← Dashboard

OSINT Threat Intelligence Report

2026-08-21 — Generated 2026-08-21 03:01:29 UTC — 3339 items

Daily Weekly Monthly Full JSON | Markdown

Total Items

3257

By Source

cisa-kev8
nvd3068
cisa-advisories7
vendor-blogs87
malware-bazaar9
abuse-ipdb20
threatfox2
otx33
general-news112

By Category

vulnerability3073
advisory91
malware9
ip-reputation20
threat-intel35
news111

Fetch Errors

None

Top 10 Highlights

SeverityTitleSourceCVEsTags
critical CVE-2026-72530 — TrueConf Server Code Injection Vulnerability cisa-kev, nvd CVE-2026-72530
critical CVE-2026-72529 — TrueConf Server Missing Authentication for Critical Function Vulnerability cisa-kev, nvd CVE-2026-72529
critical CVE-2026-64849 — MLflow Server-Side Request Forgery Vulnerability cisa-kev, nvd CVE-2026-64849, CVE-2026-69146, CVE-2026-69148
critical Siemens Simcenter Nastran cisa-advisories, vendor-blogs ics, rce
critical CVE-2026-19626 — A remote code execution vulnerability exists in Tenable Security Center's report generation function… nvd CVE-2026-19626 rce
critical CVE-2026-47766 — crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's defau… nvd CVE-2026-47766 ransomware
critical CVE-2026-19681 — An authenticated command injection vulnerability exists in Security Center related to file upload pr… nvd CVE-2026-19681
critical CVE-2026-19682 — A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker… nvd CVE-2026-19682
critical CVE-2026-48528 — Metacat is data repository software that helps researchers preserve, share, and discover data. Metac… nvd CVE-2026-48528
critical CVE-2026-73849 — Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=r… nvd CVE-2026-73849

