026-08-16 |
| high |
CVE-2026-13424 — The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to… |
vulnerability |
nvd |
CVE-2026-13424 |
|
2026-08-16 |
| high |
CVE-2026-17087 — The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerab… |
vulnerability |
nvd |
CVE-2026-17087 |
|
2026-08-16 |
| high |
CVE-2026-2497 — The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_ord… |
vulnerability |
nvd |
CVE-2026-2497 |
|
2026-08-16 |
| high |
CVE-2026-74578 — In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force s… |
vulnerability |
nvd |
CVE-2026-74578 |
|
2026-08-16 |
| high |
CVE-2026-73057 — stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing att… |
vulnerability |
nvd |
CVE-2026-73057 |
|
2026-08-16 |
| high |
CVE-2026-73060 — Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRan… |
vulnerability |
nvd |
CVE-2026-73060 |
|
2026-08-16 |
| high |
CVE-2026-73062 — Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multipli… |
vulnerability |
nvd |
CVE-2026-73062 |
|
2026-08-16 |
| high |
CVE-2026-74783 — Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails t… |
vulnerability |
nvd |
CVE-2026-74783 |
|
2026-08-16 |
| high |
CVE-2026-74787 — Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin… |
vulnerability |
nvd |
CVE-2026-74787 |
|
2026-08-16 |
| high |
CVE-2026-74788 — Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnera… |
vulnerability |
nvd |
CVE-2026-74788 |
|
2026-08-16 |
| high |
CVE-2026-74789 — Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statem… |
vulnerability |
nvd |
CVE-2026-74789 |
|
2026-08-16 |
| high |
CVE-2026-74791 — Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is c… |
vulnerability |
nvd |
CVE-2026-74791 |
|
2026-08-16 |
| high |
CVE-2026-74792 — Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested… |
vulnerability |
nvd |
CVE-2026-74792 |
|
2026-08-16 |
| high |
CVE-2026-74794 — Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the Objec… |
vulnerability |
nvd |
CVE-2026-74794 |
|
2026-08-16 |
| high |
CVE-2026-74795 — Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parse… |
vulnerability |
nvd |
CVE-2026-74795 |
|
2026-08-16 |
| high |
CVE-2026-19960 — A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function form… |
vulnerability |
nvd |
CVE-2026-19960 |
|
2026-08-16 |
| high |
CVE-2026-19962 — A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setW… |
vulnerability |
nvd |
CVE-2026-19962 |
|
2026-08-17 |
| high |
CVE-2026-19963 — A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function sta… |
vulnerability |
nvd |
CVE-2026-19963 |
|
2026-08-17 |
| high |
CVE-2026-19979 — A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE… |
vulnerability |
nvd |
CVE-2026-19979 |
|
2026-08-17 |
| high |
CVE-2026-19980 — A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE930… |
vulnerability |
nvd |
CVE-2026-19980 |
|
2026-08-17 |
| high |
CVE-2026-19981 — A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE… |
vulnerability |
nvd |
CVE-2026-19981 |
|
2026-08-17 |
| high |
CVE-2026-19982 — A security vulnerability has been detected in GL.iNet BE9300 and MT6000 4.8.x. This vulnerability af… |
vulnerability |
nvd |
CVE-2026-19982 |
|
2026-08-17 |
| high |
CVE-2026-19983 — A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE… |
vulnerability |
nvd |
CVE-2026-19983 |
|
2026-08-17 |
| high |
CVE-2026-74845 — Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulner… |
vulnerability |
nvd |
CVE-2026-74845 |
|
2026-08-17 |
| high |
CVE-2026-74798 — SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool.… |
vulnerability |
nvd |
CVE-2026-74798 |
|
2026-08-17 |
| high |
CVE-2026-74801 — SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-lin… |
vulnerability |
nvd |
CVE-2026-74801 |
|
2026-08-17 |
| high |
CVE-2026-74802 — SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-onl… |
vulnerability |
nvd |
CVE-2026-74802 |
|
2026-08-17 |
| high |
CVE-2026-74868 — SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service… |
vulnerability |
nvd |
CVE-2026-74868 |
|
2026-08-17 |
| high |
CVE-2026-74869 — stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message hand… |
vulnerability |
nvd |
CVE-2026-74869 |
ransomware |
2026-08-17 |
| high |
CVE-2026-74874 — openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographi… |
vulnerability |
nvd |
CVE-2026-74874 |
|
2026-08-17 |
| high |
CVE-2026-74877 — openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the… |
vulnerability |
nvd |
CVE-2026-74877 |
|
2026-08-17 |
| high |
CVE-2026-74879 — openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready… |
vulnerability |
nvd |
CVE-2026-74879 |
|
2026-08-17 |
| high |
CVE-2026-74882 — openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the enti… |
vulnerability |
nvd |
CVE-2026-74882 |
|
2026-08-17 |
| high |
CVE-2026-74883 — openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbo… |
vulnerability |
nvd |
CVE-2026-74883 |
|
2026-08-17 |
| high |
CVE-2026-74884 — openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path me… |
vulnerability |
nvd |
CVE-2026-74884 |
|
2026-08-17 |
| high |
CVE-2026-74888 — openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with ite… |
vulnerability |
nvd |
CVE-2026-74888 |
|
2026-08-17 |
| high |
CVE-2026-74892 — openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telem… |
vulnerability |
nvd |
CVE-2026-74892 |
|
2026-08-17 |
| high |
CVE-2026-74893 — openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py tha… |
vulnerability |
nvd |
CVE-2026-74893 |
|
2026-08-17 |
| high |
CVE-2026-16467 — Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing F… |
vulnerability |
nvd |
CVE-2026-16467 |
|
2026-08-17 |
| high |
CVE-2026-74997 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk pl… |
vulnerability |
nvd |
CVE-2026-74997 |
rce |
2026-08-17 |
| high |
CVE-2026-74998 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style S… |
vulnerability |
nvd |
CVE-2026-74998 |
|
2026-08-17 |
| high |
CVE-2026-75002 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desyn… |
vulnerability |
nvd |
CVE-2026-75002 |
|
2026-08-17 |
| high |
CVE-2026-15218 — A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. Th… |
vulnerability |
nvd |
CVE-2026-15218 |
rce |
2026-08-17 |
| high |
CVE-2026-16137 — In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credential… |
vulnerability |
nvd |
CVE-2026-16137 |
|
2026-08-17 |
| high |
CVE-2026-16138 — In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of… |
vulnerability |
nvd |
CVE-2026-16138 |
|
2026-08-17 |
| high |
CVE-2026-16139 — In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zon… |
vulnerability |
nvd |
CVE-2026-16139 |
rce |
2026-08-17 |
| high |
CVE-2026-16471 — Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Fun… |
vulnerability |
nvd |
CVE-2026-16471 |
|
2026-08-17 |
| high |
CVE-2026-19693 — extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and nev… |
vulnerability |
nvd |
CVE-2026-19693 |
|
2026-08-17 |
| high |
CVE-2026-56089 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privil… |
vulnerability |
nvd |
CVE-2026-56089, CVE-2026-59909 |
|
2026-08-17 |
| high |
CVE-2026-56090 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerab… |
vulnerability |
nvd |
CVE-2026-56090 |
|
2026-08-17 |
| high |
CVE-2026-56685 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elemen… |
vulnerability |
nvd |
CVE-2026-56685, CVE-2026-56686, CVE-2026-59910 |
|
2026-08-17 |
| high |
CVE-2026-71567 — In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variable… |
vulnerability |
nvd |
CVE-2026-71567 |
|
2026-08-17 |
| high |
CVE-2026-73646 — PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rul… |
vulnerability |
nvd |
CVE-2026-73646 |
|
2026-08-17 |
| high |
CVE-2026-75044 — In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed… |
vulnerability |
nvd |
CVE-2026-75044 |
|
2026-08-17 |
| high |
CVE-2026-75048 — In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was po… |
vulnerability |
nvd |
CVE-2026-75048 |
|
2026-08-17 |
| high |
CVE-2026-75050 — In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type par… |
vulnerability |
nvd |
CVE-2026-75050 |
|
2026-08-17 |
| high |
CVE-2026-75051 — In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was po… |
vulnerability |
nvd |
CVE-2026-75051 |
|
2026-08-17 |
| high |
CVE-2026-75056 — In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible |
vulnerability |
nvd |
CVE-2026-75056 |
rce |
2026-08-17 |
| high |
CVE-2026-75060 — In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP too… |
vulnerability |
nvd |
CVE-2026-75060 |
|
2026-08-17 |
| high |
CVE-2026-9771 — The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On bu… |
vulnerability |
nvd |
CVE-2026-9771 |
|
2026-08-17 |
| high |
CVE-2026-33437 — Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. P… |
vulnerability |
nvd |
CVE-2026-33437, CVE-2026-57485 |
|
2026-08-17 |
| high |
CVE-2026-59893 — sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/key… |
vulnerability |
nvd |
CVE-2026-59893 |
|
2026-08-17 |
| high |
CVE-2026-59902 — Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2… |
vulnerability |
nvd |
CVE-2026-59902, CVE-2026-59903, CVE-2026-75596 |
|
2026-08-17 |
| high |
CVE-2026-62982 — Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_m… |
vulnerability |
nvd |
CVE-2026-62982 |
|
2026-08-17 |
| high |
CVE-2026-71979 — INDI (Instrument Neutral Distributed Interface) indiserver through 2.2.4.2, fixed in commit 96bbd7f,… |
vulnerability |
nvd |
CVE-2026-71979 |
|
2026-08-17 |
| high |
CVE-2026-71980 — Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the d… |
vulnerability |
nvd |
CVE-2026-71980 |
|
2026-08-17 |
| high |
CVE-2026-73522 — COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthentic… |
vulnerability |
nvd |
CVE-2026-73522 |
|
2026-08-17 |
| high |
CVE-2026-73523 — COVESA Open1722 through 0.9.2 contains an integer truncation vulnerability in acf-can-listener.c tha… |
vulnerability |
nvd |
CVE-2026-73523 |
|
2026-08-17 |
| high |
CVE-2026-50773 — An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to ex… |
vulnerability |
nvd |
CVE-2026-50773 |
|
2026-08-17 |
| high |
CVE-2026-50776 — Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote atta… |
vulnerability |
nvd |
CVE-2026-50776 |
|
2026-08-17 |
| high |
CVE-2026-74238 — TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpac… |
vulnerability |
nvd |
CVE-2026-74238 |
|
2026-08-17 |
| high |
CVE-2026-54758 — Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the expandNppEnvironmentStrs… |
vulnerability |
nvd |
CVE-2026-54758 |
|
2026-08-17 |
| high |
CVE-2026-57233 — Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress functi… |
vulnerability |
nvd |
CVE-2026-57233 |
|
2026-08-17 |
| high |
CVE-2026-68005 — An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via… |
vulnerability |
nvd |
CVE-2026-68005 |
|
2026-08-17 |
| high |
CVE-2026-70495 — A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad pe… |
vulnerability |
nvd |
CVE-2026-70495 |
|
2026-08-17 |
| high |
CVE-2026-74234 — Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achi… |
vulnerability |
nvd |
CVE-2026-74234 |
|
2026-08-17 |
| high |
CVE-2026-75014 — A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability aff… |
vulnerability |
nvd |
CVE-2026-75014 |
|
2026-08-17 |
| high |
CVE-2026-19589 — Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow uni… |
vulnerability |
nvd |
CVE-2026-19589 |
|
2026-08-17 |
| high |
CVE-2026-34398 — FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mo… |
vulnerability |
nvd |
CVE-2026-34398 |
|
2026-08-17 |
| high |
CVE-2026-34399 — FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCA… |
vulnerability |
nvd |
CVE-2026-34399 |
|
2026-08-17 |
| high |
CVE-2026-34789 — FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/Prope… |
vulnerability |
nvd |
CVE-2026-34789 |
|
2026-08-17 |
| high |
CVE-2026-54356 — Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/u… |
vulnerability |
nvd |
CVE-2026-54356 |
|
2026-08-17 |
| high |
CVE-2026-63409 — Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malic… |
vulnerability |
nvd |
CVE-2026-63409 |
|
2026-08-17 |
| high |
CVE-2026-64657 — Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector… |
vulnerability |
nvd |
CVE-2026-64657 |
|
2026-08-17 |
| high |
CVE-2026-65822 — ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0,… |
vulnerability |
nvd |
CVE-2026-65822 |
|
2026-08-17 |
| high |
CVE-2026-65832 — Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthe… |
vulnerability |
nvd |
CVE-2026-65832 |
|
2026-08-17 |
| high |
CVE-2026-71518 — Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download rou… |
vulnerability |
nvd |
CVE-2026-71518 |
|
2026-08-17 |
| high |
CVE-2026-73410 — Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outbo… |
vulnerability |
nvd |
CVE-2026-73410 |
|
2026-08-17 |
| high |
CVE-2026-75103 — Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allow… |
vulnerability |
nvd |
CVE-2026-75103 |
|
2026-08-17 |
| high |
CVE-2026-75105 — phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary… |
vulnerability |
nvd |
CVE-2026-75105 |
|
2026-08-17 |
| high |
CVE-2026-75109 — Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the… |
vulnerability |
nvd |
CVE-2026-75109 |
|
2026-08-17 |
| high |
CVE-2026-75111 — Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoi… |
vulnerability |
nvd |
CVE-2026-75111 |
|
2026-08-17 |
| high |
CVE-2026-75479 — JimuReport contains an authentication bypass vulnerability in the report folder template listing end… |
vulnerability |
nvd |
CVE-2026-75479 |
|
2026-08-17 |
| high |
CVE-2026-75481 — SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when u… |
vulnerability |
nvd |
CVE-2026-75481 |
|
2026-08-17 |
| high |
CVE-2026-75482 — SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that j… |
vulnerability |
nvd |
CVE-2026-75482 |
|
2026-08-17 |
| high |
CVE-2026-43794 — A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari… |
vulnerability |
nvd |
CVE-2026-43794 |
|
2026-08-17 |
| high |
CVE-2026-45790 — Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organizati… |
vulnerability |
nvd |
CVE-2026-45790 |
|
2026-08-17 |
| high |
CVE-2026-56677 — 9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint i… |
vulnerability |
nvd |
CVE-2026-56677 |
|
2026-08-17 |
| high |
CVE-2026-65343 — A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.… |
vulnerability |
nvd |
CVE-2026-65343 |
|
2026-08-17 |
| high |
CVE-2026-65346 — An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1… |
vulnerability |
nvd |
CVE-2026-65346 |
|
2026-08-17 |
| high |
CVE-2026-67918 — Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensi… |
vulnerability |
nvd |
CVE-2026-67918 |
|
2026-08-17 |
| high |
CVE-2026-9816 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMe… |
vulnerability |
nvd |
CVE-2026-9816 |
|
2026-08-17 |
| high |
CVE-2026-67961 — An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mech… |
vulnerability |
nvd |
CVE-2026-67961 |
|
2026-08-17 |
| high |
CVE-2026-75079 — A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnera… |
vulnerability |
nvd |
CVE-2026-75079 |
|
2026-08-18 |
| high |
CVE-2026-75080 — A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0.… |
vulnerability |
nvd |
CVE-2026-75080 |
|
2026-08-18 |
| high |
CVE-2026-75089 — A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue… |
vulnerability |
nvd |
CVE-2026-75089 |
|
2026-08-18 |
| high |
CVE-2026-11801 — The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all… |
vulnerability |
nvd |
CVE-2026-11801 |
|
2026-08-18 |
| high |
CVE-2026-75091 — The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnera… |
vulnerability |
nvd |
CVE-2026-75091 |
|
2026-08-18 |
| high |
CVE-2026-15371 — Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the… |
vulnerability |
nvd |
CVE-2026-15371 |
|
2026-08-18 |
| high |
CVE-2026-15585 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN… |
vulnerability |
nvd |
CVE-2026-15585 |
|
2026-08-18 |
| high |
CVE-2026-74902 — SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flo… |
vulnerability |
nvd |
CVE-2026-74902 |
|
2026-08-18 |
| high |
CVE-2026-74904 — SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kerne… |
vulnerability |
nvd |
CVE-2026-74904 |
|
2026-08-18 |
| high |
CVE-2026-74905 — SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP… |
vulnerability |
nvd |
CVE-2026-74905 |
|
2026-08-18 |
| high |
CVE-2026-74906 — SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-… |
vulnerability |
nvd |
CVE-2026-74906 |
|
2026-08-18 |
| high |
CVE-2026-75827 — Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare… |
vulnerability |
nvd |
CVE-2026-75827 |
rce |
2026-08-18 |
| high |
CVE-2026-75828 — Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function… |
vulnerability |
nvd |
CVE-2026-75828 |
|
2026-08-18 |
| high |
CVE-2026-75829 — grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, al… |
vulnerability |
nvd |
CVE-2026-75829 |
|
2026-08-18 |
| high |
CVE-2026-75830 — grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path tra… |
vulnerability |
nvd |
CVE-2026-75830 |
|
2026-08-18 |
| high |
CVE-2026-75831 — Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media… |
vulnerability |
nvd |
CVE-2026-75831 |
|
2026-08-18 |
| high |
CVE-2026-75836 — The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.1… |
vulnerability |
nvd |
CVE-2026-75836 |
|
2026-08-18 |
| high |
CVE-2026-75840 — ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandb… |
vulnerability |
nvd |
CVE-2026-75840 |
|
2026-08-18 |
| high |
CVE-2026-75842 — ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD… |
vulnerability |
nvd |
CVE-2026-75842 |
|
2026-08-18 |
| high |
CVE-2026-75844 — ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DA… |
vulnerability |
nvd |
CVE-2026-75844 |
|
2026-08-18 |
| high |
CVE-2026-75846 — ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability… |
vulnerability |
nvd |
CVE-2026-75846 |
|
2026-08-18 |
| high |
CVE-2026-75853 — ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforc… |
vulnerability |
nvd |
CVE-2026-75853 |
|
2026-08-18 |
| high |
CVE-2026-75855 — ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint'… |
vulnerability |
nvd |
CVE-2026-75855 |
|
2026-08-18 |
| high |
CVE-2026-74935 — Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154,… |
vulnerability |
nvd |
CVE-2026-74935 |
|
2026-08-18 |
| high |
CVE-2026-74937 — Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox… |
vulnerability |
nvd |
CVE-2026-74937 |
|
2026-08-18 |
| high |
CVE-2026-74939 — Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154,… |
vulnerability |
nvd |
CVE-2026-74939 |
|
2026-08-18 |
| high |
CVE-2026-74941 — Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox… |
vulnerability |
nvd |
CVE-2026-74941 |
|
2026-08-18 |
| high |
CVE-2026-74942 — Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefo… |
vulnerability |
nvd |
CVE-2026-74942 |
|
2026-08-18 |
| high |
CVE-2026-74946 — Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. Th… |
vulnerability |
nvd |
CVE-2026-74946 |
|
2026-08-18 |
| high |
CVE-2026-74947 — Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed… |
vulnerability |
nvd |
CVE-2026-74947 |
|
2026-08-18 |
| high |
CVE-2026-74949 — Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability w… |
vulnerability |
nvd |
CVE-2026-74949 |
|
2026-08-18 |
| high |
CVE-2026-74950 — Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Fi… |
vulnerability |
nvd |
CVE-2026-74950 |
|
2026-08-18 |
| high |
CVE-2026-74952 — Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 15… |
vulnerability |
nvd |
CVE-2026-74952 |
|
2026-08-18 |
| high |
CVE-2026-74953 — Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 1… |
vulnerability |
nvd |
CVE-2026-74953 |
|
2026-08-18 |
| high |
CVE-2026-74954 — Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability w… |
vulnerability |
nvd |
CVE-2026-74954 |
|
2026-08-18 |
| high |
CVE-2026-74955 — Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154,… |
vulnerability |
nvd |
CVE-2026-74955 |
|
2026-08-18 |
| high |
CVE-2026-74958 — Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox… |
vulnerability |
nvd |
CVE-2026-74958 |
|
2026-08-18 |
| high |
CVE-2026-74962 — Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 1… |
vulnerability |
nvd |
CVE-2026-74962 |
|
2026-08-18 |
| high |
CVE-2026-74965 — Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154… |
vulnerability |
nvd |
CVE-2026-74965 |
|
2026-08-18 |
| high |
CVE-2026-74966 — Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154,… |
vulnerability |
nvd |
CVE-2026-74966 |
|
2026-08-18 |
| high |
CVE-2026-74969 — Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154,… |
vulnerability |
nvd |
CVE-2026-74969 |
|
2026-08-18 |
| high |
CVE-2026-74978 — Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR… |
vulnerability |
nvd |
CVE-2026-74978 |
|
2026-08-18 |
| high |
CVE-2026-74981 — Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firef… |
vulnerability |
nvd |
CVE-2026-74981 |
|
2026-08-18 |
| high |
CVE-2026-74982 — Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR… |
vulnerability |
nvd |
CVE-2026-74982 |
|
2026-08-18 |
| high |
CVE-2026-74983 — Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154… |
vulnerability |
nvd |
CVE-2026-74983 |
|
2026-08-18 |
| high |
CVE-2026-75778 — A vulnerability was identified in code-projects Task Management System 1.0. This affects the functio… |
vulnerability |
nvd |
CVE-2026-75778 |
|
2026-08-18 |
| high |
CVE-2026-24301 — Improper neutralization of special elements used in a command ('command injection') in Microsoft Cop… |
vulnerability |
nvd |
CVE-2026-24301 |
|
2026-08-18 |
| high |
CVE-2026-28191 — Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions. |
vulnerability |
nvd |
CVE-2026-28191 |
|
2026-08-18 |
| high |
CVE-2026-28567 — Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions. |
vulnerability |
nvd |
CVE-2026-28567 |
|
2026-08-18 |
| high |
CVE-2026-28568 — Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. |
vulnerability |
nvd |
CVE-2026-28568 |
|
2026-08-18 |
| high |
CVE-2026-28569 — Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions. |
vulnerability |
nvd |
CVE-2026-28569 |
|
2026-08-18 |
| high |
CVE-2026-28570 — Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions. |
vulnerability |
nvd |
CVE-2026-28570 |
|
2026-08-18 |
| high |
CVE-2026-28571 — Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions. |
vulnerability |
nvd |
CVE-2026-28571 |
|
2026-08-18 |
| high |
CVE-2026-32333 — Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions. |
vulnerability |
nvd |
CVE-2026-32333 |
|
2026-08-18 |
| high |
CVE-2026-32464 — Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. |
vulnerability |
nvd |
CVE-2026-32464 |
|
2026-08-18 |
| high |
CVE-2026-32465 — Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions. |
vulnerability |
nvd |
CVE-2026-32465 |
|
2026-08-18 |
| high |
CVE-2026-32466 — Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. |
vulnerability |
nvd |
CVE-2026-32466 |
|
2026-08-18 |
| high |
CVE-2026-32468 — Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. |
vulnerability |
nvd |
CVE-2026-32468 |
|
2026-08-18 |
| high |
CVE-2026-50575 — BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly inv… |
vulnerability |
nvd |
CVE-2026-50575 |
ransomware |
2026-08-18 |
| high |
CVE-2026-18534 — ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated… |
vulnerability |
nvd |
CVE-2026-18534 |
|
2026-08-18 |
| high |
CVE-2026-32472 — Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions. |
vulnerability |
nvd |
CVE-2026-32472 |
|
2026-08-18 |
| high |
CVE-2026-32473 — Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versio… |
vulnerability |
nvd |
CVE-2026-32473 |
|
2026-08-18 |
| high |
CVE-2026-32481 — Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions. |
vulnerability |
nvd |
CVE-2026-32481 |
|
2026-08-18 |
| high |
CVE-2026-32547 — Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. |
vulnerability |
nvd |
CVE-2026-32547 |
|
2026-08-18 |
| high |
CVE-2026-32549 — Unauthenticated Broken Access Control in ThumbPress < 6.5 versions. |
vulnerability |
nvd |
CVE-2026-32549 |
|
2026-08-18 |
| high |
CVE-2026-32553 — Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions. |
vulnerability |
nvd |
CVE-2026-32553 |
|
2026-08-18 |
| high |
CVE-2026-45733 — Trilium Notes is a cross-platform, hierarchical note taking application focused on building large pe… |
vulnerability |
nvd |
CVE-2026-45733 |
|
2026-08-18 |
| high |
CVE-2026-48798 — SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string… |
vulnerability |
nvd |
CVE-2026-48798 |
|
2026-08-18 |
| high |
CVE-2026-50138 — goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with Web… |
vulnerability |
nvd |
CVE-2026-50138 |
|
2026-08-18 |
| high |
CVE-2026-50187 — Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the d… |
vulnerability |
nvd |
CVE-2026-50187 |
|
2026-08-18 |
| high |
CVE-2026-56684 — Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey… |
vulnerability |
nvd |
CVE-2026-56684, CVE-2026-63639 |
rce |
2026-08-18 |
| high |
CVE-2026-59825 — Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from… |
vulnerability |
nvd |
CVE-2026-59825 |
|
2026-08-18 |
| high |
CVE-2026-61407 — Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Acce… |
vulnerability |
nvd |
CVE-2026-61407 |
|
2026-08-18 |
| high |
CVE-2026-66046 — Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic compl… |
vulnerability |
nvd |
CVE-2026-66046 |
|
2026-08-18 |
| high |
CVE-2026-66620 — Editor PHP Object Injection in OptionTree <= 2.7.3 versions. |
vulnerability |
nvd |
CVE-2026-66620 |
|
2026-08-18 |
| high |
CVE-2026-66621 — Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions. |
vulnerability |
nvd |
CVE-2026-66621 |
|
2026-08-18 |
| high |
CVE-2026-66622 — Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions. |
vulnerability |
nvd |
CVE-2026-66622 |
|
2026-08-18 |
| high |
CVE-2026-66629 — Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions. |
vulnerability |
nvd |
CVE-2026-66629 |
|
2026-08-18 |
| high |
CVE-2026-66633 — Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. |
vulnerability |
nvd |
CVE-2026-66633 |
|
2026-08-18 |
| high |
CVE-2026-66635 — Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions. |
vulnerability |
nvd |
CVE-2026-66635 |
|
2026-08-18 |
| high |
CVE-2026-66667 — Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions. |
vulnerability |
nvd |
CVE-2026-66667 |
|
2026-08-18 |
| high |
CVE-2026-66793 — A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Man… |
vulnerability |
nvd |
CVE-2026-66793 |
|
2026-08-18 |
| high |
CVE-2026-68567 — Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions. |
vulnerability |
nvd |
CVE-2026-68567 |
|
2026-08-18 |
| high |
CVE-2026-69189 — Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.use… |
vulnerability |
nvd |
CVE-2026-69189 |
|
2026-08-18 |
| high |
CVE-2026-73181 — Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 ver… |
vulnerability |
nvd |
CVE-2026-73181 |
|
2026-08-18 |
| high |
CVE-2026-73190 — Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions. |
vulnerability |
nvd |
CVE-2026-73190 |
|
2026-08-18 |
| high |
CVE-2026-73338 — Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions. |
vulnerability |
nvd |
CVE-2026-73338 |
|
2026-08-18 |
| high |
CVE-2026-73342 — Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions. |
vulnerability |
nvd |
CVE-2026-73342 |
|
2026-08-18 |
| high |
CVE-2026-73345 — Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions. |
vulnerability |
nvd |
CVE-2026-73345 |
|
2026-08-18 |
| high |
CVE-2026-73350 — Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions. |
vulnerability |
nvd |
CVE-2026-73350 |
|
2026-08-18 |
| high |
CVE-2026-73351 — Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions. |
vulnerability |
nvd |
CVE-2026-73351 |
|
2026-08-18 |
| high |
CVE-2026-73356 — Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions. |
vulnerability |
nvd |
CVE-2026-73356 |
|
2026-08-18 |
| high |
CVE-2026-73358 — Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions. |
vulnerability |
nvd |
CVE-2026-73358 |
|
2026-08-18 |
| high |
CVE-2026-73360 — Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions. |
vulnerability |
nvd |
CVE-2026-73360 |
|
2026-08-18 |
| high |
CVE-2026-73361 — Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18… |
vulnerability |
nvd |
CVE-2026-73361 |
|
2026-08-18 |
| high |
CVE-2026-73362 — Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions. |
vulnerability |
nvd |
CVE-2026-73362 |
|
2026-08-18 |
| high |
CVE-2026-73367 — Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions. |
vulnerability |
nvd |
CVE-2026-73367 |
|
2026-08-18 |
| high |
CVE-2026-73375 — Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions. |
vulnerability |
nvd |
CVE-2026-73375 |
|
2026-08-18 |
| high |
CVE-2026-73377 — Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions. |
vulnerability |
nvd |
CVE-2026-73377 |
|
2026-08-18 |
| high |
CVE-2026-73378 — Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions. |
vulnerability |
nvd |
CVE-2026-73378 |
|
2026-08-18 |
| high |
CVE-2026-73382 — Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions. |
vulnerability |
nvd |
CVE-2026-73382 |
|
2026-08-18 |
| high |
CVE-2026-73393 — Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions. |
vulnerability |
nvd |
CVE-2026-73393 |
|
2026-08-18 |
| high |
CVE-2026-73396 — Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. |
vulnerability |
nvd |
CVE-2026-73396 |
|
2026-08-18 |
| high |
CVE-2026-73400 — Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. |
vulnerability |
nvd |
CVE-2026-73400 |
|
2026-08-18 |
| high |
CVE-2026-73994 — Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. |
vulnerability |
nvd |
CVE-2026-73994 |
|
2026-08-18 |
| high |
CVE-2026-73997 — Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. |
vulnerability |
nvd |
CVE-2026-73997 |
|
2026-08-18 |
| high |
CVE-2026-74012 — Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue aff… |
vulnerability |
nvd |
CVE-2026-74012 |
|
2026-08-18 |
| high |
CVE-2026-75898 — RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "In… |
vulnerability |
nvd |
CVE-2026-75898 |
|
2026-08-18 |
| high |
CVE-2026-19500 — The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adeq… |
vulnerability |
nvd |
CVE-2026-19500 |
|
2026-08-18 |
| high |
CVE-2026-45115 — MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sa… |
vulnerability |
nvd |
CVE-2026-45115 |
|
2026-08-18 |
| high |
CVE-2026-45116 — MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly… |
vulnerability |
nvd |
CVE-2026-45116 |
|
2026-08-18 |
| high |
CVE-2026-49221 — Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stor… |
vulnerability |
nvd |
CVE-2026-49221, CVE-2026-49226, CVE-2026-49227, CVE-2026-49222, CVE-2026-49223, CVE-2026-49224, CVE-2026-49225, CVE-2026-49228 |
|
2026-08-18 |
| high |
CVE-2026-55839 — Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Mark… |
vulnerability |
nvd |
CVE-2026-55839 |
|
2026-08-18 |
| high |
CVE-2026-71365 — A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechan… |
vulnerability |
nvd |
CVE-2026-71365 |
|
2026-08-18 |
| high |
CVE-2026-75856 — CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning l… |
vulnerability |
nvd |
CVE-2026-75856 |
|
2026-08-18 |
| high |
CVE-2026-75857 — CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias… |
vulnerability |
nvd |
CVE-2026-75857 |
|
2026-08-18 |
| high |
CVE-2026-75858 — CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code… |
vulnerability |
nvd |
CVE-2026-75858 |
rce |
2026-08-18 |
| high |
CVE-2026-75859 — CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions fiel… |
vulnerability |
nvd |
CVE-2026-75859 |
|
2026-08-18 |
| high |
CVE-2026-75911 — CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter f… |
vulnerability |
nvd |
CVE-2026-75911 |
|
2026-08-18 |
| high |
CVE-2026-75912 — CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool t… |
vulnerability |
nvd |
CVE-2026-75912 |
|
2026-08-18 |
| high |
CVE-2026-75914 — CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool th… |
vulnerability |
nvd |
CVE-2026-75914 |
|
2026-08-18 |
| high |
CVE-2026-75915 — CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_ex… |
vulnerability |
nvd |
CVE-2026-75915 |
|
2026-08-18 |
| high |
CVE-2026-75926 — Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code runnin… |
vulnerability |
nvd |
CVE-2026-75926 |
|
2026-08-18 |
| high |
CVE-2026-61574 — authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Con… |
vulnerability |
nvd |
CVE-2026-61574 |
|
2026-08-18 |
| high |
CVE-2026-66782 — A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-li… |
vulnerability |
nvd |
CVE-2026-66782 |
|
2026-08-18 |
| high |
CVE-2026-66783 — A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for K… |
vulnerability |
nvd |
CVE-2026-66783 |
|
2026-08-18 |
| high |
CVE-2026-70415 — Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS… |
vulnerability |
nvd |
CVE-2026-70415 |
|
2026-08-18 |
| high |
CVE-2026-75897 — Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of t… |
vulnerability |
nvd |
CVE-2026-75897 |
|
2026-08-18 |
| high |
CVE-2026-75924 — A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole… |
vulnerability |
nvd |
CVE-2026-75924 |
|
2026-08-18 |
| high |
CVE-2026-32657 — Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRai… |
vulnerability |
nvd |
CVE-2026-32657 |
|
2026-08-18 |
| high |
CVE-2026-44472 — Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account ac… |
vulnerability |
nvd |
CVE-2026-44472 |
|
2026-08-18 |
| high |
CVE-2026-48508 — Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPer… |
vulnerability |
nvd |
CVE-2026-48508 |
|
2026-08-18 |
| high |
CVE-2026-50143 — The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, craw… |
vulnerability |
nvd |
CVE-2026-50143 |
|
2026-08-18 |
| high |
CVE-2026-54552 — sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplet… |
vulnerability |
nvd |
CVE-2026-54552 |
|
2026-08-18 |
| high |
CVE-2026-67262 — Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped… |
vulnerability |
nvd |
CVE-2026-67262 |
|
2026-08-18 |
| high |
CVE-2026-67920 — An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migr… |
vulnerability |
nvd |
CVE-2026-67920 |
|
2026-08-18 |
| high |
CVE-2026-71551 — Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabil… |
vulnerability |
nvd |
CVE-2026-71551 |
|
2026-08-18 |
| high |
CVE-2026-74038 — Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote… |
vulnerability |
nvd |
CVE-2026-74038 |
|
2026-08-18 |
| high |
CVE-2025-9210 — Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions b… |
vulnerability |
nvd |
CVE-2025-9210 |
|
2026-08-18 |
| high |
CVE-2026-24183 — NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivilege… |
vulnerability |
nvd |
CVE-2026-24183 |
|
2026-08-18 |
| high |
CVE-2026-24184 — NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon com… |
vulnerability |
nvd |
CVE-2026-24184 |
|
2026-08-18 |
| high |
CVE-2026-24185 — NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configura… |
vulnerability |
nvd |
CVE-2026-24185 |
|
2026-08-18 |
| high |
CVE-2026-47606 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an a… |
vulnerability |
nvd |
CVE-2026-47606, CVE-2026-47628, CVE-2026-47630 |
|
2026-08-18 |
| high |
CVE-2026-47629 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause impr… |
vulnerability |
nvd |
CVE-2026-47629 |
|
2026-08-18 |
| high |
CVE-2026-47719 — FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE… |
vulnerability |
nvd |
CVE-2026-47719 |
ics |
2026-08-18 |
| high |
CVE-2026-52480 — An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensiti… |
vulnerability |
nvd |
CVE-2026-52480, CVE-2026-52481 |
|
2026-08-18 |
| high |
CVE-2026-52829 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can det… |
vulnerability |
nvd |
CVE-2026-52829 |
|
2026-08-18 |
| high |
CVE-2026-59915 — Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violati… |
vulnerability |
nvd |
CVE-2026-59915 |
|
2026-08-18 |
| high |
CVE-2026-65984 — FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST… |
vulnerability |
nvd |
CVE-2026-65984 |
ics |
2026-08-18 |
| high |
CVE-2026-65985 — FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the… |
vulnerability |
nvd |
CVE-2026-65985, CVE-2026-67440, CVE-2026-67443 |
ics |
2026-08-18 |
| high |
CVE-2026-70666 — Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_u… |
vulnerability |
nvd |
CVE-2026-70666 |
|
2026-08-18 |
| high |
CVE-2026-71303 — Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_H… |
vulnerability |
nvd |
CVE-2026-71303 |
|
2026-08-18 |
| high |
CVE-2026-71307 — Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/desti… |
vulnerability |
nvd |
CVE-2026-71307 |
|
2026-08-18 |
| high |
CVE-2026-71308 — Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit… |
vulnerability |
nvd |
CVE-2026-71308 |
|
2026-08-18 |
| high |
CVE-2026-71417 — Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a no… |
vulnerability |
nvd |
CVE-2026-71417 |
|
2026-08-18 |
| high |
CVE-2026-71675 — An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the ngap_send_… |
vulnerability |
nvd |
CVE-2026-71675 |
|
2026-08-18 |
| high |
CVE-2026-71676 — Buffer Overflow vulnerability in Open5GS v.2.7.0 allows a remote attacker to cause a denial of servi… |
vulnerability |
nvd |
CVE-2026-71676 |
|
2026-08-18 |
| high |
CVE-2026-75935 — Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 migh… |
vulnerability |
nvd |
CVE-2026-75935 |
|
2026-08-18 |
| high |
CVE-2026-75936 — Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-jav… |
vulnerability |
nvd |
CVE-2026-75936 |
|
2026-08-18 |
| high |
CVE-2026-15571 — A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used… |
vulnerability |
nvd |
CVE-2026-15571 |
|
2026-08-18 |
| high |
CVE-2026-52793 — Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path i… |
vulnerability |
nvd |
CVE-2026-52793 |
|
2026-08-18 |
| high |
CVE-2026-53759 — linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integ… |
vulnerability |
nvd |
CVE-2026-53759, CVE-2026-55426, CVE-2026-73974 |
|
2026-08-18 |
| high |
CVE-2026-54347 — Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accept… |
vulnerability |
nvd |
CVE-2026-54347 |
|
2026-08-18 |
| high |
CVE-2026-54348 — Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.upd… |
vulnerability |
nvd |
CVE-2026-54348 |
|
2026-08-18 |
| high |
CVE-2026-60392 — Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Ou… |
vulnerability |
nvd |
CVE-2026-60392, CVE-2026-60412, CVE-2026-60413, CVE-2026-60414 |
|
2026-08-18 |
| high |
CVE-2026-60592 — Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Suppo… |
vulnerability |
nvd |
CVE-2026-60592 |
|
2026-08-18 |
| high |
CVE-2026-60693 — Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal O… |
vulnerability |
nvd |
CVE-2026-60693, CVE-2026-60748, CVE-2026-60769, CVE-2026-70686, CVE-2026-70764, CVE-2026-70796, CVE-2026-70803 |
|
2026-08-18 |
| high |
CVE-2026-60707 — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Securit… |
vulnerability |
nvd |
CVE-2026-60707 |
|
2026-08-18 |
| high |
CVE-2026-60726 — Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentic… |
vulnerability |
nvd |
CVE-2026-60726 |
|
2026-08-18 |
| high |
CVE-2026-60742 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA… |
vulnerability |
nvd |
CVE-2026-60742 |
|
2026-08-18 |
| high |
CVE-2026-60753 — Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation). S… |
vulnerability |
nvd |
CVE-2026-60753 |
|
2026-08-18 |
| high |
CVE-2026-60757 — Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Search). Supported… |
vulnerability |
nvd |
CVE-2026-60757 |
|
2026-08-18 |
| high |
CVE-2026-60758 — Vulnerability in the Siebel Artificial Intelligence product of Oracle Siebel CRM (component: AI). Su… |
vulnerability |
nvd |
CVE-2026-60758 |
|
2026-08-18 |
| high |
CVE-2026-60759 — Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (compo… |
vulnerability |
nvd |
CVE-2026-60759, CVE-2026-70815 |
|
2026-08-18 |
| high |
CVE-2026-60766 — Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supporte… |
vulnerability |
nvd |
CVE-2026-60766, CVE-2026-60796, CVE-2026-60797, CVE-2026-60820, CVE-2026-70859, CVE-2026-70910 |
|
2026-08-18 |
| high |
CVE-2026-60791 — Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Inte… |
vulnerability |
nvd |
CVE-2026-60791 |
|
2026-08-18 |
| high |
CVE-2026-60792 — Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastru… |
vulnerability |
nvd |
CVE-2026-60792, CVE-2026-70949 |
|
2026-08-18 |
| high |
CVE-2026-60798 — Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration). Supp… |
vulnerability |
nvd |
CVE-2026-60798, CVE-2026-70856 |
|
2026-08-18 |
| high |
CVE-2026-60808 — Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Email Marketin… |
vulnerability |
nvd |
CVE-2026-60808 |
|
2026-08-18 |
| high |
CVE-2026-60822 — Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterpri… |
vulnerability |
nvd |
CVE-2026-60822, CVE-2026-70737 |
|
2026-08-18 |
| high |
CVE-2026-60831 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Inte… |
vulnerability |
nvd |
CVE-2026-60831 |
|
2026-08-18 |
| high |
CVE-2026-60841 — Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Co… |
vulnerability |
nvd |
CVE-2026-60841, CVE-2026-60849, CVE-2026-60850, CVE-2026-60889, CVE-2026-60895, CVE-2026-60914, CVE-2026-60969 |
|
2026-08-18 |
| high |
CVE-2026-60856 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Inst… |
vulnerability |
nvd |
CVE-2026-60856 |
|
2026-08-18 |
| high |
CVE-2026-60873 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Data… |
vulnerability |
nvd |
CVE-2026-60873 |
|
2026-08-18 |
| high |
CVE-2026-60879 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Conf… |
vulnerability |
nvd |
CVE-2026-60879 |
|
2026-08-18 |
| high |
CVE-2026-60883 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Peop… |
vulnerability |
nvd |
CVE-2026-60883 |
|
2026-08-18 |
| high |
CVE-2026-60902 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Tuxe… |
vulnerability |
nvd |
CVE-2026-60902 |
|
2026-08-18 |
| high |
CVE-2026-60956 — Vulnerability in the JD Edwards EnterpriseOne US Payroll product of Oracle JD Edwards (component: Pa… |
vulnerability |
nvd |
CVE-2026-60956 |
|
2026-08-18 |
| high |
CVE-2026-60967 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: nVis… |
vulnerability |
nvd |
CVE-2026-60967 |
|
2026-08-18 |
| high |
CVE-2026-60975 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Secu… |
vulnerability |
nvd |
CVE-2026-60975 |
|
2026-08-18 |
| high |
CVE-2026-60976 — Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operat… |
vulnerability |
nvd |
CVE-2026-60976, CVE-2026-70808, CVE-2026-70809, CVE-2026-70810 |
|
2026-08-18 |
| high |
CVE-2026-61002 — Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). S… |
vulnerability |
nvd |
CVE-2026-61002 |
|
2026-08-18 |
| high |
CVE-2026-61231 — Vulnerability in the Oracle Virtual Directory product of Oracle Fusion Middleware (component: Virtua… |
vulnerability |
nvd |
CVE-2026-61231 |
|
2026-08-18 |
| high |
CVE-2026-61265 — Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component:… |
vulnerability |
nvd |
CVE-2026-61265, CVE-2026-61270 |
|
2026-08-18 |
| high |
CVE-2026-61268 — Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Busines… |
vulnerability |
nvd |
CVE-2026-61268 |
|
2026-08-18 |
| high |