All Items

Showing 3257 items

Severity Title Category Source Indicators Tags Published
critical CVE-2026-72530 — TrueConf Server Code Injection Vulnerability vulnerability cisa-kev, nvd CVE-2026-72530 2026-08-20
critical CVE-2026-72529 — TrueConf Server Missing Authentication for Critical Function Vulnerability vulnerability cisa-kev, nvd CVE-2026-72529 2026-08-20
critical CVE-2026-64849 — MLflow Server-Side Request Forgery Vulnerability vulnerability cisa-kev, nvd CVE-2026-64849, CVE-2026-69146, CVE-2026-69148 2026-08-19
critical Siemens Simcenter Nastran advisory cisa-advisories, vendor-blogs ics, rce 2026-08-18
critical CVE-2026-19626 — A remote code execution vulnerability exists in Tenable Security Center's report generation function… vulnerability nvd CVE-2026-19626 rce 2026-08-14
critical CVE-2026-47766 — crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's defau… vulnerability nvd CVE-2026-47766 ransomware 2026-08-14
critical CVE-2026-19681 — An authenticated command injection vulnerability exists in Security Center related to file upload pr… vulnerability nvd CVE-2026-19681 2026-08-14
critical CVE-2026-19682 — A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker… vulnerability nvd CVE-2026-19682 2026-08-14
critical CVE-2026-48528 — Metacat is data repository software that helps researchers preserve, share, and discover data. Metac… vulnerability nvd CVE-2026-48528 2026-08-14
critical CVE-2026-73849 — Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=r… vulnerability nvd CVE-2026-73849 2026-08-14
critical CVE-2026-19188 — A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gatew… vulnerability nvd CVE-2026-19188 2026-08-14
critical CVE-2026-49457 — erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not au… vulnerability nvd CVE-2026-49457 2026-08-14
critical CVE-2026-50027 — mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes… vulnerability nvd CVE-2026-50027 2026-08-14
critical CVE-2026-73678 — MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution… vulnerability nvd CVE-2026-73678 rce 2026-08-14
critical CVE-2026-17181 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary loc… vulnerability nvd CVE-2026-17181 2026-08-14
critical CVE-2026-17182 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and ob… vulnerability nvd CVE-2026-17182 2026-08-14
critical CVE-2026-17184 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due t… vulnerability nvd CVE-2026-17184 2026-08-14
critical CVE-2026-17186 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL command… vulnerability nvd CVE-2026-17186 2026-08-14
critical CVE-2026-19909 — PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnera… vulnerability nvd CVE-2026-19909 rce 2026-08-14
critical CVE-2026-19910 — PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnera… vulnerability nvd CVE-2026-19910 rce 2026-08-14
critical CVE-2026-14484 — The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arb… vulnerability nvd CVE-2026-14484 rce 2026-08-15
critical CVE-2026-15303 — The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to,… vulnerability nvd CVE-2026-15303 2026-08-15
critical CVE-2026-15341 — The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to… vulnerability nvd CVE-2026-15341 2026-08-15
critical CVE-2026-68457 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials fo… vulnerability nvd CVE-2026-68457 2026-08-15
critical CVE-2026-68476 — In the Linux kernel, the following vulnerability has been resolved: ipvs: reload ip header after hea… vulnerability nvd CVE-2026-68476 2026-08-15
critical CVE-2026-68477 — In the Linux kernel, the following vulnerability has been resolved: ipvs: fix more places with wrong… vulnerability nvd CVE-2026-68477 2026-08-15
critical CVE-2026-72014 — In the Linux kernel, the following vulnerability has been resolved: drbd: reject data replies with a… vulnerability nvd CVE-2026-72014 2026-08-15
critical CVE-2026-72020 — In the Linux kernel, the following vulnerability has been resolved: ipvs: reset full ip_vs_seq struc… vulnerability nvd CVE-2026-72020 2026-08-15
critical CVE-2026-72033 — In the Linux kernel, the following vulnerability has been resolved: orangefs: keep the readdir entry… vulnerability nvd CVE-2026-72033 2026-08-15
critical CVE-2026-72041 — In the Linux kernel, the following vulnerability has been resolved: espintcp: use sk_msg_free_partia… vulnerability nvd CVE-2026-72041 2026-08-15
critical CVE-2026-72046 — In the Linux kernel, the following vulnerability has been resolved: gve: fix header buffer corruptio… vulnerability nvd CVE-2026-72046 2026-08-15
critical CVE-2026-72064 — In the Linux kernel, the following vulnerability has been resolved: net: mana: Sync page pool RX fra… vulnerability nvd CVE-2026-72064 2026-08-15
critical CVE-2026-72065 — In the Linux kernel, the following vulnerability has been resolved: net: mana: Validate the packet l… vulnerability nvd CVE-2026-72065 2026-08-15
critical CVE-2026-72069 — In the Linux kernel, the following vulnerability has been resolved: locking/rt: Fix the incorrect RC… vulnerability nvd CVE-2026-72069 2026-08-15
critical CVE-2026-72083 — In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix iSCSI IS… vulnerability nvd CVE-2026-72083 2026-08-15
critical CVE-2026-72084 — In the Linux kernel, the following vulnerability has been resolved: scsi: target: Bound PR-OUT Trans… vulnerability nvd CVE-2026-72084 2026-08-15
critical CVE-2026-72085 — In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Free unsubm… vulnerability nvd CVE-2026-72085 2026-08-15
critical CVE-2026-72098 — In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix buffer overflow i… vulnerability nvd CVE-2026-72098 2026-08-15
critical CVE-2026-72129 — In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: handle inline data w… vulnerability nvd CVE-2026-72129 2026-08-15
critical CVE-2026-72130 — In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: reject short AUTH_RE… vulnerability nvd CVE-2026-72130 2026-08-15
critical CVE-2026-72137 — In the Linux kernel, the following vulnerability has been resolved: xfrm: nat_keepalive: avoid doubl… vulnerability nvd CVE-2026-72137 2026-08-15
critical CVE-2026-72139 — In the Linux kernel, the following vulnerability has been resolved: tcp: defer md5sig_info kfree pas… vulnerability nvd CVE-2026-72139 2026-08-15
critical CVE-2026-72185 — In the Linux kernel, the following vulnerability has been resolved: ntfs: fix WARN_ON for resident a… vulnerability nvd CVE-2026-72185 2026-08-15
critical CVE-2026-72186 — In the Linux kernel, the following vulnerability has been resolved: ntfs: make system files immutabl… vulnerability nvd CVE-2026-72186 2026-08-15
critical CVE-2026-72188 — In the Linux kernel, the following vulnerability has been resolved: ntfs: sanitize MFT references re… vulnerability nvd CVE-2026-72188 2026-08-15
critical CVE-2026-72191 — In the Linux kernel, the following vulnerability has been resolved: ntfs3: validate split-point offs… vulnerability nvd CVE-2026-72191 2026-08-15
critical CVE-2026-72192 — In the Linux kernel, the following vulnerability has been resolved: ntfs3: bound to_move in indx_ins… vulnerability nvd CVE-2026-72192 2026-08-15
critical CVE-2026-72193 — In the Linux kernel, the following vulnerability has been resolved: ntfs3: cap RESTART_TABLE free-ch… vulnerability nvd CVE-2026-72193 ransomware 2026-08-15
critical CVE-2026-72194 — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: add depth limit to ind… vulnerability nvd CVE-2026-72194 2026-08-15
critical CVE-2026-72199 — In the Linux kernel, the following vulnerability has been resolved: ntfs: validate resident index ro… vulnerability nvd CVE-2026-72199 2026-08-15
critical CVE-2026-72200 — In the Linux kernel, the following vulnerability has been resolved: ntfs: detect mapping-pairs LCN a… vulnerability nvd CVE-2026-72200 2026-08-15
critical CVE-2026-72201 — In the Linux kernel, the following vulnerability has been resolved: ntfs: validate index entries on… vulnerability nvd CVE-2026-72201 2026-08-15
critical CVE-2026-72206 — In the Linux kernel, the following vulnerability has been resolved: ntfs: validate index block heade… vulnerability nvd CVE-2026-72206 2026-08-15
critical CVE-2026-72207 — In the Linux kernel, the following vulnerability has been resolved: ntfs: not change 0-byte $DATA at… vulnerability nvd CVE-2026-72207 2026-08-15
critical CVE-2026-72208 — In the Linux kernel, the following vulnerability has been resolved: ntfs: add bounds check before ac… vulnerability nvd CVE-2026-72208 2026-08-15
critical CVE-2026-72209 — In the Linux kernel, the following vulnerability has been resolved: ntfs: validate attribute values… vulnerability nvd CVE-2026-72209 2026-08-15
critical CVE-2026-72210 — In the Linux kernel, the following vulnerability has been resolved: ntfs: fix off-by-one in mapping… vulnerability nvd CVE-2026-72210 2026-08-15
critical CVE-2026-72211 — In the Linux kernel, the following vulnerability has been resolved: ntfs: grow index root value befo… vulnerability nvd CVE-2026-72211 2026-08-15
critical CVE-2026-72217 — In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Bound-check xdr_buf_to_b… vulnerability nvd CVE-2026-72217 2026-08-15
critical CVE-2026-72220 — In the Linux kernel, the following vulnerability has been resolved: sunrpc: harden rq_procinfo lifec… vulnerability nvd CVE-2026-72220 2026-08-15
critical CVE-2026-72221 — In the Linux kernel, the following vulnerability has been resolved: sunrpc: wait for in-flight TLS h… vulnerability nvd CVE-2026-72221 2026-08-15
critical CVE-2026-72222 — In the Linux kernel, the following vulnerability has been resolved: sunrpc: pin svc_xprt across the… vulnerability nvd CVE-2026-72222 2026-08-15
critical CVE-2026-72226 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: prevent TVLV OOB… vulnerability nvd CVE-2026-72226 2026-08-15
critical CVE-2026-72234 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: access unicast_ttvn… vulnerability nvd CVE-2026-72234 2026-08-15
critical CVE-2026-72239 — In the Linux kernel, the following vulnerability has been resolved: x86/virt/sev: Revert "Drop WBINV… vulnerability nvd CVE-2026-72239 2026-08-15
critical CVE-2026-72248 — In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: support IP… vulnerability nvd CVE-2026-72248 2026-08-15
critical CVE-2026-72249 — In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: use dst in… vulnerability nvd CVE-2026-72249 2026-08-15
critical CVE-2026-72251 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: reload po… vulnerability nvd CVE-2026-72251 2026-08-15
critical CVE-2026-72277 — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Inject SEA if gu… vulnerability nvd CVE-2026-72277 2026-08-15
critical CVE-2026-72278 — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Re-translate VNC… vulnerability nvd CVE-2026-72278 2026-08-15
critical CVE-2026-72279 — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Respect read-onl… vulnerability nvd CVE-2026-72279 2026-08-15
critical CVE-2026-72288 — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Handle race be… vulnerability nvd CVE-2026-72288 2026-08-15
critical CVE-2026-72289 — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Check the inte… vulnerability nvd CVE-2026-72289 2026-08-15
critical CVE-2026-72291 — In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix unlikely race in… vulnerability nvd CVE-2026-72291 2026-08-15
critical CVE-2026-72296 — In the Linux kernel, the following vulnerability has been resolved: net: ife: require ETH_HLEN to be… vulnerability nvd CVE-2026-72296 2026-08-15
critical CVE-2026-72299 — In the Linux kernel, the following vulnerability has been resolved: tipc: restrict socket queue dump… vulnerability nvd CVE-2026-72299 botnet 2026-08-15
critical CVE-2026-72313 — In the Linux kernel, the following vulnerability has been resolved: drm/fb-helper: Only consider act… vulnerability nvd CVE-2026-72313 ransomware 2026-08-15
critical CVE-2026-72317 — In the Linux kernel, the following vulnerability has been resolved: SUNRPC: pin upper rpc_clnt acros… vulnerability nvd CVE-2026-72317 2026-08-15
critical CVE-2026-72318 — In the Linux kernel, the following vulnerability has been resolved: cifs: validate DFS referral stri… vulnerability nvd CVE-2026-72318 2026-08-15
critical CVE-2026-72319 — In the Linux kernel, the following vulnerability has been resolved: ipvs: ensure inner headers in IC… vulnerability nvd CVE-2026-72319 2026-08-15
critical CVE-2026-72320 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_lookup: fix catch… vulnerability nvd CVE-2026-72320 2026-08-15
critical CVE-2026-72322 — In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Fix potential UAF i… vulnerability nvd CVE-2026-72322 2026-08-15
critical CVE-2026-72323 — In the Linux kernel, the following vulnerability has been resolved: ipv4: igmp: Fix potential UAF in… vulnerability nvd CVE-2026-72323 2026-08-15
critical CVE-2026-72329 — In the Linux kernel, the following vulnerability has been resolved: net/liquidio: drop cached VF pci… vulnerability nvd CVE-2026-72329 2026-08-15
critical CVE-2026-72339 — In the Linux kernel, the following vulnerability has been resolved: qede: fix off-by-one in BD ring… vulnerability nvd CVE-2026-72339 2026-08-15
critical CVE-2026-72348 — In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6tables: mark malfo… vulnerability nvd CVE-2026-72348 2026-08-15
critical CVE-2026-72351 — In the Linux kernel, the following vulnerability has been resolved: gue: validate REMCSUM private op… vulnerability nvd CVE-2026-72351 2026-08-15
critical CVE-2026-72355 — In the Linux kernel, the following vulnerability has been resolved: netfs: Fix barriering when walki… vulnerability nvd CVE-2026-72355 2026-08-15
critical CVE-2026-72366 — In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_create_write_re… vulnerability nvd CVE-2026-72366 2026-08-15
critical CVE-2026-72381 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of fp-… vulnerability nvd CVE-2026-72381 2026-08-15
critical CVE-2026-72393 — In the Linux kernel, the following vulnerability has been resolved: eth: fbnic: don't cache shinfo a… vulnerability nvd CVE-2026-72393 2026-08-15
critical CVE-2026-72398 — In the Linux kernel, the following vulnerability has been resolved: sctp: add INIT verification afte… vulnerability nvd CVE-2026-72398 2026-08-15
critical CVE-2026-72399 — In the Linux kernel, the following vulnerability has been resolved: net: enetc: check the number of… vulnerability nvd CVE-2026-72399 2026-08-15
critical CVE-2026-72407 — In the Linux kernel, the following vulnerability has been resolved: geneve: validate inner network o… vulnerability nvd CVE-2026-72407 2026-08-15
critical CVE-2026-72408 — In the Linux kernel, the following vulnerability has been resolved: geneve: gate GRO hint in geneve_… vulnerability nvd CVE-2026-72408 2026-08-15
critical CVE-2026-72412 — In the Linux kernel, the following vulnerability has been resolved: s390/mm: Fix handling of _PAGE_U… vulnerability nvd CVE-2026-72412 2026-08-15
critical CVE-2026-72417 — In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: Validate i… vulnerability nvd CVE-2026-72417 2026-08-15
critical CVE-2026-72421 — In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: Don't ignore error ro… vulnerability nvd CVE-2026-72421 2026-08-15
critical CVE-2026-72422 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of con… vulnerability nvd CVE-2026-72422 2026-08-15
critical CVE-2026-72429 — In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix type confusion o… vulnerability nvd CVE-2026-72429 2026-08-15
critical CVE-2026-72436 — In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Don't use test… vulnerability nvd CVE-2026-72436 2026-08-15
critical CVE-2026-72442 — In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: fix and si… vulnerability nvd CVE-2026-72442 2026-08-15
critical CVE-2026-72451 — In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix xfrm state cache inser… vulnerability nvd CVE-2026-72451 2026-08-15
critical CVE-2026-72463 — In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix dev use-after-free in… vulnerability nvd CVE-2026-72463 2026-08-15
critical CVE-2026-72466 — In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Fix bcall rep leak and… vulnerability nvd CVE-2026-72466 2026-08-15
critical CVE-2026-72472 — In the Linux kernel, the following vulnerability has been resolved: nfs: use nfsi->rwsem to protect… vulnerability nvd CVE-2026-72472 2026-08-15
critical CVE-2026-72473 — In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Decouple req recycling… vulnerability nvd CVE-2026-72473 2026-08-15
critical CVE-2026-72477 — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: call _ntfs_bad_inode()… vulnerability nvd CVE-2026-72477 2026-08-15
critical CVE-2026-72491 — In the Linux kernel, the following vulnerability has been resolved: net/9p: fix race condition on rd… vulnerability nvd CVE-2026-72491 2026-08-15
critical CVE-2026-72493 — In the Linux kernel, the following vulnerability has been resolved: net: serialize netif_running() c… vulnerability nvd CVE-2026-72493 2026-08-15
critical CVE-2026-72494 — In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Replace waitqueue an… vulnerability nvd CVE-2026-72494 2026-08-15
critical CVE-2026-72495 — In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Avoid repeated req… vulnerability nvd CVE-2026-72495 2026-08-15
critical CVE-2026-72496 — In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Proper rollback if… vulnerability nvd CVE-2026-72496 2026-08-15
critical CVE-2026-72498 — In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Avoid displaying t… vulnerability nvd CVE-2026-72498 ransomware 2026-08-15
critical CVE-2026-74255 — In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in tipc_l2_send_ms… vulnerability nvd CVE-2026-74255 2026-08-15
critical CVE-2026-74267 — In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_codel: Do not cal… vulnerability nvd CVE-2026-74267 2026-08-15
critical CVE-2026-74268 — In the Linux kernel, the following vulnerability has been resolved: tcp: clear sock_ops cb flags bef… vulnerability nvd CVE-2026-74268 2026-08-15
critical CVE-2026-74269 — In the Linux kernel, the following vulnerability has been resolved: bnxt: fix head underflow on XDP… vulnerability nvd CVE-2026-74269 2026-08-15
critical CVE-2026-74279 — In the Linux kernel, the following vulnerability has been resolved: crypto: cavium/cpt - fix DMA cle… vulnerability nvd CVE-2026-74279 2026-08-15
critical CVE-2026-74280 — In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/octeontx - fix D… vulnerability nvd CVE-2026-74280 2026-08-15
critical CVE-2026-74287 — In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded address… vulnerability nvd CVE-2026-74287 2026-08-15
critical CVE-2026-74309 — In the Linux kernel, the following vulnerability has been resolved: vdpa/octeon_ep: fix IRQ-to-ring… vulnerability nvd CVE-2026-74309 2026-08-15
critical CVE-2026-74310 — In the Linux kernel, the following vulnerability has been resolved: vhost/net: complete zerocopy ubu… vulnerability nvd CVE-2026-74310 2026-08-15
critical CVE-2026-74315 — In the Linux kernel, the following vulnerability has been resolved: lockd: Avoid hashing uninitializ… vulnerability nvd CVE-2026-74315 2026-08-15
critical CVE-2026-74345 — In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix endpoint/socket as… vulnerability nvd CVE-2026-74345 2026-08-15
critical CVE-2026-74350 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate fast symlink tar… vulnerability nvd CVE-2026-74350 2026-08-15
critical CVE-2026-74361 — In the Linux kernel, the following vulnerability has been resolved: nvme: fix FDP fdpcidx bounds che… vulnerability nvd CVE-2026-74361 2026-08-15
critical CVE-2026-74376 — In the Linux kernel, the following vulnerability has been resolved: md/raid10: reset read_slot when… vulnerability nvd CVE-2026-74376 2026-08-15
critical CVE-2026-74384 — In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: fix flex array s… vulnerability nvd CVE-2026-74384 botnet 2026-08-15
critical CVE-2026-74394 — In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: fix integer overflow… vulnerability nvd CVE-2026-74394 2026-08-15
critical CVE-2026-74398 — In the Linux kernel, the following vulnerability has been resolved: ipv6: addrconf: bail out of dad_… vulnerability nvd CVE-2026-74398 2026-08-15
critical CVE-2026-74401 — In the Linux kernel, the following vulnerability has been resolved: dlm: fix add msg handle in send_… vulnerability nvd CVE-2026-74401 2026-08-15
critical CVE-2026-74406 — In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix potential null-ptr-de… vulnerability nvd CVE-2026-74406 2026-08-15
critical CVE-2026-74424 — In the Linux kernel, the following vulnerability has been resolved: fbcon: fix NULL pointer derefere… vulnerability nvd CVE-2026-74424 ransomware 2026-08-15
critical CVE-2026-74427 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix netns teardown to cance… vulnerability nvd CVE-2026-74427 2026-08-15
critical CVE-2026-74428 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix double unlock in rxrp… vulnerability nvd CVE-2026-74428 2026-08-15
critical CVE-2026-74433 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix UAF in rxgk_issue_cha… vulnerability nvd CVE-2026-74433 2026-08-15
critical CVE-2026-74434 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: Don't move a peeked OOB m… vulnerability nvd CVE-2026-74434 2026-08-15
critical CVE-2026-74436 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: serialize kernel accept p… vulnerability nvd CVE-2026-74436 2026-08-15
critical CVE-2026-74439 — In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit be… vulnerability nvd CVE-2026-74439 2026-08-15
critical CVE-2026-15826 — The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confus… vulnerability nvd CVE-2026-15826 2026-08-15
critical CVE-2026-16142 — The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and inc… vulnerability nvd CVE-2026-16142 2026-08-15
critical CVE-2026-73193 — DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wr… vulnerability nvd CVE-2026-73193 2026-08-15
critical CVE-2026-73194 — DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric place… vulnerability nvd CVE-2026-73194 2026-08-15
critical CVE-2026-74473 — In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull… vulnerability nvd CVE-2026-74473, CVE-2026-74474 2026-08-15
critical CVE-2026-74475 — In the Linux kernel, the following vulnerability has been resolved: vxlan: use neigh_ha_snapshot() i… vulnerability nvd CVE-2026-74475 2026-08-15
critical CVE-2026-74476 — In the Linux kernel, the following vulnerability has been resolved: veth: convert frag_list skbs bef… vulnerability nvd CVE-2026-74476 2026-08-15
critical CVE-2026-74478 — In the Linux kernel, the following vulnerability has been resolved: um: vector: fix use-after-free i… vulnerability nvd CVE-2026-74478 2026-08-15
critical CVE-2026-74480 — In the Linux kernel, the following vulnerability has been resolved: net: bridge: stop fast-leave aft… vulnerability nvd CVE-2026-74480 2026-08-15
critical CVE-2026-74486 — In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: use exe_file_deny_w… vulnerability nvd CVE-2026-74486 ransomware 2026-08-15
critical CVE-2026-74493 — In the Linux kernel, the following vulnerability has been resolved: net/smc: fix socket use-after-fr… vulnerability nvd CVE-2026-74493 2026-08-15
critical CVE-2026-74495 — In the Linux kernel, the following vulnerability has been resolved: igbvf: Fix leak in TX DMA error… vulnerability nvd CVE-2026-74495 2026-08-15
critical CVE-2026-74517 — In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Cancel delayed I/O API… vulnerability nvd CVE-2026-74517 2026-08-15
critical CVE-2026-74521 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: use memcmp() to compare C… vulnerability nvd CVE-2026-74521 2026-08-15
critical CVE-2026-74545 — In the Linux kernel, the following vulnerability has been resolved: rtase: fix double free of multi-… vulnerability nvd CVE-2026-74545 2026-08-15
critical CVE-2026-74556 — In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi_tcp: Bound SCSI R… vulnerability nvd CVE-2026-74556 2026-08-15
critical CVE-2026-74568 — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Fix race betwe… vulnerability nvd CVE-2026-74568 2026-08-15
critical CVE-2026-74569 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: wid… vulnerability nvd CVE-2026-74569 2026-08-15
critical CVE-2026-74570 — In the Linux kernel, the following vulnerability has been resolved: ntfs: harden runlist realloc siz… vulnerability nvd CVE-2026-74570 2026-08-15
critical CVE-2026-74573 — In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3-iommufd: Requi… vulnerability nvd CVE-2026-74573 2026-08-15
critical CVE-2026-15689 — Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisonin… vulnerability nvd CVE-2026-15689 2026-08-15
critical CVE-2026-19598 — The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalatio… vulnerability nvd CVE-2026-19598 2026-08-15
critical CVE-2026-18855 — The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f… vulnerability nvd CVE-2026-18855 rce 2026-08-15
critical CVE-2026-73041 — SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the se… vulnerability nvd CVE-2026-73041 2026-08-15
critical CVE-2026-73042 — SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing… vulnerability nvd CVE-2026-73042 2026-08-15
critical CVE-2026-73043 — SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculat… vulnerability nvd CVE-2026-73043 rce 2026-08-15
critical CVE-2026-73044 — SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored… vulnerability nvd CVE-2026-73044 2026-08-15
critical CVE-2026-73046 — SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middl… vulnerability nvd CVE-2026-73046 2026-08-15
critical CVE-2026-73050 — SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select op… vulnerability nvd CVE-2026-73050 2026-08-15
critical CVE-2026-73052 — SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them d… vulnerability nvd CVE-2026-73052 2026-08-15
critical CVE-2026-73053 — SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji func… vulnerability nvd CVE-2026-73053 2026-08-15
critical CVE-2026-19924 — A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability… vulnerability nvd CVE-2026-19924 2026-08-16
critical CVE-2026-14524 — The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insuf… vulnerability nvd CVE-2026-14524 rce 2026-08-16
critical CVE-2026-16098 — The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all version… vulnerability nvd CVE-2026-16098 rce 2026-08-16
critical CVE-2026-18432 — The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all v… vulnerability nvd CVE-2026-18432 2026-08-16
critical CVE-2026-18316 — The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data du… vulnerability nvd CVE-2026-18316 2026-08-16
critical CVE-2026-19714 — The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google iden… vulnerability nvd CVE-2026-19714 2026-08-16
critical CVE-2026-19725 — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value… vulnerability nvd CVE-2026-19725 2026-08-16
critical CVE-2026-19349 — Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 befo… vulnerability nvd CVE-2026-19349 ransomware 2026-08-16
critical CVE-2026-72887 — Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OA… vulnerability nvd CVE-2026-72887 2026-08-16
critical CVE-2026-73056 — SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication atte… vulnerability nvd CVE-2026-73056 2026-08-16
critical CVE-2026-73061 — Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that al… vulnerability nvd CVE-2026-73061 2026-08-16
critical CVE-2026-74790 — Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter change… vulnerability nvd CVE-2026-74790 2026-08-16
critical CVE-2026-19959 — A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetu… vulnerability nvd CVE-2026-19959 2026-08-16
critical CVE-2026-19961 — A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of… vulnerability nvd CVE-2026-19961 2026-08-16
critical CVE-2026-19977 — A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function http… vulnerability nvd CVE-2026-19977 2026-08-17
critical CVE-2026-74799 — SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps w… vulnerability nvd CVE-2026-74799 2026-08-17
critical CVE-2026-74800 — SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when servin… vulnerability nvd CVE-2026-74800 2026-08-17
critical CVE-2026-74872 — openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirl… vulnerability nvd CVE-2026-74872 2026-08-17
critical CVE-2026-74875 — openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema libra… vulnerability nvd CVE-2026-74875 2026-08-17
critical CVE-2026-74876 — openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that cr… vulnerability nvd CVE-2026-74876 2026-08-17
critical CVE-2026-74878 — openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection… vulnerability nvd CVE-2026-74878 2026-08-17
critical CVE-2026-74880 — openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and… vulnerability nvd CVE-2026-74880 2026-08-17
critical CVE-2026-74886 — openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the Plugin… vulnerability nvd CVE-2026-74886 2026-08-17
critical CVE-2026-74889 — openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normali… vulnerability nvd CVE-2026-74889 2026-08-17
critical CVE-2026-74891 — openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server co… vulnerability nvd CVE-2026-74891 2026-08-17
critical CVE-2026-74894 — openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token… vulnerability nvd CVE-2026-74894 2026-08-17
critical CVE-2026-74895 — openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isol… vulnerability nvd CVE-2026-74895 2026-08-17
critical CVE-2026-74896 — openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPattern… vulnerability nvd CVE-2026-74896 2026-08-17
critical CVE-2026-74899 — openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecut… vulnerability nvd CVE-2026-74899 2026-08-17
critical CVE-2026-74900 — openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsula… vulnerability nvd CVE-2026-74900 2026-08-17
critical CVE-2026-74901 — openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where… vulnerability nvd CVE-2026-74901 2026-08-17
critical CVE-2026-74843 — A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerabilit… vulnerability nvd CVE-2026-74843 2026-08-17
critical CVE-2026-14564 — Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consul… vulnerability nvd CVE-2026-14564 2026-08-17
critical CVE-2026-71566 — FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware… vulnerability nvd CVE-2026-71566 2026-08-17
critical CVE-2026-53960 — Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0… vulnerability nvd CVE-2026-53960, CVE-2026-55674 2026-08-17
critical CVE-2026-64859 — New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management sys… vulnerability nvd CVE-2026-64859, CVE-2026-64865, CVE-2026-64866, CVE-2026-64868, CVE-2026-71479 2026-08-17
critical CVE-2026-75045 — In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker c… vulnerability nvd CVE-2026-75045 2026-08-17
critical CVE-2026-50768 — File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a r… vulnerability nvd CVE-2026-50768 2026-08-17
critical CVE-2026-50769 — The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Inj… vulnerability nvd CVE-2026-50769 2026-08-17
critical CVE-2026-50770 — An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges… vulnerability nvd CVE-2026-50770 2026-08-17
critical CVE-2026-50772 — An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via… vulnerability nvd CVE-2026-50772 2026-08-17
critical CVE-2026-51346 — SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote att… vulnerability nvd CVE-2026-51346 2026-08-17
critical CVE-2026-74253 — Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in… vulnerability nvd CVE-2026-74253 rce 2026-08-17
critical CVE-2026-50774 — An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Ma… vulnerability nvd CVE-2026-50774 2026-08-17
critical CVE-2026-50775 — A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the… vulnerability nvd CVE-2026-50775 2026-08-17
critical CVE-2026-66792 — A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a use… vulnerability nvd CVE-2026-66792 2026-08-17
critical CVE-2026-19478 — GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.… vulnerability nvd CVE-2026-19478, CVE-2026-19650 2026-08-17
critical CVE-2026-67678 — File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute ar… vulnerability nvd CVE-2026-67678 2026-08-17
critical CVE-2026-68004 — An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitra… vulnerability nvd CVE-2026-68004 2026-08-17
critical CVE-2026-71472 — A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such a… vulnerability nvd CVE-2026-71472 2026-08-17
critical CVE-2026-39254 — Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execut… vulnerability nvd CVE-2026-39254, CVE-2026-39255 2026-08-17
critical CVE-2026-47686 — vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbo… vulnerability nvd CVE-2026-47686 2026-08-17
critical CVE-2026-47698 — vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.j… vulnerability nvd CVE-2026-47698 2026-08-17
critical CVE-2026-65640 — WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file uploa… vulnerability nvd CVE-2026-65640 rce 2026-08-17
critical CVE-2026-65974 — ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0,… vulnerability nvd CVE-2026-65974 rce 2026-08-17
critical CVE-2026-66795 — A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto… vulnerability nvd CVE-2026-66795 2026-08-17
critical CVE-2026-67917 — zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup res… vulnerability nvd CVE-2026-67917 2026-08-17
critical CVE-2026-67926 — An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Param… vulnerability nvd CVE-2026-67926 2026-08-17
critical CVE-2026-67965 — An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the… vulnerability nvd CVE-2026-67965 2026-08-17
critical CVE-2026-67966 — Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activ… vulnerability nvd CVE-2026-67966 2026-08-17
critical CVE-2026-67967 — Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary… vulnerability nvd CVE-2026-67967 2026-08-17
critical CVE-2026-75106 — OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an em… vulnerability nvd CVE-2026-75106 2026-08-17
critical CVE-2026-75110 — MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is en… vulnerability nvd CVE-2026-75110 2026-08-17
critical CVE-2026-42163 — Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Lear… vulnerability nvd CVE-2026-42163 2026-08-17
critical CVE-2026-51977 — An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically… vulnerability nvd CVE-2026-51977 2026-08-17
critical CVE-2026-67854 — SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code vulnerability nvd CVE-2026-67854 2026-08-17
critical CVE-2026-67868 — A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter hand… vulnerability nvd CVE-2026-67868 2026-08-17
critical CVE-2026-67960 — An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.… vulnerability nvd CVE-2026-67960 2026-08-17
critical CVE-2026-71424 — Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers… vulnerability nvd CVE-2026-71424 2026-08-17
critical CVE-2026-38165 — A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration… vulnerability nvd CVE-2026-38165 2026-08-17
critical CVE-2026-42162 — Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certai… vulnerability nvd CVE-2026-42162 2026-08-17
critical CVE-2026-42164 — Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call… vulnerability nvd CVE-2026-42164 2026-08-17
critical CVE-2026-67919 — An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.ja… vulnerability nvd CVE-2026-67919 2026-08-17
critical CVE-2026-75094 — A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /… vulnerability nvd CVE-2026-75094 2026-08-18
critical CVE-2026-15748 — The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up… vulnerability nvd CVE-2026-15748 rce 2026-08-18
critical CVE-2026-34884 — SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking… vulnerability nvd CVE-2026-34884 2026-08-18
critical CVE-2026-75626 — SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including s… vulnerability nvd CVE-2026-75626 2026-08-18
critical CVE-2026-75627 — Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unaut… vulnerability nvd CVE-2026-75627 2026-08-18
critical CVE-2026-75837 — Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required sec… vulnerability nvd CVE-2026-75837 2026-08-18
critical CVE-2026-75843 — ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor th… vulnerability nvd CVE-2026-75843 2026-08-18
critical CVE-2026-75851 — ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the… vulnerability nvd CVE-2026-75851 2026-08-18
critical CVE-2026-75852 — ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB… vulnerability nvd CVE-2026-75852 2026-08-18
critical CVE-2026-75854 — ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-pro… vulnerability nvd CVE-2026-75854 2026-08-18
critical CVE-2026-74936 — Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154… vulnerability nvd CVE-2026-74936 2026-08-18
critical CVE-2026-74938 — Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Fire… vulnerability nvd CVE-2026-74938 2026-08-18
critical CVE-2026-74940 — Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox… vulnerability nvd CVE-2026-74940 2026-08-18
critical CVE-2026-74943 — Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Fir… vulnerability nvd CVE-2026-74943 2026-08-18
critical CVE-2026-74944 — Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firef… vulnerability nvd CVE-2026-74944 2026-08-18
critical CVE-2026-74956 — Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Fir… vulnerability nvd CVE-2026-74956 2026-08-18
critical CVE-2026-74961 — Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 15… vulnerability nvd CVE-2026-74961 2026-08-18
critical CVE-2026-74964 — Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR… vulnerability nvd CVE-2026-74964, CVE-2026-74977 2026-08-18
critical CVE-2026-74979 — Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Fir… vulnerability nvd CVE-2026-74979 2026-08-18
critical CVE-2026-74985 — Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 1… vulnerability nvd CVE-2026-74985 2026-08-18
critical CVE-2026-74986 — Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in F… vulnerability nvd CVE-2026-74986 2026-08-18
critical CVE-2026-74987 — Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153.… vulnerability nvd CVE-2026-74987, CVE-2026-74990 2026-08-18
critical CVE-2026-74988 — Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showe… vulnerability nvd CVE-2026-74988 2026-08-18
critical CVE-2026-74989 — Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corru… vulnerability nvd CVE-2026-74989 2026-08-18
critical CVE-2026-75783 — A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulner… vulnerability nvd CVE-2026-75783 2026-08-18
critical CVE-2026-75874 — Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154… vulnerability nvd CVE-2026-75874 2026-08-18
critical CVE-2026-28192 — Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. vulnerability nvd CVE-2026-28192 2026-08-18
critical CVE-2026-32444 — Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. vulnerability nvd CVE-2026-32444 rce 2026-08-18
critical CVE-2026-32463 — Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. vulnerability nvd CVE-2026-32463 2026-08-18
critical CVE-2026-32470 — Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. vulnerability nvd CVE-2026-32470, CVE-2026-73993 2026-08-18
critical CVE-2026-32474 — Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. vulnerability nvd CVE-2026-32474 2026-08-18
critical CVE-2026-59940 — Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify cap… vulnerability nvd CVE-2026-59940 rce 2026-08-18
critical CVE-2026-66627 — Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. vulnerability nvd CVE-2026-66627 2026-08-18
critical CVE-2026-73187 — Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. vulnerability nvd CVE-2026-73187 2026-08-18
critical CVE-2026-73339 — Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. vulnerability nvd CVE-2026-73339 2026-08-18
critical CVE-2026-73341 — Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. vulnerability nvd CVE-2026-73341 2026-08-18
critical CVE-2026-73343 — Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. vulnerability nvd CVE-2026-73343 rce 2026-08-18
critical CVE-2026-73355 — Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions. vulnerability nvd CVE-2026-73355 2026-08-18
critical CVE-2026-73365 — Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. vulnerability nvd CVE-2026-73365 2026-08-18
critical CVE-2026-73366 — Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. vulnerability nvd CVE-2026-73366 2026-08-18
critical CVE-2026-73376 — Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. vulnerability nvd CVE-2026-73376 2026-08-18
critical CVE-2026-73380 — Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. vulnerability nvd CVE-2026-73380 2026-08-18
critical CVE-2026-73381 — Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. vulnerability nvd CVE-2026-73381 2026-08-18
critical CVE-2026-73392 — Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions. vulnerability nvd CVE-2026-73392 2026-08-18
critical CVE-2026-73397 — Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. vulnerability nvd CVE-2026-73397 2026-08-18
critical CVE-2026-73996 — Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. vulnerability nvd CVE-2026-73996 2026-08-18
critical CVE-2026-74015 — Unauthenticated SQL Injection in Readabler < 2.0.18 versions. vulnerability nvd CVE-2026-74015 2026-08-18
critical CVE-2026-75784 — A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the functio… vulnerability nvd CVE-2026-75784 2026-08-18
critical CVE-2026-12564 — A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() fu… vulnerability nvd CVE-2026-12564 2026-08-18
critical CVE-2026-45117 — MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not… vulnerability nvd CVE-2026-45117 rce 2026-08-18
critical CVE-2026-45118 — MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a… vulnerability nvd CVE-2026-45118 2026-08-18
critical CVE-2026-75913 — CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection… vulnerability nvd CVE-2026-75913 2026-08-18
critical CVE-2026-18963 — A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core… vulnerability nvd CVE-2026-18963 2026-08-18
critical CVE-2026-50576 — ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to… vulnerability nvd CVE-2026-50576, CVE-2026-50577, CVE-2026-50578, CVE-2026-52723 2026-08-18
critical CVE-2026-67271 — Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthentic… vulnerability nvd CVE-2026-67271 rce 2026-08-18
critical CVE-2026-52608 — An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attack… vulnerability nvd CVE-2026-52608 rce 2026-08-18