CVE-2026-61273 — Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Install… |
vulnerability |
nvd |
CVE-2026-61273 |
|
2026-08-18 |
| high |
CVE-2026-61284 — Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c… |
vulnerability |
nvd |
CVE-2026-61284, CVE-2026-61286, CVE-2026-61298, CVE-2026-61300, CVE-2026-70684 |
|
2026-08-18 |
| high |
CVE-2026-61296 — Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (componen… |
vulnerability |
nvd |
CVE-2026-61296 |
|
2026-08-18 |
| high |
CVE-2026-61302 — Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co… |
vulnerability |
nvd |
CVE-2026-61302, CVE-2026-71055, CVE-2026-71056, CVE-2026-71061, CVE-2026-71094, CVE-2026-71095, CVE-2026-71096, CVE-2026-71097, CVE-2026-71098, CVE-2026-71099, CVE-2026-71107, CVE-2026-71122 |
|
2026-08-18 |
| high |
CVE-2026-61305 — Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Securit… |
vulnerability |
nvd |
CVE-2026-61305, CVE-2026-71057 |
|
2026-08-18 |
| high |
CVE-2026-61306 — Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Su… |
vulnerability |
nvd |
CVE-2026-61306 |
|
2026-08-18 |
| high |
CVE-2026-61307 — Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSof… |
vulnerability |
nvd |
CVE-2026-61307 |
|
2026-08-18 |
| high |
CVE-2026-61319 — Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: I… |
vulnerability |
nvd |
CVE-2026-61319 |
|
2026-08-18 |
| high |
CVE-2026-61331 — Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component:… |
vulnerability |
nvd |
CVE-2026-61331 |
|
2026-08-18 |
| high |
CVE-2026-61340 — Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (compon… |
vulnerability |
nvd |
CVE-2026-61340, CVE-2026-70827 |
|
2026-08-18 |
| high |
CVE-2026-62448 — Vulnerability in the Oracle Email Center product of Oracle E-Business Suite (component: Message Comp… |
vulnerability |
nvd |
CVE-2026-62448 |
|
2026-08-18 |
| high |
CVE-2026-62449 — Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal… |
vulnerability |
nvd |
CVE-2026-62449, CVE-2026-62458, CVE-2026-62462 |
|
2026-08-18 |
| high |
CVE-2026-62450 — Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Intern… |
vulnerability |
nvd |
CVE-2026-62450, CVE-2026-70801 |
|
2026-08-18 |
| high |
CVE-2026-62491 — Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Opera… |
vulnerability |
nvd |
CVE-2026-62491, CVE-2026-70797, CVE-2026-70798, CVE-2026-70811 |
|
2026-08-18 |
| high |
CVE-2026-62540 — Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Plan… |
vulnerability |
nvd |
CVE-2026-62540 |
|
2026-08-18 |
| high |
CVE-2026-62599 — Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Third P… |
vulnerability |
nvd |
CVE-2026-62599 |
|
2026-08-18 |
| high |
CVE-2026-62600 — Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations… |
vulnerability |
nvd |
CVE-2026-62600, CVE-2026-62601, CVE-2026-70706 |
|
2026-08-18 |
| high |
CVE-2026-62605 — Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Intern… |
vulnerability |
nvd |
CVE-2026-62605 |
|
2026-08-18 |
| high |
CVE-2026-62607 — Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Internal Op… |
vulnerability |
nvd |
CVE-2026-62607, CVE-2026-70778 |
|
2026-08-18 |
| high |
CVE-2026-70680 — Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal… |
vulnerability |
nvd |
CVE-2026-70680 |
|
2026-08-18 |
| high |
CVE-2026-70681 — Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: JRI and… |
vulnerability |
nvd |
CVE-2026-70681 |
|
2026-08-18 |
| high |
CVE-2026-70687 — Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supp… |
vulnerability |
nvd |
CVE-2026-70687 |
|
2026-08-18 |
| high |
CVE-2026-70688 — Vulnerability in Oracle Essbase (component: Calculator). The supported version that is affected is 2… |
vulnerability |
nvd |
CVE-2026-70688 |
|
2026-08-18 |
| high |
CVE-2026-70690 — Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - Ge… |
vulnerability |
nvd |
CVE-2026-70690 |
|
2026-08-18 |
| high |
CVE-2026-70691 — Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (compon… |
vulnerability |
nvd |
CVE-2026-70691, CVE-2026-70693, CVE-2026-70697, CVE-2026-70698, CVE-2026-70703, CVE-2026-70709, CVE-2026-70712, CVE-2026-71052, CVE-2026-71053 |
supply-chain |
2026-08-18 |
| high |
CVE-2026-70692 — Vulnerability in the Oracle Marketing Encyclopedia System product of Oracle E-Business Suite (compon… |
vulnerability |
nvd |
CVE-2026-70692 |
ransomware |
2026-08-18 |
| high |
CVE-2026-70700 — Vulnerability in the Oracle Payables product of Oracle E-Business Suite (component: Internal Operati… |
vulnerability |
nvd |
CVE-2026-70700, CVE-2026-70701 |
|
2026-08-18 |
| high |
CVE-2026-70704 — Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party S… |
vulnerability |
nvd |
CVE-2026-70704 |
|
2026-08-18 |
| high |
CVE-2026-70707 — Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business Suite (component: Inter… |
vulnerability |
nvd |
CVE-2026-70707 |
|
2026-08-18 |
| high |
CVE-2026-70708 — Vulnerability in the Oracle Sales Foundation product of Oracle E-Business Suite (component: Security… |
vulnerability |
nvd |
CVE-2026-70708, CVE-2026-70710 |
|
2026-08-18 |
| high |
CVE-2026-70713 — Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Upd… |
vulnerability |
nvd |
CVE-2026-70713 |
|
2026-08-18 |
| high |
CVE-2026-70715 — Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported vers… |
vulnerability |
nvd |
CVE-2026-70715, CVE-2026-70728, CVE-2026-70731, CVE-2026-70734 |
|
2026-08-18 |
| high |
CVE-2026-70717 — Vulnerability in Oracle Autonomous Health Framework (component: Cluster Health Analyzer). Supported… |
vulnerability |
nvd |
CVE-2026-70717 |
|
2026-08-18 |
| high |
CVE-2026-70718 — Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Interna… |
vulnerability |
nvd |
CVE-2026-70718 |
|
2026-08-18 |
| high |
CVE-2026-70722 — Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component… |
vulnerability |
nvd |
CVE-2026-70722, CVE-2026-70725 |
|
2026-08-18 |
| high |
CVE-2026-70724 — Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported… |
vulnerability |
nvd |
CVE-2026-70724 |
|
2026-08-18 |
| high |
CVE-2026-70729 — Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Reque… |
vulnerability |
nvd |
CVE-2026-70729 |
|
2026-08-18 |
| high |
CVE-2026-70747 — Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Customer… |
vulnerability |
nvd |
CVE-2026-70747 |
|
2026-08-18 |
| high |
CVE-2026-70760 — Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product… |
vulnerability |
nvd |
CVE-2026-70760, CVE-2026-70930, CVE-2026-70932 |
|
2026-08-18 |
| high |
CVE-2026-70761 — Vulnerability in the Oracle Risk Management product of Oracle E-Business Suite (component: Internal… |
vulnerability |
nvd |
CVE-2026-70761, CVE-2026-70762 |
|
2026-08-18 |
| high |
CVE-2026-70763 — Vulnerability in the Oracle Operations Intelligence product of Oracle E-Business Suite (component: D… |
vulnerability |
nvd |
CVE-2026-70763 |
|
2026-08-18 |
| high |
CVE-2026-70770 — Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Inte… |
vulnerability |
nvd |
CVE-2026-70770, CVE-2026-70771, CVE-2026-70772, CVE-2026-70774 |
|
2026-08-18 |
| high |
CVE-2026-70773 — Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: K… |
vulnerability |
nvd |
CVE-2026-70773 |
|
2026-08-18 |
| high |
CVE-2026-70777 — Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal… |
vulnerability |
nvd |
CVE-2026-70777, CVE-2026-70779 |
|
2026-08-18 |
| high |
CVE-2026-70781 — Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Internal Operat… |
vulnerability |
nvd |
CVE-2026-70781 |
|
2026-08-18 |
| high |
CVE-2026-70782 — Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Intern… |
vulnerability |
nvd |
CVE-2026-70782 |
|
2026-08-18 |
| high |
CVE-2026-70783 — Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Interna… |
vulnerability |
nvd |
CVE-2026-70783 |
|
2026-08-18 |
| high |
CVE-2026-70786 — Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (componen… |
vulnerability |
nvd |
CVE-2026-70786 |
|
2026-08-18 |
| high |
CVE-2026-70790 — Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite… |
vulnerability |
nvd |
CVE-2026-70790 |
|
2026-08-18 |
| high |
CVE-2026-70791 — Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component:… |
vulnerability |
nvd |
CVE-2026-70791 |
|
2026-08-18 |
| high |
CVE-2026-70792 — Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal… |
vulnerability |
nvd |
CVE-2026-70792 |
|
2026-08-18 |
| high |
CVE-2026-70795 — Vulnerability in the Oracle Applications Platform Engineering product of Oracle E-Business Suite (co… |
vulnerability |
nvd |
CVE-2026-70795 |
|
2026-08-18 |
| high |
CVE-2026-70799 — Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: In… |
vulnerability |
nvd |
CVE-2026-70799, CVE-2026-70800 |
|
2026-08-18 |
| high |
CVE-2026-70802 — Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (compon… |
vulnerability |
nvd |
CVE-2026-70802, CVE-2026-70804 |
|
2026-08-18 |
| high |
CVE-2026-70805 — Vulnerability in the Oracle Project Planning and Control product of Oracle E-Business Suite (compone… |
vulnerability |
nvd |
CVE-2026-70805 |
|
2026-08-18 |
| high |
CVE-2026-70806 — Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal O… |
vulnerability |
nvd |
CVE-2026-70806 |
|
2026-08-18 |
| high |
CVE-2026-70807 — Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: In… |
vulnerability |
nvd |
CVE-2026-70807, CVE-2026-70812, CVE-2026-70813, CVE-2026-70814, CVE-2026-70820 |
|
2026-08-18 |
| high |
CVE-2026-70816 — Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business Suite (component: Inter… |
vulnerability |
nvd |
CVE-2026-70816, CVE-2026-70839 |
|
2026-08-18 |
| high |
CVE-2026-70829 — Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (compon… |
vulnerability |
nvd |
CVE-2026-70829, CVE-2026-70830 |
|
2026-08-18 |
| high |
CVE-2026-70833 — Vulnerability in the Oracle Landed Cost Management product of Oracle E-Business Suite (component: In… |
vulnerability |
nvd |
CVE-2026-70833 |
|
2026-08-18 |
| high |
CVE-2026-70835 — Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Ope… |
vulnerability |
nvd |
CVE-2026-70835 |
|
2026-08-18 |
| high |
CVE-2026-70837 — Vulnerability in the Oracle Financials for Asia/Pacific product of Oracle E-Business Suite (componen… |
vulnerability |
nvd |
CVE-2026-70837 |
|
2026-08-18 |
| high |
CVE-2026-70844 — Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations… |
vulnerability |
nvd |
CVE-2026-70844, CVE-2026-70845 |
|
2026-08-18 |
| high |
CVE-2026-70857 — Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supporte… |
vulnerability |
nvd |
CVE-2026-70857 |
|
2026-08-18 |
| high |
CVE-2026-70861 — Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (c… |
vulnerability |
nvd |
CVE-2026-70861 |
|
2026-08-18 |
| high |
CVE-2026-70906 — Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Jav… |
vulnerability |
nvd |
CVE-2026-70906 |
|
2026-08-18 |
| high |
CVE-2026-70918 — Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Outbound Data… |
vulnerability |
nvd |
CVE-2026-70918 |
|
2026-08-18 |
| high |
CVE-2026-70922 — Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financia… |
vulnerability |
nvd |
CVE-2026-70922 |
|
2026-08-18 |
| high |
CVE-2026-70941 — Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operatio… |
vulnerability |
nvd |
CVE-2026-70941, CVE-2026-70945 |
|
2026-08-18 |
| high |
CVE-2026-70947 — Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue).… |
vulnerability |
nvd |
CVE-2026-70947, CVE-2026-70948 |
|
2026-08-18 |
| high |
CVE-2026-70951 — Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Document Managemen… |
vulnerability |
nvd |
CVE-2026-70951 |
|
2026-08-18 |
| high |
CVE-2026-71039 — Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server)… |
vulnerability |
nvd |
CVE-2026-71039 |
supply-chain |
2026-08-18 |
| high |
CVE-2026-71041 — Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Gantt Chart). The s… |
vulnerability |
nvd |
CVE-2026-71041 |
supply-chain |
2026-08-18 |
| high |
CVE-2026-71042 — Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: PGC / Excel Plugin)… |
vulnerability |
nvd |
CVE-2026-71042 |
supply-chain |
2026-08-18 |
| high |
CVE-2026-71044 — Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The suppor… |
vulnerability |
nvd |
CVE-2026-71044 |
supply-chain |
2026-08-18 |
| high |
CVE-2026-71048 — Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: I… |
vulnerability |
nvd |
CVE-2026-71048, CVE-2026-71049, CVE-2026-71050, CVE-2026-71051 |
supply-chain |
2026-08-18 |
| high |
CVE-2026-71062 — Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected… |
vulnerability |
nvd |
CVE-2026-71062, CVE-2026-71100 |
|
2026-08-18 |
| high |
CVE-2026-71066 — Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX… |
vulnerability |
nvd |
CVE-2026-71066, CVE-2026-71067, CVE-2026-71068, CVE-2026-71069, CVE-2026-71070, CVE-2026-71071, CVE-2026-71072, CVE-2026-71075, CVE-2026-71076, CVE-2026-71077, CVE-2026-71078, CVE-2026-71080, CVE-2026-71081, CVE-2026-71082, CVE-2026-71083, CVE-2026-71087, CVE-2026-71088, CVE-2026-71089 |
supply-chain |
2026-08-18 |
| high |
CVE-2026-71092 — Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of Oracle PeopleSoft (co… |
vulnerability |
nvd |
CVE-2026-71092 |
|
2026-08-18 |
| high |
CVE-2026-71101 — Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Tax… |
vulnerability |
nvd |
CVE-2026-71101 |
|
2026-08-18 |
| high |
CVE-2026-71104 — Vulnerability in the Oracle HRMS (Netherlands) product of Oracle E-Business Suite (component: Nether… |
vulnerability |
nvd |
CVE-2026-71104 |
|
2026-08-18 |
| high |
CVE-2026-71106 — Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Appl… |
vulnerability |
nvd |
CVE-2026-71106 |
|
2026-08-18 |
| high |
CVE-2026-71111 — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Install… |
vulnerability |
nvd |
CVE-2026-71111 |
|
2026-08-18 |
| high |
CVE-2026-71112 — Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (componen… |
vulnerability |
nvd |
CVE-2026-71112 |
|
2026-08-18 |
| high |
CVE-2026-71113 — Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The su… |
vulnerability |
nvd |
CVE-2026-71113, CVE-2026-71114, CVE-2026-71115, CVE-2026-71116, CVE-2026-71125, CVE-2026-71126, CVE-2026-71127, CVE-2026-71128, CVE-2026-71129, CVE-2026-71130, CVE-2026-71131, CVE-2026-71132, CVE-2026-71134, CVE-2026-71135, CVE-2026-71136, CVE-2026-71137, CVE-2026-71138, CVE-2026-71139, CVE-2026-71140, CVE-2026-71141, CVE-2026-71151 |
|
2026-08-18 |
| high |
CVE-2026-71142 — Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communicat… |
vulnerability |
nvd |
CVE-2026-71142, CVE-2026-71143 |
|
2026-08-18 |
| high |
CVE-2026-76034 — Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execu… |
vulnerability |
nvd |
CVE-2026-76034 |
|
2026-08-18 |
| high |
CVE-2026-76037 — Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed… |
vulnerability |
nvd |
CVE-2026-76037 |
|
2026-08-18 |
| high |
CVE-2026-76038 — Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute a… |
vulnerability |
nvd |
CVE-2026-76038, CVE-2026-76047 |
|
2026-08-18 |
| high |
CVE-2026-76040 — Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attack… |
vulnerability |
nvd |
CVE-2026-76040 |
phishing |
2026-08-18 |
| high |
CVE-2026-76043 — Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to ex… |
vulnerability |
nvd |
CVE-2026-76043 |
|
2026-08-18 |
| high |
CVE-2026-76044 — Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had com… |
vulnerability |
nvd |
CVE-2026-76044 |
|
2026-08-18 |
| high |
CVE-2026-76045 — Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execut… |
vulnerability |
nvd |
CVE-2026-76045 |
|
2026-08-18 |
| high |
CVE-2026-76046 — Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote att… |
vulnerability |
nvd |
CVE-2026-76046 |
|
2026-08-18 |
| high |
CVE-2026-15315 — Tapo C200 v5 contains an improper authentication vulnerability within the login authentication verif… |
vulnerability |
nvd |
CVE-2026-15315 |
botnet |
2026-08-18 |
| high |
CVE-2026-15316 — An improper input validation vulnerability in the configuration service for processing encrypted cre… |
vulnerability |
nvd |
CVE-2026-15316 |
botnet |
2026-08-18 |
| high |
CVE-2026-50142 — libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF… |
vulnerability |
nvd |
CVE-2026-50142 |
|
2026-08-18 |
| high |
CVE-2026-50186 — 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an au… |
vulnerability |
nvd |
CVE-2026-50186 |
|
2026-08-18 |
| high |
CVE-2026-50191 — 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerabl… |
vulnerability |
nvd |
CVE-2026-50191 |
|
2026-08-18 |
| high |
CVE-2026-52854 — Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded… |
vulnerability |
nvd |
CVE-2026-52854 |
ransomware |
2026-08-18 |
| high |
CVE-2026-52872 — Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2… |
vulnerability |
nvd |
CVE-2026-52872, CVE-2026-52875 |
|
2026-08-18 |
| high |
CVE-2026-52876 — Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to v… |
vulnerability |
nvd |
CVE-2026-52876, CVE-2026-52877 |
ransomware |
2026-08-18 |
| high |
CVE-2026-53958 — 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an au… |
vulnerability |
nvd |
CVE-2026-53958 |
|
2026-08-18 |
| high |
CVE-2026-66602 — Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar all… |
vulnerability |
nvd |
CVE-2026-66602 |
|
2026-08-18 |
| high |
CVE-2026-75984 — A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. Impacted is an unknown function of th… |
vulnerability |
nvd |
CVE-2026-75984 |
|
2026-08-19 |
| high |
CVE-2026-75985 — A flaw has been found in TRENDnet Router 1.1.02b01. The affected element is an unknown function of t… |
vulnerability |
nvd |
CVE-2026-75985 |
|
2026-08-19 |
| high |
CVE-2026-75986 — A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element i… |
vulnerability |
nvd |
CVE-2026-75986 |
|
2026-08-19 |
| high |
CVE-2026-75987 — A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStr… |
vulnerability |
nvd |
CVE-2026-75987 |
|
2026-08-19 |
| high |
CVE-2026-76048 — A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element… |
vulnerability |
nvd |
CVE-2026-76048 |
|
2026-08-19 |
| high |
CVE-2026-76049 — A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affect… |
vulnerability |
nvd |
CVE-2026-76049 |
|
2026-08-19 |
| high |
CVE-2026-76050 — A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an… |
vulnerability |
nvd |
CVE-2026-76050 |
|
2026-08-19 |
| high |
CVE-2026-19942 — The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback pl… |
vulnerability |
nvd |
CVE-2026-19942 |
rce |
2026-08-19 |
| high |
CVE-2026-49415 — During execve(2) of a SUID binary, the new virtual address space is installed before the process cre… |
vulnerability |
nvd |
CVE-2026-49415 |
|
2026-08-19 |
| high |
CVE-2026-49418 — When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages i… |
vulnerability |
nvd |
CVE-2026-49418 |
|
2026-08-19 |
| high |
CVE-2026-49419 — When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference… |
vulnerability |
nvd |
CVE-2026-49419 |
|
2026-08-19 |
| high |
CVE-2026-11565 — The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in sever… |
vulnerability |
nvd |
CVE-2026-11565 |
|
2026-08-19 |
| high |
CVE-2026-12983 — The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in… |
vulnerability |
nvd |
CVE-2026-12983 |
|
2026-08-19 |
| high |
CVE-2026-13169 — The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allow… |
vulnerability |
nvd |
CVE-2026-13169 |
|
2026-08-19 |
| high |
CVE-2026-13174 — The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting u… |
vulnerability |
nvd |
CVE-2026-13174 |
|
2026-08-19 |
| high |
CVE-2026-14334 — The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly s… |
vulnerability |
nvd |
CVE-2026-14334 |
|
2026-08-19 |
| high |
CVE-2026-14861 — The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request… |
vulnerability |
nvd |
CVE-2026-14861 |
|
2026-08-19 |
| high |
CVE-2026-16570 — The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of t… |
vulnerability |
nvd |
CVE-2026-16570 |
|
2026-08-19 |
| high |
CVE-2026-16616 — The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-mov… |
vulnerability |
nvd |
CVE-2026-16616 |
|
2026-08-19 |
| high |
CVE-2026-16617 — The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's… |
vulnerability |
nvd |
CVE-2026-16617 |
|
2026-08-19 |
| high |
CVE-2026-16950 — The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a paramet… |
vulnerability |
nvd |
CVE-2026-16950 |
|
2026-08-19 |
| high |
CVE-2026-17565 — The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied v… |
vulnerability |
nvd |
CVE-2026-17565 |
|
2026-08-19 |
| high |
CVE-2026-19055 — The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parame… |
vulnerability |
nvd |
CVE-2026-19055 |
|
2026-08-19 |
| high |
CVE-2026-19056 — The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter be… |
vulnerability |
nvd |
CVE-2026-19056 |
|
2026-08-19 |
| high |
CVE-2026-19842 — The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML respon… |
vulnerability |
nvd |
CVE-2026-19842 |
|
2026-08-19 |
| high |
CVE-2026-49420 — The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without check… |
vulnerability |
nvd |
CVE-2026-49420 |
rce |
2026-08-19 |
| high |
CVE-2026-49422 — The RACK setsockopt(2) handler drops the connection lock in order to copy option data from userspace… |
vulnerability |
nvd |
CVE-2026-49422 |
|
2026-08-19 |
| high |
CVE-2026-49427 — Pages belonging to largepage shared memory objects were not explicitly wired. When sendfile(2) trans… |
vulnerability |
nvd |
CVE-2026-49427 |
|
2026-08-19 |
| high |
CVE-2026-49428 — Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly fr… |
vulnerability |
nvd |
CVE-2026-49428 |
|
2026-08-19 |
| high |
CVE-2026-49429 — The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to… |
vulnerability |
nvd |
CVE-2026-49429 |
|
2026-08-19 |
| high |
CVE-2026-15780 — The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vu… |
vulnerability |
nvd |
CVE-2026-15780 |
|
2026-08-19 |
| high |
CVE-2026-75981 — The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner… |
vulnerability |
nvd |
CVE-2026-75981 |
|
2026-08-19 |
| high |
CVE-2026-58083 — While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be… |
vulnerability |
nvd |
CVE-2026-58083 |
|
2026-08-19 |
| high |
CVE-2026-58087 — The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dro… |
vulnerability |
nvd |
CVE-2026-58087 |
|
2026-08-19 |
| high |
CVE-2026-58088 — The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the cor… |
vulnerability |
nvd |
CVE-2026-58088 |
|
2026-08-19 |
| high |
CVE-2026-32552 — Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. |
vulnerability |
nvd |
CVE-2026-32552 |
|
2026-08-19 |
| high |
CVE-2026-61986 — Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions. |
vulnerability |
nvd |
CVE-2026-61986 |
|
2026-08-19 |
| high |
CVE-2026-66596 — Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions. |
vulnerability |
nvd |
CVE-2026-66596 |
|
2026-08-19 |
| high |
CVE-2026-66668 — Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions. |
vulnerability |
nvd |
CVE-2026-66668 |
|
2026-08-19 |
| high |
CVE-2026-73182 — Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions. |
vulnerability |
nvd |
CVE-2026-73182 |
|
2026-08-19 |
| high |
CVE-2026-73184 — Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions. |
vulnerability |
nvd |
CVE-2026-73184 |
|
2026-08-19 |
| high |
CVE-2026-73354 — Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions. |
vulnerability |
nvd |
CVE-2026-73354 |
|
2026-08-19 |
| high |
CVE-2026-73384 — Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions. |
vulnerability |
nvd |
CVE-2026-73384 |
|
2026-08-19 |
| high |
CVE-2026-73385 — Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions. |
vulnerability |
nvd |
CVE-2026-73385 |
|
2026-08-19 |
| high |
CVE-2026-73386 — Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2… |
vulnerability |
nvd |
CVE-2026-73386 |
|
2026-08-19 |
| high |
CVE-2026-73387 — Unauthenticated Local File Inclusion in Resido <= 1.5 versions. |
vulnerability |
nvd |
CVE-2026-73387 |
|
2026-08-19 |
| high |
CVE-2026-73394 — Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions. |
vulnerability |
nvd |
CVE-2026-73394 |
|
2026-08-19 |
| high |
CVE-2026-76235 — A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every… |
vulnerability |
nvd |
CVE-2026-76235 |
|
2026-08-19 |
| high |
CVE-2026-43961 — A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expressio… |
vulnerability |
nvd |
CVE-2026-43961 |
|
2026-08-19 |
| high |
CVE-2026-54794 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) v… |
vulnerability |
nvd |
CVE-2026-54794 |
|
2026-08-19 |
| high |
CVE-2026-54795 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special… |
vulnerability |
nvd |
CVE-2026-54795, CVE-2026-54796, CVE-2026-56088, CVE-2026-70422, CVE-2026-71176 |
|
2026-08-19 |
| high |
CVE-2026-70421 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulne… |
vulnerability |
nvd |
CVE-2026-70421 |
|
2026-08-19 |
| high |
CVE-2026-75916 — SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autoc… |
vulnerability |
nvd |
CVE-2026-75916 |
|
2026-08-19 |
| high |
CVE-2026-75917 — SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-t… |
vulnerability |
nvd |
CVE-2026-75917 |
|
2026-08-19 |
| high |
CVE-2026-75918 — phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user… |
vulnerability |
nvd |
CVE-2026-75918 |
ransomware |
2026-08-19 |
| high |
CVE-2026-76205 — phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpo… |
vulnerability |
nvd |
CVE-2026-76205 |
|
2026-08-19 |
| high |
CVE-2026-76207 — phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me to… |
vulnerability |
nvd |
CVE-2026-76207 |
ransomware |
2026-08-19 |
| high |
CVE-2026-76208 — phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::cr… |
vulnerability |
nvd |
CVE-2026-76208 |
|
2026-08-19 |
| high |
CVE-2026-76213 — phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step whe… |
vulnerability |
nvd |
CVE-2026-76213 |
|
2026-08-19 |
| high |
CVE-2026-76214 — phpMyFAQ before 4.1.7 (affected versions <= 4.1.5) fails to persist the WebAuthn login challenge gen… |
vulnerability |
nvd |
CVE-2026-76214 |
ransomware |
2026-08-19 |
| high |
CVE-2026-76216 — Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals… |
vulnerability |
nvd |
CVE-2026-76216 |
|
2026-08-19 |
| high |
CVE-2026-76218 — GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards un… |
vulnerability |
nvd |
CVE-2026-76218 |
rce |
2026-08-19 |
| high |
CVE-2026-76219 — GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from… |
vulnerability |
nvd |
CVE-2026-76219 |
|
2026-08-19 |
| high |
CVE-2026-76220 — GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard… |
vulnerability |
nvd |
CVE-2026-76220 |
|
2026-08-19 |
| high |
CVE-2026-76221 — GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator… |
vulnerability |
nvd |
CVE-2026-76221 |
rce |
2026-08-19 |
| high |
CVE-2026-76222 — GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers… |
vulnerability |
nvd |
CVE-2026-76222 |
|
2026-08-19 |
| high |
CVE-2026-76223 — ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission che… |
vulnerability |
nvd |
CVE-2026-76223 |
|
2026-08-19 |
| high |
CVE-2026-76224 — ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulne… |
vulnerability |
nvd |
CVE-2026-76224 |
rce |
2026-08-19 |
| high |
CVE-2026-76225 — ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD C… |
vulnerability |
nvd |
CVE-2026-76225 |
|
2026-08-19 |
| high |
CVE-2026-76234 — libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic i… |
vulnerability |
nvd |
CVE-2026-76234 |
|
2026-08-19 |
| high |
CVE-2026-14970 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server process is crashing during client registrat… |
vulnerability |
nvd |
CVE-2026-14970 |
|
2026-08-19 |
| high |
CVE-2026-15061 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service could allow a remote a… |
vulnerability |
nvd |
CVE-2026-15061 |
|
2026-08-19 |
| high |
CVE-2026-15078 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to gain unauthorized… |
vulnerability |
nvd |
CVE-2026-15078 |
|
2026-08-19 |
| high |
CVE-2026-16686 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to access NFS-exported f… |
vulnerability |
nvd |
CVE-2026-16686 |
|
2026-08-19 |
| high |
CVE-2026-16703 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg… |
vulnerability |
nvd |
CVE-2026-16703, CVE-2026-16923, CVE-2026-16934, CVE-2026-16935, CVE-2026-16937, CVE-2026-16946, CVE-2026-16989, CVE-2026-16991, CVE-2026-18842 |
|
2026-08-19 |
| high |
CVE-2026-23501 — Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Specia… |
vulnerability |
nvd |
CVE-2026-23501 |
|
2026-08-19 |
| high |
CVE-2026-44829 — Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling… |
vulnerability |
nvd |
CVE-2026-44829 |
|
2026-08-19 |
| high |
CVE-2026-45741 — Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP fun… |
vulnerability |
nvd |
CVE-2026-45741 |
|
2026-08-19 |
| high |
CVE-2026-45742 — Gotenberg is a Docker-powered stateless API for PDF files. From 8.10.0 until 8.33.0, the newContext… |
vulnerability |
nvd |
CVE-2026-45742 |
|
2026-08-19 |
| high |
CVE-2026-48711 — SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SS… |
vulnerability |
nvd |
CVE-2026-48711 |
|
2026-08-19 |
| high |
CVE-2026-49253 — electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3… |
vulnerability |
nvd |
CVE-2026-49253, CVE-2026-49255 |
|
2026-08-19 |
| high |
CVE-2026-49283 — The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions… |
vulnerability |
nvd |
CVE-2026-49283 |
|
2026-08-19 |
| high |
CVE-2026-49289 — The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20… |
vulnerability |
nvd |
CVE-2026-49289 |
|
2026-08-19 |
| high |
CVE-2026-49816 — Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vuln… |
vulnerability |
nvd |
CVE-2026-49816, CVE-2026-49817 |
|
2026-08-19 |
| high |
CVE-2026-52834 — jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a cr… |
vulnerability |
nvd |
CVE-2026-52834 |
|
2026-08-19 |
| high |
CVE-2026-53477 — Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Rac… |
vulnerability |
nvd |
CVE-2026-53477 |
|
2026-08-19 |
| high |
CVE-2026-56797 — Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condit… |
vulnerability |
nvd |
CVE-2026-56797 |
|
2026-08-19 |
| high |
CVE-2026-58562 — Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A… |
vulnerability |
nvd |
CVE-2026-58562, CVE-2026-58565 |
|
2026-08-19 |
| high |
CVE-2026-58564 — Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnera… |
vulnerability |
nvd |
CVE-2026-58564 |
|
2026-08-19 |
| high |
CVE-2026-71961 — Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that a… |
vulnerability |
nvd |
CVE-2026-71961 |
|
2026-08-19 |
| high |
CVE-2026-16819 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of serv… |
vulnerability |
nvd |
CVE-2026-16819, CVE-2026-19653, CVE-2026-16855, CVE-2026-16897, CVE-2026-16952, CVE-2026-16980, CVE-2026-17009, CVE-2026-17195, CVE-2026-18822 |
|
2026-08-19 |
| high |
CVE-2026-61607 — Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's cont… |
vulnerability |
nvd |
CVE-2026-61607, CVE-2026-62666, CVE-2026-62667, CVE-2026-62668, CVE-2026-63407, CVE-2026-63408, CVE-2026-64852 |
|
2026-08-19 |
| high |
CVE-2026-62669 — Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Gra… |
vulnerability |
nvd |
CVE-2026-62669, CVE-2026-62671 |
|
2026-08-19 |
| high |
CVE-2026-20320 — A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an una… |
vulnerability |
nvd |
CVE-2026-20320 |
|
2026-08-19 |
| high |
CVE-2026-75141 — FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an… |
vulnerability |
nvd |
CVE-2026-75141 |
|
2026-08-19 |
| high |
CVE-2026-75142 — FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpeg… |
vulnerability |
nvd |
CVE-2026-75142 |
|
2026-08-19 |
| high |
CVE-2026-75144 — FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP pac… |
vulnerability |
nvd |
CVE-2026-75144 |
botnet |
2026-08-19 |
| high |
CVE-2026-75146 — FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec… |
vulnerability |
nvd |
CVE-2026-75146 |
|
2026-08-19 |
| high |
CVE-2026-75147 — FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/r… |
vulnerability |
nvd |
CVE-2026-75147 |
|
2026-08-19 |
| high |
CVE-2026-17183 — An authenticated user with permission to create or edit alert rules can bypass datasource query auth… |
vulnerability |
nvd |
CVE-2026-17183 |
|
2026-08-19 |
| high |
CVE-2026-19234 — Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is af… |
vulnerability |
nvd |
CVE-2026-19234, CVE-2026-19321 |
|
2026-08-19 |
| high |
CVE-2026-19875 — IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email… |
vulnerability |
nvd |
CVE-2026-19875 |
|
2026-08-19 |
| high |
CVE-2026-61518 — ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id pa… |
vulnerability |
nvd |
CVE-2026-61518 |
|
2026-08-19 |
| high |
CVE-2026-62680 — Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specificat… |
vulnerability |
nvd |
CVE-2026-62680, CVE-2026-62681, CVE-2026-62682, CVE-2026-71864, CVE-2026-71865, CVE-2026-71866, CVE-2026-71867, CVE-2026-71868, CVE-2026-71869, CVE-2026-71871, CVE-2026-72716, CVE-2026-72717 |
|
2026-08-19 |
| high |
CVE-2026-75149 — marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler… |
vulnerability |
nvd |
CVE-2026-75149 |
|
2026-08-19 |
| high |
CVE-2026-16930 — IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 i… |
vulnerability |
nvd |
CVE-2026-16930, CVE-2026-17063 |
|
2026-08-19 |
| high |
CVE-2026-17093 — IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW95… |
vulnerability |
nvd |
CVE-2026-17093, CVE-2026-17429, CVE-2026-16933 |
|
2026-08-19 |
| high |
CVE-2026-17100 — Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00… |
vulnerability |
nvd |
CVE-2026-17100 |
|
2026-08-19 |
| high |
CVE-2026-17494 — IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability… |
vulnerability |
nvd |
CVE-2026-17494 |
|
2026-08-19 |
| high |
CVE-2026-16661 — IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW95… |
vulnerability |
nvd |
CVE-2026-16661, CVE-2026-16707, CVE-2026-17028, CVE-2026-17091, CVE-2026-17097, CVE-2026-17414, CVE-2026-18821 |
|
2026-08-19 |
| high |
CVE-2026-16825 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain… |
vulnerability |
nvd |
CVE-2026-16825, CVE-2026-18716 |
|
2026-08-19 |
| high |
CVE-2026-16838 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical fil… |
vulnerability |
nvd |
CVE-2026-16838 |
|
2026-08-19 |
| high |
CVE-2026-16857 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to manipulate network tr… |
vulnerability |
nvd |
CVE-2026-16857 |
|
2026-08-19 |
| high |
CVE-2026-16873 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve local privileg… |
vulnerability |
nvd |
CVE-2026-16873 |
|
2026-08-19 |
| high |
CVE-2026-16874 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain root privileges… |
vulnerability |
nvd |
CVE-2026-16874 |
|
2026-08-19 |
| high |
CVE-2026-16875 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary comm… |
vulnerability |
nvd |
CVE-2026-16875, CVE-2026-16932, CVE-2026-16997 |
|
2026-08-19 |
| high |
CVE-2026-17042 — IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.… |
vulnerability |
nvd |
CVE-2026-17042 |
|
2026-08-19 |
| high |
CVE-2026-18871 — IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is af… |
vulnerability |
nvd |
CVE-2026-18871 |
|
2026-08-19 |
| high |
CVE-2026-62317 — Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's… |
vulnerability |
nvd |
CVE-2026-62317 |
|
2026-08-19 |
| high |
CVE-2026-68558 — Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integratio… |
vulnerability |
nvd |
CVE-2026-68558 |
|
2026-08-19 |
| high |
CVE-2026-68561 — Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) ru… |
vulnerability |
nvd |
CVE-2026-68561 |
|
2026-08-19 |
| high |
CVE-2026-68899 — Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation… |
vulnerability |
nvd |
CVE-2026-68899 |
|
2026-08-19 |
| high |
CVE-2026-68900 — Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/… |
vulnerability |
nvd |
CVE-2026-68900 |
|
2026-08-19 |
| high |
CVE-2026-76574 — A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the… |
vulnerability |
nvd |
CVE-2026-76574 |
|
2026-08-19 |
| high |
CVE-2026-12522 — The HL7800 cellular modem driver's +CGCONTRDP: response handler on_cmd_atcmdinfo_ipaddr() in drivers… |
vulnerability |
nvd |
CVE-2026-12522 |
|
2026-08-19 |
| high |
CVE-2026-12633 — The IPv6 neighbor-discovery code in subsys/net/ip/ipv6_nbr.c processes the 6LoWPAN Context Option (6… |
vulnerability |
nvd |
CVE-2026-12633 |
|
2026-08-19 |
| high |
CVE-2026-18544 — IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image polic… |
vulnerability |
nvd |
CVE-2026-18544 |
|
2026-08-19 |
| high |
CVE-2026-54491 — Koel is a free, open-source music streaming solution. Prior to 9.7.1, outbound podcast and radio fet… |
vulnerability |
nvd |
CVE-2026-54491 |
|
2026-08-19 |
| high |
CVE-2026-54492 — Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible create… |
vulnerability |
nvd |
CVE-2026-54492, CVE-2026-54493 |
|
2026-08-19 |
| high |
CVE-2026-62727 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… |
vulnerability |
nvd |
CVE-2026-62727 |
|
2026-08-19 |
| high |
CVE-2026-68553 — Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticat… |
vulnerability |
nvd |
CVE-2026-68553 |
|
2026-08-19 |
| high |
CVE-2026-69222 — LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.2… |
vulnerability |
nvd |
CVE-2026-69222 |
|
2026-08-19 |
| high |
CVE-2026-75569 — A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remot… |
vulnerability |
nvd |
CVE-2026-75569 |
|
2026-08-19 |
| high |
CVE-2026-75616 — An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmwa… |
vulnerability |
nvd |
CVE-2026-75616 |
botnet |
2026-08-19 |
| high |
CVE-2026-76139 — A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a s… |
vulnerability |
nvd |
CVE-2026-76139 |
|
2026-08-19 |
| high |
CVE-2026-76582 — A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected is the function popen/syst… |
vulnerability |
nvd |
CVE-2026-76582 |
|
2026-08-19 |
| high |
CVE-2026-76583 — A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affected by this vulnerability is a… |
vulnerability |
nvd |
CVE-2026-76583 |
|
2026-08-19 |
| high |
CVE-2025-36254 — IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0… |
vulnerability |
nvd |
CVE-2025-36254, CVE-2025-36255, CVE-2025-36398 |
|
2026-08-19 |
| high |
CVE-2026-76251 — In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin"… |
vulnerability |
nvd |
CVE-2026-76251 |
|
2026-08-19 |
| high |
CVE-2026-76253 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role wit… |
vulnerability |
nvd |
CVE-2026-76253, CVE-2026-76260, CVE-2026-76318, CVE-2026-76350 |
|
2026-08-19 |
| high |
CVE-2026-76254 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated u… |
vulnerability |
nvd |
CVE-2026-76254 |
phishing |
2026-08-19 |
| high |
CVE-2026-76256 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway ve… |
vulnerability |
nvd |
CVE-2026-76256, CVE-2026-76257, CVE-2026-76258, CVE-2026-76261, CVE-2026-76327, CVE-2026-76347, CVE-2026-76351 |
|
2026-08-19 |
| high |
CVE-2026-76259 — In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local… |
vulnerability |
nvd |
CVE-2026-76259 |
|
2026-08-19 |
| high |
CVE-2026-76262 — In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus servi… |
vulnerability |
nvd |
CVE-2026-76262 |
|
2026-08-19 |
| high |
CVE-2026-76263 — In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "powe… |
vulnerability |
nvd |
CVE-2026-76263, CVE-2026-76336 |
|
2026-08-19 |
| high |
CVE-2026-76309 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that d… |
vulnerability |
nvd |
CVE-2026-76309, CVE-2026-76319 |
|
2026-08-19 |
| high |
CVE-2026-76313 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the… |
vulnerability |
nvd |
CVE-2026-76313, CVE-2026-76314, CVE-2026-76315, CVE-2026-76317, CVE-2026-76323, CVE-2026-76326, CVE-2026-76331, CVE-2026-76339, CVE-2026-76343, CVE-2026-76344, CVE-2026-76352, CVE-2026-76353, CVE-2026-76354 |
rce |
2026-08-19 |
| high |
CVE-2026-76316 — In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unauthenticated user who… |
vulnerability |
nvd |
CVE-2026-76316 |
|
2026-08-19 |
| high |
CVE-2026-76320 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user coul… |
vulnerability |
nvd |
CVE-2026-76320, CVE-2026-76321, CVE-2026-76329, CVE-2026-76330, CVE-2026-76332, CVE-2026-76337 |
phishing |
2026-08-19 |
| high |
CVE-2026-76324 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power"… |
vulnerability |
nvd |
CVE-2026-76324, CVE-2026-76325, CVE-2026-76333, CVE-2026-76334, CVE-2026-76341, CVE-2026-76342, CVE-2026-76346 |
|
2026-08-19 |
| high |
CVE-2026-76335 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who do… |
vulnerability |
nvd |
CVE-2026-76335 |
|
2026-08-19 |
| high |
CVE-2026-76355 — In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the informat… |
vulnerability |
nvd |
CVE-2026-76355 |
|
2026-08-19 |
| high |
CVE-2026-76356 — In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a… |
vulnerability |
nvd |
CVE-2026-76356 |
|
2026-08-19 |
| high |
CVE-2026-76357 — In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a craf… |
vulnerability |
nvd |
CVE-2026-76357 |
|
2026-08-19 |
| high |
CVE-2026-76362 — In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffi… |
vulnerability |
nvd |
CVE-2026-76362 |
|
2026-08-19 |
| high |
CVE-2026-76387 — In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security ro… |
vulnerability |
nvd |
CVE-2026-76387 |
|
2026-08-19 |
| high |
CVE-2026-76388 — In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterpri… |
vulnerability |
nvd |
CVE-2026-76388 |
|
2026-08-19 |
| high |
CVE-2026-76389 — In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a… |
vulnerability |
nvd |
CVE-2026-76389 |
|
2026-08-19 |
| high |
CVE-2026-76391 — In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk ro… |
vulnerability |
nvd |
CVE-2026-76391, CVE-2026-76392 |
|
2026-08-19 |
| high |
CVE-2026-76394 — In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "p… |
vulnerability |
nvd |
CVE-2026-76394 |
|
2026-08-19 |
| high |
CVE-2026-76395 — In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute ar… |
vulnerability |
nvd |
CVE-2026-76395 |
|
2026-08-19 |
| high |
CVE-2026-76396 — In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capabil… |
vulnerability |
nvd |
CVE-2026-76396 |
|
2026-08-19 |
| high |
CVE-2026-76397 — In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and… |
vulnerability |
nvd |
CVE-2026-76397 |
|
2026-08-19 |
| high |
CVE-2026-76399 — In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app… |
vulnerability |
nvd |
CVE-2026-76399 |
|
2026-08-19 |
| high |
CVE-2026-76400 — In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Co… |
vulnerability |
nvd |
CVE-2026-76400, CVE-2026-76401, CVE-2026-76402 |
|
2026-08-19 |
| high |
CVE-2026-76403 — In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network… |
vulnerability |
nvd |
CVE-2026-76403 |
|
2026-08-19 |
| high |
CVE-2026-76591 — A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function… |
vulnerability |
nvd |
CVE-2026-76591 |
|
2026-08-19 |
| high |
CVE-2026-76832 — Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that al… |
vulnerability |
nvd |
CVE-2026-76832 |
|
2026-08-19 |
| high |
CVE-2026-76760 — A vulnerability was found in chenhg5 cc-connect up to 1.4.1. Affected by this vulnerability is the f… |
vulnerability |
nvd |
CVE-2026-76760 |
|
2026-08-19 |
| high |
CVE-2026-76761 — A vulnerability was identified in chenhg5 cc-connect up to 1.4.1. This affects the function shellExe… |
vulnerability |
nvd |
CVE-2026-76761 |
|
2026-08-19 |
| high |
CVE-2026-76879 — C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76879, CVE-2026-76886 |
|
2026-08-19 |
| high |
CVE-2026-76880 — RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76880 |
|
2026-08-19 |
| high |
CVE-2026-76928 — X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76928 |
|
2026-08-19 |
| high |
CVE-2026-76762 — A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an… |
vulnerability |
nvd |
CVE-2026-76762 |
|
2026-08-20 |
| high |
CVE-2026-76764 — A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an un… |
vulnerability |
nvd |
CVE-2026-76764 |
|
2026-08-20 |
| high |
CVE-2026-76783 — A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown… |
vulnerability |
nvd |
CVE-2026-76783 |
|
2026-08-20 |
| high |
CVE-2026-76795 — A vulnerability has been found in AeternaLabsHQ PullMD 3.2.0. This impacts an unknown function of th… |
vulnerability |
nvd |
CVE-2026-76795 |
|
2026-08-20 |
| high |
CVE-2026-19582 — In binutils 2.46.1 and prior versions, a victim who opens a crafted PE file using binutils could exe… |
vulnerability |
nvd |
CVE-2026-19582 |
|
2026-08-20 |
| high |
CVE-2026-15049 — The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a… |
vulnerability |
nvd |
CVE-2026-15049 |
rce |
2026-08-20 |
| high |
CVE-2026-75963 — The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up t… |
vulnerability |
nvd |
CVE-2026-75963 |
|
2026-08-20 |
| high |
CVE-2026-14946 — A high privileged remote attacker can upload a .php file and then request it directly from /uploads/… |
vulnerability |
nvd |
CVE-2026-14946 |
|
2026-08-20 |
| high |
CVE-2026-14947 — A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal se… |
vulnerability |
nvd |
CVE-2026-14947 |
|
2026-08-20 |
| high |
CVE-2026-14948 — A low privileged remote attacker can hijack an active administrative session without needing to know… |
vulnerability |
nvd |
CVE-2026-14948 |
|
2026-08-20 |
| high |
CVE-2026-14951 — An low privileged remote attacker can cause authenticated users to perform unintended actions in the… |
vulnerability |
nvd |
CVE-2026-14951 |
|
2026-08-20 |
| high |
CVE-2026-14952 — An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the… |
vulnerability |
nvd |
CVE-2026-14952 |
transport |
2026-08-20 |
| high |
CVE-2026-18917 — A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerabil… |
vulnerability |
nvd |
CVE-2026-18917 |
|
2026-08-20 |
| high |
CVE-2026-73197 — A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by se… |
vulnerability |
nvd |
CVE-2026-73197 |
|
2026-08-20 |
| high |
CVE-2026-73198 — A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `… |
vulnerability |
nvd |
CVE-2026-73198 |
|
2026-08-20 |
| high |
CVE-2025-15637 — Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. |
vulnerability |
nvd |
CVE-2025-15637 |
|
2026-08-20 |
| high |
CVE-2026-28150 — Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions. |
vulnerability |
nvd |
CVE-2026-28150 |
|
2026-08-20 |
| high |
CVE-2026-66581 — Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. |
vulnerability |
nvd |
CVE-2026-66581 |
|
2026-08-20 |
| high |
CVE-2026-66582 — Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions. |
vulnerability |
nvd |
CVE-2026-66582 |
|
2026-08-20 |
| high |
CVE-2026-66590 — Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions. |
vulnerability |
nvd |
CVE-2026-66590 |
|
2026-08-20 |
| high |
CVE-2026-66594 — Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. |
vulnerability |
nvd |
CVE-2026-66594 |
|
2026-08-20 |
| high |
CVE-2026-66597 — Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions. |
vulnerability |
nvd |
CVE-2026-66597 |
|
2026-08-20 |
| high |
CVE-2026-66598 — Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions. |
vulnerability |
nvd |
CVE-2026-66598 |
|
2026-08-20 |
| high |
CVE-2026-66604 — Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions. |
vulnerability |
nvd |
CVE-2026-66604 |
|
2026-08-20 |
| high |
CVE-2026-66605 — Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products… |
vulnerability |
nvd |
CVE-2026-66605 |
|
2026-08-20 |
| high |
CVE-2026-66606 — Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions. |
vulnerability |
nvd |
CVE-2026-66606 |
|
2026-08-20 |
| high |
CVE-2026-66607 — Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions. |
vulnerability |
nvd |
CVE-2026-66607 |
|
2026-08-20 |
| high |
CVE-2026-66611 — Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions. |
vulnerability |
nvd |
CVE-2026-66611 |
|
2026-08-20 |
| high |
CVE-2026-66612 — Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions. |
vulnerability |
nvd |
CVE-2026-66612 |
|
2026-08-20 |
| high |
CVE-2026-66614 — Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions. |
vulnerability |
nvd |
CVE-2026-66614 |
|
2026-08-20 |
| high |
CVE-2026-66615 — Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions. |
vulnerability |
nvd |
CVE-2026-66615 |
|
2026-08-20 |
| high |
CVE-2026-66616 — Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions. |
vulnerability |
nvd |
CVE-2026-66616 |
|
2026-08-20 |
| high |
CVE-2026-66673 — Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions. |
vulnerability |
nvd |
CVE-2026-66673 |
|
2026-08-20 |
| high |
CVE-2026-66677 — Subscriber Broken Authentication in Leyka <= 3.32.3 versions. |
vulnerability |
nvd |
CVE-2026-66677 |
|
2026-08-20 |
| high |
CVE-2026-68564 — Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions. |
vulnerability |
nvd |
CVE-2026-68564 |
|
2026-08-20 |
| high |
CVE-2026-73998 — Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. |
vulnerability |
nvd |
CVE-2026-73998 |
|
2026-08-20 |
| high |
CVE-2026-74013 — Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. |
vulnerability |
nvd |
CVE-2026-74013 |
|
2026-08-20 |
| high |
CVE-2026-74019 — Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions. |
vulnerability |
nvd |
CVE-2026-74019 |
|
2026-08-20 |
| high |
CVE-2026-74020 — Unauthenticated Broken Access Control in Koji <= 2.2.1 versions. |
vulnerability |
nvd |
CVE-2026-74020 |
|
2026-08-20 |
| high |
CVE-2026-74021 — Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions. |
vulnerability |
nvd |
CVE-2026-74021 |
|
2026-08-20 |
| high |
CVE-2026-76987 — A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892.… |
vulnerability |
nvd |
CVE-2026-76987 |
|
2026-08-20 |
| high |
CVE-2026-76633 — WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that a… |
vulnerability |
nvd |
CVE-2026-76633 |
|
2026-08-20 |
| high |
CVE-2026-76635 — baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows au… |
vulnerability |
nvd |
CVE-2026-76635 |
|
2026-08-20 |
| high |
CVE-2026-76833 — @cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to… |
vulnerability |
nvd |
CVE-2026-76833 |
|
2026-08-20 |
| high |
CVE-2026-76990 — A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue… |
vulnerability |
nvd |
CVE-2026-76990 |
|
2026-08-20 |
| high |
CVE-2026-16925 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege esca… |
vulnerability |
nvd |
CVE-2026-16925 |
|
2026-08-20 |
| high |
CVE-2026-16927 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges d… |
vulnerability |
nvd |
CVE-2026-16927 |
|
2026-08-20 |
| high |
CVE-2026-49825 — lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attribute… |
vulnerability |
nvd |
CVE-2026-49825 |
|
2026-08-20 |
| high |
CVE-2026-61897 — An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges… |
vulnerability |
nvd |
CVE-2026-61897 |
|
2026-08-20 |
| high |
CVE-2026-61898 — The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accounts… |
vulnerability |
nvd |
CVE-2026-61898 |
|
2026-08-20 |
| high |
CVE-2026-63490 — Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.g… |
vulnerability |
nvd |
CVE-2026-63490 |
|
2026-08-20 |
| high |
CVE-2026-76996 — A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impact… |
vulnerability |
nvd |
CVE-2026-76996 |
|
2026-08-20 |
| high |
CVE-2026-19611 — A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode… |
vulnerability |
nvd |
CVE-2026-19611 |
|
2026-08-20 |
| high |
CVE-2026-75140 — jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnera… |
vulnerability |
nvd |
CVE-2026-75140 |
|
2026-08-20 |
| high |
CVE-2026-76998 — A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0.… |
vulnerability |
nvd |
CVE-2026-76998 |
|
2026-08-20 |
| high |
CVE-2026-77004 — A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi… |
vulnerability |
nvd |
CVE-2026-77004 |
|
2026-08-20 |
| high |
CVE-2026-54449 — LangBot is a global IM bot platform designed for LLMs. In version 4.10.7 and earlier, any authentica… |
vulnerability |
nvd |
CVE-2026-54449 |
|
2026-08-20 |
| high |
CVE-2026-54616 — NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 un… |
vulnerability |
nvd |
CVE-2026-54616 |
|
2026-08-20 |
| high |
CVE-2026-61704 — Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in ind… |
vulnerability |
nvd |
CVE-2026-61704 |
|
2026-08-20 |
| high |
CVE-2026-65842 — Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote… |
vulnerability |
nvd |
CVE-2026-65842 |
|
2026-08-20 |
| high |
CVE-2026-69183 — Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-… |
vulnerability |
nvd |
CVE-2026-69183 |
|
2026-08-20 |
| high |
CVE-2026-77019 — A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an… |
vulnerability |
nvd |
CVE-2026-77019 |
|
2026-08-20 |
| high |
CVE-2026-77020 — A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by thi… |
vulnerability |
nvd |
CVE-2026-77020 |
|
2026-08-20 |
| high |
CVE-2026-77176 — A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containe… |
vulnerability |
nvd |
CVE-2026-77176 |
|
2026-08-20 |
| high |
CVE-2026-54623 — django CMS is an easy-to-use and developer-friendly enterprise content management system powered by… |
vulnerability |
nvd |
CVE-2026-54623, CVE-2026-54622, CVE-2026-54624, CVE-2026-61663, CVE-2026-63003, CVE-2026-75526 |
|
2026-08-20 |
| high |
CVE-2026-63387 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-o… |
vulnerability |
nvd |
CVE-2026-63387 |
|
2026-08-20 |
| high |
CVE-2026-63388 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-… |
vulnerability |
nvd |
CVE-2026-63388 |
|
2026-08-20 |
| high |
CVE-2026-63495 — Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebS… |
vulnerability |
nvd |
CVE-2026-63495 |
|
2026-08-20 |
| high |
CVE-2026-76641 — Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger me… |
vulnerability |
nvd |
CVE-2026-76641 |
|
2026-08-20 |
| high |
CVE-2026-77031 — A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreat… |
vulnerability |
nvd |
CVE-2026-77031 |
|
2026-08-20 |
| high |
CVE-2026-53583 — libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a… |
vulnerability |
nvd |
CVE-2026-53583, CVE-2026-53584, CVE-2026-53585, CVE-2026-53586, CVE-2026-53587 |
|
2026-08-20 |
| high |
CVE-2026-66787 — A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes.… |
vulnerability |
nvd |
CVE-2026-66787 |
|
2026-08-20 |
| high |
CVE-2026-72852 — hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configur… |
vulnerability |
nvd |
CVE-2026-72852 |
|
2026-08-20 |
| high |
CVE-2026-18420 — Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards a… |
vulnerability |
nvd |
CVE-2026-18420 |
rce |
2026-08-20 |
| high |
CVE-2026-53804 — OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encry… |
vulnerability |
nvd |
CVE-2026-53804 |
|
2026-08-20 |
| high |
CVE-2026-73040 — Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in va… |
vulnerability |
nvd |
CVE-2026-73040 |
|
2026-08-20 |
| high |
CVE-2026-73137 — A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Mana… |
vulnerability |
nvd |
CVE-2026-73137 |
|
2026-08-20 |
| high |
CVE-2026-77584 — Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has a… |
vulnerability |
nvd |
CVE-2026-77584 |
|
2026-08-20 |
| high |
CVE-2026-77638 — Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous… |
vulnerability |
nvd |
CVE-2026-77638 |
|
2026-08-20 |
| high |
CVE-2026-17003 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confid… |
vulnerability |
nvd |
CVE-2026-17003 |
|
2026-08-20 |
| high |
CVE-2026-17171 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary fi… |
vulnerability |
nvd |
CVE-2026-17171 |
|
2026-08-20 |
| high |
CVE-2026-19442 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtua… |
vulnerability |
nvd |
CVE-2026-19442 |
|
2026-08-20 |
| high |
CVE-2026-19446 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a cr… |
vulnerability |
nvd |
CVE-2026-19446 |
|
2026-08-20 |
| high |
CVE-2026-19449 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unpriv… |
vulnerability |
nvd |
CVE-2026-19449 |
|
2026-08-20 |
| high |
CVE-2026-46355 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebu… |
vulnerability |
nvd |
CVE-2026-46355 |
|
2026-08-20 |
| high |
CVE-2026-46682 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authentica… |
vulnerability |
nvd |
CVE-2026-46682 |
|
2026-08-20 |
| high |
CVE-2026-49217 — Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorizati… |
vulnerability |
nvd |
CVE-2026-49217 |
|
2026-08-20 |
| high |
CVE-2026-49436 — LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API… |
vulnerability |
nvd |
CVE-2026-49436 |
|
2026-08-20 |
| high |
CVE-2026-55013 — Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to per… |
vulnerability |
nvd |
CVE-2026-55013 |
|
2026-08-20 |
| high |
CVE-2026-55765 — CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments.… |
vulnerability |
nvd |
CVE-2026-55765, CVE-2026-55769 |
|
2026-08-20 |
| high |
CVE-2026-66800 — Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose… |
vulnerability |
nvd |
CVE-2026-66800 |
|
2026-08-20 |
| high |
CVE-2026-69419 — Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to exe… |
vulnerability |
nvd |
CVE-2026-69419 |
|
2026-08-20 |
| high |
CVE-2026-69519 — Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose infor… |
vulnerability |
nvd |
CVE-2026-69519 |
|
2026-08-20 |
| high |
CVE-2026-69543 — Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevat… |
vulnerability |
nvd |
CVE-2026-69543 |
|
2026-08-20 |
| high |
CVE-2026-69558 — Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized… |
vulnerability |
nvd |
CVE-2026-69558 |
|
2026-08-20 |
| high |
CVE-2026-69855 — Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to di… |
vulnerability |
nvd |
CVE-2026-69855 |
|
2026-08-20 |
| high |
CVE-2026-72818 — The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and app… |
vulnerability |
nvd |
CVE-2026-72818 |
|
2026-08-20 |
| high |
CVE-2026-72848 — SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documente… |
vulnerability |
nvd |
CVE-2026-72848 |
|
2026-08-20 |
| high |
CVE-2026-72860 — The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues se… |
vulnerability |
nvd |
CVE-2026-72860 |
|
2026-08-20 |
| high |
CVE-2026-77642 — tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signatur… |
vulnerability |
nvd |
CVE-2026-77642 |
|
2026-08-20 |
| high |
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities |
advisory |
vendor-blogs |
|
botnet |
2026-08-20 |
| high |
CISA, NSA, FBI warn of Siemens S7 PLC exploitation using AI-generated scripts to disrupt critical industrial processes |
advisory |
vendor-blogs |
|
ics |
2026-08-20 |
| high |
NSSTS strategy targets cybersecurity, OT/ICS resilience and technology supply chains; outlines four pillars |
advisory |
vendor-blogs |
|
ics, supply-chain |
2026-08-19 |
| high |
b93f2842c5ede1d48659eebbba629082787a8ccd17edd2571f5ada14c1252341.elf |
malware |
malware-bazaar |
b93f2842c5ede1d4…, 1c4345de3e48f3e3… |
elf, exe, whack.sh |
2026-08-21 |
| high |
611fa15a339dabc3efdfdde36db072b7cddb2b70f37dd092abf0496f3fad74c7.exe |
malware |
malware-bazaar |
611fa15a339dabc3…, 2a4721f8805f3e2b… |
ConnectWise, exe, whack.sh |
2026-08-21 |
| high |
wr.php |
malware |
malware-bazaar |
3fb78a20a4cd6939…, 9d90aadfd3b64533… |
sh |
2026-08-21 |
| high |
ok |
malware |
malware-bazaar |
b59075c2da6a7f8e…, d48beea3c242577e… |
sh |
2026-08-21 |
| high |
flutter.mipsel |
malware |
malware-bazaar |
12dd079eab15afe1…, c9e08297a9f9d908… |
elf, Mirai, upx-dec, upx, botnet |
2026-08-21 |
| high |
377339da9394e4590baa1a2aa8e433cf676718bb83a50a37fb9399eb6c8f62c7.exe |
malware |
malware-bazaar |
377339da9394e459…, eb3815f639e96df5… |
exe, signed, whack.sh |
2026-08-21 |
| high |
f4b330adc3e1cb5d4ba6f1c506d0e4d6821b83d9b033f6e0f21cfdb94c35d2c2.bin |
malware |
malware-bazaar |
f4b330adc3e1cb5d…, 61118b7b4e83504d… |
exe, signed, Vidar, botnet, infostealer |
2026-08-21 |
| high |
wr.php |
malware |
malware-bazaar |
a38e5b31a0472067…, fdf04b0361e5fcb9… |
sh |
2026-08-21 |
| high |
k.php |
malware |
malware-bazaar |
d59aa853fe50e2c4…, 1c44f812710050f6… |
sh |
2026-08-21 |
| high |
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia |
threat-intel |
otx |
b9ad79eaf7a4133f…, f6f7a94c11ea0ee0… |
spear phishing, chrome remote desktop, powershell, gmail exfiltration, onedrive, northeast asia, keylogger, lnk malware, anydesk, chrome extension, apt, phishing, botnet, infostealer |
2026-08-20 |
| high |
Distinct Clusters Target Individuals of Interest to Russia |
threat-intel |
otx |
ca3be5885afb3eb3…, 5484009071ea96c7… |
russian cyber espionage, oauth phishing, vidar, device code phishing, headrush, app password phishing, unc6293, atomic, cherrypie, unc7005, enginelight, hospitality captive portal, unc5976, whatsapp device linking, authentication abuse, phishing, infostealer |
2026-08-20 |
| high |
Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking |
threat-intel |
otx |
196.251.84.11 |
websocket hijacking, cryptocurrency payments, spyroid, phaas, callflow, ai vishing, mexican banking fraud, android rat, phishing |
2026-08-19 |
| high |
SilkParasite: Tracking a China-Nexus APT Across Central Asia |
threat-intel |
otx |
193.29.56.216 | ff22419b8ec39945…, ff33a3be2d497d93… |
dll sideloading, cookietagrat, china-nexus apt, shadowpad, deed rat, spicerat, nodeedgerat, cyberespionage, google drive c2, goginrat, nomadrat, government targeting, central asia, drivesilkrat, bloodalchemy, silkparasite, apt, phishing, botnet |
2026-08-20 |
| high |
MacSync Stealer: C2 Infrastructure Rotation |
threat-intel |
otx |
7980485fb1e0b1b1…, 277acd8e241c1341… |
macsync stealer, c2 infrastructure, macos, mac.c, clickfix, credential theft, cryptocurrency wallet, macsync, malware-as-a-service, infostealer, botnet |
2026-08-18 |
| high |
CopyCop Targets AI Investment in Armenia |
threat-intel |
otx |
|
ai infrastructure, media impersonation, geopolitical realignment, disinformation, copycop, armenia, storm-1516, influence operations |
2026-08-18 |
| high |
Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US |
threat-intel |
otx |
192.52.166.55, 209.205.197.130, 181.214.165.173, 83.147.53.130, 209.205.192.6, 139.28.36.38, 98.144.204.109 |
microsoft 365, websocket, adversary-in-the-middle, credential theft, html smuggling, phishing-as-a-service, session hijacking, 2fa bypass, phishing |
2026-08-18 |
| high |
Clop Returns with Custom Implant in Mass-Extortion Campaign |
threat-intel |
otx |
CVE-2021-27101, CVE-2023-34362, CVE-2026-12569 | 78.128.113.10, 216.152.151.204, 185.227.83.236 | 321e1fb01eb3462b…, 71a7b6b8fa5e2176… |
web shell, lemurloot, dewmode, cve-2023-34362, cve-2026-12569, ptc windchill, data exfiltration, manufacturing, credential theft, mass exploitation, extortion, cve-2021-27101, ransomware, phishing |
2026-08-19 |
| high |
Fraudulent Employment Operations |
threat-intel |
otx |
104.253.147.147, 104.253.51.76, 104.253.72.75, 104.253.134.123, 218.24.120.118, 104.253.1.79, 104.253.103.238, 104.253.111.106, 104.253.112.86, 104.253.121.146, 104.253.17.141, 104.253.19.244, 104.253.199.214, 104.253.251.19, 104.253.34.67, 104.253.47.239, 104.253.56.226, 104.253.90.150 |
insider threat, identity fraud, north korean it workers, remote work deception, fraudulent employment, purpledelta, chatgpt abuse, ai-generated personas |
2026-08-18 |
| high |
Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps |
threat-intel |
otx |
45.192.12.34, 209.99.184.50, 209.99.187.28, 104.251.180.179, 45.150.34.77 | b7e9072e5bda17e0…, d472e984c6e8f3d4… |
maas, octagon, android, accessibility abuse, cryptocurrency, vnc, overlay attack, banking trojan, botnet |
2026-08-18 |
| high |
CoolClient backdoor goes deeper: Windows kernel rootkit added |
threat-intel |
otx |
ee72ae4cc869affd…, eb79558b03766979… |
plugx, toneshell, coolclient, mustang panda, honeymyte, apt, botnet |
2026-08-14 |
| high |
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads |
news |
general-news |
|
supply-chain |
2026-08-20 |
| high |
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets |
news |
general-news |
|
ics |
2026-08-18 |
| high |
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks |
news |
general-news |
|
botnet |
2026-08-18 |
| high |
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets |
news |
general-news |
|
supply-chain |
2026-08-18 |
| high |
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic |
news |
general-news |
|
botnet |
2026-08-17 |
| high |
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies |
news |
general-news |
|
botnet |
2026-08-17 |
| high |
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS |
news |
general-news |
|
botnet |
2026-08-17 |
| high |
JFrog Artifactory Flaws Enable Software Supply Chain Attacks |
news |
general-news |
|
supply-chain |
2026-08-20 |
| high |
ICS Operators Warned of AI-Driven Attacks on Siemens PLCs |
news |
general-news |
|
ics |
2026-08-20 |
| high |
US agencies warn of AI-powered attacks on Siemens industrial controllers |
news |
general-news |
|
ics |
2026-08-20 |
| medium |
CVE-2026-19761 — A vulnerability has been found in DTStack Taier 1.4.0. Affected is the function MultipartFile.getOri… |
vulnerability |
nvd |
CVE-2026-19761 |
|
2026-08-14 |
| medium |
CVE-2026-19765 — A security flaw has been discovered in eyaushev swagger-testcase-mcp 5babb27c951fb404bc2b25ec8059361… |
vulnerability |
nvd |
CVE-2026-19765 |
botnet |
2026-08-14 |
| medium |
CVE-2026-19767 — A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects so… |
vulnerability |
nvd |
CVE-2026-19767 |
|
2026-08-14 |
| medium |
CVE-2026-19770 — A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is th… |
vulnerability |
nvd |
CVE-2026-19770 |
|
2026-08-14 |
| medium |
CVE-2026-19784 — A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This affects the function DBUpdate o… |
vulnerability |
nvd |
CVE-2026-19784 |
|
2026-08-14 |
| medium |
CVE-2026-19785 — A vulnerability has been found in francoisjacquet RosarioSIS up to 12.7.4. This vulnerability affect… |
vulnerability |
nvd |
CVE-2026-19785 |
|
2026-08-14 |
| medium |
CVE-2026-19786 — A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. This issue affects some unknown… |
vulnerability |
nvd |
CVE-2026-19786 |
|
2026-08-14 |
| medium |
CVE-2026-19787 — A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unk… |
vulnerability |
nvd |
CVE-2026-19787 |
|
2026-08-14 |
| medium |
CVE-2025-10308 — The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… |
vulnerability |
nvd |
CVE-2025-10308 |
|
2026-08-14 |
| medium |
CVE-2026-12743 — The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vul… |
vulnerability |
nvd |
CVE-2026-12743 |
ransomware |
2026-08-14 |
| medium |
CVE-2026-14290 — The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute v… |
vulnerability |
nvd |
CVE-2026-14290 |
|
2026-08-14 |
| medium |
CVE-2026-16739 — The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-c… |
vulnerability |
nvd |
CVE-2026-16739 |
|
2026-08-14 |
| medium |
CVE-2026-16810 — The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugi… |
vulnerability |
nvd |
CVE-2026-16810 |
|
2026-08-14 |
| medium |
CVE-2026-19617 — A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) met… |
vulnerability |
nvd |
CVE-2026-19617 |
|
2026-08-14 |
| medium |
CVE-2025-71405 — chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware… |
vulnerability |
nvd |
CVE-2025-71405 |
phishing |
2026-08-14 |
| medium |
CVE-2026-72812 — SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshB… |
vulnerability |
nvd |
CVE-2026-72812 |
|
2026-08-14 |
| medium |
CVE-2026-72816 — go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/… |
vulnerability |
nvd |
CVE-2026-72816 |
|
2026-08-14 |
| medium |
CVE-2026-72817 — go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middlewar… |
vulnerability |
nvd |
CVE-2026-72817 |
|
2026-08-14 |
| medium |
CVE-2026-72820 — Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers… |
vulnerability |
nvd |
CVE-2026-72820 |
|
2026-08-14 |
| medium |
CVE-2026-72821 — Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio… |
vulnerability |
nvd |
CVE-2026-72821 |
|
2026-08-14 |
| medium |
CVE-2026-72832 — Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the S… |
vulnerability |
nvd |
CVE-2026-72832 |
|
2026-08-14 |
| medium |
CVE-2026-72834 — filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint. The checksum… |
vulnerability |
nvd |
CVE-2026-72834 |
|
2026-08-14 |
| medium |
CVE-2026-72835 — filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allo… |
vulnerability |
nvd |
CVE-2026-72835 |
|
2026-08-14 |
| medium |
CVE-2026-72838 — FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-… |
vulnerability |
nvd |
CVE-2026-72838 |
|
2026-08-14 |
| medium |
CVE-2026-73048 — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFile… |
vulnerability |
nvd |
CVE-2026-73048 |
|
2026-08-14 |
| medium |
CVE-2026-73049 — SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeVie… |
vulnerability |
nvd |
CVE-2026-73049 |
|
2026-08-14 |
| medium |
CVE-2026-73630 — SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFileP… |
vulnerability |
nvd |
CVE-2026-73630 |
|
2026-08-14 |
| medium |
CVE-2026-19827 — A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStrea… |
vulnerability |
nvd |
CVE-2026-19827 |
|
2026-08-14 |
| medium |
CVE-2026-19828 — A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-20260107. This affects an unknown… |
vulnerability |
nvd |
CVE-2026-19828 |
ransomware |
2026-08-14 |
| medium |
CVE-2026-19829 — A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4-20260107. This vulnerability… |
vulnerability |
nvd |
CVE-2026-19829 |
|
2026-08-14 |
| medium |
CVE-2026-19830 — A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an un… |
vulnerability |
nvd |
CVE-2026-19830 |
|
2026-08-14 |
| medium |
CVE-2026-1621 — Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality al… |
vulnerability |
nvd |
CVE-2026-1621 |
|
2026-08-14 |
| medium |
CVE-2026-53472 — A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialU… |
vulnerability |
nvd |
CVE-2026-53472 |
|
2026-08-14 |
| medium |
CVE-2026-19879 — A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `wri… |
vulnerability |
nvd |
CVE-2026-19879 |
|
2026-08-14 |
| medium |
CVE-2026-58224 — A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integri… |
vulnerability |
nvd |
CVE-2026-58224 |
|
2026-08-14 |
| medium |
CVE-2026-13002 — A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An at… |
vulnerability |
nvd |
CVE-2026-13002 |
|
2026-08-14 |
| medium |
CVE-2026-19834 — A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the… |
vulnerability |
nvd |
CVE-2026-19834 |
|
2026-08-14 |
| medium |
CVE-2026-19836 — A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some un… |
vulnerability |
nvd |
CVE-2026-19836 |
|
2026-08-14 |
| medium |
CVE-2026-63701 — Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of… |
vulnerability |
nvd |
CVE-2026-63701 |
|
2026-08-14 |
| medium |
CVE-2026-63702 — Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credential… |
vulnerability |
nvd |
CVE-2026-63702 |
|
2026-08-14 |
| medium |
CVE-2026-66272 — Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for C… |
vulnerability |
nvd |
CVE-2026-66272 |
|
2026-08-14 |
| medium |
CVE-2026-19838 — A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects… |
vulnerability |
nvd |
CVE-2026-19838 |
|
2026-08-14 |
| medium |
CVE-2026-19839 — A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue aff… |
vulnerability |
nvd |
CVE-2026-19839 |
|
2026-08-14 |
| medium |
CVE-2026-49826 — Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker… |
vulnerability |
nvd |
CVE-2026-49826 |
phishing |
2026-08-14 |
| medium |
CVE-2026-73845 — CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_qu… |
vulnerability |
nvd |
CVE-2026-73845 |
|
2026-08-14 |
| medium |
CVE-2026-73846 — CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams… |
vulnerability |
nvd |
CVE-2026-73846 |
|
2026-08-14 |
| medium |
CVE-2026-12363 — The LoRaWAN Fragmented Data Block Transport service (subsys/lorawan/services/frag_transport.c) does… |
vulnerability |
nvd |
CVE-2026-12363 |
|
2026-08-14 |
| medium |
CVE-2026-12365 — A use-after-free exists in the Zephyr second-generation work queue (kernel/work.c) in the handling o… |
vulnerability |
nvd |
CVE-2026-12365 |
|
2026-08-14 |
| medium |
CVE-2026-19631 — A SQL injection vulnerability exists in Security Center that could allow an authenticated administra… |
vulnerability |
nvd |
CVE-2026-19631 |
|
2026-08-14 |
| medium |
CVE-2026-19636 — An issue was identified in which CSRF tokens were generated using a predictable method, potentially… |
vulnerability |
nvd |
CVE-2026-19636 |
|
2026-08-14 |
| medium |
CVE-2026-19639 — An improper access control vulnerability exists where an authenticated non-administrative applicatio… |
vulnerability |
nvd |
CVE-2026-19639 |
|
2026-08-14 |
| medium |
CVE-2026-49282 — Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name(… |
vulnerability |
nvd |
CVE-2026-49282 |
|
2026-08-14 |
| medium |
CVE-2026-73847 — Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on t… |
vulnerability |
nvd |
CVE-2026-73847 |
|
2026-08-14 |
| medium |
CVE-2026-50029 — js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a ke… |
vulnerability |
nvd |
CVE-2026-50029 |
|
2026-08-14 |
| medium |
CVE-2026-17209 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitr… |
vulnerability |
nvd |
CVE-2026-17209 |
|
2026-08-14 |
| medium |
CVE-2026-18178 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitra… |
vulnerability |
nvd |
CVE-2026-18178 |
|
2026-08-14 |
| medium |
CVE-2026-74248 — OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associ… |
vulnerability |
nvd |
CVE-2026-74248 |
|
2026-08-14 |
| medium |
CVE-2026-74240 — A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and… |
vulnerability |
nvd |
CVE-2026-74240 |
|
2026-08-14 |
| medium |
CVE-2026-74241 — A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authenticat… |
vulnerability |
nvd |
CVE-2026-74241 |
|
2026-08-14 |
| medium |
CVE-2026-74242 — A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a targe… |
vulnerability |
nvd |
CVE-2026-74242 |
|
2026-08-14 |
| medium |
CVE-2026-74243 — A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a re… |
vulnerability |
nvd |
CVE-2026-74243 |
|
2026-08-14 |
| medium |
CVE-2026-74244 — A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unau… |
vulnerability |
nvd |
CVE-2026-74244 |
|
2026-08-14 |
| medium |
CVE-2026-74245 — A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid f… |
vulnerability |
nvd |
CVE-2026-74245 |
|
2026-08-14 |
| medium |
CVE-2026-74247 — A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write acc… |
vulnerability |
nvd |
CVE-2026-74247 |
|
2026-08-14 |
| medium |
CVE-2026-74250 — In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediat… |
vulnerability |
nvd |
CVE-2026-74250 |
|
2026-08-14 |
| medium |
CVE-2026-12128 — The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via… |
vulnerability |
nvd |
CVE-2026-12128 |
|
2026-08-15 |
| medium |
CVE-2026-16080 — The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the '… |
vulnerability |
nvd |
CVE-2026-16080 |
|
2026-08-15 |
| medium |
CVE-2026-8840 — The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization… |
vulnerability |
nvd |
CVE-2026-8840 |
|
2026-08-15 |
| medium |
CVE-2026-15453 — The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generi… |
vulnerability |
nvd |
CVE-2026-15453 |
|
2026-08-15 |
| medium |
CVE-2026-15948 — The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to… |
vulnerability |
nvd |
CVE-2026-15948 |
|
2026-08-15 |
| medium |
CVE-2026-15993 — The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is v… |
vulnerability |
nvd |
CVE-2026-15993 |
ransomware |
2026-08-15 |
| medium |
CVE-2026-16586 — The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is… |
vulnerability |
nvd |
CVE-2026-16586 |
|
2026-08-15 |
| medium |
CVE-2026-17090 — The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable t… |
vulnerability |
nvd |
CVE-2026-17090 |
|
2026-08-15 |
| medium |
CVE-2026-18387 — The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to ge… |
vulnerability |
nvd |
CVE-2026-18387 |
|
2026-08-15 |
| medium |
CVE-2026-14229 — The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when renderin… |
vulnerability |
nvd |
CVE-2026-14229 |
|
2026-08-15 |
| medium |
CVE-2026-14230 — The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its… |
vulnerability |
nvd |
CVE-2026-14230 |
|
2026-08-15 |
| medium |
CVE-2026-16541 — The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user record… |
vulnerability |
nvd |
CVE-2026-16541 |
|
2026-08-15 |
| medium |
CVE-2026-18216 — The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automat… |
vulnerability |
nvd |
CVE-2026-18216 |
|
2026-08-15 |
| medium |
CVE-2026-18807 — The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic re… |
vulnerability |
nvd |
CVE-2026-18807 |
|
2026-08-15 |
| medium |
CVE-2026-73631 — Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-req… |
vulnerability |
nvd |
CVE-2026-73631 |
|
2026-08-15 |
| medium |
CVE-2026-73632 — Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-res… |
vulnerability |
nvd |
CVE-2026-73632 |
|
2026-08-15 |
| medium |
CVE-2026-12248 — The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL Injection via the 'sorting' para… |
vulnerability |
nvd |
CVE-2026-12248 |
|
2026-08-15 |
| medium |
CVE-2026-19894 — A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an u… |
vulnerability |
nvd |
CVE-2026-19894 |
|
2026-08-15 |
| medium |
CVE-2026-18165 — @fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8… |
vulnerability |
nvd |
CVE-2026-18165 |
|
2026-08-15 |
| medium |
CVE-2026-19903 — A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown… |
vulnerability |
nvd |
CVE-2026-19903 |
|
2026-08-15 |
| medium |
CVE-2026-73047 — siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in… |
vulnerability |
nvd |
CVE-2026-73047 |
|
2026-08-15 |
| medium |
CVE-2026-73055 — Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in ass… |
vulnerability |
nvd |
CVE-2026-73055 |
|
2026-08-15 |
| medium |
CVE-2026-19917 — A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unkn… |
vulnerability |
nvd |
CVE-2026-19917 |
|
2026-08-15 |
| medium |
CVE-2026-19918 — A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects th… |
vulnerability |
nvd |
CVE-2026-19918 |
|
2026-08-16 |
| medium |
CVE-2026-19920 — A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown f… |
vulnerability |
nvd |
CVE-2026-19920 |
|
2026-08-16 |
| medium |
CVE-2026-19921 — A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnera… |
vulnerability |
nvd |
CVE-2026-19921 |
|
2026-08-16 |
| medium |
CVE-2026-19923 — A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown… |
vulnerability |
nvd |
CVE-2026-19923 |
|
2026-08-16 |
| medium |
CVE-2026-19925 — A vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some… |
vulnerability |
nvd |
CVE-2026-19925 |
|
2026-08-16 |
| medium |
CVE-2026-19927 — A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of t… |
vulnerability |
nvd |
CVE-2026-19927 |
|
2026-08-16 |
| medium |
CVE-2026-19928 — A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of th… |
vulnerability |
nvd |
CVE-2026-19928 |
|
2026-08-16 |
| medium |
CVE-2026-19929 — A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplat… |
vulnerability |
nvd |
CVE-2026-19929 |
|
2026-08-16 |
| medium |
CVE-2026-19930 — A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the… |
vulnerability |
nvd |
CVE-2026-19930 |
botnet |
2026-08-16 |
| medium |
CVE-2026-2487 — The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s… |
vulnerability |
nvd |
CVE-2026-2487 |
|
2026-08-16 |
| medium |
CVE-2025-10005 — The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vul… |
vulnerability |
nvd |
CVE-2025-10005 |
|
2026-08-16 |
| medium |
CVE-2026-11780 — The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to… |
vulnerability |
nvd |
CVE-2026-11780, CVE-2026-15963 |
|
2026-08-16 |
| medium |
CVE-2026-12477 — The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Store… |
vulnerability |
nvd |
CVE-2026-12477 |
|
2026-08-16 |
| medium |
CVE-2026-12905 — The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to,… |
vulnerability |
nvd |
CVE-2026-12905 |
|
2026-08-16 |
| medium |
CVE-2026-13167 — The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin fo… |
vulnerability |
nvd |
CVE-2026-13167 |
|
2026-08-16 |
| medium |
CVE-2026-13358 — The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress… |
vulnerability |
nvd |
CVE-2026-13358 |
|
2026-08-16 |
| medium |
CVE-2026-15009 — The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin… |
vulnerability |
nvd |
CVE-2026-15009 |
|
2026-08-16 |
| medium |
CVE-2026-15066 — The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Ext… |
vulnerability |
nvd |
CVE-2026-15066 |
|
2026-08-16 |
| medium |
CVE-2026-15441 — The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and… |
vulnerability |
nvd |
CVE-2026-15441 |
phishing |
2026-08-16 |
| medium |
CVE-2026-15602 — The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQ… |
vulnerability |
nvd |
CVE-2026-15602 |
|
2026-08-16 |
| medium |
CVE-2026-15726 — The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Sho… |
vulnerability |
nvd |
CVE-2026-15726 |
|
2026-08-16 |
| medium |
CVE-2026-16079 — The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attri… |
vulnerability |
nvd |
CVE-2026-16079 |
|
2026-08-16 |
| medium |
CVE-2026-16779 — The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions… |
vulnerability |
nvd |
CVE-2026-16779 |
|
2026-08-16 |
| medium |
CVE-2026-18385 — The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restri… |
vulnerability |
nvd |
CVE-2026-18385 |
ransomware |
2026-08-16 |
| medium |
CVE-2026-19932 — A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects… |
vulnerability |
nvd |
CVE-2026-19932 |
|
2026-08-16 |
| medium |
CVE-2026-19933 — A weakness has been identified in DefaultFuction Customer-Relationship-Management-In-C-Project 2.0.… |
vulnerability |
nvd |
CVE-2026-19933 |
|
2026-08-16 |
| medium |
CVE-2026-10035 — The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all… |
vulnerability |
nvd |
CVE-2026-10035 |
|
2026-08-16 |
| medium |
CVE-2026-13712 — The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow modul… |
vulnerability |
nvd |
CVE-2026-13712 |
|
2026-08-16 |
| medium |
CVE-2026-15056 — The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin… |
vulnerability |
nvd |
CVE-2026-15056 |
|
2026-08-16 |
| medium |
CVE-2026-15345 — The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnera… |
vulnerability |
nvd |
CVE-2026-15345 |
|
2026-08-16 |
| medium |
CVE-2026-15351 — The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPr… |
vulnerability |
nvd |
CVE-2026-15351 |
|
2026-08-16 |
| medium |
CVE-2026-15384 — The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce ve… |
vulnerability |
nvd |
CVE-2026-15384 |
|
2026-08-16 |
| medium |
CVE-2026-15604 — The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… |
vulnerability |
nvd |
CVE-2026-15604 |
|
2026-08-16 |
| medium |
CVE-2026-15790 — The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… |
vulnerability |
nvd |
CVE-2026-15790 |
|
2026-08-16 |
| medium |
CVE-2026-16758 — The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortco… |
vulnerability |
nvd |
CVE-2026-16758 |
|
2026-08-16 |
| medium |
CVE-2026-16775 — The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulne… |
vulnerability |
nvd |
CVE-2026-16775 |
|
2026-08-16 |
| medium |
CVE-2026-17582 — The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to,… |
vulnerability |
nvd |
CVE-2026-17582 |
|
2026-08-16 |
| medium |
CVE-2026-18402 — The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cr… |
vulnerability |
nvd |
CVE-2026-18402 |
ransomware |
2026-08-16 |
| medium |
CVE-2026-19613 — The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of… |
vulnerability |
nvd |
CVE-2026-19613 |
|
2026-08-16 |
| medium |
CVE-2026-19711 — The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against th… |
vulnerability |
nvd |
CVE-2026-19711 |
|
2026-08-16 |
| medium |
CVE-2026-19712 — The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before out… |
vulnerability |
nvd |
CVE-2026-19712 |
|
2026-08-16 |
| medium |
CVE-2026-19726 — The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration… |
vulnerability |
nvd |
CVE-2026-19726 |
|
2026-08-16 |
| medium |
CVE-2026-19934 — A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unkno… |
vulnerability |
nvd |
CVE-2026-19934 |
|
2026-08-16 |
| medium |
CVE-2026-2283 — The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' paramet… |
vulnerability |
nvd |
CVE-2026-2283 |
|
2026-08-16 |
| medium |
CVE-2026-9767 — The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic S… |
vulnerability |
nvd |
CVE-2026-9767 |
|
2026-08-16 |
| medium |
CVE-2026-12998 — The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln… |
vulnerability |
nvd |
CVE-2026-12998 |
|
2026-08-16 |
| medium |
CVE-2026-17604 — The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t… |
vulnerability |
nvd |
CVE-2026-17604, CVE-2026-18347 |
|
2026-08-16 |
| medium |
CVE-2026-17608 — The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cro… |
vulnerability |
nvd |
CVE-2026-17608 |
|
2026-08-16 |
| medium |
CVE-2026-2357 — The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… |
vulnerability |
nvd |
CVE-2026-2357 |
|
2026-08-16 |
| medium |
CVE-2026-72888 — Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed mod… |
vulnerability |
nvd |
CVE-2026-72888 |
|
2026-08-16 |
| medium |
CVE-2026-73058 — stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blockli… |
vulnerability |
nvd |
CVE-2026-73058 |
|
2026-08-16 |
| medium |
CVE-2026-73059 — stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that c… |
vulnerability |
nvd |
CVE-2026-73059 |
|
2026-08-16 |
| medium |
CVE-2026-74785 — Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluat… |
vulnerability |
nvd |
CVE-2026-74785 |
|
2026-08-16 |
| medium |
CVE-2026-74786 — Scriban before 7.0.0 (affected versions <= 6.6.0) contains a denial-of-service vulnerability in whic… |
vulnerability |
nvd |
CVE-2026-74786 |
|
2026-08-16 |
| medium |
CVE-2026-74796 — OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during in… |
vulnerability |
nvd |
CVE-2026-74796 |
|
2026-08-16 |
| medium |
CVE-2026-19956 — A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is… |
vulnerability |
nvd |
CVE-2026-19956 |
botnet |
2026-08-16 |
| medium |