critical CVE-2026-52610 — An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote at… vulnerability nvd CVE-2026-52610 2026-08-18
critical CVE-2026-66780 — A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, whi… vulnerability nvd CVE-2026-66780 2026-08-18
critical CVE-2026-67921 — Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the Cor… vulnerability nvd CVE-2026-67921 2026-08-18
critical CVE-2026-75130 — Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute ma… vulnerability nvd CVE-2026-75130 2026-08-18
critical CVE-2026-75625 — Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest be… vulnerability nvd CVE-2026-75625 2026-08-18
critical CVE-2026-47627 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path… vulnerability nvd CVE-2026-47627 2026-08-18
critical CVE-2026-55166 — Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME… vulnerability nvd CVE-2026-55166 2026-08-18
critical CVE-2026-57826 — An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certificate chain verificatio… vulnerability nvd CVE-2026-57826 2026-08-18
critical CVE-2026-75877 — A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function Syst… vulnerability nvd CVE-2026-75877 2026-08-18
critical CVE-2026-60391 — Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv… vulnerability nvd CVE-2026-60391, CVE-2026-70739, CVE-2026-70740, CVE-2026-70741, CVE-2026-70742, CVE-2026-70743, CVE-2026-70744, CVE-2026-70745, CVE-2026-70746, CVE-2026-70749, CVE-2026-70750, CVE-2026-70751, CVE-2026-70752, CVE-2026-70753, CVE-2026-70754, CVE-2026-70758, CVE-2026-70759, CVE-2026-70765, CVE-2026-70766, CVE-2026-70767, CVE-2026-70768, CVE-2026-70769, CVE-2026-70776, CVE-2026-70780, CVE-2026-70784, CVE-2026-70785, CVE-2026-70787, CVE-2026-70788, CVE-2026-70789, CVE-2026-70793, CVE-2026-70794 2026-08-18
critical CVE-2026-60393 — Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component… vulnerability nvd CVE-2026-60393, CVE-2026-62457, CVE-2026-62463, CVE-2026-62467, CVE-2026-62471, CVE-2026-62477, CVE-2026-62481, CVE-2026-62485, CVE-2026-62492, CVE-2026-62499, CVE-2026-62500, CVE-2026-62501, CVE-2026-62502, CVE-2026-62506, CVE-2026-62509, CVE-2026-62510, CVE-2026-62511, CVE-2026-62520, CVE-2026-62522, CVE-2026-62523, CVE-2026-62526, CVE-2026-62531, CVE-2026-62535, CVE-2026-62536, CVE-2026-62537, CVE-2026-62538, CVE-2026-62539, CVE-2026-62541, CVE-2026-62543, CVE-2026-62544, CVE-2026-62545, CVE-2026-62550, CVE-2026-62551, CVE-2026-62552, CVE-2026-62553, CVE-2026-62554, CVE-2026-62555, CVE-2026-62558, CVE-2026-62564, CVE-2026-62566, CVE-2026-62568, CVE-2026-62569, CVE-2026-62570, CVE-2026-62572, CVE-2026-62573, CVE-2026-62575, CVE-2026-62576, CVE-2026-62577, CVE-2026-62579, CVE-2026-62581, CVE-2026-62583, CVE-2026-62584, CVE-2026-70956, CVE-2026-70957, CVE-2026-70958, CVE-2026-70959, CVE-2026-70961, CVE-2026-70962, CVE-2026-70963, CVE-2026-70964, CVE-2026-70965, CVE-2026-70966, CVE-2026-70967, CVE-2026-70968, CVE-2026-70971, CVE-2026-70972, CVE-2026-70973 2026-08-18
critical CVE-2026-60415 — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). S… vulnerability nvd CVE-2026-60415, CVE-2026-60672, CVE-2026-60679, CVE-2026-60680, CVE-2026-60696, CVE-2026-60698, CVE-2026-60699, CVE-2026-60702 2026-08-18
critical CVE-2026-60590 — Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (c… vulnerability nvd CVE-2026-60590, CVE-2026-60591 2026-08-18
critical CVE-2026-60715 — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Leg… vulnerability nvd CVE-2026-60715, CVE-2026-60716, CVE-2026-60720, CVE-2026-60721, CVE-2026-60722, CVE-2026-60727, CVE-2026-61066, CVE-2026-61118 2026-08-18
critical CVE-2026-60728 — Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet… vulnerability nvd CVE-2026-60728 2026-08-18
critical CVE-2026-60729 — Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Compose… vulnerability nvd CVE-2026-60729, CVE-2026-60730, CVE-2026-60731, CVE-2026-60733 2026-08-18
critical CVE-2026-60737 — Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web… vulnerability nvd CVE-2026-60737, CVE-2026-61001, CVE-2026-70924 2026-08-18
critical CVE-2026-60751 — Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Su… vulnerability nvd CVE-2026-60751, CVE-2026-60752, CVE-2026-60754, CVE-2026-60765, CVE-2026-60767, CVE-2026-60779, CVE-2026-60803 2026-08-18
critical CVE-2026-60781 — Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmissio… vulnerability nvd CVE-2026-60781, CVE-2026-60782, CVE-2026-70694, CVE-2026-70695, CVE-2026-70696, CVE-2026-70699, CVE-2026-70702 2026-08-18
critical CVE-2026-60821 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Busi… vulnerability nvd CVE-2026-60821 2026-08-18
critical CVE-2026-60853 — Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).… vulnerability nvd CVE-2026-60853, CVE-2026-60915, CVE-2026-70716, CVE-2026-70727, CVE-2026-70908, CVE-2026-70923, CVE-2026-71029, CVE-2026-71065, CVE-2026-71074, CVE-2026-71110, CVE-2026-71152, CVE-2026-71153, CVE-2026-71154, CVE-2026-71155, CVE-2026-71156, CVE-2026-71157, CVE-2026-71158, CVE-2026-71159, CVE-2026-71160, CVE-2026-71161, CVE-2026-71162, CVE-2026-71164, CVE-2026-71165, CVE-2026-71166, CVE-2026-71167, CVE-2026-73865, CVE-2026-73866, CVE-2026-73867, CVE-2026-73868, CVE-2026-73869, CVE-2026-73870, CVE-2026-73871, CVE-2026-73872, CVE-2026-73873, CVE-2026-73874, CVE-2026-73875, CVE-2026-73876, CVE-2026-73877, CVE-2026-73878, CVE-2026-73879, CVE-2026-73880, CVE-2026-73881, CVE-2026-73882, CVE-2026-73883, CVE-2026-73884, CVE-2026-73885, CVE-2026-73886, CVE-2026-73887, CVE-2026-73888, CVE-2026-73889, CVE-2026-73890, CVE-2026-73891, CVE-2026-73892, CVE-2026-73893, CVE-2026-73894, CVE-2026-73895, CVE-2026-73896, CVE-2026-73897, CVE-2026-73898, CVE-2026-73899, CVE-2026-73900, CVE-2026-73901, CVE-2026-73902, CVE-2026-73903, CVE-2026-73904, CVE-2026-73905, CVE-2026-73906, CVE-2026-73907, CVE-2026-73908, CVE-2026-73909, CVE-2026-73910, CVE-2026-73911, CVE-2026-73912, CVE-2026-73913, CVE-2026-73914, CVE-2026-73915, CVE-2026-73916, CVE-2026-73917, CVE-2026-73918, CVE-2026-73919, CVE-2026-73920, CVE-2026-73921, CVE-2026-73922, CVE-2026-73923, CVE-2026-73924, CVE-2026-73925, CVE-2026-73927, CVE-2026-73928, CVE-2026-73929, CVE-2026-73930, CVE-2026-73931, CVE-2026-73932, CVE-2026-73933, CVE-2026-73934, CVE-2026-73935, CVE-2026-73936, CVE-2026-73937, CVE-2026-73938, CVE-2026-73939 2026-08-18
critical CVE-2026-60858 — Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Secu… vulnerability nvd CVE-2026-60858, CVE-2026-61206, CVE-2026-61259, CVE-2026-61276, CVE-2026-61281, CVE-2026-61293, CVE-2026-61313, CVE-2026-61342, CVE-2026-62441, CVE-2026-62446, CVE-2026-62459, CVE-2026-62460, CVE-2026-62461, CVE-2026-62529, CVE-2026-62532, CVE-2026-62533, CVE-2026-62571, CVE-2026-62578, CVE-2026-62580, CVE-2026-62582, CVE-2026-62598, CVE-2026-62602, CVE-2026-62603, CVE-2026-62604, CVE-2026-62606, CVE-2026-70676, CVE-2026-70677, CVE-2026-70678, CVE-2026-70679, CVE-2026-70682, CVE-2026-70683, CVE-2026-70685, CVE-2026-70705, CVE-2026-70711, CVE-2026-70714, CVE-2026-70719 2026-08-18
critical CVE-2026-60860 — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messa… vulnerability nvd CVE-2026-60860, CVE-2026-60861, CVE-2026-60865, CVE-2026-60866 2026-08-18
critical CVE-2026-60903 — Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Conten… vulnerability nvd CVE-2026-60903, CVE-2026-60905, CVE-2026-60906, CVE-2026-60909, CVE-2026-60928, CVE-2026-60933, CVE-2026-60934, CVE-2026-60935, CVE-2026-60944, CVE-2026-60949, CVE-2026-60954, CVE-2026-60955, CVE-2026-60961, CVE-2026-60980, CVE-2026-60981, CVE-2026-60983, CVE-2026-61288, CVE-2026-61290, CVE-2026-61291, CVE-2026-61295, CVE-2026-70858 2026-08-18
critical CVE-2026-60916 — Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (compon… vulnerability nvd CVE-2026-60916, CVE-2026-60921, CVE-2026-60946, CVE-2026-60947, CVE-2026-60958, CVE-2026-60970, CVE-2026-60971 2026-08-18
critical CVE-2026-60977 — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core… vulnerability nvd CVE-2026-60977 2026-08-18
critical CVE-2026-60990 — Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (componen… vulnerability nvd CVE-2026-60990, CVE-2026-60991, CVE-2026-60992, CVE-2026-60993, CVE-2026-60994, CVE-2026-60995, CVE-2026-60996, CVE-2026-60998 2026-08-18
critical CVE-2026-61003 — Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MF… vulnerability nvd CVE-2026-61003 2026-08-18
critical CVE-2026-61007 — Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCente… vulnerability nvd CVE-2026-61007, CVE-2026-61008, CVE-2026-61011, CVE-2026-61016, CVE-2026-61017, CVE-2026-61018, CVE-2026-61021, CVE-2026-61022, CVE-2026-61029, CVE-2026-61032, CVE-2026-61033, CVE-2026-61034, CVE-2026-61038, CVE-2026-61040, CVE-2026-61042, CVE-2026-61045, CVE-2026-61054, CVE-2026-61058 2026-08-18
critical CVE-2026-61124 — Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime… vulnerability nvd CVE-2026-61124, CVE-2026-61177, CVE-2026-61193, CVE-2026-61199, CVE-2026-61208, CVE-2026-61212, CVE-2026-61213, CVE-2026-61215, CVE-2026-61219, CVE-2026-61222, CVE-2026-61227, CVE-2026-61228, CVE-2026-61229, CVE-2026-61230, CVE-2026-70970 2026-08-18
critical CVE-2026-61241 — Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID L… vulnerability nvd CVE-2026-61241, CVE-2026-61248, CVE-2026-61258 2026-08-18
critical CVE-2026-61272 — Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run… vulnerability nvd CVE-2026-61272 2026-08-18
critical CVE-2026-61317 — Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel C… vulnerability nvd CVE-2026-61317, CVE-2026-61318, CVE-2026-61321, CVE-2026-61326, CVE-2026-61330, CVE-2026-61332, CVE-2026-61339, CVE-2026-61341, CVE-2026-62442, CVE-2026-62452, CVE-2026-62454, CVE-2026-62455, CVE-2026-62512 2026-08-18
critical CVE-2026-62585 — Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archiva… vulnerability nvd CVE-2026-62585, CVE-2026-62586, CVE-2026-62587 2026-08-18
critical CVE-2026-62588 — Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integratio… vulnerability nvd CVE-2026-62588, CVE-2026-62589, CVE-2026-62590, CVE-2026-62591, CVE-2026-62592, CVE-2026-62593, CVE-2026-62594, CVE-2026-62595, CVE-2026-62596 2026-08-18
critical CVE-2026-62608 — Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Securi… vulnerability nvd CVE-2026-62608, CVE-2026-62609, CVE-2026-62610, CVE-2026-62611, CVE-2026-62612, CVE-2026-62613, CVE-2026-62614, CVE-2026-62615, CVE-2026-62616, CVE-2026-62617, CVE-2026-62618, CVE-2026-62619, CVE-2026-62620, CVE-2026-62621, CVE-2026-62622, CVE-2026-62623, CVE-2026-62624, CVE-2026-62625, CVE-2026-62626, CVE-2026-62627, CVE-2026-62628, CVE-2026-62629, CVE-2026-62630, CVE-2026-62631, CVE-2026-62632, CVE-2026-62633, CVE-2026-62634, CVE-2026-62635, CVE-2026-62636, CVE-2026-62637, CVE-2026-62638, CVE-2026-62639, CVE-2026-62640, CVE-2026-70668, CVE-2026-70669, CVE-2026-70670, CVE-2026-70671, CVE-2026-70672, CVE-2026-70673, CVE-2026-70674, CVE-2026-70675 2026-08-18
critical CVE-2026-62988 — Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Cu… vulnerability nvd CVE-2026-62988 2026-08-18
critical CVE-2026-70689 — Vulnerability in Oracle Essbase (component: Infrastructure). The supported version that is affected… vulnerability nvd CVE-2026-70689 2026-08-18
critical CVE-2026-70721 — Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (c… vulnerability nvd CVE-2026-70721, CVE-2026-70723, CVE-2026-70730, CVE-2026-70733, CVE-2026-70735, CVE-2026-70736, CVE-2026-70738 2026-08-18
critical CVE-2026-70817 — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Sec… vulnerability nvd CVE-2026-70817, CVE-2026-70818, CVE-2026-70819, CVE-2026-70821, CVE-2026-70822, CVE-2026-70823, CVE-2026-70824, CVE-2026-70825, CVE-2026-70826, CVE-2026-70828, CVE-2026-70831, CVE-2026-70832, CVE-2026-70834, CVE-2026-70836, CVE-2026-70838, CVE-2026-70840, CVE-2026-70841, CVE-2026-70842, CVE-2026-70843, CVE-2026-70847, CVE-2026-70848, CVE-2026-70849, CVE-2026-70850, CVE-2026-70851, CVE-2026-70853, CVE-2026-70854, CVE-2026-70909, CVE-2026-70911, CVE-2026-70912, CVE-2026-70914, CVE-2026-70916, CVE-2026-70917, CVE-2026-70919, CVE-2026-70920, CVE-2026-70921, CVE-2026-70925, CVE-2026-70928, CVE-2026-70929, CVE-2026-70933, CVE-2026-70934, CVE-2026-70935, CVE-2026-70936, CVE-2026-70937, CVE-2026-70938, CVE-2026-70939, CVE-2026-70940, CVE-2026-70942, CVE-2026-70943, CVE-2026-70944, CVE-2026-70946, CVE-2026-70950, CVE-2026-70952, CVE-2026-70960, CVE-2026-70969, CVE-2026-70974, CVE-2026-70975, CVE-2026-71013, CVE-2026-71060, CVE-2026-71085, CVE-2026-71090, CVE-2026-71091, CVE-2026-71103, CVE-2026-71105, CVE-2026-71108, CVE-2026-71109, CVE-2026-71117, CVE-2026-71118, CVE-2026-71119, CVE-2026-71120, CVE-2026-71121, CVE-2026-71123, CVE-2026-71144, CVE-2026-71145, CVE-2026-71146, CVE-2026-71147, CVE-2026-71148, CVE-2026-71149, CVE-2026-71150 2026-08-18
critical CVE-2026-70846 — Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Oper… vulnerability nvd CVE-2026-70846, CVE-2026-70852 supply-chain 2026-08-18
critical CVE-2026-70855 — Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Tr… vulnerability nvd CVE-2026-70855 2026-08-18
critical CVE-2026-70862 — Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.… vulnerability nvd CVE-2026-70862, CVE-2026-70863, CVE-2026-70864, CVE-2026-70865, CVE-2026-70866, CVE-2026-70867, CVE-2026-70868 2026-08-18
critical CVE-2026-70870 — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (compon… vulnerability nvd CVE-2026-70870, CVE-2026-70871, CVE-2026-70872, CVE-2026-70873, CVE-2026-70874, CVE-2026-70875, CVE-2026-70876, CVE-2026-70877, CVE-2026-70878, CVE-2026-70879, CVE-2026-70880, CVE-2026-70881, CVE-2026-70882, CVE-2026-70883, CVE-2026-70884, CVE-2026-70885, CVE-2026-70886, CVE-2026-70887, CVE-2026-70888, CVE-2026-70889, CVE-2026-70890, CVE-2026-70891, CVE-2026-70892, CVE-2026-70893, CVE-2026-70894, CVE-2026-70895, CVE-2026-70896, CVE-2026-70897, CVE-2026-70898, CVE-2026-70899, CVE-2026-70900, CVE-2026-70901, CVE-2026-70902, CVE-2026-70903, CVE-2026-70904 2026-08-18
critical CVE-2026-70905 — Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Agent inf… vulnerability nvd CVE-2026-70905 2026-08-18
critical CVE-2026-70926 — Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notific… vulnerability nvd CVE-2026-70926, CVE-2026-70927, CVE-2026-70931 2026-08-18
critical CVE-2026-70953 — Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Applicat… vulnerability nvd CVE-2026-70953, CVE-2026-70954, CVE-2026-70955 2026-08-18
critical CVE-2026-70976 — Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O… vulnerability nvd CVE-2026-70976, CVE-2026-70977, CVE-2026-70978, CVE-2026-70979, CVE-2026-70980, CVE-2026-70981, CVE-2026-70982, CVE-2026-70983, CVE-2026-70984, CVE-2026-70985, CVE-2026-70986, CVE-2026-70987, CVE-2026-70988, CVE-2026-70989, CVE-2026-70990, CVE-2026-70991, CVE-2026-70992, CVE-2026-70993, CVE-2026-70994, CVE-2026-70995, CVE-2026-70996, CVE-2026-70997, CVE-2026-70998, CVE-2026-70999, CVE-2026-71000, CVE-2026-71001, CVE-2026-71002, CVE-2026-71003, CVE-2026-71004, CVE-2026-71005, CVE-2026-71006, CVE-2026-71007, CVE-2026-71008, CVE-2026-71009, CVE-2026-71010, CVE-2026-71011, CVE-2026-71012, CVE-2026-71014, CVE-2026-71015, CVE-2026-71016, CVE-2026-71017, CVE-2026-71018, CVE-2026-71019, CVE-2026-71020, CVE-2026-71021, CVE-2026-71022, CVE-2026-71023, CVE-2026-71024, CVE-2026-71025, CVE-2026-71026, CVE-2026-71027, CVE-2026-71028, CVE-2026-71030, CVE-2026-71031, CVE-2026-71032, CVE-2026-71033, CVE-2026-71034, CVE-2026-71035, CVE-2026-71036, CVE-2026-71037, CVE-2026-71038 2026-08-18
critical CVE-2026-71040 — Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supp… vulnerability nvd CVE-2026-71040, CVE-2026-71043, CVE-2026-71045, CVE-2026-71046 supply-chain 2026-08-18
critical CVE-2026-71058 — Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). S… vulnerability nvd CVE-2026-71058, CVE-2026-71059 2026-08-18
critical CVE-2026-71063 — Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions th… vulnerability nvd CVE-2026-71063, CVE-2026-71064, CVE-2026-71102 2026-08-18
critical CVE-2026-76035 — Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a r… vulnerability nvd CVE-2026-76035 2026-08-18
critical CVE-2026-76036 — Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote atta… vulnerability nvd CVE-2026-76036 2026-08-18
critical CVE-2026-75976 — A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of… vulnerability nvd CVE-2026-75976 2026-08-19
critical CVE-2026-76003 — A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strc… vulnerability nvd CVE-2026-76003 2026-08-19
critical CVE-2026-76004 — A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected b… vulnerability nvd CVE-2026-76004 2026-08-19
critical CVE-2026-76008 — A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the… vulnerability nvd CVE-2026-76008 2026-08-19
critical CVE-2026-18031 — The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before est… vulnerability nvd CVE-2026-18031 2026-08-19
critical CVE-2026-18051 — The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it use… vulnerability nvd CVE-2026-18051 2026-08-19
critical CVE-2026-18776 — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of it… vulnerability nvd CVE-2026-18776, CVE-2026-18778 2026-08-19
critical CVE-2026-18937 — The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accep… vulnerability nvd CVE-2026-18937 2026-08-19
critical CVE-2026-58085 — After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to ch… vulnerability nvd CVE-2026-58085 ransomware 2026-08-19
critical CVE-2026-18371 — HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to… vulnerability nvd CVE-2026-18371 ransomware 2026-08-19
critical CVE-2026-18372 — CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault adminis… vulnerability nvd CVE-2026-18372 ransomware 2026-08-19
critical CVE-2026-66613 — Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions. vulnerability nvd CVE-2026-66613 rce 2026-08-19
critical CVE-2026-73183 — Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. vulnerability nvd CVE-2026-73183 2026-08-19
critical CVE-2026-73185 — Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. vulnerability nvd CVE-2026-73185 2026-08-19
critical CVE-2026-73347 — Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. vulnerability nvd CVE-2026-73347 2026-08-19
critical CVE-2026-73364 — Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. vulnerability nvd CVE-2026-73364 2026-08-19
critical CVE-2026-73388 — Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. vulnerability nvd CVE-2026-73388 2026-08-19
critical CVE-2026-73389 — Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. vulnerability nvd CVE-2026-73389 2026-08-19
critical CVE-2026-73390 — Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. vulnerability nvd CVE-2026-73390 2026-08-19
critical CVE-2026-73391 — Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. vulnerability nvd CVE-2026-73391 2026-08-19
critical CVE-2026-16019 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i… vulnerability nvd CVE-2026-16019, CVE-2026-74011, CVE-2026-63037, CVE-2026-63038, CVE-2026-63039 2026-08-19
critical CVE-2026-15065 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security r… vulnerability nvd CVE-2026-15065 2026-08-19
critical CVE-2026-15068 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to exe… vulnerability nvd CVE-2026-15068 2026-08-19
critical CVE-2026-16656 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges… vulnerability nvd CVE-2026-16656 2026-08-19
critical CVE-2026-16690 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser… vulnerability nvd CVE-2026-16690, CVE-2026-16706, CVE-2026-16817, CVE-2026-16818, CVE-2026-16824, CVE-2026-16827, CVE-2026-16829, CVE-2026-16831, CVE-2026-16834, CVE-2026-16836, CVE-2026-16837, CVE-2026-16846, CVE-2026-16849, CVE-2026-16851, CVE-2026-16852, CVE-2026-16866, CVE-2026-16886, CVE-2026-16924, CVE-2026-16928, CVE-2026-16958, CVE-2026-17120, CVE-2026-17121, CVE-2026-17159, CVE-2026-17163, CVE-2026-17165, CVE-2026-17170, CVE-2026-17425, CVE-2026-18670, CVE-2026-18828 2026-08-19
critical CVE-2026-16814 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod… vulnerability nvd CVE-2026-16814, CVE-2026-16840, CVE-2026-16841, CVE-2026-16845, CVE-2026-16847, CVE-2026-16850, CVE-2026-16862, CVE-2026-16864, CVE-2026-16865, CVE-2026-16872, CVE-2026-16885, CVE-2026-16894, CVE-2026-16901, CVE-2026-16903, CVE-2026-16909, CVE-2026-16913, CVE-2026-16917, CVE-2026-16919, CVE-2026-17000, CVE-2026-17006, CVE-2026-17024, CVE-2026-17040, CVE-2026-17118, CVE-2026-17122, CVE-2026-17136, CVE-2026-17138, CVE-2026-17141, CVE-2026-17145, CVE-2026-17152, CVE-2026-17157, CVE-2026-17160, CVE-2026-17436, CVE-2026-18832, CVE-2026-19437 2026-08-19
critical CVE-2026-16816 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute… vulnerability nvd CVE-2026-16816, CVE-2026-16877, CVE-2026-16911, CVE-2026-17168, CVE-2026-18824, CVE-2026-18835 2026-08-19
critical CVE-2026-47187 — SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue… vulnerability nvd CVE-2026-47187 2026-08-19
critical CVE-2026-52889 — Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hi… vulnerability nvd CVE-2026-52889 rce 2026-08-19
critical CVE-2026-53451 — Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and… vulnerability nvd CVE-2026-53451, CVE-2026-53452 2026-08-19
critical CVE-2026-71960 — Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnera… vulnerability nvd CVE-2026-71960 2026-08-19
critical CVE-2026-44252 — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4… vulnerability nvd CVE-2026-44252, CVE-2026-46343, CVE-2026-41424, CVE-2026-44255, CVE-2026-44256, CVE-2026-44901, CVE-2026-45798, CVE-2026-48024, CVE-2026-48162, CVE-2026-49392, CVE-2026-49441 2026-08-19
critical CVE-2026-20030 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork… vulnerability nvd CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, CVE-2026-20359 2026-08-19
critical CVE-2026-20231 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Wo… vulnerability nvd CVE-2026-20231, CVE-2026-20315, CVE-2026-20317, CVE-2026-20318, CVE-2026-20319 2026-08-19
critical CVE-2026-71470 — A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specificall… vulnerability nvd CVE-2026-71470 2026-08-19
critical CVE-2026-75143 — FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavforma… vulnerability nvd CVE-2026-75143 2026-08-19
critical CVE-2026-32475 — Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Usin… vulnerability nvd CVE-2026-32475 2026-08-19
critical CVE-2026-66794 — A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This… vulnerability nvd CVE-2026-66794 2026-08-19
critical CVE-2026-67581 — Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to ob… vulnerability nvd CVE-2026-67581 ransomware 2026-08-19
critical CVE-2026-73136 — Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obta… vulnerability nvd CVE-2026-73136 ransomware 2026-08-19
critical CVE-2026-73829 — Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote cl… vulnerability nvd CVE-2026-73829 ransomware 2026-08-19
critical CVE-2026-16687 — IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and… vulnerability nvd CVE-2026-16687, CVE-2026-16828, CVE-2026-16832, CVE-2026-16835, CVE-2026-16938, CVE-2026-18848 2026-08-19
critical CVE-2026-18315 — The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Auth… vulnerability nvd CVE-2026-18315 2026-08-19
critical CVE-2026-70496 — A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a c… vulnerability nvd CVE-2026-70496 2026-08-19
critical CVE-2026-16822 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC p… vulnerability nvd CVE-2026-16822 2026-08-19
critical CVE-2026-16839 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive info… vulnerability nvd CVE-2026-16839, CVE-2026-16888, CVE-2026-16972, CVE-2026-17060, CVE-2026-17423 2026-08-19
critical CVE-2026-16842 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary com… vulnerability nvd CVE-2026-16842, CVE-2026-16844, CVE-2026-16848, CVE-2026-16882, CVE-2026-17142 2026-08-19
critical CVE-2026-16869 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code… vulnerability nvd CVE-2026-16869, CVE-2026-16914, CVE-2026-16922, CVE-2026-16936, CVE-2026-16943, CVE-2026-16944, CVE-2026-16945, CVE-2026-16996, CVE-2026-17124, CVE-2026-17422, CVE-2026-18840 2026-08-19
critical CVE-2026-22306 — Download of code without integrity check, inclusion of functionality from untrusted control sphere,… vulnerability nvd CVE-2026-22306 2026-08-19
critical CVE-2026-55085 — Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/dom… vulnerability nvd CVE-2026-55085 2026-08-19
critical CVE-2026-55089 — Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/AP… vulnerability nvd CVE-2026-55089 2026-08-19
critical CVE-2026-63722 — ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthentic… vulnerability nvd CVE-2026-63722 rce 2026-08-19
critical CVE-2026-53542 — Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa… vulnerability nvd CVE-2026-53542, CVE-2026-53545, CVE-2026-53546, CVE-2026-53547, CVE-2026-53548, CVE-2026-53549 2026-08-19
critical CVE-2026-54494 — Koel is a free, open-source music streaming solution. Prior to 9.7.1, App\Helpers\Network::isPublicH… vulnerability nvd CVE-2026-54494 ransomware 2026-08-19
critical CVE-2026-76584 — A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some… vulnerability nvd CVE-2026-76584 2026-08-19
critical CVE-2026-76310 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who… vulnerability nvd CVE-2026-76310, CVE-2026-76311, CVE-2026-76338 2026-08-19
critical CVE-2026-76312 — In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who… vulnerability nvd CVE-2026-76312 2026-08-19
critical CVE-2026-76404 — In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execut… vulnerability nvd CVE-2026-76404 2026-08-19
critical CVE-2026-76589 — A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000… vulnerability nvd CVE-2026-76589 2026-08-19
critical CVE-2026-76590 — A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some… vulnerability nvd CVE-2026-76590 2026-08-19
critical CVE-2026-76850 — LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine… vulnerability nvd CVE-2026-76850 2026-08-19
critical CVE-2026-75860 — The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verifica… vulnerability nvd CVE-2026-75860 2026-08-20
critical CVE-2026-14950 — An unauthenticated remote attacker in possession of a valid session identifier is able to continue u… vulnerability nvd CVE-2026-14950 2026-08-20
critical CVE-2026-11861 — A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Dire… vulnerability nvd CVE-2026-11861 2026-08-20
critical CVE-2026-13097 — A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos pri… vulnerability nvd CVE-2026-13097 2026-08-20
critical CVE-2025-15688 — Unauthenticated SQL Injection in Capella <= 2.5.5 versions. vulnerability nvd CVE-2025-15688 2026-08-20
critical CVE-2025-15689 — Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. vulnerability nvd CVE-2025-15689 2026-08-20
critical CVE-2026-66583 — Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. vulnerability nvd CVE-2026-66583 2026-08-20
critical CVE-2026-66592 — Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. vulnerability nvd CVE-2026-66592 2026-08-20
critical CVE-2026-66593 — Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. vulnerability nvd CVE-2026-66593 2026-08-20
critical CVE-2026-66600 — Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. vulnerability nvd CVE-2026-66600 2026-08-20
critical CVE-2026-66609 — Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. vulnerability nvd CVE-2026-66609 2026-08-20
critical CVE-2026-66649 — Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. vulnerability nvd CVE-2026-66649 2026-08-20
critical CVE-2026-66672 — Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. vulnerability nvd CVE-2026-66672 2026-08-20
critical CVE-2026-66680 — Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions. vulnerability nvd CVE-2026-66680 2026-08-20
critical CVE-2026-66682 — Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. vulnerability nvd CVE-2026-66682 2026-08-20
critical CVE-2026-68566 — Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. vulnerability nvd CVE-2026-68566 2026-08-20
critical CVE-2026-73992 — Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions. vulnerability nvd CVE-2026-73992 rce 2026-08-20
critical CVE-2026-74001 — Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. vulnerability nvd CVE-2026-74001 2026-08-20
critical CVE-2026-74014 — Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions. vulnerability nvd CVE-2026-74014 2026-08-20
critical CVE-2026-74016 — Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions. vulnerability nvd CVE-2026-74016 2026-08-20
critical CVE-2026-74018 — Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. vulnerability nvd CVE-2026-74018 2026-08-20
critical CVE-2026-77068 — n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n… vulnerability nvd CVE-2026-77068 rce 2026-08-20
critical CVE-2026-18482 — Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the… vulnerability nvd CVE-2026-18482 ransomware 2026-08-20
critical CVE-2026-28164 — Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Sit… vulnerability nvd CVE-2026-28164 2026-08-20
critical CVE-2026-15706 — Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry… vulnerability nvd CVE-2026-15706 2026-08-20
critical CVE-2026-64960 — ATutor Gameme module allows users to upload files of any type and extension without restriction. Due… vulnerability nvd CVE-2026-64960 rce 2026-08-20
critical CVE-2026-64966 — ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker… vulnerability nvd CVE-2026-64966 rce 2026-08-20
critical CVE-2026-16926 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary f… vulnerability nvd CVE-2026-16926 2026-08-20
critical CVE-2026-15679 — Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution… vulnerability nvd CVE-2026-15679 rce 2026-08-20
critical CVE-2026-15686 — Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. Th… vulnerability nvd CVE-2026-15686 rce 2026-08-20
critical CVE-2026-18264 — NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows r… vulnerability nvd CVE-2026-18264 rce 2026-08-20
critical CVE-2026-18265 — OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability al… vulnerability nvd CVE-2026-18265 rce 2026-08-20
critical CVE-2026-18274 — Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This… vulnerability nvd CVE-2026-18274 rce 2026-08-20
critical CVE-2026-18279 — Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability. This vulnerability a… vulnerability nvd CVE-2026-18279 rce 2026-08-20
critical CVE-2026-18281 — Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability. Th… vulnerability nvd CVE-2026-18281 rce 2026-08-20
critical CVE-2026-18282 — Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerabil… vulnerability nvd CVE-2026-18282 rce 2026-08-20
critical CVE-2026-18285 — Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability.… vulnerability nvd CVE-2026-18285 rce 2026-08-20
critical CVE-2026-18286 — Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability. T… vulnerability nvd CVE-2026-18286 rce 2026-08-20
critical CVE-2026-18287 — Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerability. Thi… vulnerability nvd CVE-2026-18287 rce 2026-08-20
critical CVE-2026-18288 — OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This… vulnerability nvd CVE-2026-18288 rce 2026-08-20
critical CVE-2026-18289 — OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This v… vulnerability nvd CVE-2026-18289 rce 2026-08-20
critical CVE-2026-18290 — OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This v… vulnerability nvd CVE-2026-18290 rce 2026-08-20
critical CVE-2026-18291 — OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vul… vulnerability nvd CVE-2026-18291 rce 2026-08-20
critical CVE-2026-18292 — OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vul… vulnerability nvd CVE-2026-18292 rce 2026-08-20
critical CVE-2026-18293 — OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. Th… vulnerability nvd CVE-2026-18293 rce 2026-08-20
critical CVE-2026-18294 — OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This… vulnerability nvd CVE-2026-18294 rce 2026-08-20
critical CVE-2026-18295 — GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerabili… vulnerability nvd CVE-2026-18295 rce 2026-08-20
critical CVE-2026-18296 — GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vuln… vulnerability nvd CVE-2026-18296 rce 2026-08-20
critical CVE-2026-18297 — GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vul… vulnerability nvd CVE-2026-18297 rce 2026-08-20
critical CVE-2026-18298 — GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vuln… vulnerability nvd CVE-2026-18298 rce 2026-08-20
critical CVE-2026-18299 — GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows… vulnerability nvd CVE-2026-18299 rce 2026-08-20
critical CVE-2026-18300 — GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow… vulnerability nvd CVE-2026-18300 rce 2026-08-20
critical CVE-2026-18301 — GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow… vulnerability nvd CVE-2026-18301 rce 2026-08-20
critical CVE-2026-18302 — GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabi… vulnerability nvd CVE-2026-18302, CVE-2026-18307 rce 2026-08-20
critical CVE-2026-18303 — GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerab… vulnerability nvd CVE-2026-18303 rce 2026-08-20
critical CVE-2026-18304 — GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow… vulnerability nvd CVE-2026-18304, CVE-2026-18305, CVE-2026-18308 rce 2026-08-20
critical CVE-2026-18306 — GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow… vulnerability nvd CVE-2026-18306 rce 2026-08-20
critical CVE-2026-18309 — GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allo… vulnerability nvd CVE-2026-18309 rce 2026-08-20
critical CVE-2026-55642 — dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in c… vulnerability nvd CVE-2026-55642 2026-08-20
critical CVE-2026-71428 — The unstructured library provides open-source components for ingesting and pre-processing images and… vulnerability nvd CVE-2026-71428 2026-08-20
critical CVE-2026-77022 — A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the functi… vulnerability nvd CVE-2026-77022 2026-08-20
critical CVE-2026-2334 — An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges… vulnerability nvd CVE-2026-2334 rce 2026-08-20
critical CVE-2026-53424 — Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authent… vulnerability nvd CVE-2026-53424 ransomware 2026-08-20
critical CVE-2026-73256 — Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated atta… vulnerability nvd CVE-2026-73256 2026-08-20
critical CVE-2026-73257 — Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthentica… vulnerability nvd CVE-2026-73257 2026-08-20
critical CVE-2026-66785 — A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect ne… vulnerability nvd CVE-2026-66785 2026-08-20
critical CVE-2026-66788 — A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vu… vulnerability nvd CVE-2026-66788 2026-08-20
critical CVE-2026-77148 — A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the fi… vulnerability nvd CVE-2026-77148 2026-08-20
critical CVE-2026-67567 — A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a ten… vulnerability nvd CVE-2026-67567 2026-08-20
critical CVE-2026-69242 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted… vulnerability nvd CVE-2026-69242 rce 2026-08-20
critical CVE-2026-71485 — Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies… vulnerability nvd CVE-2026-71485 2026-08-20
critical CVE-2026-62834 — Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attack… vulnerability nvd CVE-2026-62834 2026-08-20
critical CVE-2026-63509 — Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over… vulnerability nvd CVE-2026-63509 2026-08-20
critical CVE-2026-65770 — Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed… vulnerability nvd CVE-2026-65770 2026-08-20
critical CVE-2026-65801 — Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to e… vulnerability nvd CVE-2026-65801 2026-08-20
critical CVE-2026-65816 — Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevat… vulnerability nvd CVE-2026-65816 2026-08-20
critical CVE-2026-66309 — Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges ov… vulnerability nvd CVE-2026-66309 2026-08-20
critical CVE-2026-68782 — Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Da… vulnerability nvd CVE-2026-68782, CVE-2026-68789 2026-08-20
critical CVE-2026-69400 — Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps a… vulnerability nvd CVE-2026-69400 2026-08-20
critical CVE-2026-69555 — Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a ne… vulnerability nvd CVE-2026-69555 2026-08-20
critical CVE-2026-69836 — Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute c… vulnerability nvd CVE-2026-69836 2026-08-20
critical CVE-2026-69851 — Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevat… vulnerability nvd CVE-2026-69851 2026-08-20
critical CVE-2026-72843 — The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/m… vulnerability nvd CVE-2026-72843 2026-08-20
critical CVE-2026-77645 — A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC Flex… vulnerability nvd CVE-2026-77645 rce 2026-08-20
critical CVE-2026-77647 — SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited i… vulnerability nvd CVE-2026-77647 2026-08-20
critical CVE-2026-77649 — The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project… vulnerability nvd CVE-2026-77649 botnet 2026-08-21
critical CVE-2026-77650 — The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a pr… vulnerability nvd CVE-2026-77650 botnet 2026-08-21
critical CVE-2026-77651 — The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project… vulnerability nvd CVE-2026-77651 botnet 2026-08-21
critical CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-20
critical CVE-2026-61363 Remote Desktop Client Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-20
critical CVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-20
critical CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-20
critical CVE-2026-69419 Azure Data Manager for Energy Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-20
critical CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-20
critical CVE-2026-54118 Microsoft SQL Server Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-20
critical CVE-2026-65811 Power BI Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-19
critical CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-18
critical CVE-2026-56642 Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-18
critical CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-17
critical CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-17
critical CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-17
critical CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-17
critical CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-17
critical CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-16
critical CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-16
critical CVE-2026-72970 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-14
critical CVE-2026-50313 Windows NTFS Remote Code Execution Vulnerability advisory vendor-blogs rce 2026-08-14
critical FBI, CISA, HHS update Medusa ransomware advisory, detail RaaS affiliate model, exploited flaws and attack tools advisory vendor-blogs ransomware 2026-08-19
critical Black Kite report finds 73% of ransomware incidents hit mid-market companies amid growing third-party and AI risks advisory vendor-blogs ransomware 2026-08-19
critical Malicious IP: 213.209.159.241 ip-reputation abuse-ipdb 213.209.159.241 2026-08-21
critical Malicious IP: 64.62.197.138 ip-reputation abuse-ipdb 64.62.197.138 2026-08-21
critical Malicious IP: 119.92.70.82 ip-reputation abuse-ipdb 119.92.70.82 2026-08-21
critical Malicious IP: 195.26.18.111 ip-reputation abuse-ipdb 195.26.18.111 2026-08-21
critical Malicious IP: 181.115.171.216 ip-reputation abuse-ipdb 181.115.171.216 2026-08-21
critical Malicious IP: 118.196.68.35 ip-reputation abuse-ipdb 118.196.68.35 2026-08-21
critical Malicious IP: 79.124.59.178 ip-reputation abuse-ipdb 79.124.59.178 2026-08-21
critical Malicious IP: 79.124.56.142 ip-reputation abuse-ipdb 79.124.56.142 2026-08-21
critical Malicious IP: 68.225.61.18 ip-reputation abuse-ipdb 68.225.61.18 2026-08-21
critical Malicious IP: 193.47.62.69 ip-reputation abuse-ipdb 193.47.62.69 2026-08-21
critical Malicious IP: 163.7.9.55 ip-reputation abuse-ipdb 163.7.9.55 2026-08-21
critical Malicious IP: 68.221.130.146 ip-reputation abuse-ipdb 68.221.130.146 2026-08-21
critical Malicious IP: 61.184.128.210 ip-reputation abuse-ipdb 61.184.128.210 2026-08-21
critical Malicious IP: 70.183.230.195 ip-reputation abuse-ipdb 70.183.230.195 2026-08-21
critical Malicious IP: 47.254.134.254 ip-reputation abuse-ipdb 47.254.134.254 2026-08-21
critical Malicious IP: 4.206.92.183 ip-reputation abuse-ipdb 4.206.92.183 2026-08-21
critical Malicious IP: 45.148.10.240 ip-reputation abuse-ipdb 45.148.10.240 2026-08-21
critical Malicious IP: 194.88.98.114 ip-reputation abuse-ipdb 194.88.98.114 2026-08-21
critical Malicious IP: 181.116.43.25 ip-reputation abuse-ipdb 181.116.43.25 2026-08-21
critical Malicious IP: 45.249.246.17 ip-reputation abuse-ipdb 45.249.246.17 2026-08-21
critical payload_delivery: undefined threat-intel threatfox ClearFake, mac-0xdcf2, macOS, Cloudflare, gif, PHP, webshell, WordPress, workers.dev, wp-admin, 21August2026, Commandline, mac-0x68dc, CobaltStrike, Vshell, 8560, asyncrat, c2, censys, compromised, etherhide, ClickFix, etherhiding, AISURU, elf, IoT, Mozi, Remus, mac-0x76c7, drb-ra, mac-0x0f14, 20August2026, ErrTraffic, Viper, Havoc, dcrat, PureHVNC, PureRAT, RAT, HypeAgent, Mythic, Supershell, 1xxbot, ArechClient, SectopRAT, CinaRAT, Quasar RAT, QuasarRAT, Yggdrasil, sliver, ResolverRAT, ConnectWise, ScreenConnect, 903ac24fcd9670b9ef2e674243d550d8, Loader, stealer, Vidar, RemusStealer, fake-plugin, nochain, SmartApeSG, win-0xa770, Windows, ValleyRAT, Kongtuke, AgentTesla, XWorm, Dropper, SocGholish, Pink, Adaptix, RevStealer, DomainShadowing, NEWTEST, Stealc, test_2, STRRAT, DanBot, CONTABO, CTFLoaderService, FakeAdobe, iso, LNK, pre-ransomware, velociraptor, cs-watermark-987654321, RemcosRAT, remcos, OffLoader, Socks5Systemz, Mirai, Vjw0rm, RedGuard, shodan, orcus, NetSupport, StarKillerC2, UNAM, AdaptixC2, PowerSploit, locust, GoPhish, phishing, cs-watermark-100000, Amos, nakedpages, Lud, 36903, MetaSploit, fake-copilot, RedLineStealer, 19August2026, njrat, Covenant, NeedleStealer, sliverfox, Gafgyt, rmm, 117ee8f56cb68a9f6a440e1b4329f856, SparkRAT, ExtRat, XTRAT, Xtreme RAT, Agentemis, Beacon, Cobalt Strike, cobeacon, clipboard, ACRStealer, Mac, Breut, darkcomet, Fynloski, klovbot, Lumma, NanoCore, SnappyClient, Diamotrix, URLscan, EvilGinx, EvilGoPhish, CHAOS, x4tte, PureLogsStealer, LxBaseRAT, ProRat, Panda, EpsteinClient, NetSupportManager, NetSupportRAT, 592a9e009f92c0e8eaea74a337b4f67c, capture-drop, honeypot, ssh-dropper, HTA, mexico, WhatsApp, sepolia, tofsee, web-inject, Spynote, HookBot, Byakugan, nc, gs-netcat, gsocket, moobot, nimplant, quasar, sectop, shadowpad, cs-watermark-1234567890, valleyrat_s2, 8395ea90eca49b3f66c2a339ab377348, 974b6b4ed30ddaa4b6f4ec27976e52d8, IRAHook, 40999, 45090, gated, poshc2, BianLian, PG, hook, Deimos, Magecart, userr, 4-72, card-theft, COLOMBIA, otp-relay, phishing-kit, telegram-exfil, tg.pe, BlakcSeeStealer, 726a8431d5d2ee941d0e6046b5948889, 17August2026, Loki, DinDoor, 16August2026, NetSupportManager RAT, Nancrat, NanoCore RAT, Remvio, Socmer, Bladabindi, Lime-Worm, Venom RAT, Farfli, Gh0st RAT, Ghost RAT, PCRat, Polygon, 6c0969259a3975582cd8a48f4c8913d7, UnamPanel, v1, 8075, 329556, 214961, kimwolf, 5fdb6df778631818165110294c620890, a6416186c7730e38c492792c820881c3, majinahanashi, Ransomware, whack.sh, 013c5d2d6312702c9bd8d7499170ed6b, aa462c8dcc4d1e29e6e35cbe1cd9ac85, build3, newbuild, 0f81469cc7638ba7c82eaddbd6b3c20a, cs-watermark-666666666, Cloudflare Inc., 15August2026, mac-0xfb64, mac-0xe447, be6f50208246a51977f7066c1ea613a0, e9bf104a963da535b0fb5aaebe6f06e1, 51c45d4bde39c5d7874e05e8c68314ca, 14August2026, cc382e7a75ab8441eee2f40142be37ed, AnimateClipper, LegionLoader, SheetRAT, MintsLoader, build1, L1, WilsonC2, panel, PhantomStrikeC2, EvilgnixC2, Tr4nsHack, ZygiskC2, AuraStealer, domain, DPRK, kimsuky, MoonPeak, Stella, golang, zimbra, zimbra-exfil, ZMBX, workes.dev, 14618, a77f04bc08864469eb801630c24264ba, AsynRAT, malware, d8b0m, ransomware, apt, botnet, infostealer 2026-08-21
critical C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2 threat-intel otx 45.158.196.184, 45.158.196.23 | 20675a659c338f72… github c2, backdoor, clickfix, oyster, initial access broker, lactrodectus, rust-based, dll sideloading, c2looper, ransomware, botnet 2026-08-17
critical Projextor: Abusing Electron in Trojanized Productivity Applications threat-intel otx e7bc36c7345b3894…, b648ec0880e9f542… javascript execution, trojanized software, impersonation websites, desktop capture, projextor, productivity applications, tamperedchef, electron framework 2026-08-17
critical Critical Elementor Pro bug exposes WordPress sites to RCE attacks news general-news rce 2026-08-20
critical Critical Zimbra RCE flaw now actively exploited in attacks news general-news rce 2026-08-20
critical Rogue ransomware affiliate poses as recovery firm to steal payments news general-news ransomware 2026-08-19
critical ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More news general-news rce 2026-08-20
critical Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE news general-news rce 2026-08-20
critical Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution news general-news rce 2026-08-20
critical Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code news general-news rce 2026-08-20
critical Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data news general-news ransomware 2026-08-19
critical Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000 news general-news ransomware 2026-08-18
critical CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE news general-news rce 2026-08-18
critical Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads news general-news rce 2026-08-17
critical ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More news general-news zeroday, supply-chain 2026-08-17
critical Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access news general-news rce 2026-08-17
critical Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware news general-news ransomware, apt 2026-08-17
critical 'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service news general-news ransomware 2026-08-18
critical Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities news general-news rce 2026-08-20
critical Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware news general-news ransomware 2026-08-19
critical Three-quarters of Ransomware Attacks Target Mid-Market Firms news general-news ransomware 2026-08-18
critical The long tail of Clop’s PTC hack is just beginning to emerge news general-news ransomware 2026-08-19
critical Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics news general-news ransomware 2026-08-18
high CVE-2026-33824 — Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability vulnerability cisa-kev CVE-2026-33824 rce 2026-08-18
high CVE-2026-59310 — Broadcom VMware vCenter Path Traversal Vulnerability vulnerability cisa-kev CVE-2026-59310 2026-08-18
high CVE-2026-55040 — Microsoft SharePoint Weak Authentication Vulnerability vulnerability cisa-kev CVE-2026-55040 2026-08-18
high CVE-2026-65400 — Apple macOS Improper Authentication Vulnerability vulnerability cisa-kev CVE-2026-65400 2026-08-18
high CVE-2025-62593 — Ray-Project Ray Code Injection Vulnerability vulnerability cisa-kev CVE-2025-62593 rce 2026-08-17
high Johnson Controls Simplex Incident Manager advisory cisa-advisories, vendor-blogs phishing, ics 2026-08-20
high Defending Against an Active Threat to Siemens S7 Series PLCs advisory cisa-advisories ics, supply-chain 2026-08-19
high CISA Malcolm advisory cisa-advisories, vendor-blogs phishing, ics 2026-08-18
high CVE-2026-19768 — Improper control of generation of code ('Code Injection') in the settings feature in Devolutions Pow… vulnerability nvd CVE-2026-19768 2026-08-14
high CVE-2026-73633 — Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an applica… vulnerability nvd CVE-2026-73633 2026-08-14
high CVE-2026-69101 — Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authen… vulnerability nvd CVE-2026-69101 2026-08-14
high CVE-2026-16772 — In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to… vulnerability nvd CVE-2026-16772 2026-08-14
high CVE-2026-53970 — ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby… vulnerability nvd CVE-2026-53970 2026-08-14
high CVE-2026-63700 — Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permissio… vulnerability nvd CVE-2026-63700 2026-08-14
high CVE-2026-66270 — Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File… vulnerability nvd CVE-2026-66270, CVE-2026-66271 rce 2026-08-14
high CVE-2026-19628 — A command injection vulnerability exists in Tenable Security Center. An authenticated administrator… vulnerability nvd CVE-2026-19628 2026-08-14
high CVE-2026-19844 — A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the func… vulnerability nvd CVE-2026-19844 2026-08-14
high CVE-2026-19845 — A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function s… vulnerability nvd CVE-2026-19845 2026-08-14
high CVE-2026-46380 — compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 a… vulnerability nvd CVE-2026-46380, CVE-2026-46345 2026-08-14
high CVE-2026-46439 — compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 a… vulnerability nvd CVE-2026-46439 2026-08-14
high CVE-2026-46603 — VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing… vulnerability nvd CVE-2026-46603 2026-08-14
high CVE-2026-12364 — The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was… vulnerability nvd CVE-2026-12364 2026-08-14
high CVE-2026-12366 — Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an… vulnerability nvd CVE-2026-12366 2026-08-14
high CVE-2026-19629 — A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Secu… vulnerability nvd CVE-2026-19629 2026-08-14
high CVE-2026-19635 — A local privilege escalation vulnerability exists in Security Center. An attacker with write access… vulnerability nvd CVE-2026-19635 2026-08-14
high CVE-2026-19679 — An input validation vulnerability exists in Security Center's file upload handling, where insufficie… vulnerability nvd CVE-2026-19679 2026-08-14
high CVE-2026-19680 — A SQL injection vulnerability exists in Security Center that could allow an attacker to access unaut… vulnerability nvd CVE-2026-19680 2026-08-14
high CVE-2026-19846 — A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function s… vulnerability nvd CVE-2026-19846 2026-08-14
high CVE-2026-19847 — A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the functi… vulnerability nvd CVE-2026-19847 2026-08-14
high CVE-2026-72970 — Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to exe… vulnerability nvd CVE-2026-72970 2026-08-14
high CVE-2025-7639 — The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operat… vulnerability nvd CVE-2025-7639 ics 2026-08-14
high CVE-2026-45699 — Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.… vulnerability nvd CVE-2026-45699, CVE-2026-45698 2026-08-14
high CVE-2026-73679 — ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module th… vulnerability nvd CVE-2026-73679 rce 2026-08-14
high CVE-2026-16708 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information… vulnerability nvd CVE-2026-16708 2026-08-14
high CVE-2026-16879 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass securit… vulnerability nvd CVE-2026-16879, CVE-2026-17079, CVE-2026-17227 2026-08-14
high CVE-2026-16905 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti… vulnerability nvd CVE-2026-16905, CVE-2026-16915, CVE-2026-17173, CVE-2026-17175, CVE-2026-18554 2026-08-14
high CVE-2026-17081 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to… vulnerability nvd CVE-2026-17081 2026-08-14
high CVE-2026-17177 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service du… vulnerability nvd CVE-2026-17177 2026-08-14
high CVE-2026-17179 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial… vulnerability nvd CVE-2026-17179 2026-08-14
high CVE-2026-73680 — Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration th… vulnerability nvd CVE-2026-73680 2026-08-14
high CVE-2026-50523 — Improper neutralization of special elements used in a command ('command injection') in Microsoft Pow… vulnerability nvd CVE-2026-50523 2026-08-14
high CVE-2026-69414 — Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Micros… vulnerability nvd CVE-2026-69414 2026-08-14
high CVE-2026-73683 — Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows un… vulnerability nvd CVE-2026-73683 ransomware 2026-08-14
high CVE-2026-14433 — The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable t… vulnerability nvd CVE-2026-14433 2026-08-15
high CVE-2026-15001 — The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalatio… vulnerability nvd CVE-2026-15001 2026-08-15
high CVE-2026-15162 — The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpre… vulnerability nvd CVE-2026-15162 2026-08-15
high CVE-2026-15312 — The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege… vulnerability nvd CVE-2026-15312 2026-08-15
high CVE-2026-15965 — The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnera… vulnerability nvd CVE-2026-15965 rce 2026-08-15
high CVE-2026-13360 — The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored… vulnerability nvd CVE-2026-13360 2026-08-15
high CVE-2026-16094 — The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vuln… vulnerability nvd CVE-2026-16094, CVE-2026-16145, CVE-2026-16146 2026-08-15
high CVE-2026-16611 — The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an… vulnerability nvd CVE-2026-16611 2026-08-15
high CVE-2026-68458 — In the Linux kernel, the following vulnerability has been resolved: binder: cache secctx size before… vulnerability nvd CVE-2026-68458 2026-08-15
high CVE-2026-68461 — In the Linux kernel, the following vulnerability has been resolved: device property: initialize the… vulnerability nvd CVE-2026-68461 2026-08-15
high CVE-2026-68462 — In the Linux kernel, the following vulnerability has been resolved: bpf: Reject negative const offse… vulnerability nvd CVE-2026-68462 2026-08-15
high CVE-2026-68466 — In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: lpc32xx_slc: fail… vulnerability nvd CVE-2026-68466 2026-08-15
high CVE-2026-68467 — In the Linux kernel, the following vulnerability has been resolved: mtd: mchp23k256: use SPI match d… vulnerability nvd CVE-2026-68467 2026-08-15
high CVE-2026-68470 — In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate extensi… vulnerability nvd CVE-2026-68470 2026-08-15
high CVE-2026-68471 — In the Linux kernel, the following vulnerability has been resolved: wifi: ieee80211: validate MLE co… vulnerability nvd CVE-2026-68471 2026-08-15
high CVE-2026-68472 — In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate EHT MLE… vulnerability nvd CVE-2026-68472 2026-08-15
high CVE-2026-68473 — In the Linux kernel, the following vulnerability has been resolved: powerpc/uaccess: correct check f… vulnerability nvd CVE-2026-68473 2026-08-15
high CVE-2026-68474 — In the Linux kernel, the following vulnerability has been resolved: powerpc/spufs: fix out-of-bounds… vulnerability nvd CVE-2026-68474 2026-08-15
high CVE-2026-68479 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: validate firmw… vulnerability nvd CVE-2026-68479 2026-08-15
high CVE-2026-72003 — In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: cyw: fix heap ov… vulnerability nvd CVE-2026-72003 2026-08-15
high CVE-2026-72005 — In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00: avoid full teardow… vulnerability nvd CVE-2026-72005 2026-08-15
high CVE-2026-72009 — In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx93-blk-ctrl: Extrac… vulnerability nvd CVE-2026-72009 2026-08-15
high CVE-2026-72012 — In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Call synchroniz… vulnerability nvd CVE-2026-72012 2026-08-15
high CVE-2026-72018 — In the Linux kernel, the following vulnerability has been resolved: dibs: loopback: validate offset… vulnerability nvd CVE-2026-72018 2026-08-15
high CVE-2026-72019 — In the Linux kernel, the following vulnerability has been resolved: macsec: don't read an unset MAC… vulnerability nvd CVE-2026-72019 2026-08-15
high CVE-2026-72021 — In the Linux kernel, the following vulnerability has been resolved: ipvs: use parsed transport offse… vulnerability nvd CVE-2026-72021 2026-08-15
high CVE-2026-72024 — In the Linux kernel, the following vulnerability has been resolved: mac802154: remove interfaces wit… vulnerability nvd CVE-2026-72024 2026-08-15
high CVE-2026-72027 — In the Linux kernel, the following vulnerability has been resolved: mm/compaction: handle free_pages… vulnerability nvd CVE-2026-72027 2026-08-15
high CVE-2026-72029 — In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: bound device of… vulnerability nvd CVE-2026-72029 2026-08-15
high CVE-2026-72034 — In the Linux kernel, the following vulnerability has been resolved: fhandle: reject detached mounts… vulnerability nvd CVE-2026-72034 2026-08-15
high CVE-2026-72035 — In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_taprio: Replace d… vulnerability nvd CVE-2026-72035 2026-08-15
high CVE-2026-72036 — In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_multiq: Replace d… vulnerability nvd CVE-2026-72036 2026-08-15
high CVE-2026-72042 — In the Linux kernel, the following vulnerability has been resolved: ipmi: Fix user refcount underflo… vulnerability nvd CVE-2026-72042 2026-08-15
high CVE-2026-72043 — In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix missing dirty pag… vulnerability nvd CVE-2026-72043 2026-08-15
high CVE-2026-72045 — In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: cn10k: restrict VF… vulnerability nvd CVE-2026-72045 2026-08-15
high CVE-2026-72049 — In the Linux kernel, the following vulnerability has been resolved: ieee802154: admin-gate legacy LL… vulnerability nvd CVE-2026-72049 2026-08-15
high CVE-2026-72051 — In the Linux kernel, the following vulnerability has been resolved: net: ip6_tunnel: require CAP_NET… vulnerability nvd CVE-2026-72051 2026-08-15
high CVE-2026-72052 — In the Linux kernel, the following vulnerability has been resolved: net: ip6_gre: require CAP_NET_AD… vulnerability nvd CVE-2026-72052 2026-08-15
high CVE-2026-72053 — In the Linux kernel, the following vulnerability has been resolved: net: ipip: require CAP_NET_ADMIN… vulnerability nvd CVE-2026-72053 2026-08-15
high CVE-2026-72054 — In the Linux kernel, the following vulnerability has been resolved: net: ip_vti: require CAP_NET_ADM… vulnerability nvd CVE-2026-72054 2026-08-15
high CVE-2026-72055 — In the Linux kernel, the following vulnerability has been resolved: net: ip6_vti: require CAP_NET_AD… vulnerability nvd CVE-2026-72055 2026-08-15
high CVE-2026-72057 — In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: preserve tc_s… vulnerability nvd CVE-2026-72057 2026-08-15
high CVE-2026-72061 — In the Linux kernel, the following vulnerability has been resolved: net: sit: require CAP_NET_ADMIN… vulnerability nvd CVE-2026-72061 2026-08-15
high CVE-2026-72066 — In the Linux kernel, the following vulnerability has been resolved: cpu: hotplug: Bound hotplug stat… vulnerability nvd CVE-2026-72066 2026-08-15
high CVE-2026-72067 — In the Linux kernel, the following vulnerability has been resolved: cpu: hotplug: Preserve per insta… vulnerability nvd CVE-2026-72067 2026-08-15
high CVE-2026-72071 — In the Linux kernel, the following vulnerability has been resolved: tracing/user_events: Fix use-aft… vulnerability nvd CVE-2026-72071 2026-08-15
high CVE-2026-72072 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: macsec: fix use-after… vulnerability nvd CVE-2026-72072 2026-08-15
high CVE-2026-72080 — In the Linux kernel, the following vulnerability has been resolved: fs/resctrl: Fix use-after-free d… vulnerability nvd CVE-2026-72080 2026-08-15
high CVE-2026-72089 — In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Reject firmware log… vulnerability nvd CVE-2026-72089 2026-08-15
high CVE-2026-72090 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Use caller client… vulnerability nvd CVE-2026-72090 2026-08-15
high CVE-2026-72093 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix use-after-fre… vulnerability nvd CVE-2026-72093 2026-08-15
high CVE-2026-72095 — In the Linux kernel, the following vulnerability has been resolved: dma-fence: Make dma_fence_dedup_… vulnerability nvd CVE-2026-72095 2026-08-15
high CVE-2026-72099 — In the Linux kernel, the following vulnerability has been resolved: dm-integrity: don't increment ha… vulnerability nvd CVE-2026-72099 2026-08-15
high CVE-2026-72100 — In the Linux kernel, the following vulnerability has been resolved: dm-integrity: fix a bug if the b… vulnerability nvd CVE-2026-72100 2026-08-15
high CVE-2026-72102 — In the Linux kernel, the following vulnerability has been resolved: dm_early_create: fix freeing use… vulnerability nvd CVE-2026-72102 2026-08-15
high CVE-2026-72103 — In the Linux kernel, the following vulnerability has been resolved: dm: avoid leaking the caller's t… vulnerability nvd CVE-2026-72103 2026-08-15
high CVE-2026-72105 — In the Linux kernel, the following vulnerability has been resolved: dm-log: fix a bitset_size overfl… vulnerability nvd CVE-2026-72105 botnet 2026-08-15
high CVE-2026-72107 — In the Linux kernel, the following vulnerability has been resolved: dm era: fix out-of-bounds memory… vulnerability nvd CVE-2026-72107 2026-08-15
high CVE-2026-72108 — In the Linux kernel, the following vulnerability has been resolved: dm thin metadata: fix metadata s… vulnerability nvd CVE-2026-72108 2026-08-15
high CVE-2026-72109 — In the Linux kernel, the following vulnerability has been resolved: net: sparx5: unregister blocking… vulnerability nvd CVE-2026-72109 2026-08-15
high CVE-2026-72110 — In the Linux kernel, the following vulnerability has been resolved: bpf,fork: wipe ->bpf_storage bef… vulnerability nvd CVE-2026-72110 2026-08-15
high CVE-2026-72111 — In the Linux kernel, the following vulnerability has been resolved: bpf: Reset register bounds befor… vulnerability nvd CVE-2026-72111 2026-08-15
high CVE-2026-72112 — In the Linux kernel, the following vulnerability has been resolved: io_uring/bpf-ops: reject re-regi… vulnerability nvd CVE-2026-72112 2026-08-15
high CVE-2026-72113 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing device ref… vulnerability nvd CVE-2026-72113 botnet 2026-08-15
high CVE-2026-72114 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: validate frame length… vulnerability nvd CVE-2026-72114 2026-08-15
high CVE-2026-72115 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: track a single source… vulnerability nvd CVE-2026-72115 2026-08-15
high CVE-2026-72116 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix stale rx/tx ops af… vulnerability nvd CVE-2026-72116 2026-08-15
high CVE-2026-72119 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: extend bcm_tx_lock usa… vulnerability nvd CVE-2026-72119 2026-08-15
high CVE-2026-72120 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu list a… vulnerability nvd CVE-2026-72120 2026-08-15
high CVE-2026-72121 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking when updat… vulnerability nvd CVE-2026-72121 2026-08-15
high CVE-2026-72122 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix lockless bound/ifi… vulnerability nvd CVE-2026-72122 2026-08-15
high CVE-2026-72123 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: defer rx_op deallocati… vulnerability nvd CVE-2026-72123 2026-08-15
high CVE-2026-72124 — In the Linux kernel, the following vulnerability has been resolved: can: isotp: serialize TX state t… vulnerability nvd CVE-2026-72124 2026-08-15
high CVE-2026-72125 — In the Linux kernel, the following vulnerability has been resolved: can: isotp: fix use-after-free r… vulnerability nvd CVE-2026-72125 2026-08-15
high CVE-2026-72126 — In the Linux kernel, the following vulnerability has been resolved: can: isotp: use unconditional sy… vulnerability nvd CVE-2026-72126 2026-08-15
high CVE-2026-72127 — In the Linux kernel, the following vulnerability has been resolved: netdev-genl: report NAPI thread… vulnerability nvd CVE-2026-72127 botnet 2026-08-15
high CVE-2026-72133 — In the Linux kernel, the following vulnerability has been resolved: spi: uniphier: Fix completion in… vulnerability nvd CVE-2026-72133 2026-08-15
high CVE-2026-72134 — In the Linux kernel, the following vulnerability has been resolved: spi: imx: reconfigure for PIO wh… vulnerability nvd CVE-2026-72134 2026-08-15
high CVE-2026-72135 — In the Linux kernel, the following vulnerability has been resolved: tpm: Make the TPM character devi… vulnerability nvd CVE-2026-72135 2026-08-15
high CVE-2026-72136 — In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_interface: require CA… vulnerability nvd CVE-2026-72136 2026-08-15
high CVE-2026-72141 — In the Linux kernel, the following vulnerability has been resolved: i2c: imx: fix locked bus on SMBu… vulnerability nvd CVE-2026-72141, CVE-2026-72142 2026-08-15
high CVE-2026-72143 — In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Restore SST-… vulnerability nvd CVE-2026-72143 2026-08-15
high CVE-2026-72144 — In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-laptop: fix m… vulnerability nvd CVE-2026-72144 2026-08-15
high CVE-2026-72146 — In the Linux kernel, the following vulnerability has been resolved: dmaengine: sh: rz-dmac: Move int… vulnerability nvd CVE-2026-72146 2026-08-15
high CVE-2026-72148 — In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Add spinlock… vulnerability nvd CVE-2026-72148 2026-08-15
high CVE-2026-72149 — In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra: Fix burst size… vulnerability nvd CVE-2026-72149 2026-08-15
high CVE-2026-72151 — In the Linux kernel, the following vulnerability has been resolved: tpm: tpm2-sessions: wait for asy… vulnerability nvd CVE-2026-72151 2026-08-15
high CVE-2026-72154 — In the Linux kernel, the following vulnerability has been resolved: openrisc: Fix jump_label smp syn… vulnerability nvd CVE-2026-72154 2026-08-15
high CVE-2026-72157 — In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Fix frags[] ov… vulnerability nvd CVE-2026-72157 2026-08-15
high CVE-2026-72160 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject dinodes with non-c… vulnerability nvd CVE-2026-72160 2026-08-15
high CVE-2026-72162 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix UBSAN array-index-out… vulnerability nvd CVE-2026-72162 2026-08-15
high CVE-2026-72164 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: avoid moving extents to o… vulnerability nvd CVE-2026-72164 2026-08-15
high CVE-2026-72165 — In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: fix condition in '… vulnerability nvd CVE-2026-72165 2026-08-15
high CVE-2026-72170 — In the Linux kernel, the following vulnerability has been resolved: 9p: skip nlink update in cachele… vulnerability nvd CVE-2026-72170 2026-08-15
high CVE-2026-72171 — In the Linux kernel, the following vulnerability has been resolved: mtd: slram: remove failed entrie… vulnerability nvd CVE-2026-72171 2026-08-15
high CVE-2026-72172 — In the Linux kernel, the following vulnerability has been resolved: mm/mm_init: fix uninitialized st… vulnerability nvd CVE-2026-72172 2026-08-15
high CVE-2026-72175 — In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: fix make_uffd_… vulnerability nvd CVE-2026-72175 2026-08-15
high CVE-2026-72181 — In the Linux kernel, the following vulnerability has been resolved: mips: sched: Fix CPUMASK_OFFSTAC… vulnerability nvd CVE-2026-72181 2026-08-15
high CVE-2026-72183 — In the Linux kernel, the following vulnerability has been resolved: landlock: Fix LANDLOCK_SCOPE_SIG… vulnerability nvd CVE-2026-72183 2026-08-15
high CVE-2026-72195 — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound attr_off in Upda… vulnerability nvd CVE-2026-72195 2026-08-15
high CVE-2026-72196 — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound copy_lcns dp->pa… vulnerability nvd CVE-2026-72196 ransomware 2026-08-15
high CVE-2026-72197 — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound DeleteIndexEntry… vulnerability nvd CVE-2026-72197 2026-08-15
high CVE-2026-72198 — In the Linux kernel, the following vulnerability has been resolved: ntfs: reject non-resident record… vulnerability nvd CVE-2026-72198 2026-08-15
high CVE-2026-72202 — In the Linux kernel, the following vulnerability has been resolved: ntfs: avoid heap allocation for… vulnerability nvd CVE-2026-72202 2026-08-15
high CVE-2026-72203 — In the Linux kernel, the following vulnerability has been resolved: ntfs: skip extent mft records in… vulnerability nvd CVE-2026-72203 2026-08-15
high CVE-2026-72204 — In the Linux kernel, the following vulnerability has been resolved: ntfs: centalize $INDEX_ROOT head… vulnerability nvd CVE-2026-72204 2026-08-15
high CVE-2026-72213 — In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb cgroup r… vulnerability nvd CVE-2026-72213 2026-08-15
high CVE-2026-72225 — In the Linux kernel, the following vulnerability has been resolved: jbd2: fix integer underflow in j… vulnerability nvd CVE-2026-72225 2026-08-15
high CVE-2026-72227 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: avoid OOB rea… vulnerability nvd CVE-2026-72227 2026-08-15
high CVE-2026-72231 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: avoid request st… vulnerability nvd CVE-2026-72231 2026-08-15
high CVE-2026-72232 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: ensure minimal ether… vulnerability nvd CVE-2026-72232 2026-08-15
high CVE-2026-72233 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: reacquire gw ad… vulnerability nvd CVE-2026-72233 2026-08-15
high CVE-2026-72235 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: retrieve ethhdr afte… vulnerability nvd CVE-2026-72235 2026-08-15
high CVE-2026-72242 — In the Linux kernel, the following vulnerability has been resolved: selinux: avoid sk_socket derefer… vulnerability nvd CVE-2026-72242 2026-08-15
high CVE-2026-72243 — In the Linux kernel, the following vulnerability has been resolved: selinux: check connect-related p… vulnerability nvd CVE-2026-72243 2026-08-15
high CVE-2026-72244 — In the Linux kernel, the following vulnerability has been resolved: gpu/buddy: bail out of try_harde… vulnerability nvd CVE-2026-72244 2026-08-15
high CVE-2026-72247 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: fix zon… vulnerability nvd CVE-2026-72247 2026-08-15
high CVE-2026-72250 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_reasm: g… vulnerability nvd CVE-2026-72250 2026-08-15
high CVE-2026-72252 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: don't… vulnerability nvd CVE-2026-72252 2026-08-15
high CVE-2026-72253 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: val… vulnerability nvd CVE-2026-72253 2026-08-15
high CVE-2026-72254 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_fib: reject fib e… vulnerability nvd CVE-2026-72254 2026-08-15
high CVE-2026-72255 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: pin bridge… vulnerability nvd CVE-2026-72255 2026-08-15
high CVE-2026-72261 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Validat… vulnerability nvd CVE-2026-72261 2026-08-15
high CVE-2026-72262 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Fix hea… vulnerability nvd CVE-2026-72262 2026-08-15
high CVE-2026-72280 — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Drop bogus WARN… vulnerability nvd CVE-2026-72280 2026-08-15
high CVE-2026-72282 — In the Linux kernel, the following vulnerability has been resolved: KVM: Move kvm_io_bus_get_dev() l… vulnerability nvd CVE-2026-72282 2026-08-15
high CVE-2026-72283 — In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Nullify irqfd->produce… vulnerability nvd CVE-2026-72283 2026-08-15
high CVE-2026-72284 — In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ignore pending PV EOI… vulnerability nvd CVE-2026-72284 2026-08-15
high CVE-2026-72285 — In the Linux kernel, the following vulnerability has been resolved: KVM: TDX: Reject concurrent chan… vulnerability nvd CVE-2026-72285 2026-08-15
high CVE-2026-72286 — In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Do not allow intra-hos… vulnerability nvd CVE-2026-72286 2026-08-15
high CVE-2026-72287 — In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Move vTPR vs. TPR Thr… vulnerability nvd CVE-2026-72287 2026-08-15
high CVE-2026-72294 — In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Check irq validi… vulnerability nvd CVE-2026-72294 2026-08-15
high CVE-2026-72295 — In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Validate irqchip… vulnerability nvd CVE-2026-72295 2026-08-15
high CVE-2026-72297 — In the Linux kernel, the following vulnerability has been resolved: net: atm: reject out-of-range tr… vulnerability nvd CVE-2026-72297 2026-08-15
high CVE-2026-72298 — In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix 32-bit integer ov… vulnerability nvd CVE-2026-72298 2026-08-15
high CVE-2026-72301 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Fix TOC… vulnerability nvd CVE-2026-72301 2026-08-15
high CVE-2026-72302 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Use ove… vulnerability nvd CVE-2026-72302 2026-08-15
high CVE-2026-72303 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-control: Validat… vulnerability nvd CVE-2026-72303 2026-08-15
high CVE-2026-72304 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-control: Fix TOC… vulnerability nvd CVE-2026-72304 2026-08-15
high CVE-2026-72310 — In the Linux kernel, the following vulnerability has been resolved: smb: client: fix overflow in pas… vulnerability nvd CVE-2026-72310 2026-08-15
high CVE-2026-72312 — In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: fix VF bringup aff… vulnerability nvd CVE-2026-72312 2026-08-15
high CVE-2026-72314 — In the Linux kernel, the following vulnerability has been resolved: regulator: core: regulator_lock_… vulnerability nvd CVE-2026-72314 2026-08-15
high CVE-2026-72315 — In the Linux kernel, the following vulnerability has been resolved: smb: client: fix busy dentry war… vulnerability nvd CVE-2026-72315 2026-08-15
high CVE-2026-72328 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix potential amd… vulnerability nvd CVE-2026-72328 2026-08-15
high CVE-2026-72330 — In the Linux kernel, the following vulnerability has been resolved: net/tls: Consume empty data reco… vulnerability nvd CVE-2026-72330 2026-08-15
high CVE-2026-72331 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix VMA access ra… vulnerability nvd CVE-2026-72331 2026-08-15
high CVE-2026-72334 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix malformed IS… vulnerability nvd CVE-2026-72334 2026-08-15
high CVE-2026-72335 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix adv monitor… vulnerability nvd CVE-2026-72335 2026-08-15
high CVE-2026-72338 — In the Linux kernel, the following vulnerability has been resolved: net/sched: act_pedit: fix TOCTOU… vulnerability nvd CVE-2026-72338 2026-08-15
high CVE-2026-72340 — In the Linux kernel, the following vulnerability has been resolved: net: microchip: vcap: fix races… vulnerability nvd CVE-2026-72340 2026-08-15
high CVE-2026-72342 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix HV VHCA stats age… vulnerability nvd CVE-2026-72342 2026-08-15
high CVE-2026-72343 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix HV VHCA stats zer… vulnerability nvd CVE-2026-72343 2026-08-15
high CVE-2026-72344 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: TC, skip peer flow cl… vulnerability nvd CVE-2026-72344 2026-08-15
high CVE-2026-72345 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5: LAG, Fix off-by-one in… vulnerability nvd CVE-2026-72345 2026-08-15
high CVE-2026-72347 — In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_connmark: reject i… vulnerability nvd CVE-2026-72347 2026-08-15
high CVE-2026-72350 — In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_u32: reject invali… vulnerability nvd CVE-2026-72350 2026-08-15
high CVE-2026-72352 — In the Linux kernel, the following vulnerability has been resolved: HID: bpf: Fix hid_bpf_get_data()… vulnerability nvd CVE-2026-72352 2026-08-15
high CVE-2026-72353 — In the Linux kernel, the following vulnerability has been resolved: ntfs: avoid stale runlist elemen… vulnerability nvd CVE-2026-72353, CVE-2026-72354 2026-08-15
high CVE-2026-72356 — In the Linux kernel, the following vulnerability has been resolved: cifs: Fix missing credit release… vulnerability nvd CVE-2026-72356 2026-08-15
high CVE-2026-72357 — In the Linux kernel, the following vulnerability has been resolved: uprobes/x86: Use proper mm_struc… vulnerability nvd CVE-2026-72357 2026-08-15
high CVE-2026-72358 — In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: prevent invalid curso… vulnerability nvd CVE-2026-72358 2026-08-15
high CVE-2026-72360 — In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Don't attempt to proc… vulnerability nvd CVE-2026-72360 2026-08-15
high CVE-2026-72364 — In the Linux kernel, the following vulnerability has been resolved: netfs: Fix writeback error handl… vulnerability nvd CVE-2026-72364 2026-08-15
high CVE-2026-72367 — In the Linux kernel, the following vulnerability has been resolved: iomap: guard io_size EOF trim ag… vulnerability nvd CVE-2026-72367 2026-08-15
high CVE-2026-72368 — In the Linux kernel, the following vulnerability has been resolved: cachefiles: Fix double unlock in… vulnerability nvd CVE-2026-72368 2026-08-15
high CVE-2026-72369 — In the Linux kernel, the following vulnerability has been resolved: minix: avoid overflow in bitmap… vulnerability nvd CVE-2026-72369 2026-08-15
high CVE-2026-72371 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix the volume AFS_VOLUME_R… vulnerability nvd CVE-2026-72371 2026-08-15
high CVE-2026-72372 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix lack of locking around… vulnerability nvd CVE-2026-72372 2026-08-15
high CVE-2026-72373 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix missing NULL pointer ch… vulnerability nvd CVE-2026-72373 2026-08-15
high CVE-2026-72374 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix callback service messag… vulnerability nvd CVE-2026-72374 2026-08-15
high CVE-2026-72375 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix reinitialisation of the… vulnerability nvd CVE-2026-72375 2026-08-15
high CVE-2026-72378 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix error code in afs_extra… vulnerability nvd CVE-2026-72378 2026-08-15
high CVE-2026-72380 — In the Linux kernel, the following vulnerability has been resolved: xen/pvcalls: bound backend respo… vulnerability nvd CVE-2026-72380 2026-08-15
high CVE-2026-72382 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject undersized DACLs b… vulnerability nvd CVE-2026-72382 2026-08-15
high CVE-2026-72383 — In the Linux kernel, the following vulnerability has been resolved: sctp: fix addr_wq_timer race in… vulnerability nvd CVE-2026-72383 2026-08-15
high CVE-2026-72389 — In the Linux kernel, the following vulnerability has been resolved: bridge: stp: Fix a potential use… vulnerability nvd CVE-2026-72389 2026-08-15
high CVE-2026-72390 — In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_teql: Introduce s… vulnerability nvd CVE-2026-72390 2026-08-15
high CVE-2026-72395 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus) Fix passing event… vulnerability nvd CVE-2026-72395 2026-08-15
high CVE-2026-72397 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/core) honor vrm_ve… vulnerability nvd CVE-2026-72397 2026-08-15
high CVE-2026-72400 — In the Linux kernel, the following vulnerability has been resolved: seg6: validate SRH length before… vulnerability nvd CVE-2026-72400 2026-08-15
high CVE-2026-72404 — In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in cleanup_bearer(… vulnerability nvd CVE-2026-72404 2026-08-15
high CVE-2026-72405 — In the Linux kernel, the following vulnerability has been resolved: net: udp_tunnel: prevent double… vulnerability nvd CVE-2026-72405 2026-08-15
high CVE-2026-72406 — In the Linux kernel, the following vulnerability has been resolved: net: sungem: fix probe error cle… vulnerability nvd CVE-2026-72406 2026-08-15
high CVE-2026-72409 — In the Linux kernel, the following vulnerability has been resolved: net: mvneta: re-enable percpu in… vulnerability nvd CVE-2026-72409 2026-08-15
high CVE-2026-72410 — In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Validate NIX maxim… vulnerability nvd CVE-2026-72410 2026-08-15
high CVE-2026-72411 — In the Linux kernel, the following vulnerability has been resolved: net: dsa: mxl862xx: fix use-afte… vulnerability nvd CVE-2026-72411 2026-08-15
high CVE-2026-72415 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: Validate written enu… vulnerability nvd CVE-2026-72415 2026-08-15
high CVE-2026-72416 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_compat: ebtables… vulnerability nvd CVE-2026-72416 2026-08-15
high CVE-2026-72418 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: prevent… vulnerability nvd CVE-2026-72418 2026-08-15
high CVE-2026-72419 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat: avoid invalid… vulnerability nvd CVE-2026-72419 botnet 2026-08-15
high CVE-2026-72420 — In the Linux kernel, the following vulnerability has been resolved: md/raid5: avoid R5_Overlap races… vulnerability nvd CVE-2026-72420 botnet 2026-08-15
high CVE-2026-72423 — In the Linux kernel, the following vulnerability has been resolved: bpf: Guard conntrack opts error… vulnerability nvd CVE-2026-72423 2026-08-15
high CVE-2026-72425 — In the Linux kernel, the following vulnerability has been resolved: ice: fix FDIR CTRL VSI resource… vulnerability nvd CVE-2026-72425 2026-08-15
high CVE-2026-72426 — In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve pointer spill meta… vulnerability nvd CVE-2026-72426 2026-08-15
high CVE-2026-72427 — In the Linux kernel, the following vulnerability has been resolved: bpf: Fix effective prog array in… vulnerability nvd CVE-2026-72427 ransomware 2026-08-15
high CVE-2026-72434 — In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: make sure gc i… vulnerability nvd CVE-2026-72434 2026-08-15
high CVE-2026-72435 — In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix order of k… vulnerability nvd CVE-2026-72435 2026-08-15
high CVE-2026-72438 — In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix writes_pending an… vulnerability nvd CVE-2026-72438 2026-08-15
high CVE-2026-72440 — In the Linux kernel, the following vulnerability has been resolved: md/raid1: fix writes_pending and… vulnerability nvd CVE-2026-72440 2026-08-15
high CVE-2026-72444 — In the Linux kernel, the following vulnerability has been resolved: flow_dissector: check device typ… vulnerability nvd CVE-2026-72444 2026-08-15
high CVE-2026-72446 — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: qcom: reject st… vulnerability nvd CVE-2026-72446 2026-08-15
high CVE-2026-72449 — In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix list_del corrupt… vulnerability nvd CVE-2026-72449 2026-08-15
high CVE-2026-72450 — In the Linux kernel, the following vulnerability has been resolved: xfrm: validate selector family a… vulnerability nvd CVE-2026-72450 2026-08-15
high CVE-2026-72452 — In the Linux kernel, the following vulnerability has been resolved: drm/i915: clear CRTC color blob… vulnerability nvd CVE-2026-72452 2026-08-15
high CVE-2026-72454 — In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Fix race in i… vulnerability nvd CVE-2026-72454 2026-08-15
high CVE-2026-72455 — In the Linux kernel, the following vulnerability has been resolved: apparmor: fix uninitialised poin… vulnerability nvd CVE-2026-72455 2026-08-15
high CVE-2026-72459 — In the Linux kernel, the following vulnerability has been resolved: apparmor: aa_label_alloc use aa_… vulnerability nvd CVE-2026-72459 2026-08-15
high CVE-2026-72460 — In the Linux kernel, the following vulnerability has been resolved: apparmor: check label build befo… vulnerability nvd CVE-2026-72460 2026-08-15
high CVE-2026-72461 — In the Linux kernel, the following vulnerability has been resolved: apparmor: fix refcount leak when… vulnerability nvd CVE-2026-72461 2026-08-15
high CVE-2026-72462 — In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race in unix socke… vulnerability nvd CVE-2026-72462 2026-08-15
high CVE-2026-72464 — In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Repost Receive buffers… vulnerability nvd CVE-2026-72464 2026-08-15
high CVE-2026-72465 — In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Sanitize the reply cre… vulnerability nvd CVE-2026-72465 2026-08-15
high CVE-2026-72469 — In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Fix ep kref imbalance… vulnerability nvd CVE-2026-72469 2026-08-15
high CVE-2026-72470 — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: resize log->one_page_b… vulnerability nvd CVE-2026-72470 ransomware 2026-08-15
high CVE-2026-72471 — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: prevent potential lcn… vulnerability nvd CVE-2026-72471 2026-08-15
high CVE-2026-72476 — In the Linux kernel, the following vulnerability has been resolved: dmaengine: Fix possible use afte… vulnerability nvd CVE-2026-72476 2026-08-15
high CVE-2026-72478 — In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: add bounds check to ru… vulnerability nvd CVE-2026-72478 ransomware 2026-08-15
high CVE-2026-72480 — In the Linux kernel, the following vulnerability has been resolved: iio: adc: xilinx-ams: fix out-of… vulnerability nvd CVE-2026-72480 2026-08-15
high CVE-2026-72482 — In the Linux kernel, the following vulnerability has been resolved: gpib: fix double decrement of de… vulnerability nvd CVE-2026-72482 2026-08-15
high CVE-2026-72483 — In the Linux kernel, the following vulnerability has been resolved: usb: host: max3421: Fix shift-ou… vulnerability nvd CVE-2026-72483 2026-08-15