CVE-2026-19957 — A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetc… |
vulnerability |
nvd |
CVE-2026-19957 |
|
2026-08-16 |
| medium |
CVE-2026-19958 — A security flaw has been discovered in iatsiuk pptr-mcp up to 0.2.7. The impacted element is the fun… |
vulnerability |
nvd |
CVE-2026-19958 |
|
2026-08-16 |
| medium |
CVE-2026-19964 — A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run… |
vulnerability |
nvd |
CVE-2026-19964 |
|
2026-08-17 |
| medium |
CVE-2026-19966 — A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affe… |
vulnerability |
nvd |
CVE-2026-19966 |
|
2026-08-17 |
| medium |
CVE-2026-19967 — A security flaw has been discovered in Open Asset Import Library Assimp 17c12da. Impacted is the fun… |
vulnerability |
nvd |
CVE-2026-19967 |
|
2026-08-17 |
| medium |
CVE-2026-19968 — A weakness has been identified in Open Asset Import Library Assimp 17c12da. The affected element is… |
vulnerability |
nvd |
CVE-2026-19968 |
|
2026-08-17 |
| medium |
CVE-2026-19969 — A security vulnerability has been detected in Open Asset Import Library Assimp 17c12da. The impacted… |
vulnerability |
nvd |
CVE-2026-19969 |
|
2026-08-17 |
| medium |
CVE-2026-19970 — A vulnerability was detected in Open Asset Import Library Assimp 17c12da. This affects the function… |
vulnerability |
nvd |
CVE-2026-19970 |
|
2026-08-17 |
| medium |
CVE-2026-19971 — A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the function main of the file /www/cgi-… |
vulnerability |
nvd |
CVE-2026-19971 |
|
2026-08-17 |
| medium |
CVE-2026-19972 — A vulnerability has been found in itsourcecode Hospital Management System 1.0. Affected is an unknow… |
vulnerability |
nvd |
CVE-2026-19972 |
|
2026-08-17 |
| medium |
CVE-2026-19973 — A vulnerability was found in itsourcecode Hospital Management System 1.0. Affected by this vulnerabi… |
vulnerability |
nvd |
CVE-2026-19973 |
|
2026-08-17 |
| medium |
CVE-2026-19974 — A security flaw has been discovered in treefrogframework treefrog-framework up to 2.11.2. This vulne… |
vulnerability |
nvd |
CVE-2026-19974 |
|
2026-08-17 |
| medium |
CVE-2026-19976 — A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.1. Impacted is the function sub_… |
vulnerability |
nvd |
CVE-2026-19976 |
|
2026-08-17 |
| medium |
CVE-2026-19978 — A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292… |
vulnerability |
nvd |
CVE-2026-19978 |
botnet |
2026-08-17 |
| medium |
CVE-2026-19984 — A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13. Affected by this issue is the functio… |
vulnerability |
nvd |
CVE-2026-19984 |
|
2026-08-17 |
| medium |
CVE-2026-19986 — A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted… |
vulnerability |
nvd |
CVE-2026-19986 |
|
2026-08-17 |
| medium |
CVE-2026-13700 — The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a s… |
vulnerability |
nvd |
CVE-2026-13700 |
|
2026-08-17 |
| medium |
CVE-2026-14832 — The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorizat… |
vulnerability |
nvd |
CVE-2026-14832 |
|
2026-08-17 |
| medium |
CVE-2026-19987 — A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. Th… |
vulnerability |
nvd |
CVE-2026-19987 |
|
2026-08-17 |
| medium |
CVE-2026-19988 — A vulnerability was detected in Alaev SEO Tools Extension up to 1.0.10 on Chrome. This impacts the f… |
vulnerability |
nvd |
CVE-2026-19988 |
|
2026-08-17 |
| medium |
CVE-2026-19993 — A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an u… |
vulnerability |
nvd |
CVE-2026-19993 |
|
2026-08-17 |
| medium |
CVE-2026-19994 — A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown func… |
vulnerability |
nvd |
CVE-2026-19994 |
|
2026-08-17 |
| medium |
CVE-2026-19996 — A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown cod… |
vulnerability |
nvd |
CVE-2026-19996 |
|
2026-08-17 |
| medium |
CVE-2026-19997 — A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown p… |
vulnerability |
nvd |
CVE-2026-19997 |
|
2026-08-17 |
| medium |
CVE-2026-19998 — A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown f… |
vulnerability |
nvd |
CVE-2026-19998 |
|
2026-08-17 |
| medium |
CVE-2026-19999 — A security vulnerability has been detected in Open Asset Import Library Assimp Assimp 17c12da. The a… |
vulnerability |
nvd |
CVE-2026-19999 |
|
2026-08-17 |
| medium |
CVE-2026-20000 — A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is… |
vulnerability |
nvd |
CVE-2026-20000 |
|
2026-08-17 |
| medium |
CVE-2026-49301 — Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vuln… |
vulnerability |
nvd |
CVE-2026-49301 |
|
2026-08-17 |
| medium |
CVE-2026-49302 — Permission control vulnerability in the notification service module. Impact: Successful exploitation… |
vulnerability |
nvd |
CVE-2026-49302 |
|
2026-08-17 |
| medium |
CVE-2026-49303 — Permission control vulnerability in the notification module. Impact: Successful exploitation of this… |
vulnerability |
nvd |
CVE-2026-49303 |
|
2026-08-17 |
| medium |
CVE-2026-49304 — Permission control vulnerability in the device key management module. Impact: Successful exploitatio… |
vulnerability |
nvd |
CVE-2026-49304 |
|
2026-08-17 |
| medium |
CVE-2026-49305 — Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of… |
vulnerability |
nvd |
CVE-2026-49305 |
|
2026-08-17 |
| medium |
CVE-2026-49307 — Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of… |
vulnerability |
nvd |
CVE-2026-49307 |
|
2026-08-17 |
| medium |
CVE-2026-49308 — Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vu… |
vulnerability |
nvd |
CVE-2026-49308 |
|
2026-08-17 |
| medium |
CVE-2026-58560 — Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vu… |
vulnerability |
nvd |
CVE-2026-58560, CVE-2026-58561 |
|
2026-08-17 |
| medium |
CVE-2026-74842 — A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452.… |
vulnerability |
nvd |
CVE-2026-74842 |
|
2026-08-17 |
| medium |
CVE-2026-74867 — SiYuan versions before 3.7.4 contain a cross-site request forgery vulnerability in the session-cooki… |
vulnerability |
nvd |
CVE-2026-74867 |
|
2026-08-17 |
| medium |
CVE-2026-74871 — openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mo… |
vulnerability |
nvd |
CVE-2026-74871 |
|
2026-08-17 |
| medium |
CVE-2026-74873 — openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in pro… |
vulnerability |
nvd |
CVE-2026-74873 |
|
2026-08-17 |
| medium |
CVE-2026-74881 — openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_cr… |
vulnerability |
nvd |
CVE-2026-74881 |
|
2026-08-17 |
| medium |
CVE-2026-74890 — openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCiph… |
vulnerability |
nvd |
CVE-2026-74890 |
|
2026-08-17 |
| medium |
CVE-2026-74999 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subj… |
vulnerability |
nvd |
CVE-2026-74999 |
|
2026-08-17 |
| medium |
CVE-2026-75000 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG… |
vulnerability |
nvd |
CVE-2026-75000 |
|
2026-08-17 |
| medium |
CVE-2026-75003 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute… |
vulnerability |
nvd |
CVE-2026-75003 |
|
2026-08-17 |
| medium |
CVE-2026-75004 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to… |
vulnerability |
nvd |
CVE-2026-75004 |
|
2026-08-17 |
| medium |
CVE-2026-75006 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS)… |
vulnerability |
nvd |
CVE-2026-75006 |
|
2026-08-17 |
| medium |
CVE-2026-75007 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to inj… |
vulnerability |
nvd |
CVE-2026-75007 |
|
2026-08-17 |
| medium |
CVE-2026-75010 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin… |
vulnerability |
nvd |
CVE-2026-75010 |
|
2026-08-17 |
| medium |
CVE-2026-59911 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into L… |
vulnerability |
nvd |
CVE-2026-59911 |
|
2026-08-17 |
| medium |
CVE-2026-10527 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile Schem… |
vulnerability |
nvd |
CVE-2026-10527 |
|
2026-08-17 |
| medium |
CVE-2026-15754 — Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint f… |
vulnerability |
nvd |
CVE-2026-15754 |
|
2026-08-17 |
| medium |
CVE-2026-16044 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving… |
vulnerability |
nvd |
CVE-2026-16044 |
|
2026-08-17 |
| medium |
CVE-2026-16045 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauth… |
vulnerability |
nvd |
CVE-2026-16045 |
|
2026-08-17 |
| medium |
CVE-2026-16046 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on wr… |
vulnerability |
nvd |
CVE-2026-16046 |
ransomware |
2026-08-17 |
| medium |
CVE-2026-16047 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate that us… |
vulnerability |
nvd |
CVE-2026-16047 |
|
2026-08-17 |
| medium |
CVE-2026-16048 — Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel… |
vulnerability |
nvd |
CVE-2026-16048 |
|
2026-08-17 |
| medium |
CVE-2026-16049 — Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify c… |
vulnerability |
nvd |
CVE-2026-16049 |
|
2026-08-17 |
| medium |
CVE-2026-55704 — Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0,… |
vulnerability |
nvd |
CVE-2026-55704 |
|
2026-08-17 |
| medium |
CVE-2026-59829 — Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1… |
vulnerability |
nvd |
CVE-2026-59829 |
|
2026-08-17 |
| medium |
CVE-2026-68762 — In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible |
vulnerability |
nvd |
CVE-2026-68762 |
|
2026-08-17 |
| medium |
CVE-2026-74858 — A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_ur… |
vulnerability |
nvd |
CVE-2026-74858 |
|
2026-08-17 |
| medium |
CVE-2026-75046 — In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the use… |
vulnerability |
nvd |
CVE-2026-75046 |
|
2026-08-17 |
| medium |
CVE-2026-75047 — In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the im… |
vulnerability |
nvd |
CVE-2026-75047 |
|
2026-08-17 |
| medium |
CVE-2026-75049 — In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted… |
vulnerability |
nvd |
CVE-2026-75049 |
|
2026-08-17 |
| medium |
CVE-2026-75053 — In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint |
vulnerability |
nvd |
CVE-2026-75053 |
|
2026-08-17 |
| medium |
CVE-2026-75054 — In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrus… |
vulnerability |
nvd |
CVE-2026-75054 |
|
2026-08-17 |
| medium |
CVE-2026-75055 — In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE |
vulnerability |
nvd |
CVE-2026-75055 |
|
2026-08-17 |
| medium |
CVE-2026-75057 — In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log |
vulnerability |
nvd |
CVE-2026-75057 |
|
2026-08-17 |
| medium |
CVE-2026-75058 — In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers |
vulnerability |
nvd |
CVE-2026-75058 |
|
2026-08-17 |
| medium |
CVE-2026-75059 — In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible |
vulnerability |
nvd |
CVE-2026-75059 |
|
2026-08-17 |
| medium |
CVE-2026-12519 — The WNC-M14A2A LTE-M modem driver mishandles unsolicited %NOTIFYEV: events in on_cmd_socknotifyev()… |
vulnerability |
nvd |
CVE-2026-12519 |
|
2026-08-17 |
| medium |
CVE-2026-12629 — The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails to acknowledge receive error interrup… |
vulnerability |
nvd |
CVE-2026-12629 |
|
2026-08-17 |
| medium |
CVE-2026-12630 — Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression code contains an out-of-bounds read in g… |
vulnerability |
nvd |
CVE-2026-12630 |
|
2026-08-17 |
| medium |
CVE-2026-68517 — Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins gu… |
vulnerability |
nvd |
CVE-2026-68517 |
|
2026-08-17 |
| medium |
CVE-2026-48053 — Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoin… |
vulnerability |
nvd |
CVE-2026-48053 |
|
2026-08-17 |
| medium |
CVE-2026-50771 — Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to… |
vulnerability |
nvd |
CVE-2026-50771 |
|
2026-08-17 |
| medium |
CVE-2026-68520 — Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in… |
vulnerability |
nvd |
CVE-2026-68520 |
|
2026-08-17 |
| medium |
CVE-2026-73424 — Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel ada… |
vulnerability |
nvd |
CVE-2026-73424 |
|
2026-08-17 |
| medium |
CVE-2026-75011 — A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the function execAsync of the fil… |
vulnerability |
nvd |
CVE-2026-75011 |
|
2026-08-17 |
| medium |
CVE-2026-63667 — ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export… |
vulnerability |
nvd |
CVE-2026-63667 |
|
2026-08-17 |
| medium |
CVE-2026-63669 — ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module'… |
vulnerability |
nvd |
CVE-2026-63669 |
|
2026-08-17 |
| medium |
CVE-2026-63670 — ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() c… |
vulnerability |
nvd |
CVE-2026-63670 |
|
2026-08-17 |
| medium |
CVE-2026-71486 — vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completi… |
vulnerability |
nvd |
CVE-2026-71486 |
|
2026-08-17 |
| medium |
CVE-2026-75012 — A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by th… |
vulnerability |
nvd |
CVE-2026-75012 |
|
2026-08-17 |
| medium |
CVE-2026-75013 — A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function se… |
vulnerability |
nvd |
CVE-2026-75013 |
|
2026-08-17 |
| medium |
CVE-2026-40506 — OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php inter… |
vulnerability |
nvd |
CVE-2026-40506 |
|
2026-08-17 |
| medium |
CVE-2026-44845 — JumpServer is an open source bastion host and an operation and maintenance security audit system. Pr… |
vulnerability |
nvd |
CVE-2026-44845, CVE-2026-44846 |
ransomware |
2026-08-17 |
| medium |
CVE-2026-54336 — JumpServer is an open source bastion host and an operation and maintenance security audit system. Fr… |
vulnerability |
nvd |
CVE-2026-54336 |
|
2026-08-17 |
| medium |
CVE-2026-65976 — Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a conne… |
vulnerability |
nvd |
CVE-2026-65976 |
|
2026-08-17 |
| medium |
CVE-2026-67925 — Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrar… |
vulnerability |
nvd |
CVE-2026-67925 |
|
2026-08-17 |
| medium |
CVE-2026-68765 — hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePas… |
vulnerability |
nvd |
CVE-2026-68765 |
|
2026-08-17 |
| medium |
CVE-2026-73560 — vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMu… |
vulnerability |
nvd |
CVE-2026-73560 |
|
2026-08-17 |
| medium |
CVE-2026-75104 — Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing atta… |
vulnerability |
nvd |
CVE-2026-75104 |
|
2026-08-17 |
| medium |
CVE-2026-75108 — Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN end… |
vulnerability |
nvd |
CVE-2026-75108 |
ransomware |
2026-08-17 |
| medium |
CVE-2026-75480 — OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-lev… |
vulnerability |
nvd |
CVE-2026-75480 |
|
2026-08-17 |
| medium |
CVE-2026-10080 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSoc… |
vulnerability |
nvd |
CVE-2026-10080 |
|
2026-08-17 |
| medium |
CVE-2026-28984 — The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS… |
vulnerability |
nvd |
CVE-2026-28984 |
|
2026-08-17 |
| medium |
CVE-2026-43667 — A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.… |
vulnerability |
nvd |
CVE-2026-43667 |
|
2026-08-17 |
| medium |
CVE-2026-43795 — The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.… |
vulnerability |
nvd |
CVE-2026-43795, CVE-2026-65338, CVE-2026-65341 |
|
2026-08-17 |
| medium |
CVE-2026-45791 — Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's user.updat… |
vulnerability |
nvd |
CVE-2026-45791 |
|
2026-08-17 |
| medium |
CVE-2026-63178 — Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Edition's PATCH /manage/admin/us… |
vulnerability |
nvd |
CVE-2026-63178 |
|
2026-08-17 |
| medium |
CVE-2026-64715 — A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari… |
vulnerability |
nvd |
CVE-2026-64715, CVE-2026-64787 |
|
2026-08-17 |
| medium |
CVE-2026-64760 — An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10… |
vulnerability |
nvd |
CVE-2026-64760 |
|
2026-08-17 |
| medium |
CVE-2026-64778 — The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and… |
vulnerability |
nvd |
CVE-2026-64778, CVE-2026-64780 |
|
2026-08-17 |
| medium |
CVE-2026-64781 — The issue was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 18… |
vulnerability |
nvd |
CVE-2026-64781 |
|
2026-08-17 |
| medium |
CVE-2026-64784 — An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Sa… |
vulnerability |
nvd |
CVE-2026-64784 |
|
2026-08-17 |
| medium |
CVE-2026-64788 — The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS… |
vulnerability |
nvd |
CVE-2026-64788, CVE-2026-65330 |
|
2026-08-17 |
| medium |
CVE-2026-65329 — An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.… |
vulnerability |
nvd |
CVE-2026-65329 |
|
2026-08-17 |
| medium |
CVE-2026-65331 — This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iO… |
vulnerability |
nvd |
CVE-2026-65331, CVE-2026-65332, CVE-2026-65333, CVE-2026-65335, CVE-2026-65336, CVE-2026-65337, CVE-2026-65340, CVE-2026-65351 |
|
2026-08-17 |
| medium |
CVE-2026-65334 — A memory corruption issue was addressed with improved state management. This issue is fixed in Safar… |
vulnerability |
nvd |
CVE-2026-65334 |
|
2026-08-17 |
| medium |
CVE-2026-65339 — A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.… |
vulnerability |
nvd |
CVE-2026-65339 |
|
2026-08-17 |
| medium |
CVE-2026-65347 — The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, m… |
vulnerability |
nvd |
CVE-2026-65347 |
|
2026-08-17 |
| medium |
CVE-2026-65349 — An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.… |
vulnerability |
nvd |
CVE-2026-65349 |
|
2026-08-17 |
| medium |
CVE-2026-75077 — A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by… |
vulnerability |
nvd |
CVE-2026-75077 |
|
2026-08-17 |
| medium |
CVE-2026-9859 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce Permissi… |
vulnerability |
nvd |
CVE-2026-9859 |
|
2026-08-17 |
| medium |
CVE-2026-75078 — A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This af… |
vulnerability |
nvd |
CVE-2026-75078 |
|
2026-08-17 |
| medium |
CVE-2026-75081 — A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the f… |
vulnerability |
nvd |
CVE-2026-75081 |
|
2026-08-18 |
| medium |
CVE-2026-75082 — A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of… |
vulnerability |
nvd |
CVE-2026-75082 |
|
2026-08-18 |
| medium |
CVE-2026-75086 — A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element… |
vulnerability |
nvd |
CVE-2026-75086 |
|
2026-08-18 |
| medium |
CVE-2026-75087 — A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown fu… |
vulnerability |
nvd |
CVE-2026-75087 |
|
2026-08-18 |
| medium |
CVE-2026-75088 — A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unkno… |
vulnerability |
nvd |
CVE-2026-75088 |
|
2026-08-18 |
| medium |
CVE-2026-75090 — A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. Affected by this issue is the… |
vulnerability |
nvd |
CVE-2026-75090 |
botnet |
2026-08-18 |
| medium |
CVE-2026-75093 — A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Te… |
vulnerability |
nvd |
CVE-2026-75093 |
botnet |
2026-08-18 |
| medium |
CVE-2026-75151 — A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0.… |
vulnerability |
nvd |
CVE-2026-75151 |
|
2026-08-18 |
| medium |
CVE-2026-19447 — Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i… |
vulnerability |
nvd |
CVE-2026-19447, CVE-2026-66603, CVE-2026-27365, CVE-2026-66591 |
|
2026-08-18 |
| medium |
CVE-2026-19608 — A flaw was found in the group policy provider of Keycloak authorization services, which is used to m… |
vulnerability |
nvd |
CVE-2026-19608 |
|
2026-08-18 |
| medium |
CVE-2026-5224 — Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technolog… |
vulnerability |
nvd |
CVE-2026-5224 |
|
2026-08-18 |
| medium |
CVE-2026-74903 — SiYuan before v3.7.4 contains an insufficient access control vulnerability in the /api/lute/spinBloc… |
vulnerability |
nvd |
CVE-2026-74903 |
|
2026-08-18 |
| medium |
CVE-2026-74907 — Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.p… |
vulnerability |
nvd |
CVE-2026-74907 |
|
2026-08-18 |
| medium |
CVE-2026-74908 — Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only… |
vulnerability |
nvd |
CVE-2026-74908 |
|
2026-08-18 |
| medium |
CVE-2026-75107 — Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append… |
vulnerability |
nvd |
CVE-2026-75107 |
|
2026-08-18 |
| medium |
CVE-2026-75832 — The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in… |
vulnerability |
nvd |
CVE-2026-75832 |
|
2026-08-18 |
| medium |
CVE-2026-75833 — The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before v… |
vulnerability |
nvd |
CVE-2026-75833 |
phishing |
2026-08-18 |
| medium |
CVE-2026-75834 — Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss()… |
vulnerability |
nvd |
CVE-2026-75834 |
|
2026-08-18 |
| medium |
CVE-2026-75835 — Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerabili… |
vulnerability |
nvd |
CVE-2026-75835 |
|
2026-08-18 |
| medium |
CVE-2026-75839 — ArcadeDB (com.arcadedb:arcadedb-server) versions <= 26.7.3 contain an insecure direct object referen… |
vulnerability |
nvd |
CVE-2026-75839 |
|
2026-08-18 |
| medium |
CVE-2026-75841 — ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function tha… |
vulnerability |
nvd |
CVE-2026-75841 |
|
2026-08-18 |
| medium |
CVE-2026-75845 — ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_ser… |
vulnerability |
nvd |
CVE-2026-75845 |
|
2026-08-18 |
| medium |
CVE-2026-75850 — ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and t… |
vulnerability |
nvd |
CVE-2026-75850 |
|
2026-08-18 |
| medium |
CVE-2026-16309 — Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies E… |
vulnerability |
nvd |
CVE-2026-16309 |
|
2026-08-18 |
| medium |
CVE-2026-74951 — Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154. |
vulnerability |
nvd |
CVE-2026-74951 |
|
2026-08-18 |
| medium |
CVE-2026-74963 — Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Fire… |
vulnerability |
nvd |
CVE-2026-74963 |
|
2026-08-18 |
| medium |
CVE-2026-74967 — Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Fi… |
vulnerability |
nvd |
CVE-2026-74967 |
ransomware |
2026-08-18 |
| medium |
CVE-2026-74968 — Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 1… |
vulnerability |
nvd |
CVE-2026-74968 |
|
2026-08-18 |
| medium |
CVE-2026-74970 — Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox… |
vulnerability |
nvd |
CVE-2026-74970 |
|
2026-08-18 |
| medium |
CVE-2026-74971 — Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixe… |
vulnerability |
nvd |
CVE-2026-74971 |
|
2026-08-18 |
| medium |
CVE-2026-74972 — Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Fir… |
vulnerability |
nvd |
CVE-2026-74972 |
|
2026-08-18 |
| medium |
CVE-2026-74973 — Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 15… |
vulnerability |
nvd |
CVE-2026-74973 |
|
2026-08-18 |
| medium |
CVE-2026-74974 — Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firef… |
vulnerability |
nvd |
CVE-2026-74974 |
|
2026-08-18 |
| medium |
CVE-2026-74975 — Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Fi… |
vulnerability |
nvd |
CVE-2026-74975 |
|
2026-08-18 |
| medium |
CVE-2026-74976 — JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox… |
vulnerability |
nvd |
CVE-2026-74976 |
|
2026-08-18 |
| medium |
CVE-2026-74980 — Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed i… |
vulnerability |
nvd |
CVE-2026-74980 |
|
2026-08-18 |
| medium |
CVE-2026-74984 — Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Fire… |
vulnerability |
nvd |
CVE-2026-74984 |
|
2026-08-18 |
| medium |
CVE-2026-32467 — Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. |
vulnerability |
nvd |
CVE-2026-32467 |
|
2026-08-18 |
| medium |
CVE-2026-50139 — goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share to… |
vulnerability |
nvd |
CVE-2026-50139 |
|
2026-08-18 |
| medium |
CVE-2026-59949 — yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementation… |
vulnerability |
nvd |
CVE-2026-59949 |
|
2026-08-18 |
| medium |
CVE-2026-66634 — Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions. |
vulnerability |
nvd |
CVE-2026-66634 |
|
2026-08-18 |
| medium |
CVE-2026-66636 — Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions. |
vulnerability |
nvd |
CVE-2026-66636 |
|
2026-08-18 |
| medium |
CVE-2026-66637 — Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions. |
vulnerability |
nvd |
CVE-2026-66637 |
|
2026-08-18 |
| medium |
CVE-2026-66638 — Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. |
vulnerability |
nvd |
CVE-2026-66638 |
|
2026-08-18 |
| medium |
CVE-2026-66639 — Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4… |
vulnerability |
nvd |
CVE-2026-66639 |
|
2026-08-18 |
| medium |
CVE-2026-66640 — Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions. |
vulnerability |
nvd |
CVE-2026-66640 |
|
2026-08-18 |
| medium |
CVE-2026-66641 — Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions. |
vulnerability |
nvd |
CVE-2026-66641 |
|
2026-08-18 |
| medium |
CVE-2026-66643 — Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions. |
vulnerability |
nvd |
CVE-2026-66643 |
|
2026-08-18 |
| medium |
CVE-2026-66644 — Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions. |
vulnerability |
nvd |
CVE-2026-66644 |
|
2026-08-18 |
| medium |
CVE-2026-66645 — Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions. |
vulnerability |
nvd |
CVE-2026-66645 |
|
2026-08-18 |
| medium |
CVE-2026-66646 — Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions. |
vulnerability |
nvd |
CVE-2026-66646 |
|
2026-08-18 |
| medium |
CVE-2026-66651 — Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions. |
vulnerability |
nvd |
CVE-2026-66651 |
|
2026-08-18 |
| medium |
CVE-2026-66679 — Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions. |
vulnerability |
nvd |
CVE-2026-66679 |
|
2026-08-18 |
| medium |
CVE-2026-68565 — Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions. |
vulnerability |
nvd |
CVE-2026-68565 |
|
2026-08-18 |
| medium |
CVE-2026-68568 — Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions. |
vulnerability |
nvd |
CVE-2026-68568 |
|
2026-08-18 |
| medium |
CVE-2026-70657 — Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks director… |
vulnerability |
nvd |
CVE-2026-70657 |
|
2026-08-18 |
| medium |
CVE-2026-73189 — Subscriber Insecure Direct Object References (IDOR) in WP Crowdfunding < 2.2.1 versions. |
vulnerability |
nvd |
CVE-2026-73189 |
|
2026-08-18 |
| medium |
CVE-2026-73348 — Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. |
vulnerability |
nvd |
CVE-2026-73348 |
|
2026-08-18 |
| medium |
CVE-2026-73352 — Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions. |
vulnerability |
nvd |
CVE-2026-73352 |
|
2026-08-18 |
| medium |
CVE-2026-73359 — Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9… |
vulnerability |
nvd |
CVE-2026-73359 |
|
2026-08-18 |
| medium |
CVE-2026-73379 — Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. |
vulnerability |
nvd |
CVE-2026-73379 |
|
2026-08-18 |
| medium |
CVE-2026-73383 — Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions. |
vulnerability |
nvd |
CVE-2026-73383 |
|
2026-08-18 |
| medium |
CVE-2026-73395 — Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking Sy… |
vulnerability |
nvd |
CVE-2026-73395 |
|
2026-08-18 |
| medium |
CVE-2026-73398 — Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. |
vulnerability |
nvd |
CVE-2026-73398 |
|
2026-08-18 |
| medium |
CVE-2026-73399 — Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. |
vulnerability |
nvd |
CVE-2026-73399 |
|
2026-08-18 |
| medium |
CVE-2026-73404 — Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. |
vulnerability |
nvd |
CVE-2026-73404 |
|
2026-08-18 |
| medium |
CVE-2026-73426 — Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix… |
vulnerability |
nvd |
CVE-2026-73426 |
|
2026-08-18 |
| medium |
CVE-2026-73995 — Subscriber Broken Authentication in User Registration <= 5.2.6 versions. |
vulnerability |
nvd |
CVE-2026-73995 |
|
2026-08-18 |
| medium |
CVE-2026-74003 — Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions. |
vulnerability |
nvd |
CVE-2026-74003 |
|
2026-08-18 |
| medium |
CVE-2026-74004 — Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <… |
vulnerability |
nvd |
CVE-2026-74004 |
|
2026-08-18 |
| medium |
CVE-2026-74006 — Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. |
vulnerability |
nvd |
CVE-2026-74006 |
|
2026-08-18 |
| medium |
CVE-2026-74007 — Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery… |
vulnerability |
nvd |
CVE-2026-74007 |
|
2026-08-18 |
| medium |
CVE-2026-74008 — Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22… |
vulnerability |
nvd |
CVE-2026-74008 |
|
2026-08-18 |
| medium |
CVE-2026-74009 — Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versio… |
vulnerability |
nvd |
CVE-2026-74009 |
|
2026-08-18 |
| medium |
CVE-2026-75032 — A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems respons… |
vulnerability |
nvd |
CVE-2026-75032 |
|
2026-08-18 |
| medium |
CVE-2026-45119 — MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module d… |
vulnerability |
nvd |
CVE-2026-45119 |
|
2026-08-18 |
| medium |
CVE-2026-45120 — MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify pr… |
vulnerability |
nvd |
CVE-2026-45120 |
|
2026-08-18 |
| medium |
CVE-2026-45121 — MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check per… |
vulnerability |
nvd |
CVE-2026-45121 |
|
2026-08-18 |
| medium |
CVE-2026-45122 — MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate… |
vulnerability |
nvd |
CVE-2026-45122 |
|
2026-08-18 |
| medium |
CVE-2026-45123 — MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not c… |
vulnerability |
nvd |
CVE-2026-45123 |
|
2026-08-18 |
| medium |
CVE-2026-45124 — MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not chec… |
vulnerability |
nvd |
CVE-2026-45124 |
|
2026-08-18 |
| medium |
CVE-2026-45125 — MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not san… |
vulnerability |
nvd |
CVE-2026-45125 |
|
2026-08-18 |
| medium |
CVE-2026-45129 — MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module doe… |
vulnerability |
nvd |
CVE-2026-45129 |
|
2026-08-18 |
| medium |
CVE-2026-45734 — MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consiste… |
vulnerability |
nvd |
CVE-2026-45734 |
ransomware |
2026-08-18 |
| medium |
CVE-2026-46482 — ### Impact The registration component does not validate the text-based _Security Question_ CAPTCHA c… |
vulnerability |
nvd |
CVE-2026-46482 |
|
2026-08-18 |
| medium |
CVE-2026-47245 — MyBB is free and open source forum software. Prior to 1.8.40, the User CP Buddy/Ignore List componen… |
vulnerability |
nvd |
CVE-2026-47245 |
|
2026-08-18 |
| medium |
CVE-2026-71477 — mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archi… |
vulnerability |
nvd |
CVE-2026-71477 |
|
2026-08-18 |
| medium |
CVE-2026-73834 — A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes.… |
vulnerability |
nvd |
CVE-2026-73834, CVE-2026-75485 |
|
2026-08-18 |
| medium |
CVE-2026-30250 — Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW!… |
vulnerability |
nvd |
CVE-2026-30250 |
|
2026-08-18 |
| medium |
CVE-2026-48744 — Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authori… |
vulnerability |
nvd |
CVE-2026-48744 |
|
2026-08-18 |
| medium |
CVE-2026-50126 — Adaguc-server is an open source geographical information system to visualize, combine, compare and s… |
vulnerability |
nvd |
CVE-2026-50126 |
|
2026-08-18 |
| medium |
CVE-2026-52606 — A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attacke… |
vulnerability |
nvd |
CVE-2026-52606, CVE-2026-52609 |
|
2026-08-18 |
| medium |
CVE-2026-55106 — authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action o… |
vulnerability |
nvd |
CVE-2026-55106 |
|
2026-08-18 |
| medium |
CVE-2026-66781 — A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuri… |
vulnerability |
nvd |
CVE-2026-66781 |
|
2026-08-18 |
| medium |
CVE-2026-49452 — WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped… |
vulnerability |
nvd |
CVE-2026-49452 |
|
2026-08-18 |
| medium |
CVE-2026-52607 — A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or e… |
vulnerability |
nvd |
CVE-2026-52607 |
|
2026-08-18 |
| medium |
CVE-2026-54570 — AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnota… |
vulnerability |
nvd |
CVE-2026-54570 |
|
2026-08-18 |
| medium |
CVE-2026-61696 — Forem is open source software for building communities. In versions before commit 92eacd16a82cf9007b… |
vulnerability |
nvd |
CVE-2026-61696 |
|
2026-08-18 |
| medium |
CVE-2026-63640 — MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecret… |
vulnerability |
nvd |
CVE-2026-63640 |
|
2026-08-18 |
| medium |
CVE-2026-68922 — MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobs… |
vulnerability |
nvd |
CVE-2026-68922 |
|
2026-08-18 |
| medium |
CVE-2026-68923 — MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py pl… |
vulnerability |
nvd |
CVE-2026-68923 |
|
2026-08-18 |
| medium |
CVE-2026-68924 — MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobs… |
vulnerability |
nvd |
CVE-2026-68924 |
|
2026-08-18 |
| medium |
CVE-2026-69160 — OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and… |
vulnerability |
nvd |
CVE-2026-69160 |
|
2026-08-18 |
| medium |
CVE-2026-73502 — kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.Val… |
vulnerability |
nvd |
CVE-2026-73502 |
|
2026-08-18 |
| medium |
CVE-2026-74039 — Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows auth… |
vulnerability |
nvd |
CVE-2026-74039 |
|
2026-08-18 |
| medium |
CVE-2026-74044 — Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster… |
vulnerability |
nvd |
CVE-2026-74044 |
|
2026-08-18 |
| medium |
CVE-2026-74046 — Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() func… |
vulnerability |
nvd |
CVE-2026-74046 |
|
2026-08-18 |
| medium |
CVE-2025-9211 — Unescaped stored values in application security page in Otalio Ship Property Management System versi… |
vulnerability |
nvd |
CVE-2025-9211 |
|
2026-08-18 |
| medium |
CVE-2026-55162 — Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certificates/verify.py accepted CRL Di… |
vulnerability |
nvd |
CVE-2026-55162 |
|
2026-08-18 |
| medium |
CVE-2026-55163 — Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:29… |
vulnerability |
nvd |
CVE-2026-55163 |
|
2026-08-18 |
| medium |
CVE-2026-55164 — Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replac… |
vulnerability |
nvd |
CVE-2026-55164 |
|
2026-08-18 |
| medium |
CVE-2026-55165 — Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifier in lemur/auth/service.py:13… |
vulnerability |
nvd |
CVE-2026-55165 |
|
2026-08-18 |
| medium |
CVE-2026-65959 — Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /… |
vulnerability |
nvd |
CVE-2026-65959 |
|
2026-08-18 |
| medium |
CVE-2026-70667 — Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificat… |
vulnerability |
nvd |
CVE-2026-70667 |
|
2026-08-18 |
| medium |
CVE-2026-12520 — The Sierra Wireless HL7800 cellular modem driver (drivers/modem/vendor_standalone/hl7800.c, located… |
vulnerability |
nvd |
CVE-2026-12520 |
|
2026-08-18 |
| medium |
CVE-2026-19670 — Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may… |
vulnerability |
nvd |
CVE-2026-19670 |
|
2026-08-18 |
| medium |
CVE-2026-19671 — Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth,… |
vulnerability |
nvd |
CVE-2026-19671 |
|
2026-08-18 |
| medium |
CVE-2026-47720 — FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengi… |
vulnerability |
nvd |
CVE-2026-47720 |
ics |
2026-08-18 |
| medium |
CVE-2026-47721 — FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/… |
vulnerability |
nvd |
CVE-2026-47721 |
ics |
2026-08-18 |
| medium |
CVE-2026-49500 — Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resoluti… |
vulnerability |
nvd |
CVE-2026-49500 |
|
2026-08-18 |
| medium |
CVE-2026-52731 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enab… |
vulnerability |
nvd |
CVE-2026-52731 |
|
2026-08-18 |
| medium |
CVE-2026-52732 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can mon… |
vulnerability |
nvd |
CVE-2026-52732 |
|
2026-08-18 |
| medium |
CVE-2026-52733 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced cha… |
vulnerability |
nvd |
CVE-2026-52733 |
|
2026-08-18 |
| medium |
CVE-2026-52734 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can caus… |
vulnerability |
nvd |
CVE-2026-52734 |
|
2026-08-18 |
| medium |
CVE-2026-52737 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious unauthenticated P2P peer… |
vulnerability |
nvd |
CVE-2026-52737 |
|
2026-08-18 |
| medium |
CVE-2026-52739 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can termi… |
vulnerability |
nvd |
CVE-2026-52739 |
|
2026-08-18 |
| medium |
CVE-2026-71317 — Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did… |
vulnerability |
nvd |
CVE-2026-71317 |
|
2026-08-18 |
| medium |
CVE-2026-71322 — Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePerm… |
vulnerability |
nvd |
CVE-2026-71322 |
|
2026-08-18 |
| medium |
CVE-2026-73529 — Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that… |
vulnerability |
nvd |
CVE-2026-73529 |
|
2026-08-18 |
| medium |
CVE-2026-75876 — A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected… |
vulnerability |
nvd |
CVE-2026-75876 |
|
2026-08-18 |
| medium |
CVE-2026-76032 — Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handl… |
vulnerability |
nvd |
CVE-2026-76032 |
|
2026-08-18 |
| medium |
CVE-2026-12631 — The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscal… |
vulnerability |
nvd |
CVE-2026-12631 |
|
2026-08-18 |
| medium |
CVE-2026-12632 — Zephyr's Precision Time Protocol receive handler ptp_msg_post_recv() in subsys/net/lib/ptp/msg.c tak… |
vulnerability |
nvd |
CVE-2026-12632 |
|
2026-08-18 |
| medium |
CVE-2026-16732 — fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 adde… |
vulnerability |
nvd |
CVE-2026-16732 |
|
2026-08-18 |
| medium |
CVE-2026-18504 — fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are… |
vulnerability |
nvd |
CVE-2026-18504 |
|
2026-08-18 |
| medium |
CVE-2026-41921 — Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in… |
vulnerability |
nvd |
CVE-2026-41921 |
|
2026-08-18 |
| medium |
CVE-2026-52817 — Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems.… |
vulnerability |
nvd |
CVE-2026-52817, CVE-2026-73973 |
apt |
2026-08-18 |
| medium |
CVE-2026-54543 — Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API comma… |
vulnerability |
nvd |
CVE-2026-54543 |
|
2026-08-18 |
| medium |
CVE-2026-55593 — Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php e… |
vulnerability |
nvd |
CVE-2026-55593 |
|
2026-08-18 |
| medium |
CVE-2026-60589 — Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ… |
vulnerability |
nvd |
CVE-2026-60589, CVE-2026-61308, CVE-2026-70907 |
|
2026-08-18 |
| medium |
CVE-2026-60682 — Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repo… |
vulnerability |
nvd |
CVE-2026-60682 |
|
2026-08-18 |
| medium |
CVE-2026-60830 — Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Suppo… |
vulnerability |
nvd |
CVE-2026-60830 |
|
2026-08-18 |
| medium |
CVE-2026-60884 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Pane… |
vulnerability |
nvd |
CVE-2026-60884 |
|
2026-08-18 |
| medium |
CVE-2026-61139 — Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Su… |
vulnerability |
nvd |
CVE-2026-61139 |
|
2026-08-18 |
| medium |
CVE-2026-61198 — Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Inter… |
vulnerability |
nvd |
CVE-2026-61198 |
|
2026-08-18 |
| medium |
CVE-2026-62475 — Vulnerability in the Oracle Shipping Execution product of Oracle E-Business Suite (component: Intern… |
vulnerability |
nvd |
CVE-2026-62475 |
|
2026-08-18 |
| medium |
CVE-2026-70720 — Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Int… |
vulnerability |
nvd |
CVE-2026-70720 |
|
2026-08-18 |
| medium |
CVE-2026-70726 — Vulnerability in the Oracle Cash Management product of Oracle E-Business Suite (component: Internal… |
vulnerability |
nvd |
CVE-2026-70726 |
|
2026-08-18 |
| medium |
CVE-2026-70732 — Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component:… |
vulnerability |
nvd |
CVE-2026-70732 |
|
2026-08-18 |
| medium |
CVE-2026-70775 — Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: User Inter… |
vulnerability |
nvd |
CVE-2026-70775 |
|
2026-08-18 |
| medium |
CVE-2026-71073 — Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The suppo… |
vulnerability |
nvd |
CVE-2026-71073, CVE-2026-71079, CVE-2026-71084 |
|
2026-08-18 |
| medium |
CVE-2026-71124 — Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authoriza… |
vulnerability |
nvd |
CVE-2026-71124 |
|
2026-08-18 |
| medium |
CVE-2026-76033 — Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attac… |
vulnerability |
nvd |
CVE-2026-76033 |
|
2026-08-18 |
| medium |
CVE-2026-76039 — Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowe… |
vulnerability |
nvd |
CVE-2026-76039 |
phishing |
2026-08-18 |
| medium |
CVE-2026-76041 — Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to poten… |
vulnerability |
nvd |
CVE-2026-76041 |
|
2026-08-18 |
| medium |
CVE-2026-47699 — Confidential Containers Guest Components provides guest tools and components for confidential contai… |
vulnerability |
nvd |
CVE-2026-47699 |
|
2026-08-18 |
| medium |
CVE-2026-48796 — CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Pr… |
vulnerability |
nvd |
CVE-2026-48796 |
|
2026-08-18 |
| medium |
CVE-2026-52873 — Streambert is a cross-platform Electron Desktop App to stream and download video content. From versi… |
vulnerability |
nvd |
CVE-2026-52873 |
|
2026-08-18 |
| medium |
CVE-2026-53959 — 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any a… |
vulnerability |
nvd |
CVE-2026-53959 |
phishing |
2026-08-18 |
| medium |
CVE-2026-62289 — libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or… |
vulnerability |
nvd |
CVE-2026-62289 |
|
2026-08-18 |
| medium |
CVE-2026-62291 — libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image s… |
vulnerability |
nvd |
CVE-2026-62291 |
|
2026-08-18 |
| medium |
CVE-2026-62377 — libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF se… |
vulnerability |
nvd |
CVE-2026-62377 |
|
2026-08-18 |
| medium |
CVE-2026-66589 — Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configure… |
vulnerability |
nvd |
CVE-2026-66589 |
|
2026-08-18 |
| medium |
CVE-2025-11729 — The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable… |
vulnerability |
nvd |
CVE-2025-11729 |
|
2026-08-19 |
| medium |
CVE-2026-75978 — A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affe… |
vulnerability |
nvd |
CVE-2026-75978 |
|
2026-08-19 |
| medium |
CVE-2026-75979 — A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function… |
vulnerability |
nvd |
CVE-2026-75979 |
|
2026-08-19 |
| medium |
CVE-2026-15421 — The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable… |
vulnerability |
nvd |
CVE-2026-15421 |
|
2026-08-19 |
| medium |
CVE-2026-13175 — The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule record… |
vulnerability |
nvd |
CVE-2026-13175 |
|
2026-08-19 |
| medium |
CVE-2026-14196 — The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a… |
vulnerability |
nvd |
CVE-2026-14196 |
|
2026-08-19 |
| medium |
CVE-2026-14287 — The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an u… |
vulnerability |
nvd |
CVE-2026-14287 |
|
2026-08-19 |
| medium |
CVE-2026-15253 — The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment tit… |
vulnerability |
nvd |
CVE-2026-15253 |
|
2026-08-19 |
| medium |
CVE-2026-16058 — The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on… |
vulnerability |
nvd |
CVE-2026-16058 |