high CVE-2026-72485 — In the Linux kernel, the following vulnerability has been resolved: coresight: platform: defer conne… vulnerability nvd CVE-2026-72485 2026-08-15
high CVE-2026-72487 — In the Linux kernel, the following vulnerability has been resolved: PCI: Check ROM header and data s… vulnerability nvd CVE-2026-72487 2026-08-15
high CVE-2026-72488 — In the Linux kernel, the following vulnerability has been resolved: soundwire: fix bug in sdw_add_el… vulnerability nvd CVE-2026-72488 2026-08-15
high CVE-2026-72489 — In the Linux kernel, the following vulnerability has been resolved: staging: nvec: fix use-after-fre… vulnerability nvd CVE-2026-72489 2026-08-15
high CVE-2026-72492 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in sam… vulnerability nvd CVE-2026-72492 2026-08-15
high CVE-2026-72497 — In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Add a max slot che… vulnerability nvd CVE-2026-72497 2026-08-15
high CVE-2026-72499 — In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Free CQ toggle pag… vulnerability nvd CVE-2026-72499 2026-08-15
high CVE-2026-72500 — In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Free SRQ toggle pa… vulnerability nvd CVE-2026-72500 2026-08-15
high CVE-2026-72502 — In the Linux kernel, the following vulnerability has been resolved: tcp: ipv6: clamp default adverti… vulnerability nvd CVE-2026-72502 2026-08-15
high CVE-2026-74256 — In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: fix integer overfl… vulnerability nvd CVE-2026-74256 botnet 2026-08-15
high CVE-2026-74257 — In the Linux kernel, the following vulnerability has been resolved: sockmap: Fix use-after-free in u… vulnerability nvd CVE-2026-74257 botnet 2026-08-15
high CVE-2026-74258 — In the Linux kernel, the following vulnerability has been resolved: bpf: Guard __get_user acesss wit… vulnerability nvd CVE-2026-74258 2026-08-15
high CVE-2026-74259 — In the Linux kernel, the following vulnerability has been resolved: cifs: remove all cifs files befo… vulnerability nvd CVE-2026-74259 2026-08-15
high CVE-2026-74260 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_dup_netdev: add nf… vulnerability nvd CVE-2026-74260 2026-08-15
high CVE-2026-74262 — In the Linux kernel, the following vulnerability has been resolved: kcm: use WRITE_ONCE() when chang… vulnerability nvd CVE-2026-74262 2026-08-15
high CVE-2026-74264 — In the Linux kernel, the following vulnerability has been resolved: net: watchdog: fix refcount trac… vulnerability nvd CVE-2026-74264 2026-08-15
high CVE-2026-74266 — In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_dualpi2: Do not c… vulnerability nvd CVE-2026-74266 botnet 2026-08-15
high CVE-2026-74270 — In the Linux kernel, the following vulnerability has been resolved: handshake: Require admin permiss… vulnerability nvd CVE-2026-74270 2026-08-15
high CVE-2026-74275 — In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix out-of-bounds ac… vulnerability nvd CVE-2026-74275 2026-08-15
high CVE-2026-74277 — In the Linux kernel, the following vulnerability has been resolved: iommu/dma-iommu: Fix wrong scatt… vulnerability nvd CVE-2026-74277 2026-08-15
high CVE-2026-74281 — In the Linux kernel, the following vulnerability has been resolved: tipc: reject inverted service ra… vulnerability nvd CVE-2026-74281 2026-08-15
high CVE-2026-74282 — In the Linux kernel, the following vulnerability has been resolved: tipc: prevent snt_unacked underf… vulnerability nvd CVE-2026-74282 2026-08-15
high CVE-2026-74283 — In the Linux kernel, the following vulnerability has been resolved: tipc: require net admin for TIPC… vulnerability nvd CVE-2026-74283 2026-08-15
high CVE-2026-74285 — In the Linux kernel, the following vulnerability has been resolved: net: Stop leased rxq before unin… vulnerability nvd CVE-2026-74285 2026-08-15
high CVE-2026-74288 — In the Linux kernel, the following vulnerability has been resolved: net: fib_rules: Don't dump dying… vulnerability nvd CVE-2026-74288 2026-08-15
high CVE-2026-74289 — In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: Don't dump dying fib_… vulnerability nvd CVE-2026-74289 2026-08-15
high CVE-2026-74292 — In the Linux kernel, the following vulnerability has been resolved: ASoC: tegra: tegra210_ahub: Vali… vulnerability nvd CVE-2026-74292 2026-08-15
high CVE-2026-74293 — In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl: fsl_audmix: Validate… vulnerability nvd CVE-2026-74293 2026-08-15
high CVE-2026-74294 — In the Linux kernel, the following vulnerability has been resolved: ASoC: meson: aiu: Validate writt… vulnerability nvd CVE-2026-74294 2026-08-15
high CVE-2026-74295 — In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: hdac_hdmi: Validat… vulnerability nvd CVE-2026-74295 2026-08-15
high CVE-2026-74296 — In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Release the HW‑provid… vulnerability nvd CVE-2026-74296 2026-08-15
high CVE-2026-74297 — In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix undefined shift o… vulnerability nvd CVE-2026-74297 2026-08-15
high CVE-2026-74300 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci: validate codec c… vulnerability nvd CVE-2026-74300 2026-08-15
high CVE-2026-74302 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix UAF in… vulnerability nvd CVE-2026-74302 2026-08-15
high CVE-2026-74305 — In the Linux kernel, the following vulnerability has been resolved: bpf: Tighten cgroup storage cook… vulnerability nvd CVE-2026-74305 2026-08-15
high CVE-2026-74306 — In the Linux kernel, the following vulnerability has been resolved: vfio/qat: fix f_pos race in qat_… vulnerability nvd CVE-2026-74306 2026-08-15
high CVE-2026-74311 — In the Linux kernel, the following vulnerability has been resolved: virtio: rtc: tear down old virtq… vulnerability nvd CVE-2026-74311 2026-08-15
high CVE-2026-74312 — In the Linux kernel, the following vulnerability has been resolved: vhost/vdpa: validate virtqueue i… vulnerability nvd CVE-2026-74312 2026-08-15
high CVE-2026-74313 — In the Linux kernel, the following vulnerability has been resolved: vduse: hold vduse_lock across ID… vulnerability nvd CVE-2026-74313 2026-08-15
high CVE-2026-74314 — In the Linux kernel, the following vulnerability has been resolved: bpf: Cancel special fields on ma… vulnerability nvd CVE-2026-74314 2026-08-15
high CVE-2026-74316 — In the Linux kernel, the following vulnerability has been resolved: NFSD: Handle layout stid in nfsd… vulnerability nvd CVE-2026-74316 2026-08-15
high CVE-2026-74317 — In the Linux kernel, the following vulnerability has been resolved: ixgbe: do not configure xps for… vulnerability nvd CVE-2026-74317 2026-08-15
high CVE-2026-74321 — In the Linux kernel, the following vulnerability has been resolved: btrfs: fix invalid pointer deref… vulnerability nvd CVE-2026-74321 2026-08-15
high CVE-2026-74322 — In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: Fix possible… vulnerability nvd CVE-2026-74322, CVE-2026-74323 2026-08-15
high CVE-2026-74325 — In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: use kfree_rcu for of… vulnerability nvd CVE-2026-74325 2026-08-15
high CVE-2026-74328 — In the Linux kernel, the following vulnerability has been resolved: iommufd: Destroy the pages conte… vulnerability nvd CVE-2026-74328 2026-08-15
high CVE-2026-74330 — In the Linux kernel, the following vulnerability has been resolved: configfs: fix lockless traversal… vulnerability nvd CVE-2026-74330 2026-08-15
high CVE-2026-74332 — In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp-sdw-sof: Bound DA… vulnerability nvd CVE-2026-74332 2026-08-15
high CVE-2026-74333 — In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp-sdw-legacy: Bound… vulnerability nvd CVE-2026-74333 2026-08-15
high CVE-2026-74334 — In the Linux kernel, the following vulnerability has been resolved: RDMA/nldev: Fix locking when acc… vulnerability nvd CVE-2026-74334 2026-08-15
high CVE-2026-74338 — In the Linux kernel, the following vulnerability has been resolved: bpf: Reject sleepable BPF_LSM_CG… vulnerability nvd CVE-2026-74338 2026-08-15
high CVE-2026-74340 — In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix OOB read from… vulnerability nvd CVE-2026-74340 2026-08-15
high CVE-2026-74341 — In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix heap overflow… vulnerability nvd CVE-2026-74341 2026-08-15
high CVE-2026-74343 — In the Linux kernel, the following vulnerability has been resolved: kernfs: fix xattr race condition… vulnerability nvd CVE-2026-74343 2026-08-15
high CVE-2026-74344 — In the Linux kernel, the following vulnerability has been resolved: bpf: Clear rb node linkage when… vulnerability nvd CVE-2026-74344 2026-08-15
high CVE-2026-74347 — In the Linux kernel, the following vulnerability has been resolved: netfilter: cttimeout: detach dat… vulnerability nvd CVE-2026-74347 2026-08-15
high CVE-2026-74349 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject FITRIM ranges shor… vulnerability nvd CVE-2026-74349 2026-08-15
high CVE-2026-74354 — In the Linux kernel, the following vulnerability has been resolved: bpf: Take mmap_lock in zap_pages… vulnerability nvd CVE-2026-74354 2026-08-15
high CVE-2026-74355 — In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix RB-tree corrupti… vulnerability nvd CVE-2026-74355 2026-08-15
high CVE-2026-74356 — In the Linux kernel, the following vulnerability has been resolved: vhost: fix vhost_get_avail_idx f… vulnerability nvd CVE-2026-74356 2026-08-15
high CVE-2026-74357 — In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix KASAN slab-out-o… vulnerability nvd CVE-2026-74357 2026-08-15
high CVE-2026-74359 — In the Linux kernel, the following vulnerability has been resolved: configfs_lookup(): don't leave -… vulnerability nvd CVE-2026-74359 2026-08-15
high CVE-2026-74363 — In the Linux kernel, the following vulnerability has been resolved: bpf: fix UAF by restoring RCU-de… vulnerability nvd CVE-2026-74363 2026-08-15
high CVE-2026-74364 — In the Linux kernel, the following vulnerability has been resolved: bpf: Reject exclusive maps as in… vulnerability nvd CVE-2026-74364 2026-08-15
high CVE-2026-74365 — In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: Handle preemption in… vulnerability nvd CVE-2026-74365 2026-08-15
high CVE-2026-74367 — In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix inconsistent a… vulnerability nvd CVE-2026-74367 2026-08-15
high CVE-2026-74371 — In the Linux kernel, the following vulnerability has been resolved: bpf: fix BPF_PROG_QUERY OOB writ… vulnerability nvd CVE-2026-74371 2026-08-15
high CVE-2026-74374 — In the Linux kernel, the following vulnerability has been resolved: md/raid1,raid10: fix error-path… vulnerability nvd CVE-2026-74374 2026-08-15
high CVE-2026-74377 — In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Copy WQE to local buff… vulnerability nvd CVE-2026-74377 2026-08-15
high CVE-2026-74378 — In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix TOCTOU heap overfl… vulnerability nvd CVE-2026-74378 2026-08-15
high CVE-2026-74380 — In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix iommu_map_sgtab… vulnerability nvd CVE-2026-74380 2026-08-15
high CVE-2026-74383 — In the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix out-of-bounds acce… vulnerability nvd CVE-2026-74383 2026-08-15
high CVE-2026-74385 — In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check return value of… vulnerability nvd CVE-2026-74385 2026-08-15
high CVE-2026-74387 — In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: midi: Serialize outpu… vulnerability nvd CVE-2026-74387 2026-08-15
high CVE-2026-74388 — In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: oss: Fix UAF at handl… vulnerability nvd CVE-2026-74388 2026-08-15
high CVE-2026-74390 — In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix out-of-bounds wr… vulnerability nvd CVE-2026-74390 2026-08-15
high CVE-2026-74396 — In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix UMR XLT cleanup o… vulnerability nvd CVE-2026-74396 2026-08-15
high CVE-2026-74397 — In the Linux kernel, the following vulnerability has been resolved: IB/mlx5: Fix transport-domain ro… vulnerability nvd CVE-2026-74397 2026-08-15
high CVE-2026-74403 — In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Check for page all… vulnerability nvd CVE-2026-74403 2026-08-15
high CVE-2026-74404 — In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix snp_filter_res… vulnerability nvd CVE-2026-74404 2026-08-15
high CVE-2026-74405 — In the Linux kernel, the following vulnerability has been resolved: OPP: Fix race between OPP additi… vulnerability nvd CVE-2026-74405 2026-08-15
high CVE-2026-74407 — In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: cancel SSR work it… vulnerability nvd CVE-2026-74407 2026-08-15
high CVE-2026-74408 — In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: fix OOB access from… vulnerability nvd CVE-2026-74408 2026-08-15
high CVE-2026-74409 — In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: add bounds check on… vulnerability nvd CVE-2026-74409 2026-08-15
high CVE-2026-74410 — In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: fix OOB read from f… vulnerability nvd CVE-2026-74410 2026-08-15
high CVE-2026-74411 — In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: Correct data type f… vulnerability nvd CVE-2026-74411 2026-08-15
high CVE-2026-74412 — In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: fix wrong pci_get_d… vulnerability nvd CVE-2026-74412 2026-08-15
high CVE-2026-74413 — In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix wrong pci_get_d… vulnerability nvd CVE-2026-74413 2026-08-15
high CVE-2026-74417 — In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix integer overflow… vulnerability nvd CVE-2026-74417 2026-08-15
high CVE-2026-74419 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Adjust size for c… vulnerability nvd CVE-2026-74419 2026-08-15
high CVE-2026-74425 — In the Linux kernel, the following vulnerability has been resolved: afs: handle CB.InitCallBackState… vulnerability nvd CVE-2026-74425 2026-08-15
high CVE-2026-74429 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the reception of a re… vulnerability nvd CVE-2026-74429 2026-08-15
high CVE-2026-74430 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix ACKALL packet handlin… vulnerability nvd CVE-2026-74430 2026-08-15
high CVE-2026-74431 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix potential infinite lo… vulnerability nvd CVE-2026-74431 2026-08-15
high CVE-2026-74435 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: rxrpc_verify_data ensure… vulnerability nvd CVE-2026-74435 2026-08-15
high CVE-2026-74438 — In the Linux kernel, the following vulnerability has been resolved: crypto: sun4i-ss - Remove insecu… vulnerability nvd CVE-2026-74438 2026-08-15
high CVE-2026-14279 — The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, a… vulnerability nvd CVE-2026-14279 2026-08-15
high CVE-2026-15142 — The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versio… vulnerability nvd CVE-2026-15142 2026-08-15
high CVE-2026-18438 — The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud!… vulnerability nvd CVE-2026-18438 rce 2026-08-15
high CVE-2026-73634 — Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an end… vulnerability nvd CVE-2026-73634 2026-08-15
high CVE-2026-73635 — Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed l… vulnerability nvd CVE-2026-73635 2026-08-15
high CVE-2026-74440 — In the Linux kernel, the following vulnerability has been resolved: drm/xe: Wait on external BO kern… vulnerability nvd CVE-2026-74440 2026-08-15
high CVE-2026-74443 — In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: bound DMA command bo… vulnerability nvd CVE-2026-74443 2026-08-15
high CVE-2026-74444 — In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: validate DRAW_PRIMIT… vulnerability nvd CVE-2026-74444 2026-08-15
high CVE-2026-74446 — In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: hold event_mutex whi… vulnerability nvd CVE-2026-74446 2026-08-15
high CVE-2026-74447 — In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix uint32_t overflo… vulnerability nvd CVE-2026-74447 2026-08-15
high CVE-2026-74449 — In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix divide-by-z… vulnerability nvd CVE-2026-74449 ransomware 2026-08-15
high CVE-2026-74450 — In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: fix pptable use-afte… vulnerability nvd CVE-2026-74450 2026-08-15
high CVE-2026-74451 — In the Linux kernel, the following vulnerability has been resolved: drm/panthor: validate firmware i… vulnerability nvd CVE-2026-74451 2026-08-15
high CVE-2026-74452 — In the Linux kernel, the following vulnerability has been resolved: drm/panthor: reject firmware sec… vulnerability nvd CVE-2026-74452 2026-08-15
high CVE-2026-74453 — In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Zero the tile state dat… vulnerability nvd CVE-2026-74453 2026-08-15
high CVE-2026-74454 — In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Supply the overflow slo… vulnerability nvd CVE-2026-74454 2026-08-15
high CVE-2026-74456 — In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: peak_usb_start():… vulnerability nvd CVE-2026-74456 2026-08-15
high CVE-2026-74461 — In the Linux kernel, the following vulnerability has been resolved: i2c: imx: Cancel hrtimer before… vulnerability nvd CVE-2026-74461 2026-08-15
high CVE-2026-74465 — In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix potential… vulnerability nvd CVE-2026-74465 zeroday 2026-08-15
high CVE-2026-74467 — In the Linux kernel, the following vulnerability has been resolved: s390/qeth: Check CAP_NET_ADMIN f… vulnerability nvd CVE-2026-74467 2026-08-15
high CVE-2026-74469 — In the Linux kernel, the following vulnerability has been resolved: sctp: prevent peer transport cou… vulnerability nvd CVE-2026-74469 2026-08-15
high CVE-2026-74470 — In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_debug: Fix REPORT ZON… vulnerability nvd CVE-2026-74470 2026-08-15
high CVE-2026-74471 — In the Linux kernel, the following vulnerability has been resolved: tracing: Check return value of _… vulnerability nvd CVE-2026-74471 2026-08-15
high CVE-2026-74479 — In the Linux kernel, the following vulnerability has been resolved: net: pktgen: fix proc entry use-… vulnerability nvd CVE-2026-74479 2026-08-15
high CVE-2026-74481 — In the Linux kernel, the following vulnerability has been resolved: mm/page_reporting: use system_fr… vulnerability nvd CVE-2026-74481 2026-08-15
high CVE-2026-74482 — In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: unlock i_mmap_rw… vulnerability nvd CVE-2026-74482 2026-08-15
high CVE-2026-74485 — In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: reject a flag chara… vulnerability nvd CVE-2026-74485 2026-08-15
high CVE-2026-74488 — In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: use the subframe… vulnerability nvd CVE-2026-74488 2026-08-15
high CVE-2026-74489 — In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix tid_tx use-a… vulnerability nvd CVE-2026-74489 2026-08-15
high CVE-2026-74490 — In the Linux kernel, the following vulnerability has been resolved: tipc: avoid use-after-free in po… vulnerability nvd CVE-2026-74490 2026-08-15
high CVE-2026-74492 — In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: do not update… vulnerability nvd CVE-2026-74492 ransomware 2026-08-15
high CVE-2026-74496 — In the Linux kernel, the following vulnerability has been resolved: fou: Fix use-after-free in fou_c… vulnerability nvd CVE-2026-74496 2026-08-15
high CVE-2026-74497 — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Clamp frame siz… vulnerability nvd CVE-2026-74497 ransomware 2026-08-15
high CVE-2026-74503 — In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Clear SNDRV_TIMER_I… vulnerability nvd CVE-2026-74503 2026-08-15
high CVE-2026-74506 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix UAF when sending a mess… vulnerability nvd CVE-2026-74506 ransomware 2026-08-15
high CVE-2026-74507 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: validate number… vulnerability nvd CVE-2026-74507 2026-08-15
high CVE-2026-74508 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: reject frames w… vulnerability nvd CVE-2026-74508 2026-08-15
high CVE-2026-74509 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix adverti… vulnerability nvd CVE-2026-74509 2026-08-15
high CVE-2026-74510 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix UAF in pair… vulnerability nvd CVE-2026-74510 2026-08-15
high CVE-2026-74512 — In the Linux kernel, the following vulnerability has been resolved: audit: fix potential use-after-f… vulnerability nvd CVE-2026-74512 2026-08-15
high CVE-2026-74513 — In the Linux kernel, the following vulnerability has been resolved: dibs: fix use-after-free of dmb_… vulnerability nvd CVE-2026-74513 botnet 2026-08-15
high CVE-2026-74515 — In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Reject adapter i… vulnerability nvd CVE-2026-74515 2026-08-15
high CVE-2026-74516 — In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Update x2APIC MSR inte… vulnerability nvd CVE-2026-74516 2026-08-15
high CVE-2026-74518 — In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix list corruption… vulnerability nvd CVE-2026-74518 botnet 2026-08-15
high CVE-2026-74519 — In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: don't free… vulnerability nvd CVE-2026-74519 2026-08-15
high CVE-2026-74520 — In the Linux kernel, the following vulnerability has been resolved: iommu/iommufd: Fix IOPF group ow… vulnerability nvd CVE-2026-74520 2026-08-15
high CVE-2026-74522 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __c… vulnerability nvd CVE-2026-74522 2026-08-15
high CVE-2026-74523 — In the Linux kernel, the following vulnerability has been resolved: qede: sync udp_tunnel ports outs… vulnerability nvd CVE-2026-74523 2026-08-15
high CVE-2026-74527 — In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Block VFs from clo… vulnerability nvd CVE-2026-74527 2026-08-15
high CVE-2026-74528 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn i… vulnerability nvd CVE-2026-74528, CVE-2026-74529, CVE-2026-74530 2026-08-15
high CVE-2026-74531 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: hold conn r… vulnerability nvd CVE-2026-74531 2026-08-15
high CVE-2026-74533 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix race of kfre… vulnerability nvd CVE-2026-74533 2026-08-15
high CVE-2026-74534 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix refcounting… vulnerability nvd CVE-2026-74534 2026-08-15
high CVE-2026-74535 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: avoid deadlocks… vulnerability nvd CVE-2026-74535 2026-08-15
high CVE-2026-74537 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: hold sk properly… vulnerability nvd CVE-2026-74537 2026-08-15
high CVE-2026-74538 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: lock sk in iso_c… vulnerability nvd CVE-2026-74538 2026-08-15
high CVE-2026-74539 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: lock sk in iso_s… vulnerability nvd CVE-2026-74539 2026-08-15
high CVE-2026-74540 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix UAF in l2c… vulnerability nvd CVE-2026-74540 2026-08-15
high CVE-2026-74541 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: clear iso_data a… vulnerability nvd CVE-2026-74541 2026-08-15
high CVE-2026-74544 — In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_u32: validate off… vulnerability nvd CVE-2026-74544 2026-08-15
high CVE-2026-74548 — In the Linux kernel, the following vulnerability has been resolved: forcedeth: fix UAF of txrx_stats… vulnerability nvd CVE-2026-74548 2026-08-15
high CVE-2026-74549 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct6775-core) Prevent ac… vulnerability nvd CVE-2026-74549 2026-08-15
high CVE-2026-74550 — In the Linux kernel, the following vulnerability has been resolved: net: do not send ICMP/NDISC Redi… vulnerability nvd CVE-2026-74550 2026-08-15
high CVE-2026-74551 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (nzxt-smart2) DMA-align o… vulnerability nvd CVE-2026-74551 2026-08-15
high CVE-2026-74554 — In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix out-of-bounds… vulnerability nvd CVE-2026-74554 2026-08-15
high CVE-2026-74557 — In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi: Fix stale-data l… vulnerability nvd CVE-2026-74557 2026-08-15
high CVE-2026-74560 — In the Linux kernel, the following vulnerability has been resolved: xsk: fix buffer leak in xsk_drop… vulnerability nvd CVE-2026-74560 botnet 2026-08-15
high CVE-2026-74561 — In the Linux kernel, the following vulnerability has been resolved: nexthop: avoid unlocked f6i_list… vulnerability nvd CVE-2026-74561 2026-08-15
high CVE-2026-74562 — In the Linux kernel, the following vulnerability has been resolved: nexthop: take nh->lock for f6i_l… vulnerability nvd CVE-2026-74562 2026-08-15
high CVE-2026-74563 — In the Linux kernel, the following vulnerability has been resolved: rds: tcp: hold the RCU lock acro… vulnerability nvd CVE-2026-74563 2026-08-15
high CVE-2026-74564 — In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_hashlimit: validat… vulnerability nvd CVE-2026-74564 2026-08-15
high CVE-2026-74565 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: make nft_o… vulnerability nvd CVE-2026-74565 2026-08-15
high CVE-2026-74567 — In the Linux kernel, the following vulnerability has been resolved: keys: fix out-of-bounds read in… vulnerability nvd CVE-2026-74567 2026-08-15
high CVE-2026-74572 — In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix deadlock betwe… vulnerability nvd CVE-2026-74572 2026-08-15
high CVE-2026-74574 — In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix fdev setup… vulnerability nvd CVE-2026-74574 2026-08-15
high CVE-2026-74575 — In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Prevent XDomain del… vulnerability nvd CVE-2026-74575 2026-08-15
high CVE-2026-74576 — In the Linux kernel, the following vulnerability has been resolved: mm/slab: prevent unbounded recur… vulnerability nvd CVE-2026-74576 2026-08-15
high CVE-2026-18500 — @fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verifi… vulnerability nvd CVE-2026-18500 2026-08-15
high CVE-2026-18549 — @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not… vulnerability nvd CVE-2026-18549 2026-08-15
high CVE-2026-19474 — @fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not… vulnerability nvd CVE-2026-19474 2026-08-15
high CVE-2026-19899 — A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected… vulnerability nvd CVE-2026-19899 2026-08-15
high CVE-2026-19900 — A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown… vulnerability nvd CVE-2026-19900 2026-08-15
high CVE-2026-19901 — A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown functi… vulnerability nvd CVE-2026-19901 2026-08-15
high CVE-2026-19905 — A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHS… vulnerability nvd CVE-2026-19905 2026-08-15
high CVE-2026-73045 — SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerabil… vulnerability nvd CVE-2026-73045 2026-08-15
high CVE-2026-73054 — SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoi… vulnerability nvd CVE-2026-73054 2026-08-15
high CVE-2026-19919 — A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown funct… vulnerability nvd CVE-2026-19919 2026-08-16
high CVE-2026-19926 — A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected el… vulnerability nvd CVE-2026-19926 2026-08-16
high CVE-2026-14498 — The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to… vulnerability nvd CVE-2026-14498 rce 2026-08-16
high CVE-2026-15002 — The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Sc… vulnerability nvd CVE-2026-15002 2026-08-16
high CVE-2026-16099 — The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to i… vulnerability nvd CVE-2026-16099 rce 2026-08-16
high CVE-2026-17123 — The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in vers… vulnerability nvd CVE-2026-17123 ransomware 2026-08-16
high CVE-2026-17533 — The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration… vulnerability nvd CVE-2026-17533 2026-08-16
high CVE-2026-17581 — The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code In… vulnerability nvd CVE-2026-17581 rce 2026-08-16
high CVE-2026-18653 — The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before u… vulnerability nvd CVE-2026-18653 2026-08-16
high CVE-2026-19717 — The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisat… vulnerability nvd CVE-2026-19717 2026-08-16
high CVE-2026-19728 — The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify th… vulnerability nvd CVE-2026-19728 2026-08-16
high CVE-2026-10734 — The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_recor… vulnerability nvd CVE-2026-10734 2026-08-16
high CVE-2026-13424 — The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to… vulnerability nvd CVE-2026-13424 2026-08-16
high CVE-2026-17087 — The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerab… vulnerability nvd CVE-2026-17087 2026-08-16
high CVE-2026-2497 — The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_ord… vulnerability nvd CVE-2026-2497 2026-08-16
high CVE-2026-74578 — In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force s… vulnerability nvd CVE-2026-74578 2026-08-16
high CVE-2026-73057 — stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing att… vulnerability nvd CVE-2026-73057 2026-08-16
high CVE-2026-73060 — Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRan… vulnerability nvd CVE-2026-73060 2026-08-16
high CVE-2026-73062 — Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multipli… vulnerability nvd CVE-2026-73062 2026-08-16
high CVE-2026-74783 — Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails t… vulnerability nvd CVE-2026-74783 2026-08-16
high CVE-2026-74787 — Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin… vulnerability nvd CVE-2026-74787 2026-08-16
high CVE-2026-74788 — Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnera… vulnerability nvd CVE-2026-74788 2026-08-16
high CVE-2026-74789 — Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statem… vulnerability nvd CVE-2026-74789 2026-08-16
high CVE-2026-74791 — Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is c… vulnerability nvd CVE-2026-74791 2026-08-16
high CVE-2026-74792 — Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested… vulnerability nvd CVE-2026-74792 2026-08-16
high CVE-2026-74794 — Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the Objec… vulnerability nvd CVE-2026-74794 2026-08-16
high CVE-2026-74795 — Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parse… vulnerability nvd CVE-2026-74795 2026-08-16
high CVE-2026-19960 — A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function form… vulnerability nvd CVE-2026-19960 2026-08-16
high CVE-2026-19962 — A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setW… vulnerability nvd CVE-2026-19962 2026-08-17
high CVE-2026-19963 — A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function sta… vulnerability nvd CVE-2026-19963 2026-08-17
high CVE-2026-19979 — A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE… vulnerability nvd CVE-2026-19979 2026-08-17
high CVE-2026-19980 — A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE930… vulnerability nvd CVE-2026-19980 2026-08-17
high CVE-2026-19981 — A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE… vulnerability nvd CVE-2026-19981 2026-08-17
high CVE-2026-19982 — A security vulnerability has been detected in GL.iNet BE9300 and MT6000 4.8.x. This vulnerability af… vulnerability nvd CVE-2026-19982 2026-08-17
high CVE-2026-19983 — A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE… vulnerability nvd CVE-2026-19983 2026-08-17
high CVE-2026-74845 — Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulner… vulnerability nvd CVE-2026-74845 2026-08-17
high CVE-2026-74798 — SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool.… vulnerability nvd CVE-2026-74798 2026-08-17
high CVE-2026-74801 — SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-lin… vulnerability nvd CVE-2026-74801 2026-08-17
high CVE-2026-74802 — SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-onl… vulnerability nvd CVE-2026-74802 2026-08-17
high CVE-2026-74868 — SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service… vulnerability nvd CVE-2026-74868 2026-08-17
high CVE-2026-74869 — stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message hand… vulnerability nvd CVE-2026-74869 ransomware 2026-08-17
high CVE-2026-74874 — openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographi… vulnerability nvd CVE-2026-74874 2026-08-17
high CVE-2026-74877 — openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the… vulnerability nvd CVE-2026-74877 2026-08-17
high CVE-2026-74879 — openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready… vulnerability nvd CVE-2026-74879 2026-08-17
high CVE-2026-74882 — openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the enti… vulnerability nvd CVE-2026-74882 2026-08-17
high CVE-2026-74883 — openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbo… vulnerability nvd CVE-2026-74883 2026-08-17
high CVE-2026-74884 — openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path me… vulnerability nvd CVE-2026-74884 2026-08-17
high CVE-2026-74888 — openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with ite… vulnerability nvd CVE-2026-74888 2026-08-17
high CVE-2026-74892 — openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telem… vulnerability nvd CVE-2026-74892 2026-08-17
high CVE-2026-74893 — openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py tha… vulnerability nvd CVE-2026-74893 2026-08-17
high CVE-2026-16467 — Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing F… vulnerability nvd CVE-2026-16467 2026-08-17
high CVE-2026-74997 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk pl… vulnerability nvd CVE-2026-74997 rce 2026-08-17
high CVE-2026-74998 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style S… vulnerability nvd CVE-2026-74998 2026-08-17
high CVE-2026-75002 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desyn… vulnerability nvd CVE-2026-75002 2026-08-17
high CVE-2026-15218 — A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. Th… vulnerability nvd CVE-2026-15218 rce 2026-08-17
high CVE-2026-16137 — In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credential… vulnerability nvd CVE-2026-16137 2026-08-17
high CVE-2026-16138 — In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of… vulnerability nvd CVE-2026-16138 2026-08-17
high CVE-2026-16139 — In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zon… vulnerability nvd CVE-2026-16139 rce 2026-08-17
high CVE-2026-16471 — Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Fun… vulnerability nvd CVE-2026-16471 2026-08-17
high CVE-2026-19693 — extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and nev… vulnerability nvd CVE-2026-19693 2026-08-17
high CVE-2026-56089 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privil… vulnerability nvd CVE-2026-56089, CVE-2026-59909 2026-08-17
high CVE-2026-56090 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerab… vulnerability nvd CVE-2026-56090 2026-08-17
high CVE-2026-56685 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elemen… vulnerability nvd CVE-2026-56685, CVE-2026-56686, CVE-2026-59910 2026-08-17
high CVE-2026-71567 — In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variable… vulnerability nvd CVE-2026-71567 2026-08-17
high CVE-2026-73646 — PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rul… vulnerability nvd CVE-2026-73646 2026-08-17
high CVE-2026-75044 — In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed… vulnerability nvd CVE-2026-75044 2026-08-17
high CVE-2026-75048 — In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was po… vulnerability nvd CVE-2026-75048 2026-08-17
high CVE-2026-75050 — In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type par… vulnerability nvd CVE-2026-75050 2026-08-17
high CVE-2026-75051 — In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was po… vulnerability nvd CVE-2026-75051 2026-08-17
high CVE-2026-75056 — In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible vulnerability nvd CVE-2026-75056 rce 2026-08-17
high CVE-2026-75060 — In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP too… vulnerability nvd CVE-2026-75060 2026-08-17
high CVE-2026-9771 — The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On bu… vulnerability nvd CVE-2026-9771 2026-08-17
high CVE-2026-33437 — Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. P… vulnerability nvd CVE-2026-33437, CVE-2026-57485 2026-08-17
high CVE-2026-59893 — sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/key… vulnerability nvd CVE-2026-59893 2026-08-17
high CVE-2026-59902 — Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2… vulnerability nvd CVE-2026-59902, CVE-2026-59903, CVE-2026-75596 2026-08-17
high CVE-2026-62982 — Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_m… vulnerability nvd CVE-2026-62982 2026-08-17
high CVE-2026-71979 — INDI (Instrument Neutral Distributed Interface) indiserver through 2.2.4.2, fixed in commit 96bbd7f,… vulnerability nvd CVE-2026-71979 2026-08-17
high CVE-2026-71980 — Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the d… vulnerability nvd CVE-2026-71980 2026-08-17
high CVE-2026-73522 — COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthentic… vulnerability nvd CVE-2026-73522 2026-08-17
high CVE-2026-73523 — COVESA Open1722 through 0.9.2 contains an integer truncation vulnerability in acf-can-listener.c tha… vulnerability nvd CVE-2026-73523 2026-08-17
high CVE-2026-50773 — An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to ex… vulnerability nvd CVE-2026-50773 2026-08-17
high CVE-2026-50776 — Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote atta… vulnerability nvd CVE-2026-50776 2026-08-17
high CVE-2026-74238 — TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpac… vulnerability nvd CVE-2026-74238 2026-08-17
high CVE-2026-54758 — Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the expandNppEnvironmentStrs… vulnerability nvd CVE-2026-54758 2026-08-17
high CVE-2026-57233 — Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress functi… vulnerability nvd CVE-2026-57233 2026-08-17
high CVE-2026-68005 — An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via… vulnerability nvd CVE-2026-68005 2026-08-17
high CVE-2026-70495 — A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad pe… vulnerability nvd CVE-2026-70495 2026-08-17
high CVE-2026-74234 — Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achi… vulnerability nvd CVE-2026-74234 2026-08-17
high CVE-2026-75014 — A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability aff… vulnerability nvd CVE-2026-75014 2026-08-17
high CVE-2026-19589 — Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow uni… vulnerability nvd CVE-2026-19589 2026-08-17
high CVE-2026-34398 — FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mo… vulnerability nvd CVE-2026-34398 2026-08-17
high CVE-2026-34399 — FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCA… vulnerability nvd CVE-2026-34399 2026-08-17
high CVE-2026-34789 — FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/Prope… vulnerability nvd CVE-2026-34789 2026-08-17
high CVE-2026-54356 — Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/u… vulnerability nvd CVE-2026-54356 2026-08-17
high CVE-2026-63409 — Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malic… vulnerability nvd CVE-2026-63409 2026-08-17
high CVE-2026-64657 — Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector… vulnerability nvd CVE-2026-64657 2026-08-17
high CVE-2026-65822 — ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0,… vulnerability nvd CVE-2026-65822 2026-08-17
high CVE-2026-65832 — Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthe… vulnerability nvd CVE-2026-65832 2026-08-17
high CVE-2026-71518 — Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download rou… vulnerability nvd CVE-2026-71518 2026-08-17
high CVE-2026-73410 — Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outbo… vulnerability nvd CVE-2026-73410 2026-08-17
high CVE-2026-75103 — Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allow… vulnerability nvd CVE-2026-75103 2026-08-17
high CVE-2026-75105 — phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary… vulnerability nvd CVE-2026-75105 2026-08-17
high CVE-2026-75109 — Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the… vulnerability nvd CVE-2026-75109 2026-08-17
high CVE-2026-75111 — Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoi… vulnerability nvd CVE-2026-75111 2026-08-17
high CVE-2026-75479 — JimuReport contains an authentication bypass vulnerability in the report folder template listing end… vulnerability nvd CVE-2026-75479 2026-08-17
high CVE-2026-75481 — SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when u… vulnerability nvd CVE-2026-75481 2026-08-17
high CVE-2026-75482 — SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that j… vulnerability nvd CVE-2026-75482 2026-08-17
high CVE-2026-43794 — A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari… vulnerability nvd CVE-2026-43794 2026-08-17
high CVE-2026-45790 — Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organizati… vulnerability nvd CVE-2026-45790 2026-08-17
high CVE-2026-56677 — 9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint i… vulnerability nvd CVE-2026-56677 2026-08-17
high CVE-2026-65343 — A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.… vulnerability nvd CVE-2026-65343 2026-08-17
high CVE-2026-65346 — An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1… vulnerability nvd CVE-2026-65346 2026-08-17
high CVE-2026-67918 — Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensi… vulnerability nvd CVE-2026-67918 2026-08-17
high CVE-2026-9816 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMe… vulnerability nvd CVE-2026-9816 2026-08-17
high CVE-2026-67961 — An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mech… vulnerability nvd CVE-2026-67961 2026-08-17
high CVE-2026-75079 — A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnera… vulnerability nvd CVE-2026-75079 2026-08-18
high CVE-2026-75080 — A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0.… vulnerability nvd CVE-2026-75080 2026-08-18
high CVE-2026-75089 — A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue… vulnerability nvd CVE-2026-75089 2026-08-18
high CVE-2026-11801 — The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all… vulnerability nvd CVE-2026-11801 2026-08-18
high CVE-2026-75091 — The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnera… vulnerability nvd CVE-2026-75091 2026-08-18
high CVE-2026-15371 — Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the… vulnerability nvd CVE-2026-15371 2026-08-18
high CVE-2026-15585 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN… vulnerability nvd CVE-2026-15585 2026-08-18
high CVE-2026-74902 — SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flo… vulnerability nvd CVE-2026-74902 2026-08-18
high CVE-2026-74904 — SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kerne… vulnerability nvd CVE-2026-74904 2026-08-18
high CVE-2026-74905 — SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP… vulnerability nvd CVE-2026-74905 2026-08-18
high CVE-2026-74906 — SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-… vulnerability nvd CVE-2026-74906 2026-08-18
high CVE-2026-75827 — Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare… vulnerability nvd CVE-2026-75827 rce 2026-08-18
high CVE-2026-75828 — Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function… vulnerability nvd CVE-2026-75828 2026-08-18
high CVE-2026-75829 — grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, al… vulnerability nvd CVE-2026-75829 2026-08-18
high CVE-2026-75830 — grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path tra… vulnerability nvd CVE-2026-75830 2026-08-18
high CVE-2026-75831 — Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media… vulnerability nvd CVE-2026-75831 2026-08-18
high CVE-2026-75836 — The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.1… vulnerability nvd CVE-2026-75836 2026-08-18
high CVE-2026-75840 — ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandb… vulnerability nvd CVE-2026-75840 2026-08-18
high CVE-2026-75842 — ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD… vulnerability nvd CVE-2026-75842 2026-08-18
high CVE-2026-75844 — ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DA… vulnerability nvd CVE-2026-75844 2026-08-18
high CVE-2026-75846 — ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability… vulnerability nvd CVE-2026-75846 2026-08-18
high CVE-2026-75853 — ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforc… vulnerability nvd CVE-2026-75853 2026-08-18
high CVE-2026-75855 — ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint'… vulnerability nvd CVE-2026-75855 2026-08-18
high CVE-2026-74935 — Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154,… vulnerability nvd CVE-2026-74935 2026-08-18
high CVE-2026-74937 — Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox… vulnerability nvd CVE-2026-74937 2026-08-18
high CVE-2026-74939 — Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154,… vulnerability nvd CVE-2026-74939 2026-08-18
high CVE-2026-74941 — Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox… vulnerability nvd CVE-2026-74941 2026-08-18
high CVE-2026-74942 — Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefo… vulnerability nvd CVE-2026-74942 2026-08-18
high CVE-2026-74946 — Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. Th… vulnerability nvd CVE-2026-74946 2026-08-18
high CVE-2026-74947 — Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed… vulnerability nvd CVE-2026-74947 2026-08-18
high CVE-2026-74949 — Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability w… vulnerability nvd CVE-2026-74949 2026-08-18
high CVE-2026-74950 — Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Fi… vulnerability nvd CVE-2026-74950 2026-08-18
high CVE-2026-74952 — Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 15… vulnerability nvd CVE-2026-74952 2026-08-18
high CVE-2026-74953 — Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 1… vulnerability nvd CVE-2026-74953 2026-08-18
high CVE-2026-74954 — Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability w… vulnerability nvd CVE-2026-74954 2026-08-18
high CVE-2026-74955 — Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154,… vulnerability nvd CVE-2026-74955 2026-08-18
high CVE-2026-74958 — Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox… vulnerability nvd CVE-2026-74958 2026-08-18
high CVE-2026-74962 — Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 1… vulnerability nvd CVE-2026-74962 2026-08-18
high CVE-2026-74965 — Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154… vulnerability nvd CVE-2026-74965 2026-08-18
high CVE-2026-74966 — Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154,… vulnerability nvd CVE-2026-74966 2026-08-18
high CVE-2026-74969 — Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154,… vulnerability nvd CVE-2026-74969 2026-08-18
high CVE-2026-74978 — Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR… vulnerability nvd CVE-2026-74978 2026-08-18
high CVE-2026-74981 — Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firef… vulnerability nvd CVE-2026-74981 2026-08-18
high CVE-2026-74982 — Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR… vulnerability nvd CVE-2026-74982 2026-08-18
high CVE-2026-74983 — Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154… vulnerability nvd CVE-2026-74983 2026-08-18
high CVE-2026-75778 — A vulnerability was identified in code-projects Task Management System 1.0. This affects the functio… vulnerability nvd CVE-2026-75778 2026-08-18
high CVE-2026-24301 — Improper neutralization of special elements used in a command ('command injection') in Microsoft Cop… vulnerability nvd CVE-2026-24301 2026-08-18
high CVE-2026-28191 — Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions. vulnerability nvd CVE-2026-28191 2026-08-18
high CVE-2026-28567 — Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions. vulnerability nvd CVE-2026-28567 2026-08-18
high CVE-2026-28568 — Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. vulnerability nvd CVE-2026-28568 2026-08-18
high CVE-2026-28569 — Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions. vulnerability nvd CVE-2026-28569 2026-08-18
high CVE-2026-28570 — Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions. vulnerability nvd CVE-2026-28570 2026-08-18
high CVE-2026-28571 — Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions. vulnerability nvd CVE-2026-28571 2026-08-18
high CVE-2026-32333 — Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions. vulnerability nvd CVE-2026-32333 2026-08-18
high CVE-2026-32464 — Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. vulnerability nvd CVE-2026-32464 2026-08-18
high CVE-2026-32465 — Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions. vulnerability nvd CVE-2026-32465 2026-08-18
high CVE-2026-32466 — Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. vulnerability nvd CVE-2026-32466 2026-08-18
high CVE-2026-32468 — Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. vulnerability nvd CVE-2026-32468 2026-08-18
high CVE-2026-50575 — BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly inv… vulnerability nvd CVE-2026-50575 ransomware 2026-08-18
high CVE-2026-18534 — ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated… vulnerability nvd CVE-2026-18534 2026-08-18
high CVE-2026-32472 — Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions. vulnerability nvd CVE-2026-32472 2026-08-18
high CVE-2026-32473 — Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versio… vulnerability nvd CVE-2026-32473 2026-08-18
high CVE-2026-32481 — Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions. vulnerability nvd CVE-2026-32481 2026-08-18
high CVE-2026-32547 — Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. vulnerability nvd CVE-2026-32547 2026-08-18
high CVE-2026-32549 — Unauthenticated Broken Access Control in ThumbPress < 6.5 versions. vulnerability nvd CVE-2026-32549 2026-08-18
high CVE-2026-32553 — Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions. vulnerability nvd CVE-2026-32553 2026-08-18
high CVE-2026-45733 — Trilium Notes is a cross-platform, hierarchical note taking application focused on building large pe… vulnerability nvd CVE-2026-45733 2026-08-18
high CVE-2026-48798 — SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string… vulnerability nvd CVE-2026-48798 2026-08-18
high CVE-2026-50138 — goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with Web… vulnerability nvd CVE-2026-50138 2026-08-18
high CVE-2026-50187 — Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the d… vulnerability nvd CVE-2026-50187 2026-08-18
high CVE-2026-56684 — Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey… vulnerability nvd CVE-2026-56684, CVE-2026-63639 rce 2026-08-18
high CVE-2026-59825 — Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from… vulnerability nvd CVE-2026-59825 2026-08-18
high CVE-2026-61407 — Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Acce… vulnerability nvd CVE-2026-61407 2026-08-18
high CVE-2026-66046 — Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic compl… vulnerability nvd CVE-2026-66046 2026-08-18
high CVE-2026-66620 — Editor PHP Object Injection in OptionTree <= 2.7.3 versions. vulnerability nvd CVE-2026-66620 2026-08-18
high CVE-2026-66621 — Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions. vulnerability nvd CVE-2026-66621 2026-08-18
high CVE-2026-66622 — Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions. vulnerability nvd CVE-2026-66622 2026-08-18
high CVE-2026-66629 — Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions. vulnerability nvd CVE-2026-66629 2026-08-18
high CVE-2026-66633 — Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. vulnerability nvd CVE-2026-66633 2026-08-18
high CVE-2026-66635 — Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions. vulnerability nvd CVE-2026-66635 2026-08-18
high CVE-2026-66667 — Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions. vulnerability nvd CVE-2026-66667 2026-08-18
high CVE-2026-66793 — A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Man… vulnerability nvd CVE-2026-66793 2026-08-18
high CVE-2026-68567 — Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions. vulnerability nvd CVE-2026-68567 2026-08-18
high CVE-2026-69189 — Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.use… vulnerability nvd CVE-2026-69189 2026-08-18
high CVE-2026-73181 — Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 ver… vulnerability nvd CVE-2026-73181 2026-08-18
high CVE-2026-73190 — Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions. vulnerability nvd CVE-2026-73190 2026-08-18
high CVE-2026-73338 — Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions. vulnerability nvd CVE-2026-73338 2026-08-18
high CVE-2026-73342 — Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions. vulnerability nvd CVE-2026-73342 2026-08-18
high CVE-2026-73345 — Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions. vulnerability nvd CVE-2026-73345 2026-08-18
high CVE-2026-73350 — Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions. vulnerability nvd CVE-2026-73350 2026-08-18
high CVE-2026-73351 — Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions. vulnerability nvd CVE-2026-73351 2026-08-18
high CVE-2026-73356 — Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions. vulnerability nvd CVE-2026-73356 2026-08-18
high CVE-2026-73358 — Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions. vulnerability nvd CVE-2026-73358 2026-08-18
high CVE-2026-73360 — Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions. vulnerability nvd CVE-2026-73360 2026-08-18
high CVE-2026-73361 — Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18… vulnerability nvd CVE-2026-73361 2026-08-18
high CVE-2026-73362 — Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions. vulnerability nvd CVE-2026-73362 2026-08-18
high CVE-2026-73367 — Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions. vulnerability nvd CVE-2026-73367 2026-08-18
high CVE-2026-73375 — Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions. vulnerability nvd CVE-2026-73375 2026-08-18
high CVE-2026-73377 — Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions. vulnerability nvd CVE-2026-73377 2026-08-18
high CVE-2026-73378 — Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions. vulnerability nvd CVE-2026-73378 2026-08-18
high CVE-2026-73382 — Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions. vulnerability nvd CVE-2026-73382 2026-08-18
high CVE-2026-73393 — Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions. vulnerability nvd CVE-2026-73393 2026-08-18
high CVE-2026-73396 — Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. vulnerability nvd CVE-2026-73396 2026-08-18
high CVE-2026-73400 — Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. vulnerability nvd CVE-2026-73400 2026-08-18
high CVE-2026-73994 — Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. vulnerability nvd CVE-2026-73994 2026-08-18
high CVE-2026-73997 — Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. vulnerability nvd CVE-2026-73997 2026-08-18
high CVE-2026-74012 — Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue aff… vulnerability nvd CVE-2026-74012 2026-08-18
high CVE-2026-75898 — RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "In… vulnerability nvd CVE-2026-75898 2026-08-18
high CVE-2026-19500 — The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adeq… vulnerability nvd CVE-2026-19500 2026-08-18
high CVE-2026-45115 — MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sa… vulnerability nvd CVE-2026-45115 2026-08-18
high CVE-2026-45116 — MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly… vulnerability nvd CVE-2026-45116 2026-08-18
high CVE-2026-49221 — Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stor… vulnerability nvd CVE-2026-49221, CVE-2026-49226, CVE-2026-49227, CVE-2026-49222, CVE-2026-49223, CVE-2026-49224, CVE-2026-49225, CVE-2026-49228 2026-08-18
high CVE-2026-55839 — Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Mark… vulnerability nvd CVE-2026-55839 2026-08-18
high CVE-2026-71365 — A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechan… vulnerability nvd CVE-2026-71365 2026-08-18
high CVE-2026-75856 — CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning l… vulnerability nvd CVE-2026-75856 2026-08-18
high CVE-2026-75857 — CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias… vulnerability nvd CVE-2026-75857 2026-08-18
high CVE-2026-75858 — CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code… vulnerability nvd CVE-2026-75858 rce 2026-08-18
high CVE-2026-75859 — CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions fiel… vulnerability nvd CVE-2026-75859 2026-08-18
high CVE-2026-75911 — CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter f… vulnerability nvd CVE-2026-75911 2026-08-18
high CVE-2026-75912 — CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool t… vulnerability nvd CVE-2026-75912 2026-08-18
high CVE-2026-75914 — CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool th… vulnerability nvd CVE-2026-75914 2026-08-18
high CVE-2026-75915 — CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_ex… vulnerability nvd CVE-2026-75915 2026-08-18
high CVE-2026-75926 — Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code runnin… vulnerability nvd CVE-2026-75926 2026-08-18
high CVE-2026-61574 — authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Con… vulnerability nvd CVE-2026-61574 2026-08-18
high CVE-2026-66782 — A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-li… vulnerability nvd CVE-2026-66782 2026-08-18
high CVE-2026-66783 — A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for K… vulnerability nvd CVE-2026-66783 2026-08-18
high CVE-2026-70415 — Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS… vulnerability nvd CVE-2026-70415 2026-08-18
high CVE-2026-75897 — Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of t… vulnerability nvd CVE-2026-75897 2026-08-18
high CVE-2026-75924 — A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole… vulnerability nvd CVE-2026-75924 2026-08-18
high CVE-2026-32657 — Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRai… vulnerability nvd CVE-2026-32657 2026-08-18
high CVE-2026-44472 — Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account ac… vulnerability nvd CVE-2026-44472 2026-08-18
high CVE-2026-48508 — Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPer… vulnerability nvd CVE-2026-48508 2026-08-18
high CVE-2026-50143 — The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, craw… vulnerability nvd CVE-2026-50143 2026-08-18
high CVE-2026-54552 — sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplet… vulnerability nvd CVE-2026-54552 2026-08-18
high CVE-2026-67262 — Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped… vulnerability nvd CVE-2026-67262 2026-08-18
high CVE-2026-67920 — An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migr… vulnerability nvd CVE-2026-67920 2026-08-18
high CVE-2026-71551 — Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabil… vulnerability nvd CVE-2026-71551 2026-08-18
high CVE-2026-74038 — Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote… vulnerability nvd CVE-2026-74038 2026-08-18
high CVE-2025-9210 — Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions b… vulnerability nvd CVE-2025-9210 2026-08-18
high CVE-2026-24183 — NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivilege… vulnerability nvd CVE-2026-24183 2026-08-18
high CVE-2026-24184 — NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon com… vulnerability nvd CVE-2026-24184 2026-08-18
high CVE-2026-24185 — NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configura… vulnerability nvd CVE-2026-24185 2026-08-18
high CVE-2026-47606 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an a… vulnerability nvd CVE-2026-47606, CVE-2026-47628, CVE-2026-47630 2026-08-18
high CVE-2026-47629 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause impr… vulnerability nvd CVE-2026-47629 2026-08-18
high CVE-2026-47719 — FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE… vulnerability nvd CVE-2026-47719 ics 2026-08-18
high CVE-2026-52480 — An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensiti… vulnerability nvd CVE-2026-52480, CVE-2026-52481 2026-08-18
high CVE-2026-52829 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can det… vulnerability nvd CVE-2026-52829 2026-08-18
high CVE-2026-59915 — Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violati… vulnerability nvd CVE-2026-59915 2026-08-18
high CVE-2026-65984 — FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST… vulnerability nvd CVE-2026-65984 ics 2026-08-18
high CVE-2026-65985 — FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the… vulnerability nvd CVE-2026-65985, CVE-2026-67440, CVE-2026-67443 ics 2026-08-18
high CVE-2026-70666 — Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_u… vulnerability nvd CVE-2026-70666 2026-08-18
high CVE-2026-71303 — Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_H… vulnerability nvd CVE-2026-71303 2026-08-18
high CVE-2026-71307 — Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/desti… vulnerability nvd CVE-2026-71307 2026-08-18
high CVE-2026-71308 — Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit… vulnerability nvd CVE-2026-71308 2026-08-18
high CVE-2026-71417 — Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a no… vulnerability nvd CVE-2026-71417 2026-08-18
high CVE-2026-71675 — An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the ngap_send_… vulnerability nvd CVE-2026-71675 2026-08-18
high CVE-2026-71676 — Buffer Overflow vulnerability in Open5GS v.2.7.0 allows a remote attacker to cause a denial of servi… vulnerability nvd CVE-2026-71676 2026-08-18
high CVE-2026-75935 — Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 migh… vulnerability nvd CVE-2026-75935 2026-08-18
high CVE-2026-75936 — Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-jav… vulnerability nvd CVE-2026-75936 2026-08-18
high CVE-2026-15571 — A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used… vulnerability nvd CVE-2026-15571 2026-08-18
high CVE-2026-52793 — Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path i… vulnerability nvd CVE-2026-52793 2026-08-18
high CVE-2026-53759 — linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integ… vulnerability nvd CVE-2026-53759, CVE-2026-55426, CVE-2026-73974 2026-08-18
high CVE-2026-54347 — Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accept… vulnerability nvd CVE-2026-54347 2026-08-18
high CVE-2026-54348 — Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.upd… vulnerability nvd CVE-2026-54348 2026-08-18
high CVE-2026-60392 — Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Ou… vulnerability nvd CVE-2026-60392, CVE-2026-60412, CVE-2026-60413, CVE-2026-60414 2026-08-18
high CVE-2026-60592 — Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Suppo… vulnerability nvd CVE-2026-60592 2026-08-18
high CVE-2026-60693 — Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal O… vulnerability nvd CVE-2026-60693, CVE-2026-60748, CVE-2026-60769, CVE-2026-70686, CVE-2026-70764, CVE-2026-70796, CVE-2026-70803 2026-08-18
high CVE-2026-60707 — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Securit… vulnerability nvd CVE-2026-60707 2026-08-18
high CVE-2026-60726 — Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentic… vulnerability nvd CVE-2026-60726 2026-08-18
high CVE-2026-60742 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA… vulnerability nvd CVE-2026-60742 2026-08-18
high CVE-2026-60753 — Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation). S… vulnerability nvd CVE-2026-60753 2026-08-18
high CVE-2026-60757 — Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Search). Supported… vulnerability nvd CVE-2026-60757 2026-08-18
high CVE-2026-60758 — Vulnerability in the Siebel Artificial Intelligence product of Oracle Siebel CRM (component: AI). Su… vulnerability nvd CVE-2026-60758 2026-08-18
high CVE-2026-60759 — Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (compo… vulnerability nvd CVE-2026-60759, CVE-2026-70815 2026-08-18
high CVE-2026-60766 — Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supporte… vulnerability nvd CVE-2026-60766, CVE-2026-60796, CVE-2026-60797, CVE-2026-60820, CVE-2026-70859, CVE-2026-70910 2026-08-18
high CVE-2026-60791 — Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Inte… vulnerability nvd CVE-2026-60791 2026-08-18
high CVE-2026-60792 — Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastru… vulnerability nvd CVE-2026-60792, CVE-2026-70949 2026-08-18
high CVE-2026-60798 — Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration). Supp… vulnerability nvd CVE-2026-60798, CVE-2026-70856 2026-08-18
high CVE-2026-60808 — Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Email Marketin… vulnerability nvd CVE-2026-60808 2026-08-18
high CVE-2026-60822 — Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterpri… vulnerability nvd CVE-2026-60822, CVE-2026-70737 2026-08-18
high CVE-2026-60831 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Inte… vulnerability nvd CVE-2026-60831 2026-08-18
high CVE-2026-60841 — Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Co… vulnerability nvd CVE-2026-60841, CVE-2026-60849, CVE-2026-60850, CVE-2026-60889, CVE-2026-60895, CVE-2026-60914, CVE-2026-60969 2026-08-18
high CVE-2026-60856 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Inst… vulnerability nvd CVE-2026-60856 2026-08-18
high CVE-2026-60873 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Data… vulnerability nvd CVE-2026-60873 2026-08-18
high CVE-2026-60879 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Conf… vulnerability nvd CVE-2026-60879 2026-08-18
high CVE-2026-60883 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Peop… vulnerability nvd CVE-2026-60883 2026-08-18
high CVE-2026-60902 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Tuxe… vulnerability nvd CVE-2026-60902 2026-08-18
high CVE-2026-60956 — Vulnerability in the JD Edwards EnterpriseOne US Payroll product of Oracle JD Edwards (component: Pa… vulnerability nvd CVE-2026-60956 2026-08-18
high CVE-2026-60967 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: nVis… vulnerability nvd CVE-2026-60967 2026-08-18
high CVE-2026-60975 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Secu… vulnerability nvd CVE-2026-60975 2026-08-18
high CVE-2026-60976 — Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operat… vulnerability nvd CVE-2026-60976, CVE-2026-70808, CVE-2026-70809, CVE-2026-70810 2026-08-18
high CVE-2026-61002 — Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: B2B Engine). S… vulnerability nvd CVE-2026-61002 2026-08-18
high CVE-2026-61231 — Vulnerability in the Oracle Virtual Directory product of Oracle Fusion Middleware (component: Virtua… vulnerability nvd CVE-2026-61231 2026-08-18
high CVE-2026-61265 — Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component:… vulnerability nvd CVE-2026-61265, CVE-2026-61270 2026-08-18
high CVE-2026-61268 — Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Busines… vulnerability nvd CVE-2026-61268 2026-08-18
high CVE-2026-61273 — Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Install… vulnerability nvd CVE-2026-61273 2026-08-18
high CVE-2026-61284 — Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c… vulnerability nvd CVE-2026-61284, CVE-2026-61286, CVE-2026-61298, CVE-2026-61300, CVE-2026-70684 2026-08-18
high CVE-2026-61296 — Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (componen… vulnerability nvd CVE-2026-61296 2026-08-18
high CVE-2026-61302 — Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (co… vulnerability nvd CVE-2026-61302, CVE-2026-71055, CVE-2026-71056, CVE-2026-71061, CVE-2026-71094, CVE-2026-71095, CVE-2026-71096, CVE-2026-71097, CVE-2026-71098, CVE-2026-71099, CVE-2026-71107, CVE-2026-71122 2026-08-18
high CVE-2026-61305 — Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Securit… vulnerability nvd CVE-2026-61305, CVE-2026-71057 2026-08-18
high CVE-2026-61306 — Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Su… vulnerability nvd CVE-2026-61306 2026-08-18
high CVE-2026-61307 — Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSof… vulnerability nvd CVE-2026-61307 2026-08-18
high CVE-2026-61319 — Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: I… vulnerability nvd CVE-2026-61319 2026-08-18
high CVE-2026-61331 — Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component:… vulnerability nvd CVE-2026-61331 2026-08-18
high CVE-2026-61340 — Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (compon… vulnerability nvd CVE-2026-61340, CVE-2026-70827 2026-08-18
high CVE-2026-62448 — Vulnerability in the Oracle Email Center product of Oracle E-Business Suite (component: Message Comp… vulnerability nvd CVE-2026-62448 2026-08-18
high CVE-2026-62449 — Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal… vulnerability nvd CVE-2026-62449, CVE-2026-62458, CVE-2026-62462 2026-08-18
high CVE-2026-62450 — Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Intern… vulnerability nvd CVE-2026-62450, CVE-2026-70801 2026-08-18
high CVE-2026-62491 — Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Opera… vulnerability nvd CVE-2026-62491, CVE-2026-70797, CVE-2026-70798, CVE-2026-70811 2026-08-18
high CVE-2026-62540 — Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Plan… vulnerability nvd CVE-2026-62540 2026-08-18
high CVE-2026-62599 — Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Third P… vulnerability nvd CVE-2026-62599 2026-08-18
high CVE-2026-62600 — Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations… vulnerability nvd CVE-2026-62600, CVE-2026-62601, CVE-2026-70706 2026-08-18
high CVE-2026-62605 — Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Intern… vulnerability nvd CVE-2026-62605 2026-08-18
high CVE-2026-62607 — Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Internal Op… vulnerability nvd CVE-2026-62607, CVE-2026-70778 2026-08-18
high CVE-2026-70680 — Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal… vulnerability nvd CVE-2026-70680 2026-08-18
high CVE-2026-70681 — Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: JRI and… vulnerability nvd CVE-2026-70681 2026-08-18
high CVE-2026-70687 — Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supp… vulnerability nvd CVE-2026-70687 2026-08-18
high CVE-2026-70688 — Vulnerability in Oracle Essbase (component: Calculator). The supported version that is affected is 2… vulnerability nvd CVE-2026-70688 2026-08-18
high CVE-2026-70690 — Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - Ge… vulnerability nvd CVE-2026-70690 2026-08-18
high CVE-2026-70691 — Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (compon… vulnerability nvd CVE-2026-70691, CVE-2026-70693, CVE-2026-70697, CVE-2026-70698, CVE-2026-70703, CVE-2026-70709, CVE-2026-70712, CVE-2026-71052, CVE-2026-71053 supply-chain 2026-08-18
high CVE-2026-70692 — Vulnerability in the Oracle Marketing Encyclopedia System product of Oracle E-Business Suite (compon… vulnerability nvd CVE-2026-70692 ransomware 2026-08-18
high CVE-2026-70700 — Vulnerability in the Oracle Payables product of Oracle E-Business Suite (component: Internal Operati… vulnerability nvd CVE-2026-70700, CVE-2026-70701 2026-08-18
high CVE-2026-70704 — Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party S… vulnerability nvd CVE-2026-70704 2026-08-18
high CVE-2026-70707 — Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business Suite (component: Inter… vulnerability nvd CVE-2026-70707 2026-08-18
high CVE-2026-70708 — Vulnerability in the Oracle Sales Foundation product of Oracle E-Business Suite (component: Security… vulnerability nvd CVE-2026-70708, CVE-2026-70710 2026-08-18
high CVE-2026-70713 — Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Upd… vulnerability nvd CVE-2026-70713 2026-08-18
high CVE-2026-70715 — Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported vers… vulnerability nvd CVE-2026-70715, CVE-2026-70728, CVE-2026-70731, CVE-2026-70734 2026-08-18
high CVE-2026-70717 — Vulnerability in Oracle Autonomous Health Framework (component: Cluster Health Analyzer). Supported… vulnerability nvd CVE-2026-70717 2026-08-18
high CVE-2026-70718 — Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Interna… vulnerability nvd CVE-2026-70718 2026-08-18
high CVE-2026-70722 — Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component… vulnerability nvd CVE-2026-70722, CVE-2026-70725 2026-08-18
high CVE-2026-70724 — Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported… vulnerability nvd CVE-2026-70724 2026-08-18
high CVE-2026-70729 — Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Reque… vulnerability nvd CVE-2026-70729 2026-08-18
high CVE-2026-70747 — Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Customer… vulnerability nvd CVE-2026-70747 2026-08-18
high CVE-2026-70760 — Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product… vulnerability nvd CVE-2026-70760, CVE-2026-70930, CVE-2026-70932 2026-08-18
high CVE-2026-70761 — Vulnerability in the Oracle Risk Management product of Oracle E-Business Suite (component: Internal… vulnerability nvd CVE-2026-70761, CVE-2026-70762 2026-08-18
high CVE-2026-70763 — Vulnerability in the Oracle Operations Intelligence product of Oracle E-Business Suite (component: D… vulnerability nvd CVE-2026-70763 2026-08-18
high CVE-2026-70770 — Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Inte… vulnerability nvd CVE-2026-70770, CVE-2026-70771, CVE-2026-70772, CVE-2026-70774 2026-08-18
high CVE-2026-70773 — Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: K… vulnerability nvd CVE-2026-70773 2026-08-18
high CVE-2026-70777 — Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal… vulnerability nvd CVE-2026-70777, CVE-2026-70779 2026-08-18
high CVE-2026-70781 — Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Internal Operat… vulnerability nvd CVE-2026-70781 2026-08-18
high CVE-2026-70782 — Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Intern… vulnerability nvd CVE-2026-70782 2026-08-18
high CVE-2026-70783 — Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Interna… vulnerability nvd CVE-2026-70783 2026-08-18
high CVE-2026-70786 — Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (componen… vulnerability nvd CVE-2026-70786 2026-08-18
high CVE-2026-70790 — Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite… vulnerability nvd CVE-2026-70790 2026-08-18
high CVE-2026-70791 — Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component:… vulnerability nvd CVE-2026-70791 2026-08-18
high CVE-2026-70792 — Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal… vulnerability nvd CVE-2026-70792 2026-08-18
high CVE-2026-70795 — Vulnerability in the Oracle Applications Platform Engineering product of Oracle E-Business Suite (co… vulnerability nvd CVE-2026-70795 2026-08-18
high CVE-2026-70799 — Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: In… vulnerability nvd CVE-2026-70799, CVE-2026-70800 2026-08-18
high CVE-2026-70802 — Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (compon… vulnerability nvd CVE-2026-70802, CVE-2026-70804 2026-08-18
high CVE-2026-70805 — Vulnerability in the Oracle Project Planning and Control product of Oracle E-Business Suite (compone… vulnerability nvd CVE-2026-70805 2026-08-18
high CVE-2026-70806 — Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal O… vulnerability nvd CVE-2026-70806 2026-08-18
high CVE-2026-70807 — Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: In… vulnerability nvd CVE-2026-70807, CVE-2026-70812, CVE-2026-70813, CVE-2026-70814, CVE-2026-70820 2026-08-18
high CVE-2026-70816 — Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business Suite (component: Inter… vulnerability nvd CVE-2026-70816, CVE-2026-70839 2026-08-18
high CVE-2026-70829 — Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (compon… vulnerability nvd CVE-2026-70829, CVE-2026-70830 2026-08-18
high CVE-2026-70833 — Vulnerability in the Oracle Landed Cost Management product of Oracle E-Business Suite (component: In… vulnerability nvd CVE-2026-70833 2026-08-18
high CVE-2026-70835 — Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Ope… vulnerability nvd CVE-2026-70835 2026-08-18
high CVE-2026-70837 — Vulnerability in the Oracle Financials for Asia/Pacific product of Oracle E-Business Suite (componen… vulnerability nvd CVE-2026-70837 2026-08-18
high CVE-2026-70844 — Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations… vulnerability nvd CVE-2026-70844, CVE-2026-70845 2026-08-18
high CVE-2026-70857 — Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supporte… vulnerability nvd CVE-2026-70857 2026-08-18
high CVE-2026-70861 — Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (c… vulnerability nvd CVE-2026-70861 2026-08-18
high CVE-2026-70906 — Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Jav… vulnerability nvd CVE-2026-70906 2026-08-18
high CVE-2026-70918 — Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Outbound Data… vulnerability nvd CVE-2026-70918 2026-08-18
high CVE-2026-70922 — Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financia… vulnerability nvd CVE-2026-70922 2026-08-18
high CVE-2026-70941 — Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operatio… vulnerability nvd CVE-2026-70941, CVE-2026-70945 2026-08-18
high CVE-2026-70947 — Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue).… vulnerability nvd CVE-2026-70947, CVE-2026-70948 2026-08-18
high CVE-2026-70951 — Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Document Managemen… vulnerability nvd CVE-2026-70951 2026-08-18
high CVE-2026-71039 — Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server)… vulnerability nvd CVE-2026-71039 supply-chain 2026-08-18
high CVE-2026-71041 — Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Gantt Chart). The s… vulnerability nvd CVE-2026-71041 supply-chain 2026-08-18
high CVE-2026-71042 — Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: PGC / Excel Plugin)… vulnerability nvd CVE-2026-71042 supply-chain 2026-08-18
high CVE-2026-71044 — Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The suppor… vulnerability nvd CVE-2026-71044 supply-chain 2026-08-18
high CVE-2026-71048 — Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: I… vulnerability nvd CVE-2026-71048, CVE-2026-71049, CVE-2026-71050, CVE-2026-71051 supply-chain 2026-08-18
high CVE-2026-71062 — Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected… vulnerability nvd CVE-2026-71062, CVE-2026-71100 2026-08-18
high CVE-2026-71066 — Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX… vulnerability nvd CVE-2026-71066, CVE-2026-71067, CVE-2026-71068, CVE-2026-71069, CVE-2026-71070, CVE-2026-71071, CVE-2026-71072, CVE-2026-71075, CVE-2026-71076, CVE-2026-71077, CVE-2026-71078, CVE-2026-71080, CVE-2026-71081, CVE-2026-71082, CVE-2026-71083, CVE-2026-71087, CVE-2026-71088, CVE-2026-71089 supply-chain 2026-08-18
high CVE-2026-71092 — Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of Oracle PeopleSoft (co… vulnerability nvd CVE-2026-71092 2026-08-18
high CVE-2026-71101 — Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Tax… vulnerability nvd CVE-2026-71101 2026-08-18
high CVE-2026-71104 — Vulnerability in the Oracle HRMS (Netherlands) product of Oracle E-Business Suite (component: Nether… vulnerability nvd CVE-2026-71104 2026-08-18
high CVE-2026-71106 — Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Appl… vulnerability nvd CVE-2026-71106 2026-08-18
high CVE-2026-71111 — Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Install… vulnerability nvd CVE-2026-71111 2026-08-18
high CVE-2026-71112 — Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (componen… vulnerability nvd CVE-2026-71112 2026-08-18
high CVE-2026-71113 — Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The su… vulnerability nvd CVE-2026-71113, CVE-2026-71114, CVE-2026-71115, CVE-2026-71116, CVE-2026-71125, CVE-2026-71126, CVE-2026-71127, CVE-2026-71128, CVE-2026-71129, CVE-2026-71130, CVE-2026-71131, CVE-2026-71132, CVE-2026-71134, CVE-2026-71135, CVE-2026-71136, CVE-2026-71137, CVE-2026-71138, CVE-2026-71139, CVE-2026-71140, CVE-2026-71141, CVE-2026-71151 2026-08-18
high CVE-2026-71142 — Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communicat… vulnerability nvd CVE-2026-71142, CVE-2026-71143 2026-08-18
high CVE-2026-76034 — Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execu… vulnerability nvd CVE-2026-76034 2026-08-18
high CVE-2026-76037 — Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed… vulnerability nvd CVE-2026-76037 2026-08-18
high CVE-2026-76038 — Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute a… vulnerability nvd CVE-2026-76038, CVE-2026-76047 2026-08-18
high CVE-2026-76040 — Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attack… vulnerability nvd CVE-2026-76040 phishing 2026-08-18
high CVE-2026-76043 — Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to ex… vulnerability nvd CVE-2026-76043 2026-08-18
high CVE-2026-76044 — Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had com… vulnerability nvd CVE-2026-76044 2026-08-18
high CVE-2026-76045 — Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execut… vulnerability nvd CVE-2026-76045 2026-08-18
high CVE-2026-76046 — Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote att… vulnerability nvd CVE-2026-76046 2026-08-18
high CVE-2026-15315 — Tapo C200 v5 contains an improper authentication vulnerability within the login authentication verif… vulnerability nvd CVE-2026-15315 botnet 2026-08-18
high CVE-2026-15316 — An improper input validation vulnerability in the configuration service for processing encrypted cre… vulnerability nvd CVE-2026-15316 botnet 2026-08-18
high CVE-2026-50142 — libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF… vulnerability nvd CVE-2026-50142 2026-08-18
high CVE-2026-50186 — 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an au… vulnerability nvd CVE-2026-50186 2026-08-18
high CVE-2026-50191 — 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerabl… vulnerability nvd CVE-2026-50191 2026-08-18
high CVE-2026-52854 — Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded… vulnerability nvd CVE-2026-52854 ransomware 2026-08-18
high CVE-2026-52872 — Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2… vulnerability nvd CVE-2026-52872, CVE-2026-52875 2026-08-18
high CVE-2026-52876 — Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to v… vulnerability nvd CVE-2026-52876, CVE-2026-52877 ransomware 2026-08-18
high CVE-2026-53958 — 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an au… vulnerability nvd CVE-2026-53958 2026-08-18
high CVE-2026-66602 — Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar all… vulnerability nvd CVE-2026-66602 2026-08-18
high CVE-2026-75984 — A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. Impacted is an unknown function of th… vulnerability nvd CVE-2026-75984 2026-08-19
high CVE-2026-75985 — A flaw has been found in TRENDnet Router 1.1.02b01. The affected element is an unknown function of t… vulnerability nvd CVE-2026-75985 2026-08-19
high CVE-2026-75986 — A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element i… vulnerability nvd CVE-2026-75986 2026-08-19
high CVE-2026-75987 — A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStr… vulnerability nvd CVE-2026-75987 2026-08-19
high CVE-2026-76048 — A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element… vulnerability nvd CVE-2026-76048 2026-08-19
high CVE-2026-76049 — A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affect… vulnerability nvd CVE-2026-76049 2026-08-19
high CVE-2026-76050 — A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an… vulnerability nvd CVE-2026-76050 2026-08-19
high CVE-2026-19942 — The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback pl… vulnerability nvd CVE-2026-19942 rce 2026-08-19
high CVE-2026-49415 — During execve(2) of a SUID binary, the new virtual address space is installed before the process cre… vulnerability nvd CVE-2026-49415 2026-08-19
high CVE-2026-49418 — When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages i… vulnerability nvd CVE-2026-49418 2026-08-19
high CVE-2026-49419 — When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference… vulnerability nvd CVE-2026-49419 2026-08-19
high CVE-2026-11565 — The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in sever… vulnerability nvd CVE-2026-11565 2026-08-19
high CVE-2026-12983 — The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in… vulnerability nvd CVE-2026-12983 2026-08-19
high CVE-2026-13169 — The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allow… vulnerability nvd CVE-2026-13169 2026-08-19
high CVE-2026-13174 — The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting u… vulnerability nvd CVE-2026-13174 2026-08-19
high CVE-2026-14334 — The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly s… vulnerability nvd CVE-2026-14334 2026-08-19
high CVE-2026-14861 — The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request… vulnerability nvd CVE-2026-14861 2026-08-19
high CVE-2026-16570 — The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of t… vulnerability nvd CVE-2026-16570 2026-08-19
high CVE-2026-16616 — The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-mov… vulnerability nvd CVE-2026-16616 2026-08-19
high CVE-2026-16617 — The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's… vulnerability nvd CVE-2026-16617 2026-08-19
high CVE-2026-16950 — The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a paramet… vulnerability nvd CVE-2026-16950 2026-08-19
high CVE-2026-17565 — The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied v… vulnerability nvd CVE-2026-17565 2026-08-19
high CVE-2026-19055 — The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parame… vulnerability nvd CVE-2026-19055 2026-08-19
high CVE-2026-19056 — The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter be… vulnerability nvd CVE-2026-19056 2026-08-19
high CVE-2026-19842 — The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML respon… vulnerability nvd CVE-2026-19842 2026-08-19
high CVE-2026-49420 — The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without check… vulnerability nvd CVE-2026-49420 rce 2026-08-19
high CVE-2026-49422 — The RACK setsockopt(2) handler drops the connection lock in order to copy option data from userspace… vulnerability nvd CVE-2026-49422 2026-08-19