|
2026-08-19 |
| medium |
CVE-2026-16979 — The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform cap… |
vulnerability |
nvd |
CVE-2026-16979 |
|
2026-08-19 |
| medium |
CVE-2026-18202 — The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types… |
vulnerability |
nvd |
CVE-2026-18202 |
|
2026-08-19 |
| medium |
CVE-2026-18231 — The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one o… |
vulnerability |
nvd |
CVE-2026-18231 |
|
2026-08-19 |
| medium |
CVE-2026-18466 — The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce,… |
vulnerability |
nvd |
CVE-2026-18466 |
|
2026-08-19 |
| medium |
CVE-2026-18777 — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its… |
vulnerability |
nvd |
CVE-2026-18777, CVE-2026-18779 |
|
2026-08-19 |
| medium |
CVE-2026-19416 — The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appoint… |
vulnerability |
nvd |
CVE-2026-19416 |
|
2026-08-19 |
| medium |
CVE-2026-19417 — The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to t… |
vulnerability |
nvd |
CVE-2026-19417 |
|
2026-08-19 |
| medium |
CVE-2026-19709 — The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer sec… |
vulnerability |
nvd |
CVE-2026-19709 |
|
2026-08-19 |
| medium |
CVE-2026-19782 — The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJA… |
vulnerability |
nvd |
CVE-2026-19782 |
|
2026-08-19 |
| medium |
CVE-2026-8810 — On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker… |
vulnerability |
nvd |
CVE-2026-8810 |
|
2026-08-19 |
| medium |
CVE-2026-15446 — The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data… |
vulnerability |
nvd |
CVE-2026-15446 |
|
2026-08-19 |
| medium |
CVE-2026-75900 — An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The ent… |
vulnerability |
nvd |
CVE-2026-75900 |
|
2026-08-19 |
| medium |
CVE-2026-76166 — A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single… |
vulnerability |
nvd |
CVE-2026-76166 |
|
2026-08-19 |
| medium |
CVE-2026-73363 — Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions. |
vulnerability |
nvd |
CVE-2026-73363 |
|
2026-08-19 |
| medium |
CVE-2026-70423 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML Externa… |
vulnerability |
nvd |
CVE-2026-70423 |
|
2026-08-19 |
| medium |
CVE-2026-70424 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname t… |
vulnerability |
nvd |
CVE-2026-70424 |
|
2026-08-19 |
| medium |
CVE-2026-75148 — cgltf through 1.15 contains an integer overflow vulnerability in the non-sparse accessor bounds chec… |
vulnerability |
nvd |
CVE-2026-75148 |
|
2026-08-19 |
| medium |
CVE-2026-75919 — phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows… |
vulnerability |
nvd |
CVE-2026-75919 |
|
2026-08-19 |
| medium |
CVE-2026-75920 — phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at con… |
vulnerability |
nvd |
CVE-2026-75920 |
|
2026-08-19 |
| medium |
CVE-2026-76206 — phpMyFAQ versions before 4.1.7 fail to validate active status in the PDF export endpoint, allowing u… |
vulnerability |
nvd |
CVE-2026-76206 |
|
2026-08-19 |
| medium |
CVE-2026-76209 — phpMyFAQ versions before v4.1.6 fail to validate the security.enableRegistration setting in API endp… |
vulnerability |
nvd |
CVE-2026-76209 |
|
2026-08-19 |
| medium |
CVE-2026-76210 — phpMyFAQ before 4.1.7 does not adequately sanitize HTML in FAQ answers before generating PDFs via TC… |
vulnerability |
nvd |
CVE-2026-76210 |
|
2026-08-19 |
| medium |
CVE-2026-76211 — phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endp… |
vulnerability |
nvd |
CVE-2026-76211 |
|
2026-08-19 |
| medium |
CVE-2026-76212 — phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the native pgsql PHP extension, declare… |
vulnerability |
nvd |
CVE-2026-76212 |
|
2026-08-19 |
| medium |
CVE-2026-76215 — phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks before returning child resources i… |
vulnerability |
nvd |
CVE-2026-76215 |
|
2026-08-19 |
| medium |
CVE-2026-76217 — GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands… |
vulnerability |
nvd |
CVE-2026-76217 |
|
2026-08-19 |
| medium |
CVE-2026-76226 — Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in baz… |
vulnerability |
nvd |
CVE-2026-76226 |
rce |
2026-08-19 |
| medium |
CVE-2026-76227 — Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including correspond… |
vulnerability |
nvd |
CVE-2026-76227 |
|
2026-08-19 |
| medium |
CVE-2026-76228 — Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) con… |
vulnerability |
nvd |
CVE-2026-76228 |
|
2026-08-19 |
| medium |
CVE-2026-76229 — Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability… |
vulnerability |
nvd |
CVE-2026-76229 |
|
2026-08-19 |
| medium |
CVE-2026-76230 — Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm m… |
vulnerability |
nvd |
CVE-2026-76230 |
|
2026-08-19 |
| medium |
CVE-2026-76231 — Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the herm… |
vulnerability |
nvd |
CVE-2026-76231 |
|
2026-08-19 |
| medium |
CVE-2026-76232 — Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv… |
vulnerability |
nvd |
CVE-2026-76232 |
|
2026-08-19 |
| medium |
CVE-2026-76233 — Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam… |
vulnerability |
nvd |
CVE-2026-76233 |
|
2026-08-19 |
| medium |
CVE-2026-76239 — Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subsc… |
vulnerability |
nvd |
CVE-2026-76239 |
|
2026-08-19 |
| medium |
CVE-2026-15961 — IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 IBM P… |
vulnerability |
nvd |
CVE-2026-15961 |
|
2026-08-19 |
| medium |
CVE-2026-32802 — Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerabil… |
vulnerability |
nvd |
CVE-2026-32802 |
|
2026-08-19 |
| medium |
CVE-2026-40507 — OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal t… |
vulnerability |
nvd |
CVE-2026-40507 |
|
2026-08-19 |
| medium |
CVE-2026-40508 — OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal temp… |
vulnerability |
nvd |
CVE-2026-40508 |
|
2026-08-19 |
| medium |
CVE-2026-40509 — OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The we… |
vulnerability |
nvd |
CVE-2026-40509 |
|
2026-08-19 |
| medium |
CVE-2026-50149 — Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, whe… |
vulnerability |
nvd |
CVE-2026-50149 |
|
2026-08-19 |
| medium |
CVE-2026-54793 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input Du… |
vulnerability |
nvd |
CVE-2026-54793 |
|
2026-08-19 |
| medium |
CVE-2026-56796 — Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File… |
vulnerability |
nvd |
CVE-2026-56796 |
|
2026-08-19 |
| medium |
CVE-2026-67266 — Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability… |
vulnerability |
nvd |
CVE-2026-67266 |
|
2026-08-19 |
| medium |
CVE-2026-67267 — Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Informat… |
vulnerability |
nvd |
CVE-2026-67267 |
|
2026-08-19 |
| medium |
CVE-2026-67268 — Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External… |
vulnerability |
nvd |
CVE-2026-67268 |
|
2026-08-19 |
| medium |
CVE-2026-76614 — OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. Th… |
vulnerability |
nvd |
CVE-2026-76614 |
|
2026-08-19 |
| medium |
CVE-2026-44253 — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3… |
vulnerability |
nvd |
CVE-2026-44253 |
|
2026-08-19 |
| medium |
CVE-2026-44254 — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1… |
vulnerability |
nvd |
CVE-2026-44254 |
|
2026-08-19 |
| medium |
CVE-2026-53654 — Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a clie… |
vulnerability |
nvd |
CVE-2026-53654 |
phishing |
2026-08-19 |
| medium |
CVE-2026-61690 — Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Co… |
vulnerability |
nvd |
CVE-2026-61690 |
|
2026-08-19 |
| medium |
CVE-2026-61842 — Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offset… |
vulnerability |
nvd |
CVE-2026-61842 |
|
2026-08-19 |
| medium |
CVE-2026-62670 — Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav… |
vulnerability |
nvd |
CVE-2026-62670 |
|
2026-08-19 |
| medium |
CVE-2026-20177 — A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 S… |
vulnerability |
nvd |
CVE-2026-20177 |
|
2026-08-19 |
| medium |
CVE-2026-20232 — A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series… |
vulnerability |
nvd |
CVE-2026-20232 |
|
2026-08-19 |
| medium |
CVE-2026-20302 — A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker wit… |
vulnerability |
nvd |
CVE-2026-20302 |
|
2026-08-19 |
| medium |
CVE-2026-20314 — A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact… |
vulnerability |
nvd |
CVE-2026-20314 |
|
2026-08-19 |
| medium |
CVE-2026-20327 — A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all… |
vulnerability |
nvd |
CVE-2026-20327 |
|
2026-08-19 |
| medium |
CVE-2026-75145 — FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packe… |
vulnerability |
nvd |
CVE-2026-75145 |
|
2026-08-19 |
| medium |
CVE-2026-18874 — A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malici… |
vulnerability |
nvd |
CVE-2026-18874 |
|
2026-08-19 |
| medium |
CVE-2026-55564 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_ge… |
vulnerability |
nvd |
CVE-2026-55564 |
ransomware |
2026-08-19 |
| medium |
CVE-2026-63117 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated R… |
vulnerability |
nvd |
CVE-2026-63117 |
|
2026-08-19 |
| medium |
CVE-2026-69159 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.29.0, planar_decompress_… |
vulnerability |
nvd |
CVE-2026-69159 |
|
2026-08-19 |
| medium |
CVE-2026-18681 — IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.0… |
vulnerability |
nvd |
CVE-2026-18681 |
|
2026-08-19 |
| medium |
CVE-2026-49870 — Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limi… |
vulnerability |
nvd |
CVE-2026-49870 |
|
2026-08-19 |
| medium |
CVE-2026-49976 — Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission… |
vulnerability |
nvd |
CVE-2026-49976 |
|
2026-08-19 |
| medium |
CVE-2026-50550 — Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users c… |
vulnerability |
nvd |
CVE-2026-50550 |
|
2026-08-19 |
| medium |
CVE-2026-55482 — Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http… |
vulnerability |
nvd |
CVE-2026-55482 |
|
2026-08-19 |
| medium |
CVE-2026-55519 — Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generi… |
vulnerability |
nvd |
CVE-2026-55519 |
|
2026-08-19 |
| medium |
CVE-2026-55703 — Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request… |
vulnerability |
nvd |
CVE-2026-55703 |
|
2026-08-19 |
| medium |
CVE-2026-16724 — IBM Virtualization Management Interface FW1110.00 through FW1110.30, FW1120.00 through FW1120.00, an… |
vulnerability |
nvd |
CVE-2026-16724 |
|
2026-08-19 |
| medium |
CVE-2026-16833 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to disclose kernel memor… |
vulnerability |
nvd |
CVE-2026-16833 |
|
2026-08-19 |
| medium |
CVE-2026-16883 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive infor… |
vulnerability |
nvd |
CVE-2026-16883, CVE-2026-16890, CVE-2026-16891, CVE-2026-17007 |
|
2026-08-19 |
| medium |
CVE-2026-55086 — Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and… |
vulnerability |
nvd |
CVE-2026-55086 |
transport |
2026-08-19 |
| medium |
CVE-2026-55087 — Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-con… |
vulnerability |
nvd |
CVE-2026-55087 |
|
2026-08-19 |
| medium |
CVE-2026-55088 — Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/expr… |
vulnerability |
nvd |
CVE-2026-55088 |
|
2026-08-19 |
| medium |
CVE-2026-63187 — Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0,… |
vulnerability |
nvd |
CVE-2026-63187 |
|
2026-08-19 |
| medium |
CVE-2026-67189 — pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnera… |
vulnerability |
nvd |
CVE-2026-67189 |
|
2026-08-19 |
| medium |
CVE-2026-68559 — Wekan is open source kanban built with Meteor. From 9.57 until 9.74, the /api/boards/:boardId/export… |
vulnerability |
nvd |
CVE-2026-68559 |
|
2026-08-19 |
| medium |
CVE-2026-68901 — Wekan is open source kanban built with Meteor. Prior to 10.38, the /api/boards/:boardId/export, /api… |
vulnerability |
nvd |
CVE-2026-68901 |
|
2026-08-19 |
| medium |
CVE-2026-76572 — A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is… |
vulnerability |
nvd |
CVE-2026-76572 |
|
2026-08-19 |
| medium |
CVE-2026-12634 — The NVS backend of the Zephyr settings subsystem (subsys/settings/src/settings_nvs.c) reads stored s… |
vulnerability |
nvd |
CVE-2026-12634 |
|
2026-08-19 |
| medium |
CVE-2026-14514 — IBM Reliable Scalable Cluster Technology (RSCT) 3.0 could allow a remote attacker to cause a denial… |
vulnerability |
nvd |
CVE-2026-14514 |
|
2026-08-19 |
| medium |
CVE-2026-14978 — HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclu… |
vulnerability |
nvd |
CVE-2026-14978 |
|
2026-08-19 |
| medium |
CVE-2026-17015 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of servic… |
vulnerability |
nvd |
CVE-2026-17015 |
|
2026-08-19 |
| medium |
CVE-2026-18849 — IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update pr… |
vulnerability |
nvd |
CVE-2026-18849 |
|
2026-08-19 |
| medium |
CVE-2026-4936 — IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.0… |
vulnerability |
nvd |
CVE-2026-4936 |
|
2026-08-19 |
| medium |
CVE-2026-4937 — IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 throug… |
vulnerability |
nvd |
CVE-2026-4937 |
|
2026-08-19 |
| medium |
CVE-2026-54738 — Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web… |
vulnerability |
nvd |
CVE-2026-54738 |
|
2026-08-19 |
| medium |
CVE-2026-54739 — Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, Lemmy's l… |
vulnerability |
nvd |
CVE-2026-54739 |
phishing |
2026-08-19 |
| medium |
CVE-2026-54740 — Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, a lower… |
vulnerability |
nvd |
CVE-2026-54740 |
|
2026-08-19 |
| medium |
CVE-2026-68552 — Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthentic… |
vulnerability |
nvd |
CVE-2026-68552 |
|
2026-08-19 |
| medium |
CVE-2026-68555 — Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TUR… |
vulnerability |
nvd |
CVE-2026-68555 |
|
2026-08-19 |
| medium |
CVE-2026-76576 — A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. This impacts the function fileDown… |
vulnerability |
nvd |
CVE-2026-76576 |
|
2026-08-19 |
| medium |
CVE-2026-76827 — A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed… |
vulnerability |
nvd |
CVE-2026-76827 |
|
2026-08-19 |
| medium |
CVE-2026-59992 — Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0… |
vulnerability |
nvd |
CVE-2026-59992 |
|
2026-08-19 |
| medium |
CVE-2026-63123 — Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev ser… |
vulnerability |
nvd |
CVE-2026-63123 |
|
2026-08-19 |
| medium |
CVE-2026-69550 — Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information… |
vulnerability |
nvd |
CVE-2026-69550 |
|
2026-08-19 |
| medium |
CVE-2026-76252 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.13, an unauthenticated user who… |
vulnerability |
nvd |
CVE-2026-76252 |
phishing |
2026-08-19 |
| medium |
CVE-2026-76255 — In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.8, and 9.4.13, a user who does not hold the… |
vulnerability |
nvd |
CVE-2026-76255 |
phishing |
2026-08-19 |
| medium |
CVE-2026-76322 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "user"… |
vulnerability |
nvd |
CVE-2026-76322 |
phishing |
2026-08-19 |
| medium |
CVE-2026-76328 — In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power"… |
vulnerability |
nvd |
CVE-2026-76328 |
phishing |
2026-08-19 |
| medium |
CVE-2026-76340 — In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could cause Splunk Enterpri… |
vulnerability |
nvd |
CVE-2026-76340 |
|
2026-08-19 |
| medium |
CVE-2026-76345 — In Splunk Enterprise versions below 10.4.2, a user with a high-privilege Splunk role that can manage… |
vulnerability |
nvd |
CVE-2026-76345 |
rce |
2026-08-19 |
| medium |
CVE-2026-76349 — In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick… |
vulnerability |
nvd |
CVE-2026-76349 |
phishing |
2026-08-19 |
| medium |
CVE-2026-76358 — In Splunk SOAR versions below 8.6.0, a user with app-install privileges could use path traversal dur… |
vulnerability |
nvd |
CVE-2026-76358 |
|
2026-08-19 |
| medium |
CVE-2026-76359 — In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversa… |
vulnerability |
nvd |
CVE-2026-76359 |
|
2026-08-19 |
| medium |
CVE-2026-76360 — In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest… |
vulnerability |
nvd |
CVE-2026-76360 |
|
2026-08-19 |
| medium |
CVE-2026-76363 — In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run arbit… |
vulnerability |
nvd |
CVE-2026-76363 |
ransomware |
2026-08-19 |
| medium |
CVE-2026-76364 — In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role cou… |
vulnerability |
nvd |
CVE-2026-76364, CVE-2026-76365 |
|
2026-08-19 |
| medium |
CVE-2026-76366 — In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representatio… |
vulnerability |
nvd |
CVE-2026-76366 |
ransomware |
2026-08-19 |
| medium |
CVE-2026-76367 — In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Commander" Splunk SOAR role coul… |
vulnerability |
nvd |
CVE-2026-76367 |
phishing |
2026-08-19 |
| medium |
CVE-2026-76370 — In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use t… |
vulnerability |
nvd |
CVE-2026-76370 |
|
2026-08-19 |
| medium |
CVE-2026-76372 — In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run playboo… |
vulnerability |
nvd |
CVE-2026-76372 |
ransomware |
2026-08-19 |
| medium |
CVE-2026-76373 — In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission… |
vulnerability |
nvd |
CVE-2026-76373, CVE-2026-76374, CVE-2026-76375 |
|
2026-08-19 |
| medium |
CVE-2026-76376 — In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who holds a role with permission… |
vulnerability |
nvd |
CVE-2026-76376 |
|
2026-08-19 |
| medium |
CVE-2026-76377 — In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with perm… |
vulnerability |
nvd |
CVE-2026-76377 |
|
2026-08-19 |
| medium |
CVE-2026-76378 — In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds… |
vulnerability |
nvd |
CVE-2026-76378 |
|
2026-08-19 |
| medium |
CVE-2026-76379 — In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permiss… |
vulnerability |
nvd |
CVE-2026-76379 |
|
2026-08-19 |
| medium |
CVE-2026-76380 — In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role wi… |
vulnerability |
nvd |
CVE-2026-76380 |
|
2026-08-19 |
| medium |
CVE-2026-76381 — In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a… |
vulnerability |
nvd |
CVE-2026-76381 |
|
2026-08-19 |
| medium |
CVE-2026-76382 — In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with permission… |
vulnerability |
nvd |
CVE-2026-76382 |
|
2026-08-19 |
| medium |
CVE-2026-76383 — In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who ho… |
vulnerability |
nvd |
CVE-2026-76383 |
|
2026-08-19 |
| medium |
CVE-2026-76384 — In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a… |
vulnerability |
nvd |
CVE-2026-76384 |
|
2026-08-19 |
| medium |
CVE-2026-76385 — In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission t… |
vulnerability |
nvd |
CVE-2026-76385 |
|
2026-08-19 |
| medium |
CVE-2026-76386 — In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to… |
vulnerability |
nvd |
CVE-2026-76386 |
|
2026-08-19 |
| medium |
CVE-2026-76390 — In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated u… |
vulnerability |
nvd |
CVE-2026-76390 |
|
2026-08-19 |
| medium |
CVE-2026-76393 — In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model bein… |
vulnerability |
nvd |
CVE-2026-76393 |
|
2026-08-19 |
| medium |
CVE-2026-76398 — In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk ro… |
vulnerability |
nvd |
CVE-2026-76398 |
|
2026-08-19 |
| medium |
CVE-2026-76405 — In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the… |
vulnerability |
nvd |
CVE-2026-76405 |
|
2026-08-19 |
| medium |
CVE-2026-76881 — CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76881, CVE-2026-76921 |
|
2026-08-19 |
| medium |
CVE-2026-76882 — Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of… |
vulnerability |
nvd |
CVE-2026-76882 |
|
2026-08-19 |
| medium |
CVE-2026-76883 — Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76883 |
|
2026-08-19 |
| medium |
CVE-2026-76889 — UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76889 |
|
2026-08-19 |
| medium |
CVE-2026-76917 — Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial… |
vulnerability |
nvd |
CVE-2026-76917 |
|
2026-08-19 |
| medium |
CVE-2026-76918 — SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76918 |
|
2026-08-19 |
| medium |
CVE-2026-76919 — ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76919 |
|
2026-08-19 |
| medium |
CVE-2026-76920 — 3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76920 |
|
2026-08-19 |
| medium |
CVE-2026-76922 — Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of… |
vulnerability |
nvd |
CVE-2026-76922 |
|
2026-08-19 |
| medium |
CVE-2026-76923 — Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial o… |
vulnerability |
nvd |
CVE-2026-76923 |
|
2026-08-19 |
| medium |
CVE-2026-76924 — Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76924 |
|
2026-08-19 |
| medium |
CVE-2026-76927 — H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76927 |
|
2026-08-19 |
| medium |
CVE-2026-76929 — Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76929 |
|
2026-08-19 |
| medium |
CVE-2026-76785 — A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Aff… |
vulnerability |
nvd |
CVE-2026-76785 |
|
2026-08-20 |
| medium |
CVE-2026-76799 — A weakness has been identified in code-projects Login Registration System 1.0. This affects an unkno… |
vulnerability |
nvd |
CVE-2026-76799 |
|
2026-08-20 |
| medium |
CVE-2026-76800 — A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of th… |
vulnerability |
nvd |
CVE-2026-76800 |
|
2026-08-20 |
| medium |
CVE-2026-76956 — In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to ins… |
vulnerability |
nvd |
CVE-2026-76956 |
|
2026-08-20 |
| medium |
CVE-2026-76957 — libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-… |
vulnerability |
nvd |
CVE-2026-76957 |
|
2026-08-20 |
| medium |
CVE-2026-13405 — The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom w… |
vulnerability |
nvd |
CVE-2026-13405 |
ransomware |
2026-08-20 |
| medium |
CVE-2026-17153 — The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all version… |
vulnerability |
nvd |
CVE-2026-17153 |
|
2026-08-20 |
| medium |
CVE-2026-19615 — The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG f… |
vulnerability |
nvd |
CVE-2026-19615 |
|
2026-08-20 |
| medium |
CVE-2026-19697 — The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload… |
vulnerability |
nvd |
CVE-2026-19697 |
|
2026-08-20 |
| medium |
CVE-2026-74992 — The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives u… |
vulnerability |
nvd |
CVE-2026-74992 |
rce |
2026-08-20 |
| medium |
CVE-2026-14949 — A low privileged remote attacker with a valid session can submit a request to the user creation func… |
vulnerability |
nvd |
CVE-2026-14949 |
|
2026-08-20 |
| medium |
CVE-2026-14953 — A low-privileged remote attacker can enumerate all configured users and identify which accounts hold… |
vulnerability |
nvd |
CVE-2026-14953 |
|
2026-08-20 |
| medium |
CVE-2026-77014 — A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator… |
vulnerability |
nvd |
CVE-2026-77014 |
|
2026-08-20 |
| medium |
CVE-2026-73196 — A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by su… |
vulnerability |
nvd |
CVE-2026-73196 |
|
2026-08-20 |
| medium |
CVE-2026-73199 — A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a n… |
vulnerability |
nvd |
CVE-2026-73199 |
|
2026-08-20 |
| medium |
CVE-2026-77066 — The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplie… |
vulnerability |
nvd |
CVE-2026-77066 |
|
2026-08-20 |
| medium |
CVE-2026-77067 — The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied ur… |
vulnerability |
nvd |
CVE-2026-77067 |
|
2026-08-20 |
| medium |
CVE-2025-53999 — Unauthenticated Broken Access Control in Altair <= 5.2.2 versions. |
vulnerability |
nvd |
CVE-2025-53999 |
|
2026-08-20 |
| medium |
CVE-2025-62307 — HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weak… |
vulnerability |
nvd |
CVE-2025-62307 |
|
2026-08-20 |
| medium |
CVE-2026-66586 — Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions. |
vulnerability |
nvd |
CVE-2026-66586 |
|
2026-08-20 |
| medium |
CVE-2026-66595 — Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions. |
vulnerability |
nvd |
CVE-2026-66595 |
|
2026-08-20 |
| medium |
CVE-2026-66601 — Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions. |
vulnerability |
nvd |
CVE-2026-66601 |
|
2026-08-20 |
| medium |
CVE-2026-66647 — Subscriber Broken Access Control in Homlisti <= 3.1.2 versions. |
vulnerability |
nvd |
CVE-2026-66647 |
|
2026-08-20 |
| medium |
CVE-2026-73402 — Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions. |
vulnerability |
nvd |
CVE-2026-73402 |
|
2026-08-20 |
| medium |
CVE-2025-62299 — HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow… |
vulnerability |
nvd |
CVE-2025-62299 |
|
2026-08-20 |
| medium |
CVE-2025-62300 — HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur w… |
vulnerability |
nvd |
CVE-2025-62300 |
|
2026-08-20 |
| medium |
CVE-2025-62306 — HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information b… |
vulnerability |
nvd |
CVE-2025-62306 |
|
2026-08-20 |
| medium |
CVE-2026-21784 — HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security heade… |
vulnerability |
nvd |
CVE-2026-21784 |
|
2026-08-20 |
| medium |
CVE-2026-28163 — Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configu… |
vulnerability |
nvd |
CVE-2026-28163 |
|
2026-08-20 |
| medium |
CVE-2026-76988 — A weakness has been identified in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This… |
vulnerability |
nvd |
CVE-2026-76988 |
|
2026-08-20 |
| medium |
CVE-2026-76989 — A security vulnerability has been detected in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13… |
vulnerability |
nvd |
CVE-2026-76989 |
|
2026-08-20 |
| medium |
CVE-2026-76634 — WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profil… |
vulnerability |
nvd |
CVE-2026-76634 |
|
2026-08-20 |
| medium |
CVE-2026-44725 — EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to vers… |
vulnerability |
nvd |
CVE-2026-44725 |
transport |
2026-08-20 |
| medium |
CVE-2026-55558 — aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_t… |
vulnerability |
nvd |
CVE-2026-55558 |
|
2026-08-20 |
| medium |
CVE-2026-76991 — A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown pa… |
vulnerability |
nvd |
CVE-2026-76991 |
|
2026-08-20 |
| medium |
CVE-2026-76993 — A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown… |
vulnerability |
nvd |
CVE-2026-76993 |
|
2026-08-20 |
| medium |
CVE-2026-76995 — A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue… |
vulnerability |
nvd |
CVE-2026-76995 |
|
2026-08-20 |
| medium |
CVE-2026-63015 — Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons c… |
vulnerability |
nvd |
CVE-2026-63015 |
|
2026-08-20 |
| medium |
CVE-2026-63016 — Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational con… |
vulnerability |
nvd |
CVE-2026-63016 |
|
2026-08-20 |
| medium |
CVE-2026-76997 — A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affecte… |
vulnerability |
nvd |
CVE-2026-76997 |
|
2026-08-20 |
| medium |
CVE-2026-76999 — A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analy… |
vulnerability |
nvd |
CVE-2026-76999 |
|
2026-08-20 |
| medium |
CVE-2026-54770 — WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_abs… |
vulnerability |
nvd |
CVE-2026-54770 |
phishing |
2026-08-20 |
| medium |
CVE-2026-55586 — SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, a crafted CHM file can supply… |
vulnerability |
nvd |
CVE-2026-55586 |
|
2026-08-20 |
| medium |
CVE-2026-61625 — VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.… |
vulnerability |
nvd |
CVE-2026-61625 |
|
2026-08-20 |
| medium |
CVE-2026-77025 — A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unkno… |
vulnerability |
nvd |
CVE-2026-77025 |
|
2026-08-20 |
| medium |
CVE-2026-54625 — django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the djan… |
vulnerability |
nvd |
CVE-2026-54625 |
|
2026-08-20 |
| medium |
CVE-2026-72844 — The Lean 4 kernel does not verify that the structure named in a projection expression matches the ty… |
vulnerability |
nvd |
CVE-2026-72844 |
|
2026-08-20 |
| medium |
CVE-2026-72847 — broot renders each file and directory name in its interactive tree view exactly as read from the fil… |
vulnerability |
nvd |
CVE-2026-72847 |
|
2026-08-20 |
| medium |
CVE-2026-73254 — Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a… |
vulnerability |
nvd |
CVE-2026-73254 |
|
2026-08-20 |
| medium |
CVE-2026-73255 — Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control a… |
vulnerability |
nvd |
CVE-2026-73255 |
|
2026-08-20 |
| medium |
CVE-2026-73258 — Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a… |
vulnerability |
nvd |
CVE-2026-73258 |
|
2026-08-20 |
| medium |
CVE-2026-73259 — Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a… |
vulnerability |
nvd |
CVE-2026-73259 |
|
2026-08-20 |
| medium |
CVE-2026-77036 — A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailCon… |
vulnerability |
nvd |
CVE-2026-77036 |
|
2026-08-20 |
| medium |
CVE-2026-43678 — An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingb… |
vulnerability |
nvd |
CVE-2026-43678 |
|
2026-08-20 |
| medium |
CVE-2026-64777 — A malicious builder peer may be able to request an in-context file by name from the host and receive… |
vulnerability |
nvd |
CVE-2026-64777 |
|
2026-08-20 |
| medium |
CVE-2026-72854 — msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_… |
vulnerability |
nvd |
CVE-2026-72854 |
|
2026-08-20 |
| medium |
CVE-2026-75514 — BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklis… |
vulnerability |
nvd |
CVE-2026-75514 |
|
2026-08-20 |
| medium |
CVE-2026-72861 — The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inv… |
vulnerability |
nvd |
CVE-2026-72861 |
|
2026-08-20 |
| medium |
CVE-2026-75910 — Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Fede… |
vulnerability |
nvd |
CVE-2026-75910 |
|
2026-08-20 |
| medium |
CVE-2026-67445 — Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP command… |
vulnerability |
nvd |
CVE-2026-67445 |
|
2026-08-20 |
| medium |
CVE-2026-67446 — Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-s… |
vulnerability |
nvd |
CVE-2026-67446 |
|
2026-08-20 |
| medium |
CVE-2026-68921 — DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpola… |
vulnerability |
nvd |
CVE-2026-68921 |
|
2026-08-20 |
| medium |
CVE-2026-76018 — Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker lev… |
vulnerability |
nvd |
CVE-2026-76018 |
phishing |
2026-08-20 |
| medium |
CVE-2026-76019 — Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacke… |
vulnerability |
nvd |
CVE-2026-76019 |
phishing |
2026-08-20 |
| medium |
CVE-2026-77506 — Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS. |
vulnerability |
nvd |
CVE-2026-77506 |
|
2026-08-20 |
| medium |
CVE-2026-77587 — Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object whe… |
vulnerability |
nvd |
CVE-2026-77587 |
|
2026-08-20 |
| medium |
CVE-2026-77639 — Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many g… |
vulnerability |
nvd |
CVE-2026-77639 |
|
2026-08-20 |
| medium |
CVE-2026-77641 — tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. Th… |
vulnerability |
nvd |
CVE-2026-77641 |
|
2026-08-20 |
| medium |
CVE-2026-16951 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute… |
vulnerability |
nvd |
CVE-2026-16951 |
|
2026-08-20 |
| medium |
CVE-2026-16964 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages an… |
vulnerability |
nvd |
CVE-2026-16964 |
|
2026-08-20 |
| medium |
CVE-2026-16973 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to disclose sensitive ker… |
vulnerability |
nvd |
CVE-2026-16973 |
|
2026-08-20 |
| medium |
CVE-2026-17424 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restr… |
vulnerability |
nvd |
CVE-2026-17424 |
|
2026-08-20 |
| medium |
CVE-2026-19448 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the… |
vulnerability |
nvd |
CVE-2026-19448 |
|
2026-08-20 |
| medium |
CVE-2026-19783 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory co… |
vulnerability |
nvd |
CVE-2026-19783 |
|
2026-08-20 |
| medium |
CVE-2026-49244 — SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public we… |
vulnerability |
nvd |
CVE-2026-49244 |
|
2026-08-20 |
| medium |
CVE-2026-54389 — Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser t… |
vulnerability |
nvd |
CVE-2026-54389 |
|
2026-08-20 |
| medium |
CVE-2026-54509 — TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link… |
vulnerability |
nvd |
CVE-2026-54509 |
|
2026-08-20 |
| medium |
CVE-2026-55015 — Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny servic… |
vulnerability |
nvd |
CVE-2026-55015 |
|
2026-08-20 |
| medium |
CVE-2026-55489 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could s… |
vulnerability |
nvd |
CVE-2026-55489 |
|
2026-08-20 |
| medium |
CVE-2026-55491 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape m… |
vulnerability |
nvd |
CVE-2026-55491 |
ransomware |
2026-08-20 |
| medium |
CVE-2026-62945 — TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions a… |
vulnerability |
nvd |
CVE-2026-62945 |
|
2026-08-20 |
| medium |
CVE-2026-67447 — Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's interna… |
vulnerability |
nvd |
CVE-2026-67447 |
|
2026-08-20 |
| medium |
CVE-2026-67448 — Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/… |
vulnerability |
nvd |
CVE-2026-67448 |
|
2026-08-20 |
| medium |
CVE-2026-70105 — Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose infor… |
vulnerability |
nvd |
CVE-2026-70105 |
|
2026-08-20 |
| medium |
CVE-2026-72846 — Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendW… |
vulnerability |
nvd |
CVE-2026-72846 |
|
2026-08-20 |
| medium |
CVE-2026-77643 — A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core… |
vulnerability |
nvd |
CVE-2026-77643 |
|
2026-08-20 |
| medium |
CVE-2026-77391 — A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS,… |
vulnerability |
nvd |
CVE-2026-77391 |
|
2026-08-21 |
| medium |
CVE-2026-77392 — A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and… |
vulnerability |
nvd |
CVE-2026-77392 |
|
2026-08-21 |
| medium |
payload: undefined |
threat-intel |
threatfox |
|
elf, IoT, ClearFake, ClickFix, etherhiding, majinahanashi, Ransomware, ErrTraffic, DPRK, kimsuky, MoonPeak, Stella, golang, zimbra, zimbra-exfil, ZMBX, ransomware, apt, botnet |
2026-08-20 |
| medium |
BRIDGEHEAD: An npm typosquatting campaign that crosses from WSL into Windows to plant a crypto-wallet stealer |
threat-intel |
otx |
6888d4c54ef2b5bf… |
rust, github-hosted-payload, browser-credentials, wsl, telegram, npm, cryptocurrency-stealer, typosquatting, in-memory-execution, supply-chain, botnet |
2026-08-20 |
| medium |
How Peer2Profit and Astroproxy Turn Your Bandwidth Into Someone Else's Product |
threat-intel |
otx |
c85c7436fdb71cf5… |
backconnect infrastructure, bandwidth-sharing, internal network exposure, privateloader, sdk analysis, proxy enumeration, peer2profit, residential proxies, astroproxy |
2026-08-20 |
| medium |
N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it |
threat-intel |
otx |
CVE-2023-48022, CVE-2026-26220, CVE-2026-27944, CVE-2026-33032, CVE-2026-39987 | e09ac5e8c23a768a…, b8e66803519f9376… |
n4d mesh controller, cve-2023-48022, cve-2026-26220, linux malware, go-titan, cve-2026-27944, ray dashboard, cve-2026-33032, n4d, cve-2026-39987, mcp exploitation, lateral movement, ai infrastructure targeting, cloudflare tunnels, credential theft, lightllm, botnet |
2026-08-20 |
| medium |
Blend between Banking Malware & Spyware |
threat-intel |
otx |
feea425cde1223fe…, 2b24e1e154eb93e5… |
wi-fi mesh relay, ukraine targeted, android, spyware, device takeover, manic, banking trojan, cryptocurrency theft, botnet, infostealer |
2026-08-20 |
| medium |
Back-to-School Cyber Risks Surge as Education Remains the World's Most Attacked Sector |
threat-intel |
otx |
6d0bd9615d730b0b… |
student targeting, education sector, phishing campaigns, back-to-school, credential theft, domain registration, apac attacks, phishing |
2026-08-20 |
| medium |
Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign |
threat-intel |
otx |
fad1e9d507c7021a…, f1aed8cf2adafa86… |
sandbox evasion, grandoreiro, mexico, dll sideloading, anti-analysis, delphi, banking trojan, latin america, botnet |
2026-08-19 |
| medium |
Backdoor delivered through software updates |
threat-intel |
otx |
cefd8928fd7411b4… |
download studio, cryptocurrency mining, software update abuse, xmrig, supply chain attack, backdoor, adblocker, torrent client, qt framework, fakembam, botnet, supply-chain |
2026-08-19 |
| medium |
Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware |
threat-intel |
otx |
e276bf8744f29c54…, f4769ba9e8065727… |
black hat, conference phishing, cryptocurrency theft, def con, atomic macos stealer, netsupport rat, clickfix, netsupport manager, google apps script, amos, phishing, infostealer |
2026-08-19 |
| medium |
Scammers are using fake crypto AML checkers to drain your wallet |
threat-intel |
otx |
|
fake aml checker, social engineering, crypto scam, wallet draining, fraudulent website, phishing, cryptocurrency, token theft, ghostdesk, ransomware |
2026-08-19 |
| medium |
77 Firefox Extensions Linked to Crypto Wallet and Credential Theft |
threat-intel |
otx |
77.91.100.175 | b65143df86edd606… |
browser extension campaign, credential stealing, supabase abuse, cloudflare workers, firefox extensions, phishing, web3 impersonation, cryptocurrency wallet theft, botnet, infostealer |
2026-08-20 |
| medium |
41 deceptive download sites show a real link, then send you somewhere else |
threat-intel |
otx |
9a3f6e69c12cb814…, c0ecbd201cc92afd… |
affiliate fraud, deceptive downloads, fake software sites, bait-and-switch, grand media, download studio, javascript redirection, fakembam, ransomware |
2026-08-20 |
| medium |
https://malbearlabs.com/shadow-hvnc-and-shadow-loader-the-kit-that-protects-its-license-better-than-its-customers-dd99520b6af3 |
threat-intel |
otx |
212.162.150.121 | f65bdff0bf9c807c…, 5ccd6c0dba9ad2ab… |
|
2026-08-19 |
| medium |
From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel |
threat-intel |
otx |
519d5f0350f78805… |
legionloader, modular architecture, maas, lummastealer, clickfix, rat, tor, cryptocurrency theft, nodejs, grpc, botnet, infostealer |
2026-08-19 |
| medium |
Beware of Phishing Emails Disguised as Quote Confirmation Requests (PhantomStealer) |
threat-intel |
otx |
05aa847cdfc69a78…, c155a21bec649260… |
clipper, uac bypass, cryptocurrency stealer, byovd, injector, phantomstealer, credential theft, process hollowing, phishing, infostealer |
2026-08-19 |
| medium |
Signed Overwolf Binary Sideloads ValleyRAT Malware in India |
threat-intel |
otx |
103.240.196.115 | 2d2a251a88632f01…, 315bda377beafb74… |
india taxation phishing, upx packing, valleyrat, astral-pe, overwolf abuse, reflective loading, process hollowing, dll sideloading, phishing, botnet |
2026-08-18 |
| medium |
Beware of Phishing Emails Disguised as Transaction Receipts |
threat-intel |
otx |
82a7410b7c56f538…, ab707764ad3fc261… |
pdf attachment, remote access, vbs script, transaction receipt lure, living-off-the-land, phishing campaign, screenconnect abuse, screenconnect, ransomware, phishing |
2026-08-18 |
| medium |
Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor |
threat-intel |
otx |
38.60.244.141 | daeac66441b88ba2…, b9622eb982f7c8b9… |
vhd file, quic protocol, cloudflare workers, china-nexus, quicagent, operation quicsilver, go backdoor, myanmar diplomats, botnet |
2026-08-17 |
| medium |
Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline |
threat-intel |
otx |
ba9d459169a30306… |
vishing, electron-malware, account-enumeration, jailbreak-prompt, telegram-exfiltration, phishing, cryptocurrency, wallet-theft, ai-assisted-development, seed-phrase-exfiltration |
2026-08-18 |
| medium |
New Mirai-Based Linux Botnet 'Evooo1Bot' Turns Victims Into Proxies |
threat-intel |
otx, general-news |
CVE-2016-6277, CVE-2007-3010, CVE-2018-14558, CVE-2019-14931, CVE-2020-10987, CVE-2021-46422, CVE-2022-37055, CVE-2024-29269, CVE-2025-10123, CVE-2025-55583 | 91.92.40.118 |
edge devices, cve-2007-3010, iot exploitation, cve-2022-37055, cve-2025-55583, cve-2020-10987, mirai variant, cve-2025-10123, cve-2021-46422, cve-2024-29269, cve-2018-14558, cve-2019-14931, ddos attacks, linux botnet, evooo1bot, cve-2016-6277, socks proxy, encrypted c2, mirai, botnet |
2026-08-14 |
| medium |
Hackers poison arrayref Rust crate to push infostealer malware |
news |
general-news |
|
infostealer |
2026-08-20 |
| medium |
How MSPs can catch phishing attacks email filters miss |
news |
general-news |
|
phishing |
2026-08-20 |
| medium |
Phishing 3.0: The Fight Moves to Agent Versus Agent |
news |
general-news |
|
phishing |
2026-08-19 |
| medium |
CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps |
news |
general-news |
|
phishing |
2026-08-14 |
| medium |
SilkParasite Threatens Central Asian Orgs With Flurry of RATs |
news |
general-news |
|
phishing |
2026-08-19 |
| medium |
Def Con Attendees Targeted by Persistent Phishing Campaign |
news |
general-news |
|
phishing |
2026-08-20 |
| medium |
Infostealers Harvest 1.7 Billion Credentials in Six Months |
news |
general-news |
|
infostealer |
2026-08-17 |
| medium |
Novel macOS Infostealer AmnesiaStealer Spread via ClickFix |
news |
general-news |
|
infostealer |
2026-08-14 |
| medium |
Fake Gemini installer delivers Vidar infostealer via Google Colab lure |
news |
general-news |
|
infostealer |
2026-08-20 |
| low |
CVE-2026-19763 — A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUt… |
vulnerability |
nvd |
CVE-2026-19763 |
|
2026-08-14 |
| low |
CVE-2026-19835 — A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an u… |
vulnerability |
nvd |
CVE-2026-19835 |
|
2026-08-14 |
| low |
CVE-2026-19837 — A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the fi… |
vulnerability |
nvd |
CVE-2026-19837 |
|
2026-08-14 |
| low |
CVE-2026-19841 — A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /e… |
vulnerability |
nvd |
CVE-2026-19841 |
|
2026-08-14 |
| low |
CVE-2026-73844 — CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect… |
vulnerability |
nvd |
CVE-2026-73844 |
|
2026-08-14 |
| low |
CVE-2026-19891 — A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02. This affects an unknown function of t… |
vulnerability |
nvd |
CVE-2026-19891 |
|
2026-08-15 |
| low |
CVE-2026-19893 — A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the f… |
vulnerability |
nvd |
CVE-2026-19893 |
|
2026-08-15 |
| low |
CVE-2026-19895 — A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects th… |
vulnerability |
nvd |
CVE-2026-19895 |
|
2026-08-15 |
| low |
CVE-2026-19896 — A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_… |
vulnerability |
nvd |
CVE-2026-19896 |
|
2026-08-15 |
| low |
CVE-2026-19897 — A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login… |
vulnerability |
nvd |
CVE-2026-19897 |
|
2026-08-15 |
| low |
CVE-2026-19898 — A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler… |
vulnerability |
nvd |
CVE-2026-19898 |
|
2026-08-15 |
| low |
CVE-2026-19904 — A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects… |
vulnerability |
nvd |
CVE-2026-19904 |
|
2026-08-15 |
| low |
CVE-2026-19906 — A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the func… |
vulnerability |
nvd |
CVE-2026-19906 |
|
2026-08-15 |
| low |
CVE-2026-19916 — A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is… |
vulnerability |
nvd |
CVE-2026-19916 |
|
2026-08-15 |
| low |
CVE-2026-19922 — A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this is… |
vulnerability |
nvd |
CVE-2026-19922 |
|
2026-08-16 |
| low |
CVE-2026-74797 — OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command w… |
vulnerability |
nvd |
CVE-2026-74797 |
|
2026-08-16 |
| low |
CVE-2026-19955 — A vulnerability was detected in TrailDB 0.6. Impacted is the function tdb_open of the file /src/tdb.… |
vulnerability |
nvd |
CVE-2026-19955 |
|
2026-08-16 |
| low |
CVE-2026-19965 — A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the functi… |
vulnerability |
nvd |
CVE-2026-19965 |
|
2026-08-17 |
| low |
CVE-2026-19975 — A weakness has been identified in Azuriom CMS up to 1.2.12. This issue affects the function transfer… |
vulnerability |
nvd |
CVE-2026-19975 |
|
2026-08-17 |
| low |
CVE-2026-19992 — A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up… |
vulnerability |
nvd |
CVE-2026-19992 |
|
2026-08-17 |
| low |
CVE-2026-19995 — A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the fi… |
vulnerability |
nvd |
CVE-2026-19995 |
|
2026-08-17 |
| low |
CVE-2026-49306 — UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerab… |
vulnerability |
nvd |
CVE-2026-49306 |
|
2026-08-17 |
| low |
CVE-2026-74870 — openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm… |
vulnerability |
nvd |
CVE-2026-74870 |
|
2026-08-17 |
| low |
CVE-2026-74885 — openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs mo… |
vulnerability |
nvd |
CVE-2026-74885 |
|
2026-08-17 |
| low |
CVE-2026-74887 — openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PR… |
vulnerability |
nvd |
CVE-2026-74887 |
|
2026-08-17 |
| low |
CVE-2026-70412 — Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a… |
vulnerability |
nvd |
CVE-2026-70412 |
|
2026-08-17 |
| low |
CVE-2026-75052 — In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content wa… |
vulnerability |
nvd |
CVE-2026-75052 |
|
2026-08-17 |
| low |
CVE-2026-75483 — powerlevel10k fails to neutralize control characters in the package.json version field when renderin… |
vulnerability |
nvd |
CVE-2026-75483 |
|
2026-08-17 |
| low |
CVE-2026-64779 — A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari… |
vulnerability |
nvd |
CVE-2026-64779, CVE-2026-64782 |
|
2026-08-17 |
| low |
CVE-2026-75587 — Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a d… |
vulnerability |
nvd |
CVE-2026-75587 |
|
2026-08-17 |
| low |
CVE-2026-9693 — Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membersh… |
vulnerability |
nvd |
CVE-2026-9693 |
|
2026-08-17 |
| low |
CVE-2026-75773 — A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the functio… |
vulnerability |
nvd |
CVE-2026-75773 |
|
2026-08-18 |
| low |
CVE-2026-75774 — A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unk… |
vulnerability |
nvd |
CVE-2026-75774 |
|
2026-08-18 |
| low |
CVE-2026-63632 — Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From… |
vulnerability |
nvd |
CVE-2026-63632 |
|
2026-08-18 |
| low |
CVE-2026-45126 — MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Security Questions module… |
vulnerability |
nvd |
CVE-2026-45126 |
|
2026-08-18 |
| low |
CVE-2026-45127 — MyBB is free and open source forum software. Prior to 1.8.40, the ACP Mass Mail module does not vali… |
vulnerability |
nvd |
CVE-2026-45127 |
|
2026-08-18 |
| low |
CVE-2026-45128 — MyBB is free and open source forum software. Prior to 1.8.40, the ACP Users View Manager module does… |
vulnerability |
nvd |
CVE-2026-45128 |
|
2026-08-18 |
| low |
CVE-2026-62684 — File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing… |
vulnerability |
nvd |
CVE-2026-62684 |
|
2026-08-18 |
| low |
CVE-2026-75904 — libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The… |
vulnerability |
nvd |
CVE-2026-75904 |
ransomware |
2026-08-18 |
| low |
CVE-2026-68927 — MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities i… |
vulnerability |
nvd |
CVE-2026-68927 |
|
2026-08-18 |
| low |
CVE-2026-67442 — FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /ap… |
vulnerability |
nvd |
CVE-2026-67442 |
ics |
2026-08-18 |
| low |
CVE-2026-76042 — Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attac… |
vulnerability |
nvd |
CVE-2026-76042 |
|
2026-08-18 |
| low |
CVE-2026-76014 — A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of t… |
vulnerability |
nvd |
CVE-2026-76014 |
|
2026-08-19 |
| low |
CVE-2026-13173 — The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit oth… |
vulnerability |
nvd |
CVE-2026-13173 |
|
2026-08-19 |
| low |
CVE-2026-14825 — The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object owners… |
vulnerability |
nvd |
CVE-2026-14825, CVE-2026-14826 |
|
2026-08-19 |
| low |
CVE-2026-19406 — The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing… |
vulnerability |
nvd |
CVE-2026-19406 |
|
2026-08-19 |
| low |
CVE-2026-75583 — keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) g… |
vulnerability |
nvd |
CVE-2026-75583 |
|
2026-08-19 |
| low |
CVE-2026-11617 — Tanium addressed a compression bomb vulnerability in Findings. |
vulnerability |
nvd |
CVE-2026-11617 |
|
2026-08-19 |
| low |
CVE-2026-18102 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memor… |
vulnerability |
nvd |
CVE-2026-18102 |
|
2026-08-19 |
| low |
CVE-2026-75476 — Tanium addressed a compression bomb vulnerability in Threat Response. |
vulnerability |
nvd |
CVE-2026-75476 |
|
2026-08-19 |
| low |
CVE-2026-76348 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk ro… |
vulnerability |
nvd |
CVE-2026-76348 |
|
2026-08-19 |
| low |
CVE-2026-76361 — In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/suppor… |
vulnerability |
nvd |
CVE-2026-76361 |
|
2026-08-19 |
| low |
CVE-2026-76368 — In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permis… |
vulnerability |
nvd |
CVE-2026-76368 |
ransomware |
2026-08-19 |
| low |
CVE-2026-76369 — In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outsi… |
vulnerability |
nvd |
CVE-2026-76369 |
|
2026-08-19 |
| low |
CVE-2026-76371 — In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in… |
vulnerability |
nvd |
CVE-2026-76371 |
ransomware |
2026-08-19 |
| low |
CVE-2026-76884 — ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76884 |
|
2026-08-19 |
| low |
CVE-2026-76885 — Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76885 |
|
2026-08-19 |
| low |
CVE-2026-76887 — Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of serv… |
vulnerability |
nvd |
CVE-2026-76887 |
|
2026-08-19 |
| low |
CVE-2026-76888 — RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76888 |
|
2026-08-19 |
| low |
CVE-2026-76890 — Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76890, CVE-2026-76891 |
|
2026-08-19 |
| low |
CVE-2026-76926 — BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76926 |
|
2026-08-19 |
| low |
CVE-2026-19699 — The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of it… |
vulnerability |
nvd |
CVE-2026-19699 |
|
2026-08-20 |
| low |
CVE-2026-73542 — Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle at… |
vulnerability |
nvd |
CVE-2026-73542 |
|
2026-08-20 |
| low |
CVE-2026-64846 — Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation e… |
vulnerability |
nvd |
CVE-2026-64846 |
|
2026-08-20 |
| low |
CVE-2026-49996 — SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle s… |
vulnerability |
nvd |
CVE-2026-49996 |
|
2026-08-20 |
| low |
CVE-2026-77151 — A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the func… |
vulnerability |
nvd |
CVE-2026-77151 |
|
2026-08-20 |
| low |
CVE-2026-77640 — tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream wit… |
vulnerability |
nvd |
CVE-2026-77640 |
|
2026-08-20 |
| low |
CVE-2026-49245 — SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline qu… |
vulnerability |
nvd |
CVE-2026-49245 |
phishing |
2026-08-20 |
| low |
CVE-2026-77648 — In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_f… |
vulnerability |
nvd |
CVE-2026-77648 |
|
2026-08-20 |
| unknown |
CISA Adds Two Known Exploited Vulnerabilities to Catalog |
advisory |
cisa-advisories |
|
|
2026-08-20 |
| unknown |
CISA Adds One Known Exploited Vulnerability to Catalog |
advisory |
cisa-advisories |
|
|
2026-08-19 |
| unknown |
CISA Adds Four Known Exploited Vulnerabilities to Catalog |
advisory |
cisa-advisories |
|
|
2026-08-18 |
| unknown |
CVE-2026-72813 — actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range hea… |
vulnerability |
nvd |
CVE-2026-72813 |
|
2026-08-14 |
| unknown |
CVE-2026-72814 — The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerabi… |
vulnerability |
nvd |
CVE-2026-72814 |
|
2026-08-14 |
| unknown |
CVE-2026-72815 — go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP mid… |
vulnerability |
nvd |
CVE-2026-72815 |
|
2026-08-14 |
| unknown |
CVE-2026-73051 — actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 pa… |
vulnerability |
nvd |
CVE-2026-73051 |
|
2026-08-14 |
| unknown |
CVE-2026-19870 — Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM b… |
vulnerability |
nvd |
CVE-2026-19870 |
|
2026-08-14 |
| unknown |
CVE-2026-19871 — Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.… |
vulnerability |
nvd |
CVE-2026-19871 |
|
2026-08-14 |
| unknown |
CVE-2026-19880 — Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows… |
vulnerability |
nvd |
CVE-2026-19880 |
|
2026-08-14 |
| unknown |
CVE-2026-13196 — Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image ma… |
vulnerability |
nvd |
CVE-2026-13196 |
|
2026-08-14 |
| unknown |
CVE-2026-13197 — Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper… |
vulnerability |
nvd |
CVE-2026-13197, CVE-2026-13198 |
|
2026-08-14 |
| unknown |
CVE-2026-19884 — In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integra… |
vulnerability |
nvd |
CVE-2026-19884 |
|
2026-08-14 |
| unknown |
CVE-2026-57469 — Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the we… |
vulnerability |
nvd |
CVE-2026-57469 |
|
2026-08-14 |
| unknown |
CVE-2026-57471 — Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Director… |
vulnerability |
nvd |
CVE-2026-57471, CVE-2026-57472 |
|
2026-08-14 |
| unknown |
CVE-2026-47191 — kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git c… |
vulnerability |
nvd |
CVE-2026-47191 |
|
2026-08-14 |
| unknown |
CVE-2026-47192 — kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, ka… |
vulnerability |
nvd |
CVE-2026-47192 |
|
2026-08-14 |
| unknown |
CVE-2026-49986 — The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to vers… |
vulnerability |
nvd |
CVE-2026-49986 |
|
2026-08-14 |
| unknown |
CVE-2026-49989 — CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can… |
vulnerability |
nvd |
CVE-2026-49989 |
|
2026-08-14 |
| unknown |
CVE-2026-73107 — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
vulnerability |
nvd |
CVE-2026-73107, CVE-2026-39925, CVE-2026-18932, CVE-2026-72044, CVE-2026-72246, CVE-2026-74511, CVE-2026-60106, CVE-2026-60107, CVE-2026-54385, CVE-2026-73692, CVE-2026-73103, CVE-2026-73104, CVE-2026-73105, CVE-2026-73106, CVE-2026-73111, CVE-2026-73112, CVE-2026-74226, CVE-2026-74227, CVE-2026-74228, CVE-2026-18502, CVE-2026-18862, CVE-2026-19561, CVE-2026-19562, CVE-2026-19563, CVE-2026-76632, CVE-2026-72845, CVE-2026-46533, CVE-2026-46534, CVE-2026-46535, CVE-2026-46536, CVE-2026-46537, CVE-2026-53993, CVE-2026-6260, CVE-2026-6822, CVE-2026-8717, CVE-2026-63723, CVE-2026-72858 |
|
2026-08-14 |
| unknown |
CVE-2026-49263 — Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend a… |
vulnerability |
nvd |
CVE-2026-49263 |
|
2026-08-14 |
| unknown |
CVE-2026-63361 — LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerab… |
vulnerability |
nvd |
CVE-2026-63361 |
|
2026-08-14 |
| unknown |
CVE-2026-73850 — Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vul… |
vulnerability |
nvd |
CVE-2026-73850 |
|
2026-08-14 |
| unknown |
CVE-2026-18403 — LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Cent… |
vulnerability |
nvd |
CVE-2026-18403 |
|
2026-08-14 |
| unknown |
CVE-2026-19908 — PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows networ… |
vulnerability |
nvd |
CVE-2026-19908 |
|
2026-08-14 |
| unknown |
CVE-2026-27871 — Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 all… |
vulnerability |
nvd |
CVE-2026-27871 |
|
2026-08-14 |
| unknown |
CVE-2026-34492 — External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipu… |
vulnerability |
nvd |
CVE-2026-34492 |
|
2026-08-14 |
| unknown |
CVE-2026-64887 — Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic… |
vulnerability |
nvd |
CVE-2026-64887 |
|
2026-08-14 |
| unknown |
CVE-2026-67365 — Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthe… |
vulnerability |
nvd |
CVE-2026-67365 |
|
2026-08-14 |
| unknown |
CVE-2026-71571 — Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagen… |
vulnerability |
nvd |
CVE-2026-71571 |
|
2026-08-14 |
| unknown |
CVE-2026-67366 — Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 -… |
vulnerability |
nvd |
CVE-2026-67366 |
|
2026-08-14 |
| unknown |
CVE-2026-71570 — Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A… |
vulnerability |
nvd |
CVE-2026-71570 |
|
2026-08-14 |
| unknown |
CVE-2026-73682 — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. CVE-2026… |
vulnerability |
nvd |
CVE-2026-73682 |
|
2026-08-14 |
| unknown |
CVE-2026-63649 — The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows… |
vulnerability |
nvd |
CVE-2026-63649 |
|
2026-08-14 |
| unknown |
CVE-2026-63650 — OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified… |
vulnerability |
nvd |
CVE-2026-63650 |
|
2026-08-14 |
| unknown |
CVE-2026-16007 — AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with… |
vulnerability |
nvd |
CVE-2026-16007 |
|
2026-08-15 |
| unknown |
CVE-2026-68455 — In the Linux kernel, the following vulnerability has been resolved: liveupdate: validate session typ… |
vulnerability |
nvd |
CVE-2026-68455 |
|
2026-08-15 |
| unknown |
CVE-2026-68456 — In the Linux kernel, the following vulnerability has been resolved: usb: atm: ueagle-atm: wait for p… |
vulnerability |
nvd |
CVE-2026-68456 |
|
2026-08-15 |
| unknown |
CVE-2026-68459 — In the Linux kernel, the following vulnerability has been resolved: f2fs: fix potential deadlock in… |
vulnerability |
nvd |
CVE-2026-68459, CVE-2026-68460 |
|
2026-08-15 |
| unknown |
CVE-2026-68463 — In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-esdhc-imx: use pm_run… |
vulnerability |
nvd |
CVE-2026-68463 |
|
2026-08-15 |
| unknown |
CVE-2026-68464 — In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-esdhc-imx: disable ir… |
vulnerability |
nvd |
CVE-2026-68464 |
|
2026-08-15 |
| unknown |
CVE-2026-68465 — In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-esdhc-imx: fix esdhc_… |
vulnerability |
nvd |
CVE-2026-68465 |
|
2026-08-15 |
| unknown |
CVE-2026-68468 — In the Linux kernel, the following vulnerability has been resolved: mtd: virt-concat: free duplicate… |
vulnerability |
nvd |
CVE-2026-68468 |
|
2026-08-15 |
| unknown |
CVE-2026-68469 — In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: fix permanently b… |
vulnerability |
nvd |
CVE-2026-68469 |
|
2026-08-15 |
| unknown |
CVE-2026-68475 — In the Linux kernel, the following vulnerability has been resolved: reset: sunxi: fix memory region… |
vulnerability |
nvd |
CVE-2026-68475 |
|
2026-08-15 |
| unknown |
CVE-2026-68478 — In the Linux kernel, the following vulnerability has been resolved: memstick: ms_block: reject a car… |
vulnerability |
nvd |
CVE-2026-68478 |
|
2026-08-15 |
| unknown |
CVE-2026-72004 — In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix memory leak… |
vulnerability |
nvd |
CVE-2026-72004 |
|
2026-08-15 |
| unknown |
CVE-2026-72006 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5: free mlx5_st_idx_data… |
vulnerability |
nvd |
CVE-2026-72006 |
|
2026-08-15 |
| unknown |
CVE-2026-72007 — In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx: Fix i.MX8MP VC800… |
vulnerability |
nvd |
CVE-2026-72007 |
|
2026-08-15 |
| unknown |
CVE-2026-72008 — In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: Fix possible… |
vulnerability |
nvd |
CVE-2026-72008 |
|
2026-08-15 |
| unknown |
CVE-2026-72010 — In the Linux kernel, the following vulnerability has been resolved: cgroup/cpuset: rebind mm mempoli… |
vulnerability |
nvd |
CVE-2026-72010 |
|
2026-08-15 |
| unknown |
CVE-2026-72011 — In the Linux kernel, the following vulnerability has been resolved: s390/diag: Add missing array_ind… |
vulnerability |
nvd |
CVE-2026-72011 |
|
2026-08-15 |
| unknown |
CVE-2026-72013 — In the Linux kernel, the following vulnerability has been resolved: riscv: Prevent NULL pointer dere… |
vulnerability |
nvd |
CVE-2026-72013 |
|
2026-08-15 |
| unknown |
CVE-2026-72015 — In the Linux kernel, the following vulnerability has been resolved: fs/resctrl: Fix double-add of ps… |
vulnerability |
nvd |
CVE-2026-72015 |
|
2026-08-15 |
| unknown |
CVE-2026-72016 — In the Linux kernel, the following vulnerability has been resolved: cpu/hotplug: Fix NULL kobject wa… |
vulnerability |
nvd |
CVE-2026-72016 |
|
2026-08-15 |
| unknown |
CVE-2026-72017 — In the Linux kernel, the following vulnerability has been resolved: net: macb: drop in-flight Tx SKB… |
vulnerability |
nvd |
CVE-2026-72017 |
|
2026-08-15 |
| unknown |
CVE-2026-72022 — In the Linux kernel, the following vulnerability has been resolved: llc: fix SAP refcount leak in ll… |
vulnerability |
nvd |
CVE-2026-72022 |
|
2026-08-15 |
| unknown |
CVE-2026-72023 — In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix SQB pointer le… |
vulnerability |
nvd |
CVE-2026-72023 |
|
2026-08-15 |
| unknown |
CVE-2026-72025 — In the Linux kernel, the following vulnerability has been resolved: s390/monwriter: Reject buffer re… |
vulnerability |
nvd |
CVE-2026-72025 |
|
2026-08-15 |
| unknown |
CVE-2026-72026 — In the Linux kernel, the following vulnerability has been resolved: irqchip/irq-riscv-imsic-early: F… |
vulnerability |
nvd |
CVE-2026-72026 |
|
2026-08-15 |
| unknown |
CVE-2026-72028 — In the Linux kernel, the following vulnerability has been resolved: riscv: probes: save original sp… |
vulnerability |
nvd |
CVE-2026-72028 |
|
2026-08-15 |
| unknown |
CVE-2026-72030 — In the Linux kernel, the following vulnerability has been resolved: ata: libata-core: Reject an inva… |
vulnerability |
nvd |
CVE-2026-72030 |
|
2026-08-15 |
| unknown |
CVE-2026-72031 — In the Linux kernel, the following vulnerability has been resolved: ata: libata-core: Add NOLPM quir… |
vulnerability |
nvd |
CVE-2026-72031 |
|
2026-08-15 |
| unknown |
CVE-2026-72032 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, fix matcher leak… |
vulnerability |
nvd |
CVE-2026-72032 |
|
2026-08-15 |
| unknown |
CVE-2026-72037 — In the Linux kernel, the following vulnerability has been resolved: net: lan743x: Initialize eth_sys… |
vulnerability |
nvd |
CVE-2026-72037 |
|
2026-08-15 |
| unknown |
CVE-2026-72038 — In the Linux kernel, the following vulnerability has been resolved: net: liquidio: fix BAR resource… |
vulnerability |
nvd |
CVE-2026-72038 |
|
2026-08-15 |
| unknown |
CVE-2026-72039 — In the Linux kernel, the following vulnerability has been resolved: bnx2x: fix potential memory leak… |
vulnerability |
nvd |
CVE-2026-72039 |
|
2026-08-15 |
| unknown |
CVE-2026-72040 — In the Linux kernel, the following vulnerability has been resolved: ipmi: fix refcount leak in i_ipm… |
vulnerability |
nvd |
CVE-2026-72040 |
|
2026-08-15 |
| unknown |
CVE-2026-72047 — In the Linux kernel, the following vulnerability has been resolved: ieee802154: ca8210: fix pointer… |
vulnerability |
nvd |
CVE-2026-72047 |
|
2026-08-15 |
| unknown |
CVE-2026-72048 — In the Linux kernel, the following vulnerability has been resolved: ieee802154: ca8210: fix cas_ctl… |
vulnerability |
nvd |
CVE-2026-72048 |
|
2026-08-15 |
| unknown |
CVE-2026-72050 — In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Free BPID bitmap o… |
vulnerability |
nvd |
CVE-2026-72050 |
|
2026-08-15 |
| unknown |
CVE-2026-72056 — In the Linux kernel, the following vulnerability has been resolved: net: ena: clean up XDP TX queues… |
vulnerability |
nvd |
CVE-2026-72056 |
|
2026-08-15 |
| unknown |
CVE-2026-72058 — In the Linux kernel, the following vulnerability has been resolved: net: ixp4xx_hss: fix duplicate H… |
vulnerability |
nvd |
CVE-2026-72058 |
|
2026-08-15 |
| unknown |
CVE-2026-72059 — In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: destroy DMA poo… |
vulnerability |
nvd |
CVE-2026-72059 |
|
2026-08-15 |
| unknown |
CVE-2026-72060 — In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: icssg: guard… |
vulnerability |
nvd |
CVE-2026-72060 |
|
2026-08-15 |
| unknown |
CVE-2026-72062 — In the Linux kernel, the following vulnerability has been resolved: gpio: mt7621: avoid corruption o… |
vulnerability |
nvd |
CVE-2026-72062 |
|
2026-08-15 |
| unknown |
CVE-2026-72063 — In the Linux kernel, the following vulnerability has been resolved: gpio: tegra: do not call pinctrl… |
vulnerability |
nvd |
CVE-2026-72063 |
|
2026-08-15 |
| unknown |
CVE-2026-72068 — In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Use u64 multip… |
vulnerability |
nvd |
CVE-2026-72068 |
|
2026-08-15 |
| unknown |
CVE-2026-72070 — In the Linux kernel, the following vulnerability has been resolved: wifi: libertas_tf: fix use-after… |
vulnerability |
nvd |
CVE-2026-72070 |
|
2026-08-15 |
| unknown |
CVE-2026-72073 — In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: fix use-after-free… |
vulnerability |
nvd |
CVE-2026-72073 |
|
2026-08-15 |
| unknown |
CVE-2026-72074 — In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix type confus… |
vulnerability |
nvd |
CVE-2026-72074 |
|
2026-08-15 |
| unknown |
CVE-2026-72075 — In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix race condit… |
vulnerability |
nvd |
CVE-2026-72075 |
|
2026-08-15 |
| unknown |
CVE-2026-72076 — In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix out-of-boun… |
vulnerability |
nvd |
CVE-2026-72076 |
|
2026-08-15 |
| unknown |
CVE-2026-72077 — In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix firmware le… |
vulnerability |
nvd |
CVE-2026-72077 |
|
2026-08-15 |
| unknown |
CVE-2026-72078 — In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - validate contro… |
vulnerability |
nvd |
CVE-2026-72078 |
|
2026-08-15 |
| unknown |
CVE-2026-72079 — In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix use-after-f… |
vulnerability |
nvd |
CVE-2026-72079 |
|
2026-08-15 |
| unknown |
CVE-2026-72081 — In the Linux kernel, the following vulnerability has been resolved: scsi: elx: efct: Fix I/O leak on… |
vulnerability |
nvd |
CVE-2026-72081 |
|
2026-08-15 |
| unknown |
CVE-2026-72082 — In the Linux kernel, the following vulnerability has been resolved: scsi: elx: efct: Fix refcount le… |
vulnerability |
nvd |
CVE-2026-72082 |
|
2026-08-15 |
| unknown |
CVE-2026-72086 — In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Free the co… |
vulnerability |
nvd |
CVE-2026-72086 |
|
2026-08-15 |
| unknown |
CVE-2026-72087 — In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix memory leak in l… |
vulnerability |
nvd |
CVE-2026-72087 |
|
2026-08-15 |
| unknown |
CVE-2026-72088 — In the Linux kernel, the following vulnerability has been resolved: scsi: hpsa: Fix DMA mapping leak… |
vulnerability |
nvd |
CVE-2026-72088 |
|
2026-08-15 |
| unknown |
CVE-2026-72091 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: reject user comma… |
vulnerability |
nvd |
CVE-2026-72091 |
|
2026-08-15 |
| unknown |
CVE-2026-72092 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: reject command su… |
vulnerability |
nvd |
CVE-2026-72092 |
|
2026-08-15 |
| unknown |
CVE-2026-72094 — In the Linux kernel, the following vulnerability has been resolved: dma-buf: dma-fence: Fix potentia… |
vulnerability |
nvd |
CVE-2026-72094 |
|
2026-08-15 |
| unknown |
CVE-2026-72096 — In the Linux kernel, the following vulnerability has been resolved: dm-verity: make error counter at… |
vulnerability |
nvd |
CVE-2026-72096 |
|
2026-08-15 |
| unknown |
CVE-2026-72097 — In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix a possible NULL p… |
vulnerability |
nvd |
CVE-2026-72097 |
|
2026-08-15 |
| unknown |
CVE-2026-72101 — In the Linux kernel, the following vulnerability has been resolved: dm-integrity: fix leaking uninit… |
vulnerability |
nvd |
CVE-2026-72101 |
|
2026-08-15 |
| unknown |
CVE-2026-72104 — In the Linux kernel, the following vulnerability has been resolved: dm-pcache: reject option groups… |
vulnerability |
nvd |
CVE-2026-72104 |
|
2026-08-15 |
| unknown |
CVE-2026-72106 — In the Linux kernel, the following vulnerability has been resolved: dm-ioctl: fix a possible overflo… |
vulnerability |
nvd |
CVE-2026-72106 |
|
2026-08-15 |
| unknown |
CVE-2026-72117 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix data race on rx_st… |
vulnerability |
nvd |
CVE-2026-72117 |
|
2026-08-15 |
| unknown |
CVE-2026-72118 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix CAN frame rx/tx st… |
vulnerability |
nvd |
CVE-2026-72118 |
|
2026-08-15 |
| unknown |
CVE-2026-72128 — In the Linux kernel, the following vulnerability has been resolved: nvmet: fix refcount leak in nvme… |
vulnerability |
nvd |
CVE-2026-72128 |
|
2026-08-15 |
| unknown |
CVE-2026-72131 — In the Linux kernel, the following vulnerability has been resolved: nvme-apple: Prevent shared tags… |
vulnerability |
nvd |
CVE-2026-72131 |
|
2026-08-15 |
| unknown |
CVE-2026-72132 — In the Linux kernel, the following vulnerability has been resolved: NFS: Charge unstable writes by r… |
vulnerability |
nvd |
CVE-2026-72132 |
|
2026-08-15 |
| unknown |
CVE-2026-72138 — In the Linux kernel, the following vulnerability has been resolved: xen/gntdev: fix error handling i… |
vulnerability |
nvd |
CVE-2026-72138 |
|
2026-08-15 |
| unknown |
CVE-2026-72140 — In the Linux kernel, the following vulnerability has been resolved: i2c: mlxbf: Fix use-after-free i… |
vulnerability |
nvd |
CVE-2026-72140 |
|
2026-08-15 |
| unknown |
CVE-2026-72145 — In the Linux kernel, the following vulnerability has been resolved: platform/x86/intel/tpmi: use cle… |
vulnerability |
nvd |
CVE-2026-72145 |
|
2026-08-15 |
| unknown |
CVE-2026-72147 — In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma-pcie: Reject… |
vulnerability |
nvd |
CVE-2026-72147 |
|
2026-08-15 |
| unknown |
CVE-2026-72150 — In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix uninitialized xprt_c… |
vulnerability |
nvd |
CVE-2026-72150 |
|
2026-08-15 |
| unknown |
CVE-2026-72152 — In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_tis_spi: Use wait_woken… |
vulnerability |
nvd |
CVE-2026-72152 |
|
2026-08-15 |
| unknown |
CVE-2026-72153 — In the Linux kernel, the following vulnerability has been resolved: irqchip/crossbar: Use correct in… |
vulnerability |
nvd |
CVE-2026-72153 |
|
2026-08-15 |
| unknown |
CVE-2026-72155 — In the Linux kernel, the following vulnerability has been resolved: mtd: spi-nor: swp: Improve locki… |
vulnerability |
nvd |
CVE-2026-72155 |
|
2026-08-15 |
| unknown |
CVE-2026-72156 — In the Linux kernel, the following vulnerability has been resolved: fpga: microchip-spi: fix zero he… |
vulnerability |
nvd |
CVE-2026-72156 |
|
2026-08-15 |
| unknown |
CVE-2026-72158 — In the Linux kernel, the following vulnerability has been resolved: fpga: dfl: add bounds check in d… |
vulnerability |
nvd |
CVE-2026-72158 |
|
2026-08-15 |
| unknown |
CVE-2026-72159 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject non-inline dinodes… |
vulnerability |
nvd |
CVE-2026-72159 |
|
2026-08-15 |
| unknown |
CVE-2026-72161 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: add journal NULL check in… |
vulnerability |
nvd |
CVE-2026-72161 |
|
2026-08-15 |
| unknown |
CVE-2026-72163 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix NULL h_transaction de… |
vulnerability |
nvd |
CVE-2026-72163 |
|
2026-08-15 |
| unknown |
CVE-2026-72166 — In the Linux kernel, the following vulnerability has been resolved: net/9p: fix infinite loop in p9_… |
vulnerability |
nvd |
CVE-2026-72166 |
|
2026-08-15 |
| unknown |
CVE-2026-72167 — In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: pl353: fix probe r… |
vulnerability |
nvd |
CVE-2026-72167 |
|
2026-08-15 |
| unknown |
CVE-2026-72168 — In the Linux kernel, the following vulnerability has been resolved: mtd: maps: vmu-flash: fix fault… |
vulnerability |
nvd |
CVE-2026-72168 |
|
2026-08-15 |
| unknown |
CVE-2026-72169 — In the Linux kernel, the following vulnerability has been resolved: kho: make sure scratch size is a… |
vulnerability |
nvd |
CVE-2026-72169 |
|
2026-08-15 |
| unknown |
CVE-2026-72173 — In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: do not warn on… |
vulnerability |
nvd |
CVE-2026-72173 |
|
2026-08-15 |
| unknown |
CVE-2026-72174 — In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: fix hugetlb se… |
vulnerability |
nvd |
CVE-2026-72174 |
|
2026-08-15 |
| unknown |
CVE-2026-72176 — In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: put stat… |
vulnerability |
nvd |
CVE-2026-72176 |
|
2026-08-15 |
| unknown |
CVE-2026-72177 — In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: fix dir… |
vulnerability |
nvd |
CVE-2026-72177 |
|
2026-08-15 |
| unknown |
CVE-2026-72178 — In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: always put unsucc… |
vulnerability |
nvd |
CVE-2026-72178 |
|
2026-08-15 |
| unknown |
CVE-2026-72179 — In the Linux kernel, the following vulnerability has been resolved: riscv: cacheinfo: Fix node refer… |
vulnerability |
nvd |
CVE-2026-72179 |
|
2026-08-15 |
| unknown |
CVE-2026-72180 — In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: preserve pmd_swp… |
vulnerability |
nvd |
CVE-2026-72180 |
|
2026-08-15 |
| unknown |
CVE-2026-72182 — In the Linux kernel, the following vulnerability has been resolved: power: supply: charger-manager:… |
vulnerability |
nvd |
CVE-2026-72182 |
|
2026-08-15 |
| unknown |
CVE-2026-72184 — In the Linux kernel, the following vulnerability has been resolved: ntfs: fix hole runlist memory le… |
vulnerability |
nvd |
CVE-2026-72184 |
|
2026-08-15 |
| unknown |
CVE-2026-72187 — In the Linux kernel, the following vulnerability has been resolved: ntfs: avoid self-deadlock during… |
vulnerability |
nvd |
CVE-2026-72187 |
|
2026-08-15 |
| unknown |
CVE-2026-72189 — In the Linux kernel, the following vulnerability has been resolved: ntfs: fail attrlist updates when… |
vulnerability |
nvd |
CVE-2026-72189 |
|
2026-08-15 |
| unknown |
CVE-2026-72190 — In the Linux kernel, the following vulnerability has been resolved: ntfs: fix mrec_lock ABBA deadloc… |
vulnerability |
nvd |
CVE-2026-72190 |
|
2026-08-15 |
| unknown |
CVE-2026-72205 — In the Linux kernel, the following vulnerability has been resolved: ntfs: free volume-wide resources… |
vulnerability |
nvd |
CVE-2026-72205 |
|
2026-08-15 |
| unknown |
CVE-2026-72212 — In the Linux kernel, the following vulnerability has been resolved: mm/memory_hotplug: fix incorrect… |
vulnerability |
nvd |
CVE-2026-72212 |
|
2026-08-15 |
| unknown |
CVE-2026-72214 — In the Linux kernel, the following vulnerability has been resolved: power: supply: cpcap-battery: Fi… |
vulnerability |
nvd |
CVE-2026-72214 |
|
2026-08-15 |
| unknown |
CVE-2026-72215 — In the Linux kernel, the following vulnerability has been resolved: MIPS: DEC: Ensure 32-bit stack l… |
vulnerability |
nvd |
CVE-2026-72215 |
|
2026-08-15 |
| unknown |
CVE-2026-72216 — In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom: Fix leak when… |
vulnerability |
nvd |
CVE-2026-72216 |
|
2026-08-15 |
| unknown |
CVE-2026-72218 — In the Linux kernel, the following vulnerability has been resolved: lockd: Plug nlm_file refcount le… |
vulnerability |
nvd |
CVE-2026-72218 |
|
2026-08-15 |
| unknown |
CVE-2026-72219 — In the Linux kernel, the following vulnerability has been resolved: lockd: Plug nlm_file leak when n… |
vulnerability |
nvd |
CVE-2026-72219 |
|
2026-08-15 |
| unknown |
CVE-2026-72223 — In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: Free arena sub-alloc… |
vulnerability |
nvd |
CVE-2026-72223 |
|
2026-08-15 |
| unknown |
CVE-2026-72224 — In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: Free arenas on btt_i… |
vulnerability |
nvd |
CVE-2026-72224 |
|
2026-08-15 |
| unknown |
CVE-2026-72228 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: frag: fix primary_if… |
vulnerability |
nvd |
CVE-2026-72228 |
|
2026-08-15 |
| unknown |
CVE-2026-72229 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: clean untagged VLAN… |
vulnerability |
nvd |
CVE-2026-72229 |
|
2026-08-15 |
| unknown |
CVE-2026-72230 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: frag: free unfragmen… |
vulnerability |
nvd |
CVE-2026-72230 |
|
2026-08-15 |
| unknown |
CVE-2026-72236 — In the Linux kernel, the following vulnerability has been resolved: s390/perf_cpum_cf: Add missing a… |
vulnerability |
nvd |
CVE-2026-72236 |
|
2026-08-15 |
| unknown |
CVE-2026-72237 — In the Linux kernel, the following vulnerability has been resolved: perf/x86/amd/brs: Fix kernel add… |
vulnerability |
nvd |
CVE-2026-72237 |
|
2026-08-15 |
| unknown |
CVE-2026-72238 — In the Linux kernel, the following vulnerability has been resolved: x86/boot: Validate console=uart8… |
vulnerability |
nvd |
CVE-2026-72238 |
|
2026-08-15 |
| unknown |
CVE-2026-72240 — In the Linux kernel, the following vulnerability has been resolved: mfd: sm501: Fix reference leak o… |
vulnerability |
nvd |
CVE-2026-72240 |
|
2026-08-15 |
| unknown |
CVE-2026-72241 — In the Linux kernel, the following vulnerability has been resolved: leds: uleds: Fix potential buffe… |
vulnerability |
nvd |
CVE-2026-72241 |
|
2026-08-15 |
| unknown |
CVE-2026-72245 — In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix device referenc… |
vulnerability |
nvd |
CVE-2026-72245 |
|
2026-08-15 |
| unknown |
CVE-2026-72256 — In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_cluster: reject te… |
vulnerability |
nvd |
CVE-2026-72256 |
|
2026-08-15 |
| unknown |
CVE-2026-72257 — In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: q6apm: fix NULL poin… |
vulnerability |
nvd |
CVE-2026-72257 |
|
2026-08-15 |
| unknown |
CVE-2026-72258 — In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8183: Release… |
vulnerability |
nvd |
CVE-2026-72258 |
|
2026-08-15 |
| unknown |
CVE-2026-72259 — In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8192: Release… |
vulnerability |
nvd |
CVE-2026-72259 |
|
2026-08-15 |
| unknown |
CVE-2026-72260 — In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8192: Check ru… |
vulnerability |
nvd |
CVE-2026-72260 |
|
2026-08-15 |
| unknown |
CVE-2026-72263 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: topology: fix memory… |
vulnerability |
nvd |
CVE-2026-72263 |
|
2026-08-15 |
| unknown |
CVE-2026-72264 — In the Linux kernel, the following vulnerability has been resolved: fbdev: tridentfb: fix potential… |
vulnerability |
nvd |
CVE-2026-72264 |
|
2026-08-15 |
| unknown |
CVE-2026-72265 — In the Linux kernel, the following vulnerability has been resolved: fbdev: nvidia: fix potential mem… |
vulnerability |
nvd |
CVE-2026-72265 |
|
2026-08-15 |
| unknown |
CVE-2026-72266 — In the Linux kernel, the following vulnerability has been resolved: fbdev: vesafb: fix memory leak i… |
vulnerability |
nvd |
CVE-2026-72266 |
|
2026-08-15 |
| unknown |
CVE-2026-72267 — In the Linux kernel, the following vulnerability has been resolved: fbdev: carminefb: fix potential… |
vulnerability |
nvd |
CVE-2026-72267 |
|
2026-08-15 |
| unknown |
CVE-2026-72268 — In the Linux kernel, the following vulnerability has been resolved: fbdev: tdfxfb: fix potential mem… |
vulnerability |
nvd |
CVE-2026-72268 |
|
2026-08-15 |
| unknown |
CVE-2026-72269 — In the Linux kernel, the following vulnerability has been resolved: fbdev: uvesafb: fix potential me… |
vulnerability |
nvd |
CVE-2026-72269 |
|
2026-08-15 |
| unknown |
CVE-2026-72270 — In the Linux kernel, the following vulnerability has been resolved: fbdev: s3fb: fix potential memor… |
vulnerability |
nvd |
CVE-2026-72270 |
|
2026-08-15 |
| unknown |
CVE-2026-72271 — In the Linux kernel, the following vulnerability has been resolved: fbdev: i740fb: fix potential mem… |
vulnerability |
nvd |
CVE-2026-72271 |
|
2026-08-15 |
| unknown |
CVE-2026-72272 — In the Linux kernel, the following vulnerability has been resolved: fbdev: radeon: fix potential mem… |
vulnerability |
nvd |
CVE-2026-72272 |
|
2026-08-15 |
| unknown |
CVE-2026-72273 — In the Linux kernel, the following vulnerability has been resolved: fbdev: efifb: fix memory leak in… |
vulnerability |
nvd |
CVE-2026-72273 |
|
2026-08-15 |
| unknown |
CVE-2026-72274 — In the Linux kernel, the following vulnerability has been resolved: fbdev: hecubafb: fix potential m… |
vulnerability |
nvd |
CVE-2026-72274 |
|
2026-08-15 |
| unknown |
CVE-2026-72275 — In the Linux kernel, the following vulnerability has been resolved: fbdev: broadsheetfb: fix potenti… |
vulnerability |
nvd |
CVE-2026-72275 |
|
2026-08-15 |
| unknown |
CVE-2026-72276 — In the Linux kernel, the following vulnerability has been resolved: fbdev: metronomefb: fix potentia… |
vulnerability |
nvd |
CVE-2026-72276 |
|
2026-08-15 |
| unknown |
CVE-2026-72281 — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: account pKVM reclaim… |
vulnerability |
nvd |
CVE-2026-72281 |
|
2026-08-15 |
| unknown |
CVE-2026-72290 — In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix GISC refcoun… |
vulnerability |
nvd |
CVE-2026-72290 |
|
2026-08-15 |
| unknown |
CVE-2026-72292 — In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Initialize KVM_S390_G… |
vulnerability |
nvd |
CVE-2026-72292 |
|
2026-08-15 |
| unknown |
CVE-2026-72293 — In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: Add missing rad… |
vulnerability |
nvd |
CVE-2026-72293 |
|
2026-08-15 |
| unknown |
CVE-2026-72300 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: topology: validate ve… |
vulnerability |
nvd |
CVE-2026-72300 |
|
2026-08-15 |
| unknown |
CVE-2026-72305 — In the Linux kernel, the following vulnerability has been resolved: VDUSE: avoid leaking information… |
vulnerability |
nvd |
CVE-2026-72305 |
|
2026-08-15 |
| unknown |
CVE-2026-72306 — In the Linux kernel, the following vulnerability has been resolved: vduse: Fix race in vduse_dev_msg… |
vulnerability |
nvd |
CVE-2026-72306 |
|
2026-08-15 |
| unknown |
CVE-2026-72307 — In the Linux kernel, the following vulnerability has been resolved: mlxsw: fix refcount leak in mlxs… |
vulnerability |
nvd |
CVE-2026-72307, CVE-2026-72308 |
|
2026-08-15 |
| unknown |
CVE-2026-72309 — In the Linux kernel, the following vulnerability has been resolved: tracing/remotes: Fix leak in tra… |
vulnerability |
nvd |
CVE-2026-72309 |
|
2026-08-15 |
| unknown |
CVE-2026-72311 — In the Linux kernel, the following vulnerability has been resolved: drm/xe: free madvise VMA array o… |
vulnerability |
nvd |
CVE-2026-72311 |
|
2026-08-15 |
| unknown |
CVE-2026-72316 — In the Linux kernel, the following vulnerability has been resolved: dm era: fix NULL pointer derefer… |
vulnerability |
nvd |
CVE-2026-72316 |
|
2026-08-15 |
| unknown |
CVE-2026-72321 — In the Linux kernel, the following vulnerability has been resolved: ipv4: igmp: Fix potential memory… |
vulnerability |
nvd |
CVE-2026-72321 |
|
2026-08-15 |
| unknown |
CVE-2026-72324 — In the Linux kernel, the following vulnerability has been resolved: gpio: mvebu: free generic chips… |
vulnerability |
nvd |
CVE-2026-72324 |
|
2026-08-15 |
| unknown |
CVE-2026-72325 — In the Linux kernel, the following vulnerability has been resolved: perf/x86/amd/core: Avoid enablin… |
vulnerability |
nvd |
CVE-2026-72325 |
|
2026-08-15 |
| unknown |
CVE-2026-72326 — In the Linux kernel, the following vulnerability has been resolved: net/sched: cake: reject overhead… |
vulnerability |
nvd |
CVE-2026-72326 |
|
2026-08-15 |
| unknown |
CVE-2026-72327 — In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Reject invalid indirect… |
vulnerability |
nvd |
CVE-2026-72327 |
|
2026-08-15 |
| unknown |
CVE-2026-72332 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Prevent PM resume… |
vulnerability |
nvd |
CVE-2026-72332 |
|
2026-08-15 |
| unknown |
CVE-2026-72333 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix tx ident l… |
vulnerability |
nvd |
CVE-2026-72333 |
|
2026-08-15 |
| unknown |
CVE-2026-72336 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: 6lowpan: hold L2CAP c… |
vulnerability |
nvd |
CVE-2026-72336 |
|
2026-08-15 |
| unknown |
CVE-2026-72337 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: 6lowpan: avoid untrac… |
vulnerability |
nvd |
CVE-2026-72337 |
|
2026-08-15 |
| unknown |
CVE-2026-72341 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix publication race… |
vulnerability |
nvd |
CVE-2026-72341 |
|
2026-08-15 |
| unknown |
CVE-2026-72346 — In the Linux kernel, the following vulnerability has been resolved: platform/x86: bitland-mifs-wmi:… |
vulnerability |
nvd |
CVE-2026-72346 |
|
2026-08-15 |
| unknown |
CVE-2026-72349 — In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_rateest: fix u64 t… |
vulnerability |
nvd |
CVE-2026-72349 |
|
2026-08-15 |
| unknown |
CVE-2026-72359 — In the Linux kernel, the following vulnerability has been resolved: drm/xe: fix NPD in bo_meminfo()… |
vulnerability |
nvd |
CVE-2026-72359 |
|
2026-08-15 |
| unknown |
CVE-2026-72361 — In the Linux kernel, the following vulnerability has been resolved: drm/xe/hw_engine: Fix double-fre… |
vulnerability |
nvd |
CVE-2026-72361 |
|
2026-08-15 |
| unknown |
CVE-2026-72362 — In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: Fix NULL pointer dere… |
vulnerability |
nvd |
CVE-2026-72362 |
|
2026-08-15 |
| unknown |
CVE-2026-72363 — In the Linux kernel, the following vulnerability has been resolved: netfs: Fix folio state after ENO… |
vulnerability |
nvd |
CVE-2026-72363 |
|
2026-08-15 |
| unknown |
CVE-2026-72365 — In the Linux kernel, the following vulnerability has been resolved: netfs: Fix writethrough to use c… |
vulnerability |
nvd |
CVE-2026-72365 |
|
2026-08-15 |
| unknown |
CVE-2026-72370 — In the Linux kernel, the following vulnerability has been resolved: iomap: release pages on atomic d… |
vulnerability |
nvd |
CVE-2026-72370 |
|
2026-08-15 |
| unknown |
CVE-2026-72376 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix misplaced inc of net->c… |
vulnerability |
nvd |
CVE-2026-72376 |
|
2026-08-15 |
| unknown |
CVE-2026-72377 — In the Linux kernel, the following vulnerability has been resolved: afs: Remove setting of AS_RELEAS… |
vulnerability |
nvd |
CVE-2026-72377 |
|
2026-08-15 |
| unknown |
CVE-2026-72379 — In the Linux kernel, the following vulnerability has been resolved: fs: refuse O_TMPFILE creation wi… |
vulnerability |
nvd |
CVE-2026-72379 |
|
2026-08-15 |
| unknown |
CVE-2026-72384 — In the Linux kernel, the following vulnerability has been resolved: irqchip/ts4800: Fix missing chai… |
vulnerability |
nvd |
CVE-2026-72384 |
|
2026-08-15 |
| unknown |