high CVE-2026-49427 — Pages belonging to largepage shared memory objects were not explicitly wired. When sendfile(2) trans… vulnerability nvd CVE-2026-49427 2026-08-19
high CVE-2026-49428 — Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly fr… vulnerability nvd CVE-2026-49428 2026-08-19
high CVE-2026-49429 — The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to… vulnerability nvd CVE-2026-49429 2026-08-19
high CVE-2026-15780 — The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vu… vulnerability nvd CVE-2026-15780 2026-08-19
high CVE-2026-75981 — The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner… vulnerability nvd CVE-2026-75981 2026-08-19
high CVE-2026-58083 — While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be… vulnerability nvd CVE-2026-58083 2026-08-19
high CVE-2026-58087 — The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dro… vulnerability nvd CVE-2026-58087 2026-08-19
high CVE-2026-58088 — The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the cor… vulnerability nvd CVE-2026-58088 2026-08-19
high CVE-2026-32552 — Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. vulnerability nvd CVE-2026-32552 2026-08-19
high CVE-2026-61986 — Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions. vulnerability nvd CVE-2026-61986 2026-08-19
high CVE-2026-66596 — Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions. vulnerability nvd CVE-2026-66596 2026-08-19
high CVE-2026-66668 — Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions. vulnerability nvd CVE-2026-66668 2026-08-19
high CVE-2026-73182 — Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions. vulnerability nvd CVE-2026-73182 2026-08-19
high CVE-2026-73184 — Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions. vulnerability nvd CVE-2026-73184 2026-08-19
high CVE-2026-73354 — Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions. vulnerability nvd CVE-2026-73354 2026-08-19
high CVE-2026-73384 — Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions. vulnerability nvd CVE-2026-73384 2026-08-19
high CVE-2026-73385 — Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions. vulnerability nvd CVE-2026-73385 2026-08-19
high CVE-2026-73386 — Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2… vulnerability nvd CVE-2026-73386 2026-08-19
high CVE-2026-73387 — Unauthenticated Local File Inclusion in Resido <= 1.5 versions. vulnerability nvd CVE-2026-73387 2026-08-19
high CVE-2026-73394 — Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions. vulnerability nvd CVE-2026-73394 2026-08-19
high CVE-2026-76235 — A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every… vulnerability nvd CVE-2026-76235 2026-08-19
high CVE-2026-43961 — A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expressio… vulnerability nvd CVE-2026-43961 2026-08-19
high CVE-2026-54794 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) v… vulnerability nvd CVE-2026-54794 2026-08-19
high CVE-2026-54795 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special… vulnerability nvd CVE-2026-54795, CVE-2026-54796, CVE-2026-56088, CVE-2026-70422, CVE-2026-71176 2026-08-19
high CVE-2026-70421 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulne… vulnerability nvd CVE-2026-70421 2026-08-19
high CVE-2026-75916 — SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autoc… vulnerability nvd CVE-2026-75916 2026-08-19
high CVE-2026-75917 — SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-t… vulnerability nvd CVE-2026-75917 2026-08-19
high CVE-2026-75918 — phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user… vulnerability nvd CVE-2026-75918 ransomware 2026-08-19
high CVE-2026-76205 — phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpo… vulnerability nvd CVE-2026-76205 2026-08-19
high CVE-2026-76207 — phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me to… vulnerability nvd CVE-2026-76207 ransomware 2026-08-19
high CVE-2026-76208 — phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::cr… vulnerability nvd CVE-2026-76208 2026-08-19
high CVE-2026-76213 — phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step whe… vulnerability nvd CVE-2026-76213 2026-08-19
high CVE-2026-76214 — phpMyFAQ before 4.1.7 (affected versions <= 4.1.5) fails to persist the WebAuthn login challenge gen… vulnerability nvd CVE-2026-76214 ransomware 2026-08-19
high CVE-2026-76216 — Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals… vulnerability nvd CVE-2026-76216 2026-08-19
high CVE-2026-76218 — GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards un… vulnerability nvd CVE-2026-76218 rce 2026-08-19
high CVE-2026-76219 — GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from… vulnerability nvd CVE-2026-76219 2026-08-19
high CVE-2026-76220 — GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard… vulnerability nvd CVE-2026-76220 2026-08-19
high CVE-2026-76221 — GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator… vulnerability nvd CVE-2026-76221 rce 2026-08-19
high CVE-2026-76222 — GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers… vulnerability nvd CVE-2026-76222 2026-08-19
high CVE-2026-76223 — ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission che… vulnerability nvd CVE-2026-76223 2026-08-19
high CVE-2026-76224 — ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulne… vulnerability nvd CVE-2026-76224 rce 2026-08-19
high CVE-2026-76225 — ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD C… vulnerability nvd CVE-2026-76225 2026-08-19
high CVE-2026-76234 — libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic i… vulnerability nvd CVE-2026-76234 2026-08-19
high CVE-2026-14970 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server process is crashing during client registrat… vulnerability nvd CVE-2026-14970 2026-08-19
high CVE-2026-15061 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service could allow a remote a… vulnerability nvd CVE-2026-15061 2026-08-19
high CVE-2026-15078 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to gain unauthorized… vulnerability nvd CVE-2026-15078 2026-08-19
high CVE-2026-16686 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to access NFS-exported f… vulnerability nvd CVE-2026-16686 2026-08-19
high CVE-2026-16703 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg… vulnerability nvd CVE-2026-16703, CVE-2026-16923, CVE-2026-16934, CVE-2026-16935, CVE-2026-16937, CVE-2026-16946, CVE-2026-16989, CVE-2026-16991, CVE-2026-18842 2026-08-19
high CVE-2026-23501 — Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Specia… vulnerability nvd CVE-2026-23501 2026-08-19
high CVE-2026-44829 — Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling… vulnerability nvd CVE-2026-44829 2026-08-19
high CVE-2026-45741 — Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP fun… vulnerability nvd CVE-2026-45741 2026-08-19
high CVE-2026-45742 — Gotenberg is a Docker-powered stateless API for PDF files. From 8.10.0 until 8.33.0, the newContext… vulnerability nvd CVE-2026-45742 2026-08-19
high CVE-2026-48711 — SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SS… vulnerability nvd CVE-2026-48711 2026-08-19
high CVE-2026-49253 — electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3… vulnerability nvd CVE-2026-49253, CVE-2026-49255 2026-08-19
high CVE-2026-49283 — The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions… vulnerability nvd CVE-2026-49283 2026-08-19
high CVE-2026-49289 — The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20… vulnerability nvd CVE-2026-49289 2026-08-19
high CVE-2026-49816 — Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vuln… vulnerability nvd CVE-2026-49816, CVE-2026-49817 2026-08-19
high CVE-2026-52834 — jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a cr… vulnerability nvd CVE-2026-52834 2026-08-19
high CVE-2026-53477 — Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Rac… vulnerability nvd CVE-2026-53477 2026-08-19
high CVE-2026-56797 — Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condit… vulnerability nvd CVE-2026-56797 2026-08-19
high CVE-2026-58562 — Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A… vulnerability nvd CVE-2026-58562, CVE-2026-58565 2026-08-19
high CVE-2026-58564 — Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnera… vulnerability nvd CVE-2026-58564 2026-08-19
high CVE-2026-71961 — Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that a… vulnerability nvd CVE-2026-71961 2026-08-19
high CVE-2026-16819 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of serv… vulnerability nvd CVE-2026-16819, CVE-2026-19653, CVE-2026-16855, CVE-2026-16897, CVE-2026-16952, CVE-2026-16980, CVE-2026-17009, CVE-2026-17195, CVE-2026-18822 2026-08-19
high CVE-2026-61607 — Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's cont… vulnerability nvd CVE-2026-61607, CVE-2026-62666, CVE-2026-62667, CVE-2026-62668, CVE-2026-63407, CVE-2026-63408, CVE-2026-64852 2026-08-19
high CVE-2026-62669 — Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Gra… vulnerability nvd CVE-2026-62669, CVE-2026-62671 2026-08-19
high CVE-2026-20320 — A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an una… vulnerability nvd CVE-2026-20320 2026-08-19
high CVE-2026-75141 — FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an… vulnerability nvd CVE-2026-75141 2026-08-19
high CVE-2026-75142 — FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpeg… vulnerability nvd CVE-2026-75142 2026-08-19
high CVE-2026-75144 — FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP pac… vulnerability nvd CVE-2026-75144 botnet 2026-08-19
high CVE-2026-75146 — FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec… vulnerability nvd CVE-2026-75146 2026-08-19
high CVE-2026-75147 — FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/r… vulnerability nvd CVE-2026-75147 2026-08-19
high CVE-2026-17183 — An authenticated user with permission to create or edit alert rules can bypass datasource query auth… vulnerability nvd CVE-2026-17183 2026-08-19
high CVE-2026-19234 — Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is af… vulnerability nvd CVE-2026-19234, CVE-2026-19321 2026-08-19
high CVE-2026-19875 — IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email… vulnerability nvd CVE-2026-19875 2026-08-19
high CVE-2026-61518 — ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id pa… vulnerability nvd CVE-2026-61518 2026-08-19
high CVE-2026-62680 — Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specificat… vulnerability nvd CVE-2026-62680, CVE-2026-62681, CVE-2026-62682, CVE-2026-71864, CVE-2026-71865, CVE-2026-71866, CVE-2026-71867, CVE-2026-71868, CVE-2026-71869, CVE-2026-71871, CVE-2026-72716, CVE-2026-72717 2026-08-19
high CVE-2026-75149 — marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler… vulnerability nvd CVE-2026-75149 2026-08-19
high CVE-2026-16930 — IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 i… vulnerability nvd CVE-2026-16930, CVE-2026-17063 2026-08-19
high CVE-2026-17093 — IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW95… vulnerability nvd CVE-2026-17093, CVE-2026-17429, CVE-2026-16933 2026-08-19
high CVE-2026-17100 — Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00… vulnerability nvd CVE-2026-17100 2026-08-19
high CVE-2026-17494 — IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability… vulnerability nvd CVE-2026-17494 2026-08-19
high CVE-2026-16661 — IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW95… vulnerability nvd CVE-2026-16661, CVE-2026-16707, CVE-2026-17028, CVE-2026-17091, CVE-2026-17097, CVE-2026-17414, CVE-2026-18821 2026-08-19
high CVE-2026-16825 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain… vulnerability nvd CVE-2026-16825, CVE-2026-18716 2026-08-19
high CVE-2026-16838 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical fil… vulnerability nvd CVE-2026-16838 2026-08-19
high CVE-2026-16857 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to manipulate network tr… vulnerability nvd CVE-2026-16857 2026-08-19
high CVE-2026-16873 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve local privileg… vulnerability nvd CVE-2026-16873 2026-08-19
high CVE-2026-16874 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain root privileges… vulnerability nvd CVE-2026-16874 2026-08-19
high CVE-2026-16875 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary comm… vulnerability nvd CVE-2026-16875, CVE-2026-16932, CVE-2026-16997 2026-08-19
high CVE-2026-17042 — IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.… vulnerability nvd CVE-2026-17042 2026-08-19
high CVE-2026-18871 — IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is af… vulnerability nvd CVE-2026-18871 2026-08-19
high CVE-2026-62317 — Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's… vulnerability nvd CVE-2026-62317 2026-08-19
high CVE-2026-68558 — Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integratio… vulnerability nvd CVE-2026-68558 2026-08-19
high CVE-2026-68561 — Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) ru… vulnerability nvd CVE-2026-68561 2026-08-19
high CVE-2026-68899 — Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation… vulnerability nvd CVE-2026-68899 2026-08-19
high CVE-2026-68900 — Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/… vulnerability nvd CVE-2026-68900 2026-08-19
high CVE-2026-76574 — A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the… vulnerability nvd CVE-2026-76574 2026-08-19
high CVE-2026-12522 — The HL7800 cellular modem driver's +CGCONTRDP: response handler on_cmd_atcmdinfo_ipaddr() in drivers… vulnerability nvd CVE-2026-12522 2026-08-19
high CVE-2026-12633 — The IPv6 neighbor-discovery code in subsys/net/ip/ipv6_nbr.c processes the 6LoWPAN Context Option (6… vulnerability nvd CVE-2026-12633 2026-08-19
high CVE-2026-18544 — IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image polic… vulnerability nvd CVE-2026-18544 2026-08-19
high CVE-2026-54491 — Koel is a free, open-source music streaming solution. Prior to 9.7.1, outbound podcast and radio fet… vulnerability nvd CVE-2026-54491 2026-08-19
high CVE-2026-54492 — Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible create… vulnerability nvd CVE-2026-54492, CVE-2026-54493 2026-08-19
high CVE-2026-62727 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… vulnerability nvd CVE-2026-62727 2026-08-19
high CVE-2026-68553 — Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticat… vulnerability nvd CVE-2026-68553 2026-08-19
high CVE-2026-69222 — LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.2… vulnerability nvd CVE-2026-69222 2026-08-19
high CVE-2026-75569 — A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remot… vulnerability nvd CVE-2026-75569 2026-08-19
high CVE-2026-75616 — An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmwa… vulnerability nvd CVE-2026-75616 botnet 2026-08-19
high CVE-2026-76139 — A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a s… vulnerability nvd CVE-2026-76139 2026-08-19
high CVE-2026-76582 — A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected is the function popen/syst… vulnerability nvd CVE-2026-76582 2026-08-19
high CVE-2026-76583 — A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affected by this vulnerability is a… vulnerability nvd CVE-2026-76583 2026-08-19
high CVE-2025-36254 — IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0… vulnerability nvd CVE-2025-36254, CVE-2025-36255, CVE-2025-36398 2026-08-19
high CVE-2026-76251 — In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin"… vulnerability nvd CVE-2026-76251 2026-08-19
high CVE-2026-76253 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role wit… vulnerability nvd CVE-2026-76253, CVE-2026-76260, CVE-2026-76318, CVE-2026-76350 2026-08-19
high CVE-2026-76254 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated u… vulnerability nvd CVE-2026-76254 phishing 2026-08-19
high CVE-2026-76256 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway ve… vulnerability nvd CVE-2026-76256, CVE-2026-76257, CVE-2026-76258, CVE-2026-76261, CVE-2026-76327, CVE-2026-76347, CVE-2026-76351 2026-08-19
high CVE-2026-76259 — In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local… vulnerability nvd CVE-2026-76259 2026-08-19
high CVE-2026-76262 — In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus servi… vulnerability nvd CVE-2026-76262 2026-08-19
high CVE-2026-76263 — In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "powe… vulnerability nvd CVE-2026-76263, CVE-2026-76336 2026-08-19
high CVE-2026-76309 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that d… vulnerability nvd CVE-2026-76309, CVE-2026-76319 2026-08-19
high CVE-2026-76313 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the… vulnerability nvd CVE-2026-76313, CVE-2026-76314, CVE-2026-76315, CVE-2026-76317, CVE-2026-76323, CVE-2026-76326, CVE-2026-76331, CVE-2026-76339, CVE-2026-76343, CVE-2026-76344, CVE-2026-76352, CVE-2026-76353, CVE-2026-76354 rce 2026-08-19
high CVE-2026-76316 — In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unauthenticated user who… vulnerability nvd CVE-2026-76316 2026-08-19
high CVE-2026-76320 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user coul… vulnerability nvd CVE-2026-76320, CVE-2026-76321, CVE-2026-76329, CVE-2026-76330, CVE-2026-76332, CVE-2026-76337 phishing 2026-08-19
high CVE-2026-76324 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power"… vulnerability nvd CVE-2026-76324, CVE-2026-76325, CVE-2026-76333, CVE-2026-76334, CVE-2026-76341, CVE-2026-76342, CVE-2026-76346 2026-08-19
high CVE-2026-76335 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who do… vulnerability nvd CVE-2026-76335 2026-08-19
high CVE-2026-76355 — In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the informat… vulnerability nvd CVE-2026-76355 2026-08-19
high CVE-2026-76356 — In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a… vulnerability nvd CVE-2026-76356 2026-08-19
high CVE-2026-76357 — In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a craf… vulnerability nvd CVE-2026-76357 2026-08-19
high CVE-2026-76362 — In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffi… vulnerability nvd CVE-2026-76362 2026-08-19
high CVE-2026-76387 — In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security ro… vulnerability nvd CVE-2026-76387 2026-08-19
high CVE-2026-76388 — In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterpri… vulnerability nvd CVE-2026-76388 2026-08-19
high CVE-2026-76389 — In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a… vulnerability nvd CVE-2026-76389 2026-08-19
high CVE-2026-76391 — In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk ro… vulnerability nvd CVE-2026-76391, CVE-2026-76392 2026-08-19
high CVE-2026-76394 — In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "p… vulnerability nvd CVE-2026-76394 2026-08-19
high CVE-2026-76395 — In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute ar… vulnerability nvd CVE-2026-76395 2026-08-19
high CVE-2026-76396 — In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capabil… vulnerability nvd CVE-2026-76396 2026-08-19
high CVE-2026-76397 — In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and… vulnerability nvd CVE-2026-76397 2026-08-19
high CVE-2026-76399 — In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app… vulnerability nvd CVE-2026-76399 2026-08-19
high CVE-2026-76400 — In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Co… vulnerability nvd CVE-2026-76400, CVE-2026-76401, CVE-2026-76402 2026-08-19
high CVE-2026-76403 — In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network… vulnerability nvd CVE-2026-76403 2026-08-19
high CVE-2026-76591 — A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function… vulnerability nvd CVE-2026-76591 2026-08-19
high CVE-2026-76832 — Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that al… vulnerability nvd CVE-2026-76832 2026-08-19
high CVE-2026-76760 — A vulnerability was found in chenhg5 cc-connect up to 1.4.1. Affected by this vulnerability is the f… vulnerability nvd CVE-2026-76760 2026-08-19
high CVE-2026-76761 — A vulnerability was identified in chenhg5 cc-connect up to 1.4.1. This affects the function shellExe… vulnerability nvd CVE-2026-76761 2026-08-19
high CVE-2026-76879 — C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service vulnerability nvd CVE-2026-76879, CVE-2026-76886 2026-08-19
high CVE-2026-76880 — RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service vulnerability nvd CVE-2026-76880 2026-08-19
high CVE-2026-76928 — X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service vulnerability nvd CVE-2026-76928 2026-08-19
high CVE-2026-76762 — A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an… vulnerability nvd CVE-2026-76762 2026-08-20
high CVE-2026-76764 — A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an un… vulnerability nvd CVE-2026-76764 2026-08-20
high CVE-2026-76783 — A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown… vulnerability nvd CVE-2026-76783 2026-08-20
high CVE-2026-76795 — A vulnerability has been found in AeternaLabsHQ PullMD 3.2.0. This impacts an unknown function of th… vulnerability nvd CVE-2026-76795 2026-08-20
high CVE-2026-19582 — In binutils 2.46.1 and prior versions, a victim who opens a crafted PE file using binutils could exe… vulnerability nvd CVE-2026-19582 2026-08-20
high CVE-2026-15049 — The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a… vulnerability nvd CVE-2026-15049 rce 2026-08-20
high CVE-2026-75963 — The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up t… vulnerability nvd CVE-2026-75963 2026-08-20
high CVE-2026-14946 — A high privileged remote attacker can upload a .php file and then request it directly from /uploads/… vulnerability nvd CVE-2026-14946 2026-08-20
high CVE-2026-14947 — A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal se… vulnerability nvd CVE-2026-14947 2026-08-20
high CVE-2026-14948 — A low privileged remote attacker can hijack an active administrative session without needing to know… vulnerability nvd CVE-2026-14948 2026-08-20
high CVE-2026-14951 — An low privileged remote attacker can cause authenticated users to perform unintended actions in the… vulnerability nvd CVE-2026-14951 2026-08-20
high CVE-2026-14952 — An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the… vulnerability nvd CVE-2026-14952 transport 2026-08-20
high CVE-2026-18917 — A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerabil… vulnerability nvd CVE-2026-18917 2026-08-20
high CVE-2026-73197 — A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by se… vulnerability nvd CVE-2026-73197 2026-08-20
high CVE-2026-73198 — A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `… vulnerability nvd CVE-2026-73198 2026-08-20
high CVE-2025-15637 — Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. vulnerability nvd CVE-2025-15637 2026-08-20
high CVE-2026-28150 — Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions. vulnerability nvd CVE-2026-28150 2026-08-20
high CVE-2026-66581 — Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. vulnerability nvd CVE-2026-66581 2026-08-20
high CVE-2026-66582 — Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions. vulnerability nvd CVE-2026-66582 2026-08-20
high CVE-2026-66590 — Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions. vulnerability nvd CVE-2026-66590 2026-08-20
high CVE-2026-66594 — Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. vulnerability nvd CVE-2026-66594 2026-08-20
high CVE-2026-66597 — Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions. vulnerability nvd CVE-2026-66597 2026-08-20
high CVE-2026-66598 — Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions. vulnerability nvd CVE-2026-66598 2026-08-20
high CVE-2026-66604 — Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions. vulnerability nvd CVE-2026-66604 2026-08-20
high CVE-2026-66605 — Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products… vulnerability nvd CVE-2026-66605 2026-08-20
high CVE-2026-66606 — Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions. vulnerability nvd CVE-2026-66606 2026-08-20
high CVE-2026-66607 — Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions. vulnerability nvd CVE-2026-66607 2026-08-20
high CVE-2026-66611 — Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions. vulnerability nvd CVE-2026-66611 2026-08-20
high CVE-2026-66612 — Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions. vulnerability nvd CVE-2026-66612 2026-08-20
high CVE-2026-66614 — Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions. vulnerability nvd CVE-2026-66614 2026-08-20
high CVE-2026-66615 — Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions. vulnerability nvd CVE-2026-66615 2026-08-20
high CVE-2026-66616 — Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions. vulnerability nvd CVE-2026-66616 2026-08-20
high CVE-2026-66673 — Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions. vulnerability nvd CVE-2026-66673 2026-08-20
high CVE-2026-66677 — Subscriber Broken Authentication in Leyka <= 3.32.3 versions. vulnerability nvd CVE-2026-66677 2026-08-20
high CVE-2026-68564 — Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions. vulnerability nvd CVE-2026-68564 2026-08-20
high CVE-2026-73998 — Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. vulnerability nvd CVE-2026-73998 2026-08-20
high CVE-2026-74013 — Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. vulnerability nvd CVE-2026-74013 2026-08-20
high CVE-2026-74019 — Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions. vulnerability nvd CVE-2026-74019 2026-08-20
high CVE-2026-74020 — Unauthenticated Broken Access Control in Koji <= 2.2.1 versions. vulnerability nvd CVE-2026-74020 2026-08-20
high CVE-2026-74021 — Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions. vulnerability nvd CVE-2026-74021 2026-08-20
high CVE-2026-76987 — A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892.… vulnerability nvd CVE-2026-76987 2026-08-20
high CVE-2026-76633 — WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that a… vulnerability nvd CVE-2026-76633 2026-08-20
high CVE-2026-76635 — baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows au… vulnerability nvd CVE-2026-76635 2026-08-20
high CVE-2026-76833 — @cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to… vulnerability nvd CVE-2026-76833 2026-08-20
high CVE-2026-76990 — A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue… vulnerability nvd CVE-2026-76990 2026-08-20
high CVE-2026-16925 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege esca… vulnerability nvd CVE-2026-16925 2026-08-20
high CVE-2026-16927 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges d… vulnerability nvd CVE-2026-16927 2026-08-20
high CVE-2026-49825 — lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attribute… vulnerability nvd CVE-2026-49825 2026-08-20
high CVE-2026-61897 — An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges… vulnerability nvd CVE-2026-61897 2026-08-20
high CVE-2026-61898 — The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accounts… vulnerability nvd CVE-2026-61898 2026-08-20
high CVE-2026-63490 — Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.g… vulnerability nvd CVE-2026-63490 2026-08-20
high CVE-2026-76996 — A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impact… vulnerability nvd CVE-2026-76996 2026-08-20
high CVE-2026-19611 — A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode… vulnerability nvd CVE-2026-19611 2026-08-20
high CVE-2026-75140 — jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnera… vulnerability nvd CVE-2026-75140 2026-08-20
high CVE-2026-76998 — A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0.… vulnerability nvd CVE-2026-76998 2026-08-20
high CVE-2026-77004 — A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi… vulnerability nvd CVE-2026-77004 2026-08-20
high CVE-2026-54449 — LangBot is a global IM bot platform designed for LLMs. In version 4.10.7 and earlier, any authentica… vulnerability nvd CVE-2026-54449 2026-08-20
high CVE-2026-54616 — NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 un… vulnerability nvd CVE-2026-54616 2026-08-20
high CVE-2026-61704 — Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in ind… vulnerability nvd CVE-2026-61704 2026-08-20
high CVE-2026-65842 — Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote… vulnerability nvd CVE-2026-65842 2026-08-20
high CVE-2026-69183 — Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-… vulnerability nvd CVE-2026-69183 2026-08-20
high CVE-2026-77019 — A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an… vulnerability nvd CVE-2026-77019 2026-08-20
high CVE-2026-77020 — A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by thi… vulnerability nvd CVE-2026-77020 2026-08-20
high CVE-2026-77176 — A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containe… vulnerability nvd CVE-2026-77176 2026-08-20
high CVE-2026-54623 — django CMS is an easy-to-use and developer-friendly enterprise content management system powered by… vulnerability nvd CVE-2026-54623, CVE-2026-54622, CVE-2026-54624, CVE-2026-61663, CVE-2026-63003, CVE-2026-75526 2026-08-20
high CVE-2026-63387 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-o… vulnerability nvd CVE-2026-63387 2026-08-20
high CVE-2026-63388 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-… vulnerability nvd CVE-2026-63388 2026-08-20
high CVE-2026-63495 — Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebS… vulnerability nvd CVE-2026-63495 2026-08-20
high CVE-2026-76641 — Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger me… vulnerability nvd CVE-2026-76641 2026-08-20
high CVE-2026-77031 — A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreat… vulnerability nvd CVE-2026-77031 2026-08-20
high CVE-2026-53583 — libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a… vulnerability nvd CVE-2026-53583, CVE-2026-53584, CVE-2026-53585, CVE-2026-53586, CVE-2026-53587 2026-08-20
high CVE-2026-66787 — A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes.… vulnerability nvd CVE-2026-66787 2026-08-20
high CVE-2026-72852 — hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configur… vulnerability nvd CVE-2026-72852 2026-08-20
high CVE-2026-18420 — Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards a… vulnerability nvd CVE-2026-18420 rce 2026-08-20
high CVE-2026-53804 — OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encry… vulnerability nvd CVE-2026-53804 2026-08-20
high CVE-2026-73040 — Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in va… vulnerability nvd CVE-2026-73040 2026-08-20
high CVE-2026-73137 — A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Mana… vulnerability nvd CVE-2026-73137 2026-08-20
high CVE-2026-77584 — Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has a… vulnerability nvd CVE-2026-77584 2026-08-20
high CVE-2026-77638 — Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous… vulnerability nvd CVE-2026-77638 2026-08-20
high CVE-2026-17003 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confid… vulnerability nvd CVE-2026-17003 2026-08-20
high CVE-2026-17171 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary fi… vulnerability nvd CVE-2026-17171 2026-08-20
high CVE-2026-19442 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtua… vulnerability nvd CVE-2026-19442 2026-08-20
high CVE-2026-19446 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a cr… vulnerability nvd CVE-2026-19446 2026-08-20
high CVE-2026-19449 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unpriv… vulnerability nvd CVE-2026-19449 2026-08-20
high CVE-2026-46355 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebu… vulnerability nvd CVE-2026-46355 2026-08-20
high CVE-2026-46682 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authentica… vulnerability nvd CVE-2026-46682 2026-08-20
high CVE-2026-49217 — Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorizati… vulnerability nvd CVE-2026-49217 2026-08-20
high CVE-2026-49436 — LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API… vulnerability nvd CVE-2026-49436 2026-08-20
high CVE-2026-55013 — Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to per… vulnerability nvd CVE-2026-55013 2026-08-20
high CVE-2026-55765 — CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments.… vulnerability nvd CVE-2026-55765, CVE-2026-55769 2026-08-20
high CVE-2026-66800 — Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose… vulnerability nvd CVE-2026-66800 2026-08-20
high CVE-2026-69419 — Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to exe… vulnerability nvd CVE-2026-69419 2026-08-20
high CVE-2026-69519 — Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose infor… vulnerability nvd CVE-2026-69519 2026-08-20
high CVE-2026-69543 — Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevat… vulnerability nvd CVE-2026-69543 2026-08-20
high CVE-2026-69558 — Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized… vulnerability nvd CVE-2026-69558 2026-08-20
high CVE-2026-69855 — Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to di… vulnerability nvd CVE-2026-69855 2026-08-20
high CVE-2026-72818 — The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and app… vulnerability nvd CVE-2026-72818 2026-08-20
high CVE-2026-72848 — SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documente… vulnerability nvd CVE-2026-72848 2026-08-20
high CVE-2026-72860 — The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues se… vulnerability nvd CVE-2026-72860 2026-08-20
high CVE-2026-77642 — tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signatur… vulnerability nvd CVE-2026-77642 2026-08-20
high UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities advisory vendor-blogs botnet 2026-08-20
high CISA, NSA, FBI warn of Siemens S7 PLC exploitation using AI-generated scripts to disrupt critical industrial processes advisory vendor-blogs ics 2026-08-20
high NSSTS strategy targets cybersecurity, OT/ICS resilience and technology supply chains; outlines four pillars advisory vendor-blogs ics, supply-chain 2026-08-19
high b93f2842c5ede1d48659eebbba629082787a8ccd17edd2571f5ada14c1252341.elf malware malware-bazaar b93f2842c5ede1d4…, 1c4345de3e48f3e3… elf, exe, whack.sh 2026-08-21
high 611fa15a339dabc3efdfdde36db072b7cddb2b70f37dd092abf0496f3fad74c7.exe malware malware-bazaar 611fa15a339dabc3…, 2a4721f8805f3e2b… ConnectWise, exe, whack.sh 2026-08-21
high wr.php malware malware-bazaar 3fb78a20a4cd6939…, 9d90aadfd3b64533… sh 2026-08-21
high ok malware malware-bazaar b59075c2da6a7f8e…, d48beea3c242577e… sh 2026-08-21
high flutter.mipsel malware malware-bazaar 12dd079eab15afe1…, c9e08297a9f9d908… elf, Mirai, upx-dec, upx, botnet 2026-08-21
high 377339da9394e4590baa1a2aa8e433cf676718bb83a50a37fb9399eb6c8f62c7.exe malware malware-bazaar 377339da9394e459…, eb3815f639e96df5… exe, signed, whack.sh 2026-08-21
high f4b330adc3e1cb5d4ba6f1c506d0e4d6821b83d9b033f6e0f21cfdb94c35d2c2.bin malware malware-bazaar f4b330adc3e1cb5d…, 61118b7b4e83504d… exe, signed, Vidar, botnet, infostealer 2026-08-21
high wr.php malware malware-bazaar a38e5b31a0472067…, fdf04b0361e5fcb9… sh 2026-08-21
high k.php malware malware-bazaar d59aa853fe50e2c4…, 1c44f812710050f6… sh 2026-08-21
high Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia threat-intel otx b9ad79eaf7a4133f…, f6f7a94c11ea0ee0… spear phishing, chrome remote desktop, powershell, gmail exfiltration, onedrive, northeast asia, keylogger, lnk malware, anydesk, chrome extension, apt, phishing, botnet, infostealer 2026-08-20
high Distinct Clusters Target Individuals of Interest to Russia threat-intel otx ca3be5885afb3eb3…, 5484009071ea96c7… russian cyber espionage, oauth phishing, vidar, device code phishing, headrush, app password phishing, unc6293, atomic, cherrypie, unc7005, enginelight, hospitality captive portal, unc5976, whatsapp device linking, authentication abuse, phishing, infostealer 2026-08-20
high Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking threat-intel otx 196.251.84.11 websocket hijacking, cryptocurrency payments, spyroid, phaas, callflow, ai vishing, mexican banking fraud, android rat, phishing 2026-08-19
high SilkParasite: Tracking a China-Nexus APT Across Central Asia threat-intel otx 193.29.56.216 | ff22419b8ec39945…, ff33a3be2d497d93… dll sideloading, cookietagrat, china-nexus apt, shadowpad, deed rat, spicerat, nodeedgerat, cyberespionage, google drive c2, goginrat, nomadrat, government targeting, central asia, drivesilkrat, bloodalchemy, silkparasite, apt, phishing, botnet 2026-08-20
high MacSync Stealer: C2 Infrastructure Rotation threat-intel otx 7980485fb1e0b1b1…, 277acd8e241c1341… macsync stealer, c2 infrastructure, macos, mac.c, clickfix, credential theft, cryptocurrency wallet, macsync, malware-as-a-service, infostealer, botnet 2026-08-18
high CopyCop Targets AI Investment in Armenia threat-intel otx ai infrastructure, media impersonation, geopolitical realignment, disinformation, copycop, armenia, storm-1516, influence operations 2026-08-18
high Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US threat-intel otx 192.52.166.55, 209.205.197.130, 181.214.165.173, 83.147.53.130, 209.205.192.6, 139.28.36.38, 98.144.204.109 microsoft 365, websocket, adversary-in-the-middle, credential theft, html smuggling, phishing-as-a-service, session hijacking, 2fa bypass, phishing 2026-08-18
high Clop Returns with Custom Implant in Mass-Extortion Campaign threat-intel otx CVE-2021-27101, CVE-2023-34362, CVE-2026-12569 | 78.128.113.10, 216.152.151.204, 185.227.83.236 | 321e1fb01eb3462b…, 71a7b6b8fa5e2176… web shell, lemurloot, dewmode, cve-2023-34362, cve-2026-12569, ptc windchill, data exfiltration, manufacturing, credential theft, mass exploitation, extortion, cve-2021-27101, ransomware, phishing 2026-08-19
high Fraudulent Employment Operations threat-intel otx 104.253.147.147, 104.253.51.76, 104.253.72.75, 104.253.134.123, 218.24.120.118, 104.253.1.79, 104.253.103.238, 104.253.111.106, 104.253.112.86, 104.253.121.146, 104.253.17.141, 104.253.19.244, 104.253.199.214, 104.253.251.19, 104.253.34.67, 104.253.47.239, 104.253.56.226, 104.253.90.150 insider threat, identity fraud, north korean it workers, remote work deception, fraudulent employment, purpledelta, chatgpt abuse, ai-generated personas 2026-08-18
high Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps threat-intel otx 45.192.12.34, 209.99.184.50, 209.99.187.28, 104.251.180.179, 45.150.34.77 | b7e9072e5bda17e0…, d472e984c6e8f3d4… maas, octagon, android, accessibility abuse, cryptocurrency, vnc, overlay attack, banking trojan, botnet 2026-08-18
high Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads news general-news supply-chain 2026-08-20
high Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets news general-news ics 2026-08-18
high TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks news general-news botnet 2026-08-18
high 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets news general-news supply-chain 2026-08-18
high Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic news general-news botnet 2026-08-17
high Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies news general-news botnet 2026-08-17
high Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS news general-news botnet 2026-08-17
high JFrog Artifactory Flaws Enable Software Supply Chain Attacks news general-news supply-chain 2026-08-20
high ICS Operators Warned of AI-Driven Attacks on Siemens PLCs news general-news ics 2026-08-20
high US agencies warn of AI-powered attacks on Siemens industrial controllers news general-news ics 2026-08-20
medium CVE-2026-19827 — A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStrea… vulnerability nvd CVE-2026-19827 2026-08-14
medium CVE-2026-19828 — A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-20260107. This affects an unknown… vulnerability nvd CVE-2026-19828 ransomware 2026-08-14
medium CVE-2026-19829 — A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4-20260107. This vulnerability… vulnerability nvd CVE-2026-19829 2026-08-14
medium CVE-2026-19830 — A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an un… vulnerability nvd CVE-2026-19830 2026-08-14
medium CVE-2026-1621 — Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality al… vulnerability nvd CVE-2026-1621 2026-08-14
medium CVE-2026-53472 — A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialU… vulnerability nvd CVE-2026-53472 2026-08-14
medium CVE-2026-19879 — A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `wri… vulnerability nvd CVE-2026-19879 2026-08-14
medium CVE-2026-58224 — A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integri… vulnerability nvd CVE-2026-58224 2026-08-14
medium CVE-2026-13002 — A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An at… vulnerability nvd CVE-2026-13002 2026-08-14
medium CVE-2026-19834 — A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the… vulnerability nvd CVE-2026-19834 2026-08-14
medium CVE-2026-19836 — A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some un… vulnerability nvd CVE-2026-19836 2026-08-14
medium CVE-2026-63701 — Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of… vulnerability nvd CVE-2026-63701 2026-08-14
medium CVE-2026-63702 — Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credential… vulnerability nvd CVE-2026-63702 2026-08-14
medium CVE-2026-66272 — Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for C… vulnerability nvd CVE-2026-66272 2026-08-14
medium CVE-2026-19838 — A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects… vulnerability nvd CVE-2026-19838 2026-08-14
medium CVE-2026-19839 — A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue aff… vulnerability nvd CVE-2026-19839 2026-08-14
medium CVE-2026-49826 — Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker… vulnerability nvd CVE-2026-49826 phishing 2026-08-14
medium CVE-2026-73845 — CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_qu… vulnerability nvd CVE-2026-73845 2026-08-14
medium CVE-2026-73846 — CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams… vulnerability nvd CVE-2026-73846 2026-08-14
medium CVE-2026-12363 — The LoRaWAN Fragmented Data Block Transport service (subsys/lorawan/services/frag_transport.c) does… vulnerability nvd CVE-2026-12363 2026-08-14
medium CVE-2026-12365 — A use-after-free exists in the Zephyr second-generation work queue (kernel/work.c) in the handling o… vulnerability nvd CVE-2026-12365 2026-08-14
medium CVE-2026-19631 — A SQL injection vulnerability exists in Security Center that could allow an authenticated administra… vulnerability nvd CVE-2026-19631 2026-08-14
medium CVE-2026-19636 — An issue was identified in which CSRF tokens were generated using a predictable method, potentially… vulnerability nvd CVE-2026-19636 2026-08-14
medium CVE-2026-19639 — An improper access control vulnerability exists where an authenticated non-administrative applicatio… vulnerability nvd CVE-2026-19639 2026-08-14
medium CVE-2026-49282 — Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name(… vulnerability nvd CVE-2026-49282 2026-08-14
medium CVE-2026-73847 — Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on t… vulnerability nvd CVE-2026-73847 2026-08-14
medium CVE-2026-50029 — js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a ke… vulnerability nvd CVE-2026-50029 2026-08-14
medium CVE-2026-17209 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitr… vulnerability nvd CVE-2026-17209 2026-08-14