CVE-2026-72385 — In the Linux kernel, the following vulnerability has been resolved: tracing/fprobe: Fix NULL pointer… |
vulnerability |
nvd |
CVE-2026-72385 |
|
2026-08-15 |
| unknown |
CVE-2026-72386 — In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix a leak when a g… |
vulnerability |
nvd |
CVE-2026-72386 |
|
2026-08-15 |
| unknown |
CVE-2026-72387 — In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix potential inval… |
vulnerability |
nvd |
CVE-2026-72387 |
|
2026-08-15 |
| unknown |
CVE-2026-72388 — In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Always use the IRQ-… |
vulnerability |
nvd |
CVE-2026-72388 |
|
2026-08-15 |
| unknown |
CVE-2026-72391 — In the Linux kernel, the following vulnerability has been resolved: net: phy: sfp: free mii_bus in s… |
vulnerability |
nvd |
CVE-2026-72391 |
|
2026-08-15 |
| unknown |
CVE-2026-72392 — In the Linux kernel, the following vulnerability has been resolved: ipv6: fib6: fix NULL deref in fi… |
vulnerability |
nvd |
CVE-2026-72392 |
|
2026-08-15 |
| unknown |
CVE-2026-72394 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (aspeed-g6-pwm-tach) Guar… |
vulnerability |
nvd |
CVE-2026-72394 |
|
2026-08-15 |
| unknown |
CVE-2026-72396 — In the Linux kernel, the following vulnerability has been resolved: hwmon: adm1275: Prevent reading… |
vulnerability |
nvd |
CVE-2026-72396 |
|
2026-08-15 |
| unknown |
CVE-2026-72401 — In the Linux kernel, the following vulnerability has been resolved: bpf: Fix insn_aux_data leak on v… |
vulnerability |
nvd |
CVE-2026-72401 |
|
2026-08-15 |
| unknown |
CVE-2026-72402 — In the Linux kernel, the following vulnerability has been resolved: bpf: Mask pseudo pointer values… |
vulnerability |
nvd |
CVE-2026-72402 |
|
2026-08-15 |
| unknown |
CVE-2026-72403 — In the Linux kernel, the following vulnerability has been resolved: ALSA: FCP: Fix NULL pointer dere… |
vulnerability |
nvd |
CVE-2026-72403 |
|
2026-08-15 |
| unknown |
CVE-2026-72413 — In the Linux kernel, the following vulnerability has been resolved: sctp: fix err_chunk memory leaks… |
vulnerability |
nvd |
CVE-2026-72413 |
|
2026-08-15 |
| unknown |
CVE-2026-72414 — In the Linux kernel, the following vulnerability has been resolved: net: dsa: sja1105: round up PTP… |
vulnerability |
nvd |
CVE-2026-72414 |
|
2026-08-15 |
| unknown |
CVE-2026-72424 — In the Linux kernel, the following vulnerability has been resolved: rtc: msc313: fix NULL deref in s… |
vulnerability |
nvd |
CVE-2026-72424 |
|
2026-08-15 |
| unknown |
CVE-2026-72428 — In the Linux kernel, the following vulnerability has been resolved: bpf: Fix stack slot index in nos… |
vulnerability |
nvd |
CVE-2026-72428 |
|
2026-08-15 |
| unknown |
CVE-2026-72430 — In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix nf_connla… |
vulnerability |
nvd |
CVE-2026-72430 |
|
2026-08-15 |
| unknown |
CVE-2026-72431 — In the Linux kernel, the following vulnerability has been resolved: alloc_tag: fix use-after-free in… |
vulnerability |
nvd |
CVE-2026-72431 |
|
2026-08-15 |
| unknown |
CVE-2026-72432 — In the Linux kernel, the following vulnerability has been resolved: tpm_crb: Check ACPI_COMPANION()… |
vulnerability |
nvd |
CVE-2026-72432 |
|
2026-08-15 |
| unknown |
CVE-2026-72433 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_meta_bridge: fix… |
vulnerability |
nvd |
CVE-2026-72433 |
|
2026-08-15 |
| unknown |
CVE-2026-72437 — In the Linux kernel, the following vulnerability has been resolved: md/raid1: free r1_bio when REQ_N… |
vulnerability |
nvd |
CVE-2026-72437 |
|
2026-08-15 |
| unknown |
CVE-2026-72439 — In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix writes_pending le… |
vulnerability |
nvd |
CVE-2026-72439 |
|
2026-08-15 |
| unknown |
CVE-2026-72441 — In the Linux kernel, the following vulnerability has been resolved: ieee802154: fix kernel-infoleak… |
vulnerability |
nvd |
CVE-2026-72441 |
|
2026-08-15 |
| unknown |
CVE-2026-72443 — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Kill MIDI 2.0 U… |
vulnerability |
nvd |
CVE-2026-72443 |
|
2026-08-15 |
| unknown |
CVE-2026-72445 — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: qcom: clear ope… |
vulnerability |
nvd |
CVE-2026-72445 |
|
2026-08-15 |
| unknown |
CVE-2026-72447 — In the Linux kernel, the following vulnerability has been resolved: sctp: hold socket lock when dump… |
vulnerability |
nvd |
CVE-2026-72447 |
|
2026-08-15 |
| unknown |
CVE-2026-72448 — In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix leak of SQ tim… |
vulnerability |
nvd |
CVE-2026-72448 |
|
2026-08-15 |
| unknown |
CVE-2026-72453 — In the Linux kernel, the following vulnerability has been resolved: regcache: Do not overwrite error… |
vulnerability |
nvd |
CVE-2026-72453 |
|
2026-08-15 |
| unknown |
CVE-2026-72456 — In the Linux kernel, the following vulnerability has been resolved: apparmor: release exe file resou… |
vulnerability |
nvd |
CVE-2026-72456 |
|
2026-08-15 |
| unknown |
CVE-2026-72457 — In the Linux kernel, the following vulnerability has been resolved: apparmor: fail policy unpack on… |
vulnerability |
nvd |
CVE-2026-72457 |
|
2026-08-15 |
| unknown |
CVE-2026-72458 — In the Linux kernel, the following vulnerability has been resolved: apparmor: fix NULL pointer deref… |
vulnerability |
nvd |
CVE-2026-72458 |
|
2026-08-15 |
| unknown |
CVE-2026-72467 — In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Check frwr_wp_create()… |
vulnerability |
nvd |
CVE-2026-72467 |
|
2026-08-15 |
| unknown |
CVE-2026-72468 — In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Initialize re_id befor… |
vulnerability |
nvd |
CVE-2026-72468 |
|
2026-08-15 |
| unknown |
CVE-2026-72474 — In the Linux kernel, the following vulnerability has been resolved: dmaengine: dma-axi-dmac: use DMA… |
vulnerability |
nvd |
CVE-2026-72474 |
|
2026-08-15 |
| unknown |
CVE-2026-72475 — In the Linux kernel, the following vulnerability has been resolved: dmaengine: dma-axi-dmac: Properl… |
vulnerability |
nvd |
CVE-2026-72475 |
|
2026-08-15 |
| unknown |
CVE-2026-72479 — In the Linux kernel, the following vulnerability has been resolved: iio: accel: mma8452: handle I2C… |
vulnerability |
nvd |
CVE-2026-72479 |
|
2026-08-15 |
| unknown |
CVE-2026-72481 — In the Linux kernel, the following vulnerability has been resolved: iio: magnetometer: ak8975: fix p… |
vulnerability |
nvd |
CVE-2026-72481 |
|
2026-08-15 |
| unknown |
CVE-2026-72484 — In the Linux kernel, the following vulnerability has been resolved: staging: most: video: avoid doub… |
vulnerability |
nvd |
CVE-2026-72484 |
|
2026-08-15 |
| unknown |
CVE-2026-72486 — In the Linux kernel, the following vulnerability has been resolved: mailbox: mtk-adsp: fix UAF durin… |
vulnerability |
nvd |
CVE-2026-72486 |
|
2026-08-15 |
| unknown |
CVE-2026-72490 — In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix stainfo… |
vulnerability |
nvd |
CVE-2026-72490 |
|
2026-08-15 |
| unknown |
CVE-2026-72501 — In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Initialize dpi var… |
vulnerability |
nvd |
CVE-2026-72501 |
|
2026-08-15 |
| unknown |
CVE-2026-74261 — In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: avoid stale FIFO cell… |
vulnerability |
nvd |
CVE-2026-74261 |
|
2026-08-15 |
| unknown |
CVE-2026-74263 — In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: check skb_clone… |
vulnerability |
nvd |
CVE-2026-74263 |
|
2026-08-15 |
| unknown |
CVE-2026-74265 — In the Linux kernel, the following vulnerability has been resolved: net: mana: initialize gdma queue… |
vulnerability |
nvd |
CVE-2026-74265 |
|
2026-08-15 |
| unknown |
CVE-2026-74271 — In the Linux kernel, the following vulnerability has been resolved: power: supply: core: fix supplie… |
vulnerability |
nvd |
CVE-2026-74271 |
|
2026-08-15 |
| unknown |
CVE-2026-74272 — In the Linux kernel, the following vulnerability has been resolved: cxl/region: Resolve region delet… |
vulnerability |
nvd |
CVE-2026-74272 |
|
2026-08-15 |
| unknown |
CVE-2026-74273 — In the Linux kernel, the following vulnerability has been resolved: cxl/region: Block region delete… |
vulnerability |
nvd |
CVE-2026-74273 |
|
2026-08-15 |
| unknown |
CVE-2026-74274 — In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fill first free targ… |
vulnerability |
nvd |
CVE-2026-74274 |
|
2026-08-15 |
| unknown |
CVE-2026-74276 — In the Linux kernel, the following vulnerability has been resolved: spi: xilinx: use FIFO occupancy… |
vulnerability |
nvd |
CVE-2026-74276 |
|
2026-08-15 |
| unknown |
CVE-2026-74278 — In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: Fix kernel heap addre… |
vulnerability |
nvd |
CVE-2026-74278 |
|
2026-08-15 |
| unknown |
CVE-2026-74284 — In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_hfsc: Don't make… |
vulnerability |
nvd |
CVE-2026-74284 |
|
2026-08-15 |
| unknown |
CVE-2026-74286 — In the Linux kernel, the following vulnerability has been resolved: net: pfcp: allocate per-cpu tsta… |
vulnerability |
nvd |
CVE-2026-74286 |
|
2026-08-15 |
| unknown |
CVE-2026-74290 — In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_flow: Dont expose… |
vulnerability |
nvd |
CVE-2026-74290 |
|
2026-08-15 |
| unknown |
CVE-2026-74291 — In the Linux kernel, the following vulnerability has been resolved: ASoC: topology: Check PCM and DA… |
vulnerability |
nvd |
CVE-2026-74291 |
|
2026-08-15 |
| unknown |
CVE-2026-74298 — In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix FRMR set pinned p… |
vulnerability |
nvd |
CVE-2026-74298 |
|
2026-08-15 |
| unknown |
CVE-2026-74299 — In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix FRMR aging push t… |
vulnerability |
nvd |
CVE-2026-74299 |
|
2026-08-15 |
| unknown |
CVE-2026-74301 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtk: fix URB leak i… |
vulnerability |
nvd |
CVE-2026-74301 |
|
2026-08-15 |
| unknown |
CVE-2026-74303 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_qca: fix NULL poi… |
vulnerability |
nvd |
CVE-2026-74303, CVE-2026-74304 |
|
2026-08-15 |
| unknown |
CVE-2026-74307 — In the Linux kernel, the following vulnerability has been resolved: ext4: validate donor file superb… |
vulnerability |
nvd |
CVE-2026-74307 |
|
2026-08-15 |
| unknown |
CVE-2026-74308 — In the Linux kernel, the following vulnerability has been resolved: ext4: fix kernel BUG in ext4_wri… |
vulnerability |
nvd |
CVE-2026-74308 |
|
2026-08-15 |
| unknown |
CVE-2026-74318 — In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock cloning inli… |
vulnerability |
nvd |
CVE-2026-74318 |
|
2026-08-15 |
| unknown |
CVE-2026-74319 — In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix deadlock waiti… |
vulnerability |
nvd |
CVE-2026-74319 |
|
2026-08-15 |
| unknown |
CVE-2026-74320 — In the Linux kernel, the following vulnerability has been resolved: fbdev: sm501fb: Fix buffer error… |
vulnerability |
nvd |
CVE-2026-74320 |
|
2026-08-15 |
| unknown |
CVE-2026-74324 — In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: validate skb… |
vulnerability |
nvd |
CVE-2026-74324 |
|
2026-08-15 |
| unknown |
CVE-2026-74326 — In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix resource… |
vulnerability |
nvd |
CVE-2026-74326 |
|
2026-08-15 |
| unknown |
CVE-2026-74327 — In the Linux kernel, the following vulnerability has been resolved: vmalloc: fix NULL pointer derefe… |
vulnerability |
nvd |
CVE-2026-74327 |
|
2026-08-15 |
| unknown |
CVE-2026-74329 — In the Linux kernel, the following vulnerability has been resolved: watchdog: unregister PM notifier… |
vulnerability |
nvd |
CVE-2026-74329 |
|
2026-08-15 |
| unknown |
CVE-2026-74331 — In the Linux kernel, the following vulnerability has been resolved: firmware_loader: Fix recursive l… |
vulnerability |
nvd |
CVE-2026-74331 |
|
2026-08-15 |
| unknown |
CVE-2026-74335 — In the Linux kernel, the following vulnerability has been resolved: bpf: Fix NULL pointer dereferenc… |
vulnerability |
nvd |
CVE-2026-74335 |
|
2026-08-15 |
| unknown |
CVE-2026-74336 — In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bound S1G TIM PV… |
vulnerability |
nvd |
CVE-2026-74336 |
|
2026-08-15 |
| unknown |
CVE-2026-74337 — In the Linux kernel, the following vulnerability has been resolved: bpf: Fix NMI/tracepoint re-entry… |
vulnerability |
nvd |
CVE-2026-74337 |
|
2026-08-15 |
| unknown |
CVE-2026-74339 — In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: Clear variable event… |
vulnerability |
nvd |
CVE-2026-74339 |
|
2026-08-15 |
| unknown |
CVE-2026-74342 — In the Linux kernel, the following vulnerability has been resolved: kernfs: link kn to its parent be… |
vulnerability |
nvd |
CVE-2026-74342 |
|
2026-08-15 |
| unknown |
CVE-2026-74346 — In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix OOB read during… |
vulnerability |
nvd |
CVE-2026-74346 |
|
2026-08-15 |
| unknown |
CVE-2026-74348 — In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: require a ref for loc… |
vulnerability |
nvd |
CVE-2026-74348 |
|
2026-08-15 |
| unknown |
CVE-2026-74351 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: rebase copied fsdlm LVB p… |
vulnerability |
nvd |
CVE-2026-74351 |
|
2026-08-15 |
| unknown |
CVE-2026-74352 — In the Linux kernel, the following vulnerability has been resolved: of: reserved_mem: avoid post-ini… |
vulnerability |
nvd |
CVE-2026-74352 |
|
2026-08-15 |
| unknown |
CVE-2026-74353 — In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: always resume_all af… |
vulnerability |
nvd |
CVE-2026-74353 |
|
2026-08-15 |
| unknown |
CVE-2026-74358 — In the Linux kernel, the following vulnerability has been resolved: ext4: fix fast commit wait/wake… |
vulnerability |
nvd |
CVE-2026-74358 |
|
2026-08-15 |
| unknown |
CVE-2026-74360 — In the Linux kernel, the following vulnerability has been resolved: bpf: Reject exclusive maps for b… |
vulnerability |
nvd |
CVE-2026-74360 |
|
2026-08-15 |
| unknown |
CVE-2026-74362 — In the Linux kernel, the following vulnerability has been resolved: ext2: fix ignored return value o… |
vulnerability |
nvd |
CVE-2026-74362 |
|
2026-08-15 |
| unknown |
CVE-2026-74366 — In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix NULL deref in… |
vulnerability |
nvd |
CVE-2026-74366 |
|
2026-08-15 |
| unknown |
CVE-2026-74368 — In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in… |
vulnerability |
nvd |
CVE-2026-74368 |
|
2026-08-15 |
| unknown |
CVE-2026-74369 — In the Linux kernel, the following vulnerability has been resolved: liveupdate: fix u-a-f in luo_fil… |
vulnerability |
nvd |
CVE-2026-74369 |
|
2026-08-15 |
| unknown |
CVE-2026-74370 — In the Linux kernel, the following vulnerability has been resolved: liveupdate: fix TOCTOU race in l… |
vulnerability |
nvd |
CVE-2026-74370 |
|
2026-08-15 |
| unknown |
CVE-2026-74372 — In the Linux kernel, the following vulnerability has been resolved: raid1: fix nr_pending leak in RE… |
vulnerability |
nvd |
CVE-2026-74372 |
|
2026-08-15 |
| unknown |
CVE-2026-74373 — In the Linux kernel, the following vulnerability has been resolved: md/raid1,raid10: fix bio account… |
vulnerability |
nvd |
CVE-2026-74373 |
|
2026-08-15 |
| unknown |
CVE-2026-74375 — In the Linux kernel, the following vulnerability has been resolved: md/raid1,raid10: fix deadlock in… |
vulnerability |
nvd |
CVE-2026-74375 |
|
2026-08-15 |
| unknown |
CVE-2026-74379 — In the Linux kernel, the following vulnerability has been resolved: dax/kmem: account for partial di… |
vulnerability |
nvd |
CVE-2026-74379 |
|
2026-08-15 |
| unknown |
CVE-2026-74381 — In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Allow entries in BO… |
vulnerability |
nvd |
CVE-2026-74381 |
|
2026-08-15 |
| unknown |
CVE-2026-74382 — In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_bpf: prevent unbo… |
vulnerability |
nvd |
CVE-2026-74382 |
|
2026-08-15 |
| unknown |
CVE-2026-74386 — In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix page fragment cac… |
vulnerability |
nvd |
CVE-2026-74386 |
|
2026-08-15 |
| unknown |
CVE-2026-74389 — In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix log flood after cm… |
vulnerability |
nvd |
CVE-2026-74389 |
|
2026-08-15 |
| unknown |
CVE-2026-74391 — In the Linux kernel, the following vulnerability has been resolved: tracing: Bound synthetic-field s… |
vulnerability |
nvd |
CVE-2026-74391 |
|
2026-08-15 |
| unknown |
CVE-2026-74392 — In the Linux kernel, the following vulnerability has been resolved: dm: limit target bio polling to… |
vulnerability |
nvd |
CVE-2026-74392 |
|
2026-08-15 |
| unknown |
CVE-2026-74393 — In the Linux kernel, the following vulnerability has been resolved: drm/syncobj: Fix memory leak in… |
vulnerability |
nvd |
CVE-2026-74393 |
|
2026-08-15 |
| unknown |
CVE-2026-74395 — In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix devx subscribe-ev… |
vulnerability |
nvd |
CVE-2026-74395 |
|
2026-08-15 |
| unknown |
CVE-2026-74399 — In the Linux kernel, the following vulnerability has been resolved: evm: terminate and bound the evm… |
vulnerability |
nvd |
CVE-2026-74399 |
|
2026-08-15 |
| unknown |
CVE-2026-74400 — In the Linux kernel, the following vulnerability has been resolved: bpf: fix crash in bpf_[set|remov… |
vulnerability |
nvd |
CVE-2026-74400 |
|
2026-08-15 |
| unknown |
CVE-2026-74402 — In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-sha204a - fix bloc… |
vulnerability |
nvd |
CVE-2026-74402 |
|
2026-08-15 |
| unknown |
CVE-2026-74414 — In the Linux kernel, the following vulnerability has been resolved: hfsplus: Remove the duplicate at… |
vulnerability |
nvd |
CVE-2026-74414 |
|
2026-08-15 |
| unknown |
CVE-2026-74415 — In the Linux kernel, the following vulnerability has been resolved: spi: atcspi200: fix use-after-fr… |
vulnerability |
nvd |
CVE-2026-74415 |
|
2026-08-15 |
| unknown |
CVE-2026-74416 — In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix memory leak in r… |
vulnerability |
nvd |
CVE-2026-74416 |
|
2026-08-15 |
| unknown |
CVE-2026-74418 — In the Linux kernel, the following vulnerability has been resolved: dma-fence: Fix potential tracepo… |
vulnerability |
nvd |
CVE-2026-74418 |
|
2026-08-15 |
| unknown |
CVE-2026-74420 — In the Linux kernel, the following vulnerability has been resolved: drm/gpusvm: Reject VMAs with VM_… |
vulnerability |
nvd |
CVE-2026-74420 |
|
2026-08-15 |
| unknown |
CVE-2026-74421 — In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: dw_dp: Switch to d… |
vulnerability |
nvd |
CVE-2026-74421 |
|
2026-08-15 |
| unknown |
CVE-2026-74422 — In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: inno-hdmi: Switch… |
vulnerability |
nvd |
CVE-2026-74422 |
|
2026-08-15 |
| unknown |
CVE-2026-74423 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix leak when pin… |
vulnerability |
nvd |
CVE-2026-74423 |
|
2026-08-15 |
| unknown |
CVE-2026-74426 — In the Linux kernel, the following vulnerability has been resolved: afs: fix NULL pointer dereferenc… |
vulnerability |
nvd |
CVE-2026-74426 |
|
2026-08-15 |
| unknown |
CVE-2026-74432 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix leak of released call… |
vulnerability |
nvd |
CVE-2026-74432 |
|
2026-08-15 |
| unknown |
CVE-2026-74437 — In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix deadlock if… |
vulnerability |
nvd |
CVE-2026-74437 |
|
2026-08-15 |
| unknown |
CVE-2026-74441 — In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Fix race condi… |
vulnerability |
nvd |
CVE-2026-74441 |
|
2026-08-15 |
| unknown |
CVE-2026-74442 — In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: avoid destroy_workqu… |
vulnerability |
nvd |
CVE-2026-74442 |
|
2026-08-15 |
| unknown |
CVE-2026-74445 — In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: reject DX_BIND_QUERY… |
vulnerability |
nvd |
CVE-2026-74445 |
|
2026-08-15 |
| unknown |
CVE-2026-74448 — In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix QID bit leak in… |
vulnerability |
nvd |
CVE-2026-74448 |
|
2026-08-15 |
| unknown |
CVE-2026-74455 — In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: validate uCAN rec… |
vulnerability |
nvd |
CVE-2026-74455 |
|
2026-08-15 |
| unknown |
CVE-2026-74457 — In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: add bounds check… |
vulnerability |
nvd |
CVE-2026-74457 |
|
2026-08-15 |
| unknown |
CVE-2026-74458 — In the Linux kernel, the following vulnerability has been resolved: can: kvaser_usb_leaf: kvaser_usb… |
vulnerability |
nvd |
CVE-2026-74458 |
|
2026-08-15 |
| unknown |
CVE-2026-74459 — In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_read_bulk… |
vulnerability |
nvd |
CVE-2026-74459 |
|
2026-08-15 |
| unknown |
CVE-2026-74460 — In the Linux kernel, the following vulnerability has been resolved: can: ems_usb: validate CPC messa… |
vulnerability |
nvd |
CVE-2026-74460 |
|
2026-08-15 |
| unknown |
CVE-2026-74462 — In the Linux kernel, the following vulnerability has been resolved: i2c: imx: mark I2C adapter when… |
vulnerability |
nvd |
CVE-2026-74462 |
|
2026-08-15 |
| unknown |
CVE-2026-74463 — In the Linux kernel, the following vulnerability has been resolved: i2c: jz4780: Cache host clock ra… |
vulnerability |
nvd |
CVE-2026-74463 |
|
2026-08-15 |
| unknown |
CVE-2026-74464 — In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix skb leak o… |
vulnerability |
nvd |
CVE-2026-74464 |
|
2026-08-15 |
| unknown |
CVE-2026-74466 — In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Close speculative m… |
vulnerability |
nvd |
CVE-2026-74466 |
|
2026-08-15 |
| unknown |
CVE-2026-74468 — In the Linux kernel, the following vulnerability has been resolved: gpio: pch: use raw_spinlock_t fo… |
vulnerability |
nvd |
CVE-2026-74468 |
|
2026-08-15 |
| unknown |
CVE-2026-74472 — In the Linux kernel, the following vulnerability has been resolved: ublk: reset kernel-owned dev_inf… |
vulnerability |
nvd |
CVE-2026-74472 |
|
2026-08-15 |
| unknown |
CVE-2026-74477 — In the Linux kernel, the following vulnerability has been resolved: uprobes: Fix NULL pointer derefe… |
vulnerability |
nvd |
CVE-2026-74477 |
|
2026-08-15 |
| unknown |
CVE-2026-74483 — In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: don't leak the user… |
vulnerability |
nvd |
CVE-2026-74483 |
|
2026-08-15 |
| unknown |
CVE-2026-74484 — In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: don't let an 'F' en… |
vulnerability |
nvd |
CVE-2026-74484 |
|
2026-08-15 |
| unknown |
CVE-2026-74487 — In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: restore write acces… |
vulnerability |
nvd |
CVE-2026-74487 |
|
2026-08-15 |
| unknown |
CVE-2026-74491 — In the Linux kernel, the following vulnerability has been resolved: of/address: Fix NULL bus derefer… |
vulnerability |
nvd |
CVE-2026-74491 |
|
2026-08-15 |
| unknown |
CVE-2026-74494 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject repeated SMB2 NEGO… |
vulnerability |
nvd |
CVE-2026-74494 |
|
2026-08-15 |
| unknown |
CVE-2026-74498 — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix DMA buffer… |
vulnerability |
nvd |
CVE-2026-74498 |
|
2026-08-15 |
| unknown |
CVE-2026-74499 — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write i… |
vulnerability |
nvd |
CVE-2026-74499 |
|
2026-08-15 |
| unknown |
CVE-2026-74500 — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix stack info… |
vulnerability |
nvd |
CVE-2026-74500 |
|
2026-08-15 |
| unknown |
CVE-2026-74501 — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix use-after-f… |
vulnerability |
nvd |
CVE-2026-74501 |
|
2026-08-15 |
| unknown |
CVE-2026-74502 — In the Linux kernel, the following vulnerability has been resolved: ALSA: ump: fix double free of ou… |
vulnerability |
nvd |
CVE-2026-74502 |
|
2026-08-15 |
| unknown |
CVE-2026-74504 — In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: Fix division by zero… |
vulnerability |
nvd |
CVE-2026-74504 |
|
2026-08-15 |
| unknown |
CVE-2026-74505 — In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire: Fix UAF at error ha… |
vulnerability |
nvd |
CVE-2026-74505 |
|
2026-08-15 |
| unknown |
CVE-2026-74514 — In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix memory accou… |
vulnerability |
nvd |
CVE-2026-74514 |
|
2026-08-15 |
| unknown |
CVE-2026-74524 — In the Linux kernel, the following vulnerability has been resolved: riscv: mm: Fix out-of-bounds pag… |
vulnerability |
nvd |
CVE-2026-74524 |
|
2026-08-15 |
| unknown |
CVE-2026-74525 — In the Linux kernel, the following vulnerability has been resolved: net: sxgbe: free TX rings on RX… |
vulnerability |
nvd |
CVE-2026-74525 |
|
2026-08-15 |
| unknown |
CVE-2026-74526 — In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix potential dead… |
vulnerability |
nvd |
CVE-2026-74526 |
|
2026-08-15 |
| unknown |
CVE-2026-74532 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: Validate len… |
vulnerability |
nvd |
CVE-2026-74532 |
|
2026-08-15 |
| unknown |
CVE-2026-74536 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix leaking sk a… |
vulnerability |
nvd |
CVE-2026-74536 |
|
2026-08-15 |
| unknown |
CVE-2026-74542 — In the Linux kernel, the following vulnerability has been resolved: netfs: Fix folio_queue ENOMEM in… |
vulnerability |
nvd |
CVE-2026-74542 |
|
2026-08-15 |
| unknown |
CVE-2026-74543 — In the Linux kernel, the following vulnerability has been resolved: net: udp_tunnel: fix memory leak… |
vulnerability |
nvd |
CVE-2026-74543 |
|
2026-08-15 |
| unknown |
CVE-2026-74546 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (adt7470) Fix divide-by-z… |
vulnerability |
nvd |
CVE-2026-74546 |
|
2026-08-15 |
| unknown |
CVE-2026-74547 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (adt7470) Fix busy-loop a… |
vulnerability |
nvd |
CVE-2026-74547 |
|
2026-08-15 |
| unknown |
CVE-2026-74552 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Only report alarms… |
vulnerability |
nvd |
CVE-2026-74552 |
|
2026-08-15 |
| unknown |
CVE-2026-74553 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct6775-core) Fix number… |
vulnerability |
nvd |
CVE-2026-74553 |
|
2026-08-15 |
| unknown |
CVE-2026-74555 — In the Linux kernel, the following vulnerability has been resolved: scsi: libsas: Fix HA resume dead… |
vulnerability |
nvd |
CVE-2026-74555 |
|
2026-08-15 |
| unknown |
CVE-2026-74558 — In the Linux kernel, the following vulnerability has been resolved: xsk: reclaim invalid Tx descript… |
vulnerability |
nvd |
CVE-2026-74558 |
|
2026-08-15 |
| unknown |
CVE-2026-74559 — In the Linux kernel, the following vulnerability has been resolved: xsk: drain continuation descs af… |
vulnerability |
nvd |
CVE-2026-74559 |
|
2026-08-15 |
| unknown |
CVE-2026-74566 — In the Linux kernel, the following vulnerability has been resolved: keys: make keyring key-chunk byt… |
vulnerability |
nvd |
CVE-2026-74566 |
|
2026-08-15 |
| unknown |
CVE-2026-74571 — In the Linux kernel, the following vulnerability has been resolved: btrfs: skip global block reserve… |
vulnerability |
nvd |
CVE-2026-74571 |
|
2026-08-15 |
| unknown |
CVE-2026-74577 — In the Linux kernel, the following vulnerability has been resolved: net: mpls: initialize rtm_tos in… |
vulnerability |
nvd |
CVE-2026-74577 |
|
2026-08-15 |
| unknown |
CVE-2026-74764 — Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When pr… |
vulnerability |
nvd |
CVE-2026-74764 |
|
2026-08-15 |
| unknown |
CVE-2026-74767 — Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) fi… |
vulnerability |
nvd |
CVE-2026-74767 |
|
2026-08-15 |
| unknown |
CVE-2026-74251 — Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0… |
vulnerability |
nvd |
CVE-2026-74251 |
|
2026-08-16 |
| unknown |
CVE-2026-74784 — Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that… |
vulnerability |
nvd |
CVE-2026-74784 |
|
2026-08-16 |
| unknown |
CVE-2026-50601 — A security vulnerability has been identified in the Planet9 desktop application where a hardcoded re… |
vulnerability |
nvd |
CVE-2026-50601 |
|
2026-08-17 |
| unknown |
CVE-2026-50602 — A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned t… |
vulnerability |
nvd |
CVE-2026-50602 |
|
2026-08-17 |
| unknown |
CVE-2026-74579 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: fix mask… |
vulnerability |
nvd |
CVE-2026-74579 |
|
2026-08-17 |
| unknown |
CVE-2026-15623 — A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chroni… |
vulnerability |
nvd |
CVE-2026-15623 |
|
2026-08-17 |
| unknown |
CVE-2026-22072 — Loading arbitrary external URLs through WebView components introduces malicious JS code that can ste… |
vulnerability |
nvd |
CVE-2026-22072 |
|
2026-08-17 |
| unknown |
CVE-2026-40126 — OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be… |
vulnerability |
nvd |
CVE-2026-40126 |
|
2026-08-17 |
| unknown |
CVE-2026-18674 — On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attribu… |
vulnerability |
nvd |
CVE-2026-18674 |
|
2026-08-17 |
| unknown |
CVE-2026-13202 — A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue a… |
vulnerability |
nvd |
CVE-2026-13202 |
|
2026-08-17 |
| unknown |
CVE-2026-73851 — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who co… |
vulnerability |
nvd |
CVE-2026-73851 |
|
2026-08-17 |
| unknown |
CVE-2025-27621 — UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.… |
vulnerability |
nvd |
CVE-2025-27621, CVE-2025-27770, CVE-2025-27771, CVE-2025-27772 |
|
2026-08-17 |
| unknown |
CVE-2026-40144 — A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privileg… |
vulnerability |
nvd |
CVE-2026-40144 |
|
2026-08-17 |
| unknown |
CVE-2026-40145 — A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deploymen… |
vulnerability |
nvd |
CVE-2026-40145 |
|
2026-08-17 |
| unknown |
CVE-2026-61666 — websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driv… |
vulnerability |
nvd |
CVE-2026-61666 |
|
2026-08-17 |
| unknown |
CVE-2026-68518 — Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_… |
vulnerability |
nvd |
CVE-2026-68518 |
|
2026-08-17 |
| unknown |
CVE-2026-54284 — sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction an… |
vulnerability |
nvd |
CVE-2026-54284 |
|
2026-08-17 |
| unknown |
CVE-2026-59894 — sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.p… |
vulnerability |
nvd |
CVE-2026-59894 |
|
2026-08-17 |
| unknown |
CVE-2026-68519 — Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run(… |
vulnerability |
nvd |
CVE-2026-68519 |
|
2026-08-17 |
| unknown |
CVE-2026-71491 — sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlpars… |
vulnerability |
nvd |
CVE-2026-71491 |
|
2026-08-17 |
| unknown |
CVE-2026-74254 — Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Pag… |
vulnerability |
nvd |
CVE-2026-74254 |
|
2026-08-17 |
| unknown |
CVE-2026-12553 — HP has identified a potential vulnerability in HP Web Jetadmin (WJA) that may allow an unauthenticat… |
vulnerability |
nvd |
CVE-2026-12553 |
|
2026-08-17 |
| unknown |
CVE-2026-17639 — Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condi… |
vulnerability |
nvd |
CVE-2026-17639 |
|
2026-08-17 |
| unknown |
CVE-2026-71693 — Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by… |
vulnerability |
nvd |
CVE-2026-71693 |
|
2026-08-17 |
| unknown |
CVE-2026-52886 — Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the back… |
vulnerability |
nvd |
CVE-2026-52886 |
|
2026-08-17 |
| unknown |
CVE-2026-71553 — ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api… |
vulnerability |
nvd |
CVE-2026-71553 |
|
2026-08-17 |
| unknown |
CVE-2026-71858 — Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attack… |
vulnerability |
nvd |
CVE-2026-71858 |
|
2026-08-17 |
| unknown |
CVE-2026-35219 — Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/s… |
vulnerability |
nvd |
CVE-2026-35219 |
|
2026-08-17 |
| unknown |
CVE-2026-47683 — vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in l… |
vulnerability |
nvd |
CVE-2026-47683 |
|
2026-08-17 |
| unknown |
CVE-2026-75529 — Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality… |
vulnerability |
nvd |
CVE-2026-75529 |
|
2026-08-17 |
| unknown |
CVE-2026-75531 — Pandora contains a stored cross-site scripting (XSS) vulnerability in the rendering of URL observabl… |
vulnerability |
nvd |
CVE-2026-75531 |
|
2026-08-17 |
| unknown |
CVE-2026-11817 — This vulnerability only affects Grafana stacks configured with multiple organizations; single-organi… |
vulnerability |
nvd |
CVE-2026-11817 |
|
2026-08-17 |
| unknown |
CVE-2026-43971 — Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directi… |
vulnerability |
nvd |
CVE-2026-43971 |
|
2026-08-18 |
| unknown |
CVE-2026-18929 — Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processi… |
vulnerability |
nvd |
CVE-2026-18929 |
|
2026-08-18 |
| unknown |
CVE-2026-75838 — DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where… |
vulnerability |
nvd |
CVE-2026-75838 |
|
2026-08-18 |
| unknown |
CVE-2026-18751 — External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue aff… |
vulnerability |
nvd |
CVE-2026-18751 |
|
2026-08-18 |
| unknown |
CVE-2026-1199 — Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests… |
vulnerability |
nvd |
CVE-2026-1199 |
|
2026-08-18 |
| unknown |
CVE-2026-23922 — The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak… |
vulnerability |
nvd |
CVE-2026-23922 |
|
2026-08-18 |
| unknown |
CVE-2026-23929 — Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps.… |
vulnerability |
nvd |
CVE-2026-23929 |
|
2026-08-18 |
| unknown |
CVE-2026-23930 — An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by send… |
vulnerability |
nvd |
CVE-2026-23930 |
|
2026-08-18 |
| unknown |
CVE-2026-23931 — The frontend validatate.api.exists action can be exploited by authenticated users to extract plainte… |
vulnerability |
nvd |
CVE-2026-23931 |
|
2026-08-18 |
| unknown |
CVE-2026-23933 — In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written… |
vulnerability |
nvd |
CVE-2026-23933 |
|
2026-08-18 |
| unknown |
CVE-2026-23934 — An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sendin… |
vulnerability |
nvd |
CVE-2026-23934 |
|
2026-08-18 |
| unknown |
CVE-2026-23935 — A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/prepr… |
vulnerability |
nvd |
CVE-2026-23935 |
|
2026-08-18 |
| unknown |
CVE-2026-23937 — The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key l… |
vulnerability |
nvd |
CVE-2026-23937 |
|
2026-08-18 |
| unknown |
CVE-2026-23938 — An authenticated administrator is able to crash Zabbix server or proxy by creating specifically craf… |
vulnerability |
nvd |
CVE-2026-23938 |
|
2026-08-18 |
| unknown |
CVE-2026-45532 — DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a pa… |
vulnerability |
nvd |
CVE-2026-45532 |
|
2026-08-18 |
| unknown |
CVE-2026-59781 — When Zabbix Agent was installed on Windows into a custom installation directory, the installer did n… |
vulnerability |
nvd |
CVE-2026-59781 |
|
2026-08-18 |
| unknown |
CVE-2026-74934 — Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox… |
vulnerability |
nvd |
CVE-2026-74934 |
|
2026-08-18 |
| unknown |
CVE-2026-74945 — Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154,… |
vulnerability |
nvd |
CVE-2026-74945 |
|
2026-08-18 |
| unknown |
CVE-2026-74948 — Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firef… |
vulnerability |
nvd |
CVE-2026-74948 |
|
2026-08-18 |
| unknown |
CVE-2026-74957 — Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firef… |
vulnerability |
nvd |
CVE-2026-74957 |
|
2026-08-18 |
| unknown |
CVE-2026-74959 — Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154,… |
vulnerability |
nvd |
CVE-2026-74959 |
|
2026-08-18 |
| unknown |
CVE-2026-74960 — Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Fi… |
vulnerability |
nvd |
CVE-2026-74960 |
|
2026-08-18 |
| unknown |
CVE-2026-17084 — The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the lat… |
vulnerability |
nvd |
CVE-2026-17084 |
|
2026-08-18 |
| unknown |
CVE-2026-68939 — Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-… |
vulnerability |
nvd |
CVE-2026-68939 |
|
2026-08-18 |
| unknown |
CVE-2026-71539 — n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git n… |
vulnerability |
nvd |
CVE-2026-71539 |
|
2026-08-18 |
| unknown |
CVE-2026-75872 — HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticat… |
vulnerability |
nvd |
CVE-2026-75872 |
|
2026-08-18 |
| unknown |
CVE-2026-75890 — Rejected reason: Duplicate of CVE-2026-50236. This CVE ID was reserved in error for a finding that a… |
vulnerability |
nvd |
CVE-2026-75890 |
|
2026-08-18 |
| unknown |
CVE-2026-15806 — The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWit… |
vulnerability |
nvd |
CVE-2026-15806 |
|
2026-08-18 |
| unknown |
CVE-2026-19501 — CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize sprea… |
vulnerability |
nvd |
CVE-2026-19501 |
|
2026-08-18 |
| unknown |
CVE-2026-62357 — Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.IN… |
vulnerability |
nvd |
CVE-2026-62357 |
|
2026-08-18 |
| unknown |
CVE-2026-63328 — Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager… |
vulnerability |
nvd |
CVE-2026-63328 |
|
2026-08-18 |
| unknown |
CVE-2026-71574 — Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.… |
vulnerability |
nvd |
CVE-2026-71574 |
|
2026-08-18 |
| unknown |
CVE-2026-72532 — Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.… |
vulnerability |
nvd |
CVE-2026-72532 |
|
2026-08-18 |
| unknown |
CVE-2026-73073 — Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autol… |
vulnerability |
nvd |
CVE-2026-73073 |
|
2026-08-18 |
| unknown |
CVE-2026-73337 — Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insuff… |
vulnerability |
nvd |
CVE-2026-73337 |
|
2026-08-18 |
| unknown |
CVE-2026-73371 — Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-… |
vulnerability |
nvd |
CVE-2026-73371 |
|
2026-08-18 |
| unknown |
CVE-2026-73373 — Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 -… |
vulnerability |
nvd |
CVE-2026-73373 |
|
2026-08-18 |
| unknown |
CVE-2026-19869 — @neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication ru… |
vulnerability |
nvd |
CVE-2026-19869 |
|
2026-08-18 |
| unknown |
CVE-2026-54730 — authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google… |
vulnerability |
nvd |
CVE-2026-54730 |
|
2026-08-18 |
| unknown |
CVE-2026-57580 — authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Sourc… |
vulnerability |
nvd |
CVE-2026-57580 |
|
2026-08-18 |
| unknown |
CVE-2026-61634 — The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact w… |
vulnerability |
nvd |
CVE-2026-61634, CVE-2026-63335, CVE-2026-63336, CVE-2026-63337, CVE-2026-69219, CVE-2026-69220 |
|
2026-08-18 |
| unknown |
CVE-2026-71572 — Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0… |
vulnerability |
nvd |
CVE-2026-71572 |
|
2026-08-18 |
| unknown |
CVE-2026-71573 — Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An… |
vulnerability |
nvd |
CVE-2026-71573 |
|
2026-08-18 |
| unknown |
CVE-2026-72531 — Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0… |
vulnerability |
nvd |
CVE-2026-72531 |
|
2026-08-18 |
| unknown |
CVE-2026-73336 — Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Impr… |
vulnerability |
nvd |
CVE-2026-73336 |
|
2026-08-18 |
| unknown |
CVE-2026-73372 — Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1… |
vulnerability |
nvd |
CVE-2026-73372 |
|
2026-08-18 |
| unknown |
CVE-2026-18392 — Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in… |
vulnerability |
nvd |
CVE-2026-18392 |
|
2026-08-18 |
| unknown |
CVE-2026-50161 — libre is a generic library for real-time communications with asynchronous input and output support.… |
vulnerability |
nvd |
CVE-2026-50161 |
|
2026-08-18 |
| unknown |
CVE-2026-50167 — Kurrier is a modern, self-hosted workspace for email, calendar, contacts, and storage. Prior to 1.2.… |
vulnerability |
nvd |
CVE-2026-50167 |
|
2026-08-18 |
| unknown |
CVE-2026-53533 — aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rc… |
vulnerability |
nvd |
CVE-2026-53533 |
|
2026-08-18 |
| unknown |
CVE-2026-63641 — MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies i… |
vulnerability |
nvd |
CVE-2026-63641 |
|
2026-08-18 |
| unknown |
CVE-2026-63642 — MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in de… |
vulnerability |
nvd |
CVE-2026-63642 |
|
2026-08-18 |
| unknown |
CVE-2026-63643 — MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR hand… |
vulnerability |
nvd |
CVE-2026-63643 |
|
2026-08-18 |
| unknown |
CVE-2026-67846 — Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a pote… |
vulnerability |
nvd |
CVE-2026-67846 |
|
2026-08-18 |
| unknown |
CVE-2026-71878 — Missing authentication in initial setup functionality left exposed after initial setup is completed… |
vulnerability |
nvd |
CVE-2026-71878 |
|
2026-08-18 |
| unknown |
CVE-2026-71879 — Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integr… |
vulnerability |
nvd |
CVE-2026-71879 |
|
2026-08-18 |
| unknown |
CVE-2026-71880 — Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions… |
vulnerability |
nvd |
CVE-2026-71880 |
|
2026-08-18 |
| unknown |
CVE-2026-17106 — The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and th… |
vulnerability |
nvd |
CVE-2026-17106 |
|
2026-08-18 |
| unknown |
CVE-2026-52735 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd… |
vulnerability |
nvd |
CVE-2026-52735 |
|
2026-08-18 |
| unknown |
CVE-2026-52736 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer ca… |
vulnerability |
nvd |
CVE-2026-52736 |
|
2026-08-18 |
| unknown |
CVE-2026-52738 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a consensus-valid block containing a… |
vulnerability |
nvd |
CVE-2026-52738 |
|
2026-08-18 |
| unknown |
CVE-2026-53453 — Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.… |
vulnerability |
nvd |
CVE-2026-53453, CVE-2026-53454, CVE-2026-53455, CVE-2026-53456, CVE-2026-53457, CVE-2026-53458 |
|
2026-08-18 |
| unknown |
CVE-2026-56867 — Rejected reason: reserved but not needed |
vulnerability |
nvd |
CVE-2026-56867, CVE-2026-56868, CVE-2026-56869, CVE-2026-56870, CVE-2026-56871, CVE-2026-56872, CVE-2026-56873, CVE-2026-56874 |
|
2026-08-18 |
| unknown |
CVE-2026-21580 — This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vul… |
vulnerability |
nvd |
CVE-2026-21580 |
|
2026-08-18 |
| unknown |
CVE-2026-21582 — This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026… |
vulnerability |
nvd |
CVE-2026-21582 |
|
2026-08-18 |
| unknown |
CVE-2026-21584 — This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 1… |
vulnerability |
nvd |
CVE-2026-21584 |
|
2026-08-18 |
| unknown |
CVE-2026-62292 — libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted unco… |
vulnerability |
nvd |
CVE-2026-62292 |
|
2026-08-18 |
| unknown |
CVE-2026-11751 — A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS… |
vulnerability |
nvd |
CVE-2026-11751 |
|
2026-08-19 |
| unknown |
CVE-2026-66358 — A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an a… |
vulnerability |
nvd |
CVE-2026-66358 |
|
2026-08-19 |
| unknown |
CVE-2026-70408 — An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-… |
vulnerability |
nvd |
CVE-2026-70408 |
|
2026-08-19 |
| unknown |
CVE-2026-49421 — The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH fl… |
vulnerability |
nvd |
CVE-2026-49421 |
|
2026-08-19 |
| unknown |
CVE-2026-49426 — When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of… |
vulnerability |
nvd |
CVE-2026-49426 |
|
2026-08-19 |
| unknown |
CVE-2026-49430 — The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a… |
vulnerability |
nvd |
CVE-2026-49430 |
|
2026-08-19 |
| unknown |
CVE-2026-49431 — The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an… |
vulnerability |
nvd |
CVE-2026-49431 |
|
2026-08-19 |
| unknown |
CVE-2026-49423 — When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremen… |
vulnerability |
nvd |
CVE-2026-49423 |
|
2026-08-19 |
| unknown |
CVE-2026-49424 — The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux… |
vulnerability |
nvd |
CVE-2026-49424 |
|
2026-08-19 |
| unknown |
CVE-2026-49425 — The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct… |
vulnerability |
nvd |
CVE-2026-49425 |
|
2026-08-19 |
| unknown |
CVE-2026-58081 — Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the… |
vulnerability |
nvd |
CVE-2026-58081 |
|
2026-08-19 |
| unknown |
CVE-2026-58082 — The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate char… |
vulnerability |
nvd |
CVE-2026-58082 |
|
2026-08-19 |
| unknown |
CVE-2026-58084 — To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the curren… |
vulnerability |
nvd |
CVE-2026-58084 |
|
2026-08-19 |
| unknown |
CVE-2026-58086 — As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was always denied to a jailed… |
vulnerability |
nvd |
CVE-2026-58086 |
|
2026-08-19 |
| unknown |
CVE-2026-72889 — Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verif… |
vulnerability |
nvd |
CVE-2026-72889 |
|
2026-08-19 |
| unknown |
CVE-2026-75589 — Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with… |
vulnerability |
nvd |
CVE-2026-75589 |
|
2026-08-19 |
| unknown |
CVE-2026-76164 — AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission… |
vulnerability |
nvd |
CVE-2026-76164 |
|
2026-08-19 |
| unknown |
CVE-2026-16440 — In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations causes a… |
vulnerability |
nvd |
CVE-2026-16440 |
|
2026-08-19 |
| unknown |
CVE-2026-19489 — Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.3… |
vulnerability |
nvd |
CVE-2026-19489, CVE-2026-19490 |
|
2026-08-19 |
| unknown |
CVE-2026-67363 — Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The… |
vulnerability |
nvd |
CVE-2026-67363 |
|
2026-08-19 |
| unknown |
CVE-2026-67364 — Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / C… |
vulnerability |
nvd |
CVE-2026-67364 |
|
2026-08-19 |
| unknown |
CVE-2026-50719 — The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-cont… |
vulnerability |
nvd |
CVE-2026-50719 |
|
2026-08-19 |
| unknown |
CVE-2026-50720 — The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the… |
vulnerability |
nvd |
CVE-2026-50720 |
|
2026-08-19 |
| unknown |
CVE-2026-51366 — SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to… |
vulnerability |
nvd |
CVE-2026-51366 |
|
2026-08-19 |
| unknown |
CVE-2026-51367 — An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive i… |
vulnerability |
nvd |
CVE-2026-51367 |
|
2026-08-19 |
| unknown |
CVE-2026-65609 — nnn is vulnerable to Out-of-Bound write vulnerability. Due to lack of validation of attacker-control… |
vulnerability |
nvd |
CVE-2026-65609 |
|
2026-08-19 |
| unknown |
CVE-2026-65610 — nnn stores homelen variable as uchar_t, which can only represent values in the range 0-255. An attac… |
vulnerability |
nvd |
CVE-2026-65610 |
|
2026-08-19 |
| unknown |
CVE-2026-65611 — nnn does not sanitize the path variable. An attacker can create a directory on a shared filesystem,… |
vulnerability |
nvd |
CVE-2026-65611 |
|
2026-08-19 |
| unknown |
CVE-2026-65612 — nnn does not sanitize the filename variable. An attacker can place a file with a crafted name on a s… |
vulnerability |
nvd |
CVE-2026-65612 |
|
2026-08-19 |
| unknown |
CVE-2026-71694 — An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b456321217521… |
vulnerability |
nvd |
CVE-2026-71694 |
|
2026-08-19 |
| unknown |
CVE-2026-74803 — Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image… |
vulnerability |
nvd |
CVE-2026-74803 |
|
2026-08-19 |
| unknown |
CVE-2026-74804 — Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo… |
vulnerability |
nvd |
CVE-2026-74804 |
|
2026-08-19 |
| unknown |
CVE-2026-75114 — Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo <… |
vulnerability |
nvd |
CVE-2026-75114 |
|
2026-08-19 |
| unknown |
CVE-2026-76236 — stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw i… |
vulnerability |
nvd |
CVE-2026-76236 |
|
2026-08-19 |
| unknown |
CVE-2026-76237 — stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulner… |
vulnerability |
nvd |
CVE-2026-76237 |
|
2026-08-19 |
| unknown |
CVE-2026-76238 — stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the de… |
vulnerability |
nvd |
CVE-2026-76238 |
|
2026-08-19 |
| unknown |
CVE-2026-76240 — stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defen… |
vulnerability |
nvd |
CVE-2026-76240 |
|
2026-08-19 |
| unknown |
CVE-2026-76241 — stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration f… |
vulnerability |
nvd |
CVE-2026-76241 |
|
2026-08-19 |
| unknown |
CVE-2026-76242 — stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separat… |
vulnerability |
nvd |
CVE-2026-76242 |
|
2026-08-19 |
| unknown |
CVE-2026-76243 — stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-… |
vulnerability |
nvd |
CVE-2026-76243 |
|
2026-08-19 |
| unknown |
CVE-2026-76244 — stigmem-node contains an insecure default configuration vulnerability that allows federation traffic… |
vulnerability |
nvd |
CVE-2026-76244 |
|
2026-08-19 |
| unknown |
CVE-2026-76245 — stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federat… |
vulnerability |
nvd |
CVE-2026-76245 |
|
2026-08-19 |
| unknown |
CVE-2026-18526 — HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerabi… |
vulnerability |
nvd |
CVE-2026-18526 |
|
2026-08-19 |
| unknown |
CVE-2026-18756 — HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space… |
vulnerability |
nvd |
CVE-2026-18756 |
|
2026-08-19 |
| unknown |
CVE-2026-45272 — MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook.… |
vulnerability |
nvd |
CVE-2026-45272 |
|
2026-08-19 |
| unknown |
CVE-2026-45273 — MyBooks is an ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSe… |
vulnerability |
nvd |
CVE-2026-45273 |
|
2026-08-19 |
| unknown |
CVE-2026-45274 — MyBooks is anebook management web server also known as Talebook. In 3.41.2 and earlier, the SignUp.p… |
vulnerability |
nvd |
CVE-2026-45274 |
|
2026-08-19 |
| unknown |
CVE-2026-52792 — Algernon is a small self-contained pure-Go web server. Prior to 1.17.9, Algernon on Windows selects… |
vulnerability |
nvd |
CVE-2026-52792 |
|
2026-08-19 |
| unknown |
CVE-2026-75949 — Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDi… |
vulnerability |
nvd |
CVE-2026-75949 |
|
2026-08-19 |
| unknown |
CVE-2026-75950 — Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory… |
vulnerability |
nvd |
CVE-2026-75950 |
|
2026-08-19 |
| unknown |
CVE-2026-75951 — Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions)… |
vulnerability |
nvd |
CVE-2026-75951 |
|
2026-08-19 |
| unknown |
CVE-2026-75952 — Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Token… |
vulnerability |
nvd |
CVE-2026-75952 |
|
2026-08-19 |
| unknown |
CVE-2026-75953 — Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient addres… |
vulnerability |
nvd |
CVE-2026-75953 |
|
2026-08-19 |
| unknown |
CVE-2026-75954 — Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Se… |
vulnerability |
nvd |
CVE-2026-75954 |
|
2026-08-19 |
| unknown |
CVE-2026-75955 — Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - co… |
vulnerability |
nvd |
CVE-2026-75955 |
|
2026-08-19 |
| unknown |
CVE-2026-75956 — Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirector… |
vulnerability |
nvd |
CVE-2026-75956 |
|
2026-08-19 |
| unknown |
CVE-2026-76203 — Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer… |
vulnerability |
nvd |
CVE-2026-76203 |
|
2026-08-19 |
| unknown |
CVE-2026-18430 — HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notificat… |
vulnerability |
nvd |
CVE-2026-18430 |
|
2026-08-19 |
| unknown |
CVE-2026-19672 — The tarfile module's tar and data extraction filters created directories outside the destination for… |
vulnerability |
nvd |
CVE-2026-19672 |
|
2026-08-19 |
| unknown |
CVE-2026-62672 — Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and func… |
vulnerability |
nvd |
CVE-2026-62672 |
|
2026-08-19 |
| unknown |
CVE-2026-62673 — Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess… |
vulnerability |
nvd |
CVE-2026-62673 |
|
2026-08-19 |
| unknown |
CVE-2026-64850 — Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/… |
vulnerability |
nvd |
CVE-2026-64850 |
|
2026-08-19 |
| unknown |
CVE-2026-64851 — Grav Shortcode Core Plugin allows for the development shortcode plugins that utilize the common form… |
vulnerability |
nvd |
CVE-2026-64851 |
|
2026-08-19 |
| unknown |
CVE-2026-50173 — Flow-Like is a platform for building end-to-end use cases. Prior to version 1.0.4, `GET /api/v1/apps… |
vulnerability |
nvd |
CVE-2026-50173 |
|
2026-08-19 |
| unknown |
CVE-2025-14600 — An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized ad… |
vulnerability |
nvd |
CVE-2025-14600 |
|
2026-08-19 |
| unknown |
CVE-2025-14603 — The application component processes user-supplied parameters insecurely, passing them into SQL queri… |
vulnerability |
nvd |
CVE-2025-14603 |
|
2026-08-19 |
| unknown |
CVE-2026-55191 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients th… |
vulnerability |
nvd |
CVE-2026-55191 |
|
2026-08-19 |
| unknown |
CVE-2026-55192 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP H.264 deco… |
vulnerability |
nvd |
CVE-2026-55192 |
|
2026-08-19 |
| unknown |
CVE-2026-55193 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients us… |
vulnerability |
nvd |
CVE-2026-55193 |
|
2026-08-19 |
| unknown |
CVE-2026-55194 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fr… |
vulnerability |
nvd |
CVE-2026-55194 |
|
2026-08-19 |
| unknown |
CVE-2026-55648 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy… |
vulnerability |
nvd |
CVE-2026-55648 |
|
2026-08-19 |
| unknown |
CVE-2026-63633 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode… |
vulnerability |
nvd |
CVE-2026-63633 |
|
2026-08-19 |
| unknown |
CVE-2026-63652 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv… |
vulnerability |
nvd |
CVE-2026-63652 |
|
2026-08-19 |
| unknown |
CVE-2026-73541 — Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote… |
vulnerability |
nvd |
CVE-2026-73541 |
|
2026-08-19 |
| unknown |
CVE-2026-19198 — Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common BulkAc… |
vulnerability |
nvd |
CVE-2026-19198 |
|
2026-08-19 |
| unknown |
CVE-2026-55483 — Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.… |
vulnerability |
nvd |
CVE-2026-55483 |
|
2026-08-19 |
| unknown |
CVE-2026-55643 — Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS flo… |
vulnerability |
nvd |
CVE-2026-55643 |
|
2026-08-19 |
| unknown |
CVE-2026-55694 — Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /ap… |
vulnerability |
nvd |
CVE-2026-55694 |
|
2026-08-19 |
| unknown |
CVE-2026-61807 — Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier… |
vulnerability |
nvd |
CVE-2026-61807 |
|
2026-08-19 |
| unknown |
CVE-2026-75618 — Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker… |
vulnerability |
nvd |
CVE-2026-75618 |
|
2026-08-19 |
| unknown |
CVE-2026-75619 — Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authen… |
vulnerability |
nvd |
CVE-2026-75619 |
|
2026-08-19 |
| unknown |
CVE-2026-17590 — Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-32475. Reason:… |
vulnerability |
nvd |
CVE-2026-17590 |
|
2026-08-19 |
| unknown |
CVE-2026-19505 — Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirks… |
vulnerability |
nvd |
CVE-2026-19505 |
|
2026-08-19 |
| unknown |
CVE-2026-19506 — Race condition in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attack… |
vulnerability |
nvd |
CVE-2026-19506 |
|
2026-08-19 |
| unknown |
CVE-2026-19507 — Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` all… |
vulnerability |
nvd |
CVE-2026-19507 |
|
2026-08-19 |
| unknown |
CVE-2026-19508 — Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-20… |
vulnerability |
nvd |
CVE-2026-19508 |
|
2026-08-19 |
| unknown |
CVE-2026-19509 — Improper input validation in `ajaxSet_wireless_network_configuration.jst` in RDK-B WebUI `rdkb-2025q… |
vulnerability |
nvd |
CVE-2026-19509 |
|
2026-08-19 |
| unknown |
CVE-2026-54742 — Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.2… |
vulnerability |
nvd |
CVE-2026-54742 |
|
2026-08-19 |
| unknown |
CVE-2026-55090 — Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/Exp… |
vulnerability |
nvd |
CVE-2026-55090 |
|
2026-08-19 |
| unknown |
CVE-2026-61711 — BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and… |
vulnerability |
nvd |
CVE-2026-61711, CVE-2026-61712, CVE-2026-75593 |
|
2026-08-19 |
| unknown |
CVE-2026-63188 — Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto… |
vulnerability |
nvd |
CVE-2026-63188 |
|
2026-08-19 |
| unknown |
CVE-2026-68560 — Wekan is open source kanban built with Meteor. Prior to 9.75, models/fileValidation.js interpolated… |
vulnerability |
nvd |
CVE-2026-68560 |
|
2026-08-19 |
| unknown |
CVE-2026-75112 — A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insuf… |
vulnerability |
nvd |
CVE-2026-75112 |
|
2026-08-19 |
| unknown |
CVE-2026-76647 — Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JS… |
vulnerability |
nvd |
CVE-2026-76647 |
|
2026-08-19 |
| unknown |
CVE-2026-54741 — Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, Lemmy b… |
vulnerability |
nvd |
CVE-2026-54741 |
|
2026-08-19 |
| unknown |
CVE-2026-54743 — Lemmy is a link aggregator and forum for the fediverse. Prior to lemmy-ui 0.19.19-beta.1, LemmyNet/l… |
vulnerability |
nvd |
CVE-2026-54743 |
|
2026-08-19 |
| unknown |
CVE-2026-61556 — LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. From 10.26.0 unt… |
vulnerability |
nvd |
CVE-2026-61556 |
|
2026-08-19 |
| unknown |
CVE-2026-68554 — Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path att… |
vulnerability |
nvd |
CVE-2026-68554 |
|
2026-08-19 |
| unknown |
CVE-2026-75595 — Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.… |
vulnerability |
nvd |
CVE-2026-75595 |
|
2026-08-19 |
| unknown |
CVE-2026-76878 — In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects q… |
vulnerability |
nvd |
CVE-2026-76878 |
|
2026-08-19 |
| unknown |
CVE-2026-8619 — An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150… |
vulnerability |
nvd |
CVE-2026-8619 |
|
2026-08-20 |
| unknown |
CVE-2026-75628 — Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login be… |
vulnerability |
nvd |
CVE-2026-75628 |
|
2026-08-20 |
| unknown |
CVE-2025-14602 — The application generates uploaded file names using a weak and predictable method based on the reque… |
vulnerability |
nvd |
CVE-2025-14602 |
|
2026-08-20 |
| unknown |
CVE-2026-14163 — In affected versions of Octopus Server under certain circumstances it is possible for sensitive vari… |
vulnerability |
nvd |
CVE-2026-14163 |
|
2026-08-20 |
| unknown |
CVE-2026-71368 — F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged… |
vulnerability |
nvd |
CVE-2026-71368 |
|
2026-08-20 |
| unknown |
CVE-2025-14601 — An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative… |
vulnerability |
nvd |
CVE-2025-14601 |
|
2026-08-20 |
| unknown |
CVE-2026-75948 — Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The fronten… |
vulnerability |
nvd |
CVE-2026-75948 |
|
2026-08-20 |
| unknown |
CVE-2026-76564 — Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0… |
vulnerability |
nvd |
CVE-2026-76564 |
|
2026-08-20 |
| unknown |
CVE-2026-76565 — Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Car… |
vulnerability |
nvd |
CVE-2026-76565 |
|
2026-08-20 |
| unknown |
CVE-2026-76569 — Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1… |
vulnerability |
nvd |
CVE-2026-76569 |
|
2026-08-20 |
| unknown |
CVE-2026-76610 — Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment co… |
vulnerability |
nvd |
CVE-2026-76610 |
|
2026-08-20 |
| unknown |
CVE-2026-77026 — Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.… |
vulnerability |
nvd |
CVE-2026-77026 |
|
2026-08-20 |
| unknown |
CVE-2026-77069 — n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential… |
vulnerability |
nvd |
CVE-2026-77069 |
|
2026-08-20 |
| unknown |
CVE-2026-77070 — n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node… |
vulnerability |
nvd |
CVE-2026-77070 |
|
2026-08-20 |
| unknown |
CVE-2026-77071 — n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the S… |
vulnerability |
nvd |
CVE-2026-77071 |
|
2026-08-20 |
| unknown |
CVE-2026-77072 — n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting vulnerability in the… |
vulnerability |
nvd |
CVE-2026-77072 |
|
2026-08-20 |
| unknown |
CVE-2026-77073 — n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_co… |
vulnerability |
nvd |
CVE-2026-77073 |
|
2026-08-20 |
| unknown |
CVE-2026-77074 — n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image n… |
vulnerability |
nvd |
CVE-2026-77074 |
|
2026-08-20 |
| unknown |
CVE-2026-77075 — n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vul… |
vulnerability |
nvd |
CVE-2026-77075 |
|
2026-08-20 |
| unknown |
CVE-2026-77076 — n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in… |
vulnerability |
nvd |
CVE-2026-77076 |
|
2026-08-20 |
| unknown |
CVE-2026-77077 — n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape.… |
vulnerability |
nvd |
CVE-2026-77077 |
|
2026-08-20 |
| unknown |
CVE-2026-77079 — n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (r… |
vulnerability |
nvd |
CVE-2026-77079 |
|
2026-08-20 |
| unknown |
CVE-2026-77080 — n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and… |
vulnerability |
nvd |
CVE-2026-77080 |
|
2026-08-20 |
| unknown |
CVE-2026-77081 — n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in t… |
vulnerability |
nvd |
CVE-2026-77081 |
|
2026-08-20 |
| unknown |
CVE-2026-77082 — n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denia… |
vulnerability |
nvd |
CVE-2026-77082 |
|
2026-08-20 |
| unknown |
CVE-2026-77083 — n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaSc… |
vulnerability |
nvd |
CVE-2026-77083 |
|
2026-08-20 |
| unknown |
CVE-2026-77084 — n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the… |
vulnerability |
nvd |
CVE-2026-77084 |
|
2026-08-20 |
| unknown |
CVE-2026-77085 — n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent t… |
vulnerability |
nvd |
CVE-2026-77085 |
|
2026-08-20 |
| unknown |
CVE-2026-77118 — A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage()… |
vulnerability |
nvd |
CVE-2026-77118 |
|
2026-08-20 |
| unknown |
CVE-2026-7485 — Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all… |
vulnerability |
nvd |
CVE-2026-7485 |
|
2026-08-20 |
| unknown |
CVE-2026-64961 — ATutor is vulnerable to authentication bypass . Although a token validation check is present in the… |
vulnerability |
nvd |
CVE-2026-64961 |
|
2026-08-20 |
| unknown |
CVE-2026-64962 — ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attack… |
vulnerability |
nvd |
CVE-2026-64962 |
|
2026-08-20 |
| unknown |
CVE-2026-64963 — A path traversal vulnerability in ATutor allows an authenticated user to access files from other cou… |
vulnerability |
nvd |
CVE-2026-64963 |
|
2026-08-20 |
| unknown |
CVE-2026-64964 — ATutor generates predictable email confirmation tokens due to the use of insufficiently random value… |
vulnerability |
nvd |
CVE-2026-64964 |
|
2026-08-20 |
| unknown |
CVE-2026-64965 — ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints. A low-pri… |
vulnerability |
nvd |
CVE-2026-64965 |
|
2026-08-20 |
| unknown |
CVE-2026-64967 — A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative p… |
vulnerability |
nvd |
CVE-2026-64967 |
|
2026-08-20 |
| unknown |
CVE-2026-64968 — ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated admi… |
vulnerability |
nvd |
CVE-2026-64968 |
|
2026-08-20 |
| unknown |
CVE-2026-64969 — ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related en… |
vulnerability |
nvd |
CVE-2026-64969 |
|
2026-08-20 |
| unknown |
CVE-2026-64970 — ATutor is vulnerable to Stored Cross Site Scripting in registration functionality. An attacker can r… |
vulnerability |
nvd |
CVE-2026-64970 |
|
2026-08-20 |
| unknown |
CVE-2026-64971 — ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially… |
vulnerability |
nvd |
CVE-2026-64971 |
|
2026-08-20 |
| unknown |
CVE-2026-64972 — ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker… |
vulnerability |
nvd |
CVE-2026-64972 |
|
2026-08-20 |
| unknown |
CVE-2026-70383 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Esto… |
vulnerability |
nvd |
CVE-2026-70383 |
|
2026-08-20 |
| unknown |
CVE-2026-73220 — CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0… |
vulnerability |
nvd |
CVE-2026-73220 |
|
2026-08-20 |
| unknown |
CVE-2026-63040 — Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource per… |
vulnerability |
nvd |
CVE-2026-63040 |
|
2026-08-20 |
| unknown |
CVE-2026-63042 — Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can… |
vulnerability |
nvd |
CVE-2026-63042 |
|
2026-08-20 |
| unknown |
CVE-2026-63043 — Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host file… |
vulnerability |
nvd |
CVE-2026-63043 |
|
2026-08-20 |
| unknown |
CVE-2026-63044 — Server-Side Request Forgery (SSRF) vulnerability in Apache InLong. Any authenticated user (no admin… |
vulnerability |
nvd |
CVE-2026-63044 |
|
2026-08-20 |
| unknown |
CVE-2026-13121 — Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulne… |
vulnerability |
nvd |
CVE-2026-13121, CVE-2026-18262, CVE-2026-18263 |
|
2026-08-20 |
| unknown |
CVE-2026-18267 — Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability. This vulnerability al… |
vulnerability |
nvd |
CVE-2026-18267 |
|
2026-08-20 |
| unknown |
CVE-2026-18268 — Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability. This vuln… |
vulnerability |
nvd |
CVE-2026-18268 |
|
2026-08-20 |
| unknown |
CVE-2026-18269 — Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution Vulnerability. This vulne… |
vulnerability |
nvd |
CVE-2026-18269 |
|
2026-08-20 |
| unknown |
CVE-2026-18270 — Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability. T… |
vulnerability |
nvd |
CVE-2026-18270 |
|
2026-08-20 |
| unknown |
CVE-2026-18271 — Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerab… |
vulnerability |
nvd |
CVE-2026-18271 |
|
2026-08-20 |
| unknown |
CVE-2026-18272 — Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability. This vulnerability allows phys… |
vulnerability |
nvd |
CVE-2026-18272 |
|
2026-08-20 |
| unknown |
CVE-2026-18273 — Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability. This v… |
vulnerability |
nvd |
CVE-2026-18273 |
|
2026-08-20 |
| unknown |
CVE-2026-18278 — Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability. This v… |
vulnerability |
nvd |
CVE-2026-18278 |
|
2026-08-20 |
| unknown |
CVE-2026-18280 — Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allo… |
vulnerability |
nvd |
CVE-2026-18280 |
|
2026-08-20 |
| unknown |
CVE-2026-18283 — Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physica… |
vulnerability |
nvd |
CVE-2026-18283 |
|
2026-08-20 |
| unknown |
CVE-2026-18284 — Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerability. This… |
vulnerability |
nvd |
CVE-2026-18284 |
|
2026-08-20 |
| unknown |
CVE-2026-40345 — deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects.… |
vulnerability |
nvd |
CVE-2026-40345 |
|
2026-08-20 |
| unknown |
CVE-2026-54136 — Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows an… |
vulnerability |
nvd |
CVE-2026-54136 |
|
2026-08-20 |
| unknown |
CVE-2026-55095 — OpenProject is open-source, web-based project management software. In version 17.5.1 and earlier, an… |
vulnerability |
nvd |
CVE-2026-55095 |
|
2026-08-20 |
| unknown |
CVE-2026-63481 — Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In versio… |
vulnerability |
nvd |
CVE-2026-63481 |
|
2026-08-20 |
| unknown |
CVE-2026-71492 — Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, Dir… |
vulnerability |
nvd |
CVE-2026-71492 |
|
2026-08-20 |
| unknown |
CVE-2026-53425 — Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to… |
vulnerability |
nvd |
CVE-2026-53425 |
|
2026-08-20 |
| unknown |
CVE-2026-63379 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunk… |
vulnerability |
nvd |
CVE-2026-63379 |
|
2026-08-20 |
| unknown |
CVE-2026-63380 — Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid li… |
vulnerability |
nvd |
CVE-2026-63380 |
|
2026-08-20 |
| unknown |
CVE-2026-63381 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after… |
vulnerability |
nvd |
CVE-2026-63381 |
|
2026-08-20 |
| unknown |
CVE-2026-63382 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp pars… |
vulnerability |
nvd |
CVE-2026-63382 |
|
2026-08-20 |
| unknown |
CVE-2026-63383 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond… |
vulnerability |
nvd |
CVE-2026-63383 |
|
2026-08-20 |
| unknown |
CVE-2026-63384 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrec… |
vulnerability |
nvd |
CVE-2026-63384 |
|
2026-08-20 |
| unknown |
CVE-2026-63385 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP pa… |
vulnerability |
nvd |
CVE-2026-63385 |
|
2026-08-20 |
| unknown |
CVE-2026-73251 — Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impers… |
vulnerability |
nvd |
CVE-2026-73251 |
|
2026-08-20 |
| unknown |
CVE-2026-73253 — Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network at… |
vulnerability |
nvd |
CVE-2026-73253 |
|
2026-08-20 |
| unknown |
CVE-2026-15743 — Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable… |
vulnerability |
nvd |
CVE-2026-15743 |
|
2026-08-20 |
| unknown |
CVE-2026-19586 — A pre-authentication OS command injection vulnerability has been identified in Omada gateways config… |
vulnerability |
nvd |
CVE-2026-19586 |
|
2026-08-20 |
| unknown |
CVE-2026-19683 — A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During com… |
vulnerability |
nvd |
CVE-2026-19683 |
|
2026-08-20 |
| unknown |
CVE-2026-50190 — Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in… |
vulnerability |
nvd |
CVE-2026-50190 |
|
2026-08-20 |
| unknown |
CVE-2026-53569 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted to… |
vulnerability |
nvd |
CVE-2026-53569 |
|
2026-08-20 |
| unknown |
CVE-2026-62315 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_… |
vulnerability |
nvd |
CVE-2026-62315 |
|
2026-08-20 |
| unknown |
CVE-2026-63654 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted fr… |
vulnerability |
nvd |
CVE-2026-63654 |
|
2026-08-20 |
| unknown |
CVE-2026-66001 — Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and aut… |
vulnerability |
nvd |
CVE-2026-66001 |
|
2026-08-20 |
| unknown |
CVE-2026-66002 — Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-… |
vulnerability |
nvd |
CVE-2026-66002 |
|
2026-08-20 |
| unknown |
CVE-2026-9033 — An unauthenticated attacker with network access to the captive portal service of an affected device… |
vulnerability |
nvd |
CVE-2026-9033 |
|
2026-08-20 |
| unknown |
CVE-2026-19755 — NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing a… |
vulnerability |
nvd |
CVE-2026-19755 |
|
2026-08-20 |
| unknown |
CVE-2026-43798 — A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write… |
vulnerability |
nvd |
CVE-2026-43798 |
|
2026-08-20 |
| unknown |
CVE-2026-52021 — An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remote attacker to obtain sensitiv… |
vulnerability |
nvd |
CVE-2026-52021 |
|
2026-08-20 |
| unknown |
CVE-2026-70651 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips b… |
vulnerability |
nvd |
CVE-2026-70651, CVE-2026-70652 |
|
2026-08-20 |
| unknown |
CVE-2026-70653 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-s… |
vulnerability |
nvd |
CVE-2026-70653 |
|
2026-08-20 |
| unknown |
CVE-2026-70654 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applicati… |
vulnerability |
nvd |
CVE-2026-70654 |
|
2026-08-20 |
| unknown |
CVE-2026-74836 — Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unaut… |
vulnerability |
nvd |
CVE-2026-74836 |
|
2026-08-20 |
| unknown |
CVE-2026-75484 — Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows… |
vulnerability |
nvd |
CVE-2026-75484 |
|
2026-08-20 |
| unknown |
CVE-2026-76017 — Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to e… |
vulnerability |
nvd |
CVE-2026-76017 |
|
2026-08-20 |
| unknown |
CVE-2026-76020 — Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute a… |
vulnerability |
nvd |
CVE-2026-76020 |
|
2026-08-20 |
| unknown |
CVE-2026-76021 — Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute… |
vulnerability |
nvd |
CVE-2026-76021 |
|
2026-08-20 |
| unknown |
CVE-2026-76022 — Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to exe… |
vulnerability |
nvd |
CVE-2026-76022 |
|
2026-08-20 |
| unknown |
CVE-2026-76023 — Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed… |
vulnerability |
nvd |
CVE-2026-76023 |
|
2026-08-20 |
| unknown |
CVE-2025-52182 — The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure… |
vulnerability |
nvd |
CVE-2025-52182 |
|
2026-08-20 |
| unknown |
CVE-2026-50192 — Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the… |
vulnerability |
nvd |
CVE-2026-50192 |
|
2026-08-20 |
| unknown |
CVE-2026-54505 — TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK int… |
vulnerability |
nvd |
CVE-2026-54505 |
|
2026-08-20 |
| unknown |
CVE-2026-54508 — TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before n… |
vulnerability |
nvd |
CVE-2026-54508 |
|
2026-08-20 |
| unknown |
CVE-2026-55893 — Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.… |
vulnerability |
nvd |
CVE-2026-55893, CVE-2026-55894 |
|
2026-08-20 |
| unknown |
CVE-2026-64773 — An attacker that can reach a container's published TCP port may be able to force the host's forwardi… |
vulnerability |
nvd |
CVE-2026-64773 |
|
2026-08-20 |
| unknown |
CVE-2026-77644 — A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliabili… |
vulnerability |
nvd |
CVE-2026-77644 |
|
2026-08-20 |
| unknown |
CVE-2026-77646 — A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PT… |
vulnerability |
nvd |
CVE-2026-77646 |
|
2026-08-20 |
| unknown |
CVE-2026-77113 — Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allow… |
vulnerability |
nvd |
CVE-2026-77113 |
|
2026-08-20 |
| unknown |
CVE-2026-16520 — Improper input validation and Exposure of sensitive information through data queries vulnerability i… |
vulnerability |
nvd |
CVE-2026-16520 |
|
2026-08-21 |
| unknown |
CVE-2026-20679 — The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Son… |
vulnerability |
nvd |
CVE-2026-20679 |
|
2026-08-21 |
| unknown |
CVE-2026-43679 — This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An… |
vulnerability |
nvd |
CVE-2026-43679 |
|
2026-08-21 |
| unknown |
CVE-2026-76155 — Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a rem… |
vulnerability |
nvd |
CVE-2026-76155 |
|
2026-08-21 |
| unknown |
CVE-2026-76156 — OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.… |
vulnerability |
nvd |
CVE-2026-76156 |
|
2026-08-21 |
| unknown |
CVE-2026-76157 — Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management… |
vulnerability |
nvd |
CVE-2026-76157 |
|
2026-08-21 |
| unknown |
CVE-2026-62834 Azure Data Factory Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-68789 Azure SQL Database Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-69519 Azure Stack HCI Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-69851 Microsoft Entra ID Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-62703 Windows DWM Core Library Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-62754 Windows Kerberos Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-65786 Desktop Window Manager Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-55015 Microsoft Remote Help Denial of Service Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-55013 Windows Remote Help Defense Spoofing Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-70105 Microsoft Word Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-63509 Microsoft Fabric Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-65816 Azure Arc Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-66800 Azure Data Factory Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-69400 Azure Logic Apps Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-69558 Microsoft Partner Center Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-69543 Azure Virtual Machines Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-69855 Microsoft Copilot in Azure Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
CVE-2026-62705 Microsoft Brokering File System Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
CVE-2026-65675 CoPilot Chat Security Feature Bypass Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
CVE-2026-50383 Windows Print Spooler Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
CVE-2026-49798 Windows Kernel Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
CVE-2026-58647 Microsoft PowerBI Report Server Spoofing Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
CVE-2026-42912 Windows Telephony Service Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
CVE-2026-24301 Microsoft Copilot Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-18 |
| unknown |
CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-18 |
| unknown |
CVE-2026-47632 Azure Connected Machine Agent Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-18 |
| unknown |
CVE-2026-50419 Windows Kernel Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-18 |
| unknown |
CVE-2026-58612 PowerShell Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-17 |
| unknown |
CVE-2026-62886 .NET Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-17 |
| unknown |
CVE-2026-65769 Microsoft Teams iOS Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-16 |
| unknown |
CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-16 |
| unknown |
CVE-2026-65767 Microsoft Teams for Android Spoofing Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-16 |
| unknown |
CVE-2026-61347 Windows Event Logging Service Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-14 |
| unknown |
CVE-2026-62746 Win32k Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-14 |
| unknown |
CVE-2026-62777 Windows License Manager Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-14 |
| unknown |
CVE-2026-65671 Remote Access API Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-14 |
| unknown |
CVE-2026-68821 Windows Package Manager Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-14 |
| unknown |
Chromium: CVE-2026-19560 Use after free in Blink |
advisory |
vendor-blogs |
|
|
2026-08-14 |
| unknown |
Chromium: CVE-2026-19559 Use after free in HTML |
advisory |
vendor-blogs |
|
|
2026-08-14 |
| unknown |
Chromium: CVE-2026-19558 Use after free in Extensions |
advisory |
vendor-blogs |
|
|
2026-08-14 |
| unknown |
Chromium: CVE-2026-19557 Use after free in TabStrip |
advisory |
vendor-blogs |
|
|
2026-08-14 |
| unknown |
Chromium: CVE-2026-19556 Use after free in V8 |
advisory |
vendor-blogs |
|
|
2026-08-14 |
| unknown |
CVE-2026-59126 Windows Event Logging Service Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-14 |
| unknown |
CVE-2026-59119 PowerShell Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-14 |
| unknown |
CVE-2026-32153 Windows Speech Runtime Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-14 |
| unknown |
Is Cyber missing the Marque? |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
Describing attacks with crime script analysis |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
SD1791 | OTTO® Fleet Manager – Weak Password Hashing Configuration |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
NIST offers resource-constrained BACS operators practical steps to address OT cybersecurity threats and risks |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
Bitdefender traces SilkParasite cyberespionage campaign across Central Asia to seven RAT families, China-nexus tooling |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
Senators introduce bipartisan Quantum-GUARD Act to boost US electric grid against emerging quantum cyber threats |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
Georgia Cyber Resiliency Center aligns rural healthcare cybersecurity, cyber resilience with CMS Rural Health Transformation goals |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
From Hype to Operational Reality: What We Learned at AI in OT Cyber |
advisory |
vendor-blogs |
|
|
2026-08-18 |
| unknown |
Citrix urges admins to patch new NetScaler flaws as soon as possible |
news |
general-news |
|
|
2026-08-20 |
| unknown |
CISA warns of hackers exploiting critical MLflow vulnerability |
news |
general-news |
|
|
2026-08-20 |
| unknown |
New Manic Android malware can exfiltrate data through nearby devices |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Microsoft says August Windows updates may cause gaming issues |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Healthtech firm CareCloud data breach impacts 3.7 million patients |
news |
general-news |
|
|
2026-08-19 |
| unknown |
US warns of AI-powered attacks on Siemens PLCs in critical infrastructure |
news |
general-news |
|
|
2026-08-19 |
| unknown |
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure |
news |
general-news |
|
|
2026-08-20 |
| unknown |
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Why "Shady AI" is Security's Next Big Governance Problem |
news |
general-news |
|
|
2026-08-20 |
| unknown |
CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices |
news |
general-news |
|
|
2026-08-20 |
| unknown |
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands |
news |
general-news |
|
|
2026-08-20 |
| unknown |
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second |
news |
general-news |
|
|
2026-08-19 |
| unknown |
OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior |
news |
general-news |
|
|
2026-08-19 |
| unknown |
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P |
news |
general-news |
|
|
2026-08-19 |
| unknown |
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data |
news |
general-news |
|
|
2026-08-19 |
| unknown |
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation |
news |
general-news |
|
|
2026-08-19 |
| unknown |
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure |
news |
general-news |
|
|
2026-08-19 |
| unknown |
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025 |
news |
general-news |
|
|
2026-08-18 |
| unknown |
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects |
news |
general-news |
|
|
2026-08-17 |
| unknown |
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection |
news |
general-news |
|
|
2026-08-17 |
| unknown |
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch |
news |
general-news |
|
|
2026-08-15 |
| unknown |
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner |
news |
general-news |
|
|
2026-08-15 |
| unknown |
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware |
news |
general-news |
|
|
2026-08-14 |
| unknown |
Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers |
news |
general-news |
|
|
2026-08-14 |
| unknown |
New CUSTODY Framework Constrains AI Agents Inside the Network |
news |
general-news |
|
|
2026-08-20 |
| unknown |
N-able Bug Exposes Password Vault Master Keys |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks |
news |
general-news |
|
|
2026-08-20 |
| unknown |
'Grandoreiro' Malware Resurfaces With Mexico Campaign |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Agentic AI Presents New Insider Threat Model for Orgs |
news |
general-news |
|
|
2026-08-19 |
| unknown |
China-Linked Hacker Shows AI Capabilities in APAC Attack |
news |
general-news |
|
|
2026-08-19 |
| unknown |
Critical GitLab Zero-Click Flaw Poses Mitigation Challenges |
news |
general-news |
|
|
2026-08-18 |
| unknown |
'CoSnitch' Attack Tricked Copilot Into Mapping Out Architecture |
news |
general-news |
|
|
2026-08-18 |
| unknown |
The 'Industrial Accidents' Behind Rogue AI Agent Attacks — and the Sandbox Failures Exposed |
news |
general-news |
|
|
2026-08-18 |
| unknown |
Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud |
news |
general-news |
|
|
2026-08-18 |
| unknown |
Video Call Exploit Chains Two Flaws in Unisoc Modems |
news |
general-news |
|
|
2026-08-17 |
| unknown |
'Turf War' Between Claude Agents Leads to Self-Replicating Malware |
news |
general-news |
|
|
2026-08-17 |
| unknown |
Hugging Face Breach Raises Big Questions About AI Security Controls |
news |
general-news |
|
|
2026-08-17 |
| unknown |
Mission-Driven Security: Inside a Global Bank's Defense |
news |
general-news |
|
|
2026-08-14 |
| unknown |
Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI |
news |
general-news |
|
|
2026-08-14 |
| unknown |
Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office |
news |
general-news |
|
|
2026-08-14 |
| unknown |
Hackers Target Zimbra Servers in Active Exploitation Campaign |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities |
news |
general-news |
|
|
2026-08-20 |
| unknown |
MLflow Vulnerability Exploited for Cloud Credential Theft |
news |
general-news |
|
|
2026-08-20 |
| unknown |
OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Critical GitLab Flaw Exploited Shortly After Disclosure |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Exclusive: Linux Foundation's Akrites to Go Live in September |
news |
general-news |
|
|
2026-08-19 |
| unknown |
MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra |
news |
general-news |
|
|
2026-08-19 |
| unknown |
OpenAI Tightens AI Safeguards Following Hugging Face Incident |
news |
general-news |
|
|
2026-08-19 |
| unknown |
Enterprise Applications Carry 4.31x More Critical and High Vulnerabilities |
news |
general-news |
|
|
2026-08-18 |
| unknown |
NASA Ground Control Software Flaw Enables Unauthenticated Commands |
news |
general-news |
|
|
2026-08-18 |
| unknown |
Cyber Incident Disrupts Student Services at UT San Antonio |
news |
general-news |
|
|
2026-08-18 |
| unknown |
WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover |
news |
general-news |
|
|
2026-08-17 |
| unknown |
SafePal Data Breach Hits Tens of Thousands of Customers |
news |
general-news |
|
|
2026-08-17 |
| unknown |
Corero brings cloud-based AI threat analysis to SmartWall ONE |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Researchers find a loophole that lets expired credit cards make unauthorized payments |
news |
general-news |
|
|
2026-08-20 |
| unknown |
8,539 reasons to rethink how vulnerabilities get patched |
news |
general-news |
|
|
2026-08-20 |
| unknown |
China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Electronic health record company CareCloud says 3.7 million people affected by breach |
news |
general-news |
|
|
2026-08-19 |
| unknown |
NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology |
news |
general-news |
|
|
2026-08-19 |
| unknown |
Latvian officials resign after cyberattack exposes data on 1.2 million people |
news |
general-news |
|
|
2026-08-19 |
| unknown |
The push to designate AI as the next critical infrastructure sector |
news |
general-news |
|
|
2026-08-20 |
| unknown |
AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn |
news |
general-news |
|
|
2026-08-19 |
| unknown |
Details emerge on BlackFile’s recent attacks on financial companies |
news |
general-news |
|
|
2026-08-17 |
| unknown |
Irregular says ‘human oversight’ responsible for AI sandbox escape incidents |
news |
general-news |
|
|
2026-08-17 |