medium CVE-2026-18178 — IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitra… vulnerability nvd CVE-2026-18178 2026-08-14
medium CVE-2026-74248 — OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associ… vulnerability nvd CVE-2026-74248 2026-08-14
medium CVE-2026-74240 — A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and… vulnerability nvd CVE-2026-74240 2026-08-14
medium CVE-2026-74241 — A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authenticat… vulnerability nvd CVE-2026-74241 2026-08-14
medium CVE-2026-74242 — A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a targe… vulnerability nvd CVE-2026-74242 2026-08-14
medium CVE-2026-74243 — A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a re… vulnerability nvd CVE-2026-74243 2026-08-14
medium CVE-2026-74244 — A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unau… vulnerability nvd CVE-2026-74244 2026-08-14
medium CVE-2026-74245 — A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid f… vulnerability nvd CVE-2026-74245 2026-08-14
medium CVE-2026-74247 — A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write acc… vulnerability nvd CVE-2026-74247 2026-08-14
medium CVE-2026-74250 — In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediat… vulnerability nvd CVE-2026-74250 2026-08-14
medium CVE-2026-12128 — The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via… vulnerability nvd CVE-2026-12128 2026-08-15
medium CVE-2026-16080 — The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the '… vulnerability nvd CVE-2026-16080 2026-08-15
medium CVE-2026-8840 — The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization… vulnerability nvd CVE-2026-8840 2026-08-15
medium CVE-2026-15453 — The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generi… vulnerability nvd CVE-2026-15453 2026-08-15
medium CVE-2026-15948 — The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to… vulnerability nvd CVE-2026-15948 2026-08-15
medium CVE-2026-15993 — The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is v… vulnerability nvd CVE-2026-15993 ransomware 2026-08-15
medium CVE-2026-16586 — The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is… vulnerability nvd CVE-2026-16586 2026-08-15
medium CVE-2026-17090 — The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable t… vulnerability nvd CVE-2026-17090 2026-08-15
medium CVE-2026-18387 — The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to ge… vulnerability nvd CVE-2026-18387 2026-08-15
medium CVE-2026-14229 — The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when renderin… vulnerability nvd CVE-2026-14229 2026-08-15
medium CVE-2026-14230 — The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its… vulnerability nvd CVE-2026-14230 2026-08-15
medium CVE-2026-16541 — The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user record… vulnerability nvd CVE-2026-16541 2026-08-15
medium CVE-2026-18216 — The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automat… vulnerability nvd CVE-2026-18216 2026-08-15
medium CVE-2026-18807 — The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic re… vulnerability nvd CVE-2026-18807 2026-08-15
medium CVE-2026-73631 — Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-req… vulnerability nvd CVE-2026-73631 2026-08-15
medium CVE-2026-73632 — Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-res… vulnerability nvd CVE-2026-73632 2026-08-15
medium CVE-2026-12248 — The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL Injection via the 'sorting' para… vulnerability nvd CVE-2026-12248 2026-08-15
medium CVE-2026-19894 — A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an u… vulnerability nvd CVE-2026-19894 2026-08-15
medium CVE-2026-18165 — @fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8… vulnerability nvd CVE-2026-18165 2026-08-15
medium CVE-2026-19903 — A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown… vulnerability nvd CVE-2026-19903 2026-08-15
medium CVE-2026-73047 — siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in… vulnerability nvd CVE-2026-73047 2026-08-15
medium CVE-2026-73055 — Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in ass… vulnerability nvd CVE-2026-73055 2026-08-15
medium CVE-2026-19917 — A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unkn… vulnerability nvd CVE-2026-19917 2026-08-15
medium CVE-2026-19918 — A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects th… vulnerability nvd CVE-2026-19918 2026-08-16
medium CVE-2026-19920 — A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown f… vulnerability nvd CVE-2026-19920 2026-08-16
medium CVE-2026-19921 — A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnera… vulnerability nvd CVE-2026-19921 2026-08-16
medium CVE-2026-19923 — A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown… vulnerability nvd CVE-2026-19923 2026-08-16
medium CVE-2026-19925 — A vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some… vulnerability nvd CVE-2026-19925 2026-08-16
medium CVE-2026-19927 — A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of t… vulnerability nvd CVE-2026-19927 2026-08-16
medium CVE-2026-19928 — A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of th… vulnerability nvd CVE-2026-19928 2026-08-16
medium CVE-2026-19929 — A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplat… vulnerability nvd CVE-2026-19929 2026-08-16
medium CVE-2026-19930 — A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the… vulnerability nvd CVE-2026-19930 botnet 2026-08-16
medium CVE-2026-2487 — The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s… vulnerability nvd CVE-2026-2487 2026-08-16
medium CVE-2025-10005 — The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vul… vulnerability nvd CVE-2025-10005 2026-08-16
medium CVE-2026-11780 — The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to… vulnerability nvd CVE-2026-11780, CVE-2026-15963 2026-08-16
medium CVE-2026-12477 — The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Store… vulnerability nvd CVE-2026-12477 2026-08-16
medium CVE-2026-12905 — The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to,… vulnerability nvd CVE-2026-12905 2026-08-16
medium CVE-2026-13167 — The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin fo… vulnerability nvd CVE-2026-13167 2026-08-16
medium CVE-2026-13358 — The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress… vulnerability nvd CVE-2026-13358 2026-08-16
medium CVE-2026-15009 — The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin… vulnerability nvd CVE-2026-15009 2026-08-16
medium CVE-2026-15066 — The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Ext… vulnerability nvd CVE-2026-15066 2026-08-16
medium CVE-2026-15441 — The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and… vulnerability nvd CVE-2026-15441 phishing 2026-08-16
medium CVE-2026-15602 — The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQ… vulnerability nvd CVE-2026-15602 2026-08-16
medium CVE-2026-15726 — The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Sho… vulnerability nvd CVE-2026-15726 2026-08-16
medium CVE-2026-16079 — The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attri… vulnerability nvd CVE-2026-16079 2026-08-16
medium CVE-2026-16779 — The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions… vulnerability nvd CVE-2026-16779 2026-08-16
medium CVE-2026-18385 — The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restri… vulnerability nvd CVE-2026-18385 ransomware 2026-08-16
medium CVE-2026-19932 — A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects… vulnerability nvd CVE-2026-19932 2026-08-16
medium CVE-2026-19933 — A weakness has been identified in DefaultFuction Customer-Relationship-Management-In-C-Project 2.0.… vulnerability nvd CVE-2026-19933 2026-08-16
medium CVE-2026-10035 — The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all… vulnerability nvd CVE-2026-10035 2026-08-16
medium CVE-2026-13712 — The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow modul… vulnerability nvd CVE-2026-13712 2026-08-16
medium CVE-2026-15056 — The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin… vulnerability nvd CVE-2026-15056 2026-08-16
medium CVE-2026-15345 — The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnera… vulnerability nvd CVE-2026-15345 2026-08-16
medium CVE-2026-15351 — The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPr… vulnerability nvd CVE-2026-15351 2026-08-16
medium CVE-2026-15384 — The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce ve… vulnerability nvd CVE-2026-15384 2026-08-16
medium CVE-2026-15604 — The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… vulnerability nvd CVE-2026-15604 2026-08-16
medium CVE-2026-15790 — The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… vulnerability nvd CVE-2026-15790 2026-08-16
medium CVE-2026-16758 — The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortco… vulnerability nvd CVE-2026-16758 2026-08-16
medium CVE-2026-16775 — The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulne… vulnerability nvd CVE-2026-16775 2026-08-16
medium CVE-2026-17582 — The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to,… vulnerability nvd CVE-2026-17582 2026-08-16
medium CVE-2026-18402 — The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cr… vulnerability nvd CVE-2026-18402 ransomware 2026-08-16
medium CVE-2026-19613 — The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of… vulnerability nvd CVE-2026-19613 2026-08-16
medium CVE-2026-19711 — The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against th… vulnerability nvd CVE-2026-19711 2026-08-16
medium CVE-2026-19712 — The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before out… vulnerability nvd CVE-2026-19712 2026-08-16
medium CVE-2026-19726 — The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration… vulnerability nvd CVE-2026-19726 2026-08-16
medium CVE-2026-19934 — A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unkno… vulnerability nvd CVE-2026-19934 2026-08-16
medium CVE-2026-2283 — The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' paramet… vulnerability nvd CVE-2026-2283 2026-08-16
medium CVE-2026-9767 — The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic S… vulnerability nvd CVE-2026-9767 2026-08-16
medium CVE-2026-12998 — The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln… vulnerability nvd CVE-2026-12998 2026-08-16
medium CVE-2026-17604 — The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t… vulnerability nvd CVE-2026-17604, CVE-2026-18347 2026-08-16
medium CVE-2026-17608 — The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cro… vulnerability nvd CVE-2026-17608 2026-08-16
medium CVE-2026-2357 — The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… vulnerability nvd CVE-2026-2357 2026-08-16
medium CVE-2026-72888 — Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed mod… vulnerability nvd CVE-2026-72888 2026-08-16
medium CVE-2026-73058 — stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blockli… vulnerability nvd CVE-2026-73058 2026-08-16
medium CVE-2026-73059 — stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that c… vulnerability nvd CVE-2026-73059 2026-08-16
medium CVE-2026-74785 — Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluat… vulnerability nvd CVE-2026-74785 2026-08-16
medium CVE-2026-74786 — Scriban before 7.0.0 (affected versions <= 6.6.0) contains a denial-of-service vulnerability in whic… vulnerability nvd CVE-2026-74786 2026-08-16
medium CVE-2026-74796 — OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during in… vulnerability nvd CVE-2026-74796 2026-08-16
medium CVE-2026-19956 — A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is… vulnerability nvd CVE-2026-19956 botnet 2026-08-16
medium CVE-2026-19957 — A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetc… vulnerability nvd CVE-2026-19957 2026-08-16
medium CVE-2026-19958 — A security flaw has been discovered in iatsiuk pptr-mcp up to 0.2.7. The impacted element is the fun… vulnerability nvd CVE-2026-19958 2026-08-16
medium CVE-2026-19964 — A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run… vulnerability nvd CVE-2026-19964 2026-08-17
medium CVE-2026-19966 — A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affe… vulnerability nvd CVE-2026-19966 2026-08-17
medium CVE-2026-19967 — A security flaw has been discovered in Open Asset Import Library Assimp 17c12da. Impacted is the fun… vulnerability nvd CVE-2026-19967 2026-08-17
medium CVE-2026-19968 — A weakness has been identified in Open Asset Import Library Assimp 17c12da. The affected element is… vulnerability nvd CVE-2026-19968 2026-08-17
medium CVE-2026-19969 — A security vulnerability has been detected in Open Asset Import Library Assimp 17c12da. The impacted… vulnerability nvd CVE-2026-19969 2026-08-17
medium CVE-2026-19970 — A vulnerability was detected in Open Asset Import Library Assimp 17c12da. This affects the function… vulnerability nvd CVE-2026-19970 2026-08-17
medium CVE-2026-19971 — A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the function main of the file /www/cgi-… vulnerability nvd CVE-2026-19971 2026-08-17
medium CVE-2026-19972 — A vulnerability has been found in itsourcecode Hospital Management System 1.0. Affected is an unknow… vulnerability nvd CVE-2026-19972 2026-08-17
medium CVE-2026-19973 — A vulnerability was found in itsourcecode Hospital Management System 1.0. Affected by this vulnerabi… vulnerability nvd CVE-2026-19973 2026-08-17
medium CVE-2026-19974 — A security flaw has been discovered in treefrogframework treefrog-framework up to 2.11.2. This vulne… vulnerability nvd CVE-2026-19974 2026-08-17
medium CVE-2026-19976 — A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.1. Impacted is the function sub_… vulnerability nvd CVE-2026-19976 2026-08-17
medium CVE-2026-19978 — A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292… vulnerability nvd CVE-2026-19978 botnet 2026-08-17
medium CVE-2026-19984 — A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13. Affected by this issue is the functio… vulnerability nvd CVE-2026-19984 2026-08-17
medium CVE-2026-19986 — A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted… vulnerability nvd CVE-2026-19986 2026-08-17
medium CVE-2026-13700 — The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a s… vulnerability nvd CVE-2026-13700 2026-08-17
medium CVE-2026-14832 — The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorizat… vulnerability nvd CVE-2026-14832 2026-08-17
medium CVE-2026-19987 — A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. Th… vulnerability nvd CVE-2026-19987 2026-08-17
medium CVE-2026-19988 — A vulnerability was detected in Alaev SEO Tools Extension up to 1.0.10 on Chrome. This impacts the f… vulnerability nvd CVE-2026-19988 2026-08-17
medium CVE-2026-19993 — A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an u… vulnerability nvd CVE-2026-19993 2026-08-17
medium CVE-2026-19994 — A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown func… vulnerability nvd CVE-2026-19994 2026-08-17
medium CVE-2026-19996 — A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown cod… vulnerability nvd CVE-2026-19996 2026-08-17
medium CVE-2026-19997 — A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown p… vulnerability nvd CVE-2026-19997 2026-08-17
medium CVE-2026-19998 — A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown f… vulnerability nvd CVE-2026-19998 2026-08-17
medium CVE-2026-19999 — A security vulnerability has been detected in Open Asset Import Library Assimp Assimp 17c12da. The a… vulnerability nvd CVE-2026-19999 2026-08-17
medium CVE-2026-20000 — A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is… vulnerability nvd CVE-2026-20000 2026-08-17
medium CVE-2026-49301 — Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vuln… vulnerability nvd CVE-2026-49301 2026-08-17
medium CVE-2026-49302 — Permission control vulnerability in the notification service module. Impact: Successful exploitation… vulnerability nvd CVE-2026-49302 2026-08-17
medium CVE-2026-49303 — Permission control vulnerability in the notification module. Impact: Successful exploitation of this… vulnerability nvd CVE-2026-49303 2026-08-17
medium CVE-2026-49304 — Permission control vulnerability in the device key management module. Impact: Successful exploitatio… vulnerability nvd CVE-2026-49304 2026-08-17
medium CVE-2026-49305 — Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of… vulnerability nvd CVE-2026-49305 2026-08-17
medium CVE-2026-49307 — Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of… vulnerability nvd CVE-2026-49307 2026-08-17
medium CVE-2026-49308 — Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vu… vulnerability nvd CVE-2026-49308 2026-08-17
medium CVE-2026-58560 — Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vu… vulnerability nvd CVE-2026-58560, CVE-2026-58561 2026-08-17
medium CVE-2026-74842 — A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452.… vulnerability nvd CVE-2026-74842 2026-08-17
medium CVE-2026-74867 — SiYuan versions before 3.7.4 contain a cross-site request forgery vulnerability in the session-cooki… vulnerability nvd CVE-2026-74867 2026-08-17
medium CVE-2026-74871 — openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mo… vulnerability nvd CVE-2026-74871 2026-08-17
medium CVE-2026-74873 — openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in pro… vulnerability nvd CVE-2026-74873 2026-08-17
medium CVE-2026-74881 — openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_cr… vulnerability nvd CVE-2026-74881 2026-08-17
medium CVE-2026-74890 — openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCiph… vulnerability nvd CVE-2026-74890 2026-08-17
medium CVE-2026-74999 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subj… vulnerability nvd CVE-2026-74999 2026-08-17
medium CVE-2026-75000 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG… vulnerability nvd CVE-2026-75000 2026-08-17
medium CVE-2026-75003 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute… vulnerability nvd CVE-2026-75003 2026-08-17
medium CVE-2026-75004 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to… vulnerability nvd CVE-2026-75004 2026-08-17
medium CVE-2026-75006 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS)… vulnerability nvd CVE-2026-75006 2026-08-17
medium CVE-2026-75007 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to inj… vulnerability nvd CVE-2026-75007 2026-08-17
medium CVE-2026-75010 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin… vulnerability nvd CVE-2026-75010 2026-08-17
medium CVE-2026-59911 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into L… vulnerability nvd CVE-2026-59911 2026-08-17
medium CVE-2026-10527 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile Schem… vulnerability nvd CVE-2026-10527 2026-08-17
medium CVE-2026-15754 — Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint f… vulnerability nvd CVE-2026-15754 2026-08-17
medium CVE-2026-16044 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving… vulnerability nvd CVE-2026-16044 2026-08-17
medium CVE-2026-16045 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauth… vulnerability nvd CVE-2026-16045 2026-08-17
medium CVE-2026-16046 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on wr… vulnerability nvd CVE-2026-16046 ransomware 2026-08-17
medium CVE-2026-16047 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate that us… vulnerability nvd CVE-2026-16047 2026-08-17
medium CVE-2026-16048 — Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel… vulnerability nvd CVE-2026-16048 2026-08-17
medium CVE-2026-16049 — Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify c… vulnerability nvd CVE-2026-16049 2026-08-17
medium CVE-2026-55704 — Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0,… vulnerability nvd CVE-2026-55704 2026-08-17
medium CVE-2026-59829 — Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1… vulnerability nvd CVE-2026-59829 2026-08-17
medium CVE-2026-68762 — In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible vulnerability nvd CVE-2026-68762 2026-08-17
medium CVE-2026-74858 — A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_ur… vulnerability nvd CVE-2026-74858 2026-08-17
medium CVE-2026-75046 — In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the use… vulnerability nvd CVE-2026-75046 2026-08-17
medium CVE-2026-75047 — In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the im… vulnerability nvd CVE-2026-75047 2026-08-17
medium CVE-2026-75049 — In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted… vulnerability nvd CVE-2026-75049 2026-08-17
medium CVE-2026-75053 — In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint vulnerability nvd CVE-2026-75053 2026-08-17
medium CVE-2026-75054 — In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrus… vulnerability nvd CVE-2026-75054 2026-08-17
medium CVE-2026-75055 — In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE vulnerability nvd CVE-2026-75055 2026-08-17
medium CVE-2026-75057 — In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log vulnerability nvd CVE-2026-75057 2026-08-17
medium CVE-2026-75058 — In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers vulnerability nvd CVE-2026-75058 2026-08-17
medium CVE-2026-75059 — In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible vulnerability nvd CVE-2026-75059 2026-08-17
medium CVE-2026-12519 — The WNC-M14A2A LTE-M modem driver mishandles unsolicited %NOTIFYEV: events in on_cmd_socknotifyev()… vulnerability nvd CVE-2026-12519 2026-08-17
medium CVE-2026-12629 — The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails to acknowledge receive error interrup… vulnerability nvd CVE-2026-12629 2026-08-17
medium CVE-2026-12630 — Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression code contains an out-of-bounds read in g… vulnerability nvd CVE-2026-12630 2026-08-17
medium CVE-2026-68517 — Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins gu… vulnerability nvd CVE-2026-68517 2026-08-17
medium CVE-2026-48053 — Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoin… vulnerability nvd CVE-2026-48053 2026-08-17
medium CVE-2026-50771 — Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to… vulnerability nvd CVE-2026-50771 2026-08-17
medium CVE-2026-68520 — Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in… vulnerability nvd CVE-2026-68520 2026-08-17
medium CVE-2026-73424 — Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel ada… vulnerability nvd CVE-2026-73424 2026-08-17
medium CVE-2026-75011 — A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the function execAsync of the fil… vulnerability nvd CVE-2026-75011 2026-08-17
medium CVE-2026-63667 — ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export… vulnerability nvd CVE-2026-63667 2026-08-17
medium CVE-2026-63669 — ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module'… vulnerability nvd CVE-2026-63669 2026-08-17
medium CVE-2026-63670 — ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() c… vulnerability nvd CVE-2026-63670 2026-08-17
medium CVE-2026-71486 — vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completi… vulnerability nvd CVE-2026-71486 2026-08-17
medium CVE-2026-75012 — A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by th… vulnerability nvd CVE-2026-75012 2026-08-17
medium CVE-2026-75013 — A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function se… vulnerability nvd CVE-2026-75013 2026-08-17
medium CVE-2026-40506 — OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php inter… vulnerability nvd CVE-2026-40506 2026-08-17
medium CVE-2026-44845 — JumpServer is an open source bastion host and an operation and maintenance security audit system. Pr… vulnerability nvd CVE-2026-44845, CVE-2026-44846 ransomware 2026-08-17
medium CVE-2026-54336 — JumpServer is an open source bastion host and an operation and maintenance security audit system. Fr… vulnerability nvd CVE-2026-54336 2026-08-17
medium CVE-2026-65976 — Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a conne… vulnerability nvd CVE-2026-65976 2026-08-17
medium CVE-2026-67925 — Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrar… vulnerability nvd CVE-2026-67925 2026-08-17
medium CVE-2026-68765 — hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePas… vulnerability nvd CVE-2026-68765 2026-08-17
medium CVE-2026-73560 — vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMu… vulnerability nvd CVE-2026-73560 2026-08-17
medium CVE-2026-75104 — Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing atta… vulnerability nvd CVE-2026-75104 2026-08-17
medium CVE-2026-75108 — Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN end… vulnerability nvd CVE-2026-75108 ransomware 2026-08-17
medium CVE-2026-75480 — OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-lev… vulnerability nvd CVE-2026-75480 2026-08-17
medium CVE-2026-10080 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSoc… vulnerability nvd CVE-2026-10080 2026-08-17
medium CVE-2026-28984 — The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS… vulnerability nvd CVE-2026-28984 2026-08-17
medium CVE-2026-43667 — A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.… vulnerability nvd CVE-2026-43667 2026-08-17
medium CVE-2026-43795 — The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.… vulnerability nvd CVE-2026-43795, CVE-2026-65338, CVE-2026-65341 2026-08-17
medium CVE-2026-45791 — Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's user.updat… vulnerability nvd CVE-2026-45791 2026-08-17
medium CVE-2026-63178 — Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Edition's PATCH /manage/admin/us… vulnerability nvd CVE-2026-63178 2026-08-17
medium CVE-2026-64715 — A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari… vulnerability nvd CVE-2026-64715, CVE-2026-64787 2026-08-17
medium CVE-2026-64760 — An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10… vulnerability nvd CVE-2026-64760 2026-08-17
medium CVE-2026-64778 — The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and… vulnerability nvd CVE-2026-64778, CVE-2026-64780 2026-08-17
medium CVE-2026-64781 — The issue was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 18… vulnerability nvd CVE-2026-64781 2026-08-17
medium CVE-2026-64784 — An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Sa… vulnerability nvd CVE-2026-64784 2026-08-17
medium CVE-2026-64788 — The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS… vulnerability nvd CVE-2026-64788, CVE-2026-65330 2026-08-17
medium CVE-2026-65329 — An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.… vulnerability nvd CVE-2026-65329 2026-08-17
medium CVE-2026-65331 — This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iO… vulnerability nvd CVE-2026-65331, CVE-2026-65332, CVE-2026-65333, CVE-2026-65335, CVE-2026-65336, CVE-2026-65337, CVE-2026-65340, CVE-2026-65351 2026-08-17
medium CVE-2026-65334 — A memory corruption issue was addressed with improved state management. This issue is fixed in Safar… vulnerability nvd CVE-2026-65334 2026-08-17
medium CVE-2026-65339 — A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.… vulnerability nvd CVE-2026-65339 2026-08-17
medium CVE-2026-65347 — The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, m… vulnerability nvd CVE-2026-65347 2026-08-17
medium CVE-2026-65349 — An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.… vulnerability nvd CVE-2026-65349 2026-08-17
medium CVE-2026-75077 — A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by… vulnerability nvd CVE-2026-75077 2026-08-17
medium CVE-2026-9859 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce Permissi… vulnerability nvd CVE-2026-9859 2026-08-17
medium CVE-2026-75078 — A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This af… vulnerability nvd CVE-2026-75078 2026-08-17
medium CVE-2026-75081 — A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the f… vulnerability nvd CVE-2026-75081 2026-08-18
medium CVE-2026-75082 — A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of… vulnerability nvd CVE-2026-75082 2026-08-18
medium CVE-2026-75086 — A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element… vulnerability nvd CVE-2026-75086 2026-08-18
medium CVE-2026-75087 — A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown fu… vulnerability nvd CVE-2026-75087 2026-08-18
medium CVE-2026-75088 — A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unkno… vulnerability nvd CVE-2026-75088 2026-08-18
medium CVE-2026-75090 — A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. Affected by this issue is the… vulnerability nvd CVE-2026-75090 botnet 2026-08-18
medium CVE-2026-75093 — A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Te… vulnerability nvd CVE-2026-75093 botnet 2026-08-18
medium CVE-2026-75151 — A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0.… vulnerability nvd CVE-2026-75151 2026-08-18
medium CVE-2026-19447 — Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i… vulnerability nvd CVE-2026-19447, CVE-2026-66603, CVE-2026-27365, CVE-2026-66591 2026-08-18
medium CVE-2026-19608 — A flaw was found in the group policy provider of Keycloak authorization services, which is used to m… vulnerability nvd CVE-2026-19608 2026-08-18
medium CVE-2026-5224 — Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technolog… vulnerability nvd CVE-2026-5224 2026-08-18
medium CVE-2026-74903 — SiYuan before v3.7.4 contains an insufficient access control vulnerability in the /api/lute/spinBloc… vulnerability nvd CVE-2026-74903 2026-08-18
medium CVE-2026-74907 — Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.p… vulnerability nvd CVE-2026-74907 2026-08-18
medium CVE-2026-74908 — Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only… vulnerability nvd CVE-2026-74908 2026-08-18
medium CVE-2026-75107 — Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append… vulnerability nvd CVE-2026-75107 2026-08-18
medium CVE-2026-75832 — The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in… vulnerability nvd CVE-2026-75832 2026-08-18
medium CVE-2026-75833 — The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before v… vulnerability nvd CVE-2026-75833 phishing 2026-08-18
medium CVE-2026-75834 — Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss()… vulnerability nvd CVE-2026-75834 2026-08-18
medium CVE-2026-75835 — Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerabili… vulnerability nvd CVE-2026-75835 2026-08-18
medium CVE-2026-75839 — ArcadeDB (com.arcadedb:arcadedb-server) versions <= 26.7.3 contain an insecure direct object referen… vulnerability nvd CVE-2026-75839 2026-08-18
medium CVE-2026-75841 — ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function tha… vulnerability nvd CVE-2026-75841 2026-08-18
medium CVE-2026-75845 — ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_ser… vulnerability nvd CVE-2026-75845 2026-08-18
medium CVE-2026-75850 — ArcadeDB before 26.8.1 fails to bind the authenticated principal (setCurrentUser) on its batch and t… vulnerability nvd CVE-2026-75850 2026-08-18
medium CVE-2026-16309 — Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies E… vulnerability nvd CVE-2026-16309 2026-08-18
medium CVE-2026-74951 — Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154. vulnerability nvd CVE-2026-74951 2026-08-18
medium CVE-2026-74963 — Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Fire… vulnerability nvd CVE-2026-74963 2026-08-18
medium CVE-2026-74967 — Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Fi… vulnerability nvd CVE-2026-74967 ransomware 2026-08-18
medium CVE-2026-74968 — Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 1… vulnerability nvd CVE-2026-74968 2026-08-18
medium CVE-2026-74970 — Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox… vulnerability nvd CVE-2026-74970 2026-08-18
medium CVE-2026-74971 — Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixe… vulnerability nvd CVE-2026-74971 2026-08-18
medium CVE-2026-74972 — Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Fir… vulnerability nvd CVE-2026-74972 2026-08-18
medium CVE-2026-74973 — Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 15… vulnerability nvd CVE-2026-74973 2026-08-18
medium CVE-2026-74974 — Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firef… vulnerability nvd CVE-2026-74974 2026-08-18
medium CVE-2026-74975 — Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Fi… vulnerability nvd CVE-2026-74975 2026-08-18
medium CVE-2026-74976 — JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox… vulnerability nvd CVE-2026-74976 2026-08-18
medium CVE-2026-74980 — Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed i… vulnerability nvd CVE-2026-74980 2026-08-18
medium CVE-2026-74984 — Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Fire… vulnerability nvd CVE-2026-74984 2026-08-18
medium CVE-2026-32467 — Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. vulnerability nvd CVE-2026-32467 2026-08-18
medium CVE-2026-50139 — goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share to… vulnerability nvd CVE-2026-50139 2026-08-18
medium CVE-2026-59949 — yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementation… vulnerability nvd CVE-2026-59949 2026-08-18
medium CVE-2026-66634 — Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions. vulnerability nvd CVE-2026-66634 2026-08-18
medium CVE-2026-66636 — Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions. vulnerability nvd CVE-2026-66636 2026-08-18
medium CVE-2026-66637 — Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions. vulnerability nvd CVE-2026-66637 2026-08-18
medium CVE-2026-66638 — Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. vulnerability nvd CVE-2026-66638 2026-08-18
medium CVE-2026-66639 — Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4… vulnerability nvd CVE-2026-66639 2026-08-18
medium CVE-2026-66640 — Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions. vulnerability nvd CVE-2026-66640 2026-08-18
medium CVE-2026-66641 — Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions. vulnerability nvd CVE-2026-66641 2026-08-18
medium CVE-2026-66643 — Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions. vulnerability nvd CVE-2026-66643 2026-08-18
medium CVE-2026-66644 — Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions. vulnerability nvd CVE-2026-66644 2026-08-18
medium CVE-2026-66645 — Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions. vulnerability nvd CVE-2026-66645 2026-08-18
medium CVE-2026-66646 — Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions. vulnerability nvd CVE-2026-66646 2026-08-18
medium CVE-2026-66651 — Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions. vulnerability nvd CVE-2026-66651 2026-08-18
medium CVE-2026-66679 — Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions. vulnerability nvd CVE-2026-66679 2026-08-18
medium CVE-2026-68565 — Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions. vulnerability nvd CVE-2026-68565 2026-08-18
medium CVE-2026-68568 — Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions. vulnerability nvd CVE-2026-68568 2026-08-18
medium CVE-2026-70657 — Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks director… vulnerability nvd CVE-2026-70657 2026-08-18
medium CVE-2026-73189 — Subscriber Insecure Direct Object References (IDOR) in WP Crowdfunding < 2.2.1 versions. vulnerability nvd CVE-2026-73189 2026-08-18
medium CVE-2026-73348 — Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. vulnerability nvd CVE-2026-73348 2026-08-18
medium CVE-2026-73352 — Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions. vulnerability nvd CVE-2026-73352 2026-08-18
medium CVE-2026-73359 — Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9… vulnerability nvd CVE-2026-73359 2026-08-18
medium CVE-2026-73379 — Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. vulnerability nvd CVE-2026-73379 2026-08-18
medium CVE-2026-73383 — Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions. vulnerability nvd CVE-2026-73383 2026-08-18
medium CVE-2026-73395 — Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking Sy… vulnerability nvd CVE-2026-73395 2026-08-18
medium CVE-2026-73398 — Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. vulnerability nvd CVE-2026-73398 2026-08-18
medium CVE-2026-73399 — Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. vulnerability nvd CVE-2026-73399 2026-08-18
medium CVE-2026-73404 — Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. vulnerability nvd CVE-2026-73404 2026-08-18
medium CVE-2026-73426 — Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix… vulnerability nvd CVE-2026-73426 2026-08-18
medium CVE-2026-73995 — Subscriber Broken Authentication in User Registration <= 5.2.6 versions. vulnerability nvd CVE-2026-73995 2026-08-18
medium CVE-2026-74003 — Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions. vulnerability nvd CVE-2026-74003 2026-08-18
medium CVE-2026-74004 — Subscriber Broken Access Control in Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms <… vulnerability nvd CVE-2026-74004 2026-08-18
medium CVE-2026-74006 — Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. vulnerability nvd CVE-2026-74006 2026-08-18
medium CVE-2026-74007 — Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery… vulnerability nvd CVE-2026-74007 2026-08-18
medium CVE-2026-74008 — Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22… vulnerability nvd CVE-2026-74008 2026-08-18
medium CVE-2026-74009 — Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versio… vulnerability nvd CVE-2026-74009 2026-08-18
medium CVE-2026-75032 — A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems respons… vulnerability nvd CVE-2026-75032 2026-08-18
medium CVE-2026-45119 — MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module d… vulnerability nvd CVE-2026-45119 2026-08-18
medium CVE-2026-45120 — MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify pr… vulnerability nvd CVE-2026-45120 2026-08-18
medium CVE-2026-45121 — MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check per… vulnerability nvd CVE-2026-45121 2026-08-18
medium CVE-2026-45122 — MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate… vulnerability nvd CVE-2026-45122 2026-08-18
medium CVE-2026-45123 — MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not c… vulnerability nvd CVE-2026-45123 2026-08-18
medium CVE-2026-45124 — MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not chec… vulnerability nvd CVE-2026-45124 2026-08-18
medium CVE-2026-45125 — MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not san… vulnerability nvd CVE-2026-45125 2026-08-18
medium CVE-2026-45129 — MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module doe… vulnerability nvd CVE-2026-45129 2026-08-18
medium CVE-2026-45734 — MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consiste… vulnerability nvd CVE-2026-45734 ransomware 2026-08-18
medium CVE-2026-46482 — ### Impact The registration component does not validate the text-based _Security Question_ CAPTCHA c… vulnerability nvd CVE-2026-46482 2026-08-18
medium CVE-2026-47245 — MyBB is free and open source forum software. Prior to 1.8.40, the User CP Buddy/Ignore List componen… vulnerability nvd CVE-2026-47245 2026-08-18
medium CVE-2026-71477 — mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archi… vulnerability nvd CVE-2026-71477 2026-08-18
medium CVE-2026-73834 — A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes.… vulnerability nvd CVE-2026-73834, CVE-2026-75485 2026-08-18
medium CVE-2026-30250 — Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW!… vulnerability nvd CVE-2026-30250 2026-08-18
medium CVE-2026-48744 — Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authori… vulnerability nvd CVE-2026-48744 2026-08-18
medium CVE-2026-50126 — Adaguc-server is an open source geographical information system to visualize, combine, compare and s… vulnerability nvd CVE-2026-50126 2026-08-18
medium CVE-2026-52606 — A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attacke… vulnerability nvd CVE-2026-52606, CVE-2026-52609 2026-08-18
medium CVE-2026-55106 — authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action o… vulnerability nvd CVE-2026-55106 2026-08-18
medium CVE-2026-66781 — A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuri… vulnerability nvd CVE-2026-66781 2026-08-18
medium CVE-2026-49452 — WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped… vulnerability nvd CVE-2026-49452 2026-08-18
medium CVE-2026-52607 — A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or e… vulnerability nvd CVE-2026-52607 2026-08-18
medium CVE-2026-54570 — AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnota… vulnerability nvd CVE-2026-54570 2026-08-18
medium CVE-2026-61696 — Forem is open source software for building communities. In versions before commit 92eacd16a82cf9007b… vulnerability nvd CVE-2026-61696 2026-08-18
medium CVE-2026-63640 — MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecret… vulnerability nvd CVE-2026-63640 2026-08-18
medium CVE-2026-68922 — MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobs… vulnerability nvd CVE-2026-68922 2026-08-18
medium CVE-2026-68923 — MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py pl… vulnerability nvd CVE-2026-68923 2026-08-18
medium CVE-2026-68924 — MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobs… vulnerability nvd CVE-2026-68924 2026-08-18
medium CVE-2026-69160 — OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and… vulnerability nvd CVE-2026-69160 2026-08-18
medium CVE-2026-73502 — kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.Val… vulnerability nvd CVE-2026-73502 2026-08-18
medium CVE-2026-74039 — Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows auth… vulnerability nvd CVE-2026-74039 2026-08-18
medium CVE-2026-74044 — Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster… vulnerability nvd CVE-2026-74044 2026-08-18
medium CVE-2026-74046 — Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() func… vulnerability nvd CVE-2026-74046 2026-08-18
medium CVE-2025-9211 — Unescaped stored values in application security page in Otalio Ship Property Management System versi… vulnerability nvd CVE-2025-9211 2026-08-18
medium CVE-2026-55162 — Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certificates/verify.py accepted CRL Di… vulnerability nvd CVE-2026-55162 2026-08-18
medium CVE-2026-55163 — Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:29… vulnerability nvd CVE-2026-55163 2026-08-18
medium CVE-2026-55164 — Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replac… vulnerability nvd CVE-2026-55164 2026-08-18
medium CVE-2026-55165 — Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifier in lemur/auth/service.py:13… vulnerability nvd CVE-2026-55165 2026-08-18
medium CVE-2026-65959 — Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /… vulnerability nvd CVE-2026-65959 2026-08-18
medium CVE-2026-70667 — Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificat… vulnerability nvd CVE-2026-70667 2026-08-18
medium CVE-2026-12520 — The Sierra Wireless HL7800 cellular modem driver (drivers/modem/vendor_standalone/hl7800.c, located… vulnerability nvd CVE-2026-12520 2026-08-18
medium CVE-2026-19670 — Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may… vulnerability nvd CVE-2026-19670 2026-08-18
medium CVE-2026-19671 — Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth,… vulnerability nvd CVE-2026-19671 2026-08-18
medium CVE-2026-47720 — FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengi… vulnerability nvd CVE-2026-47720 ics 2026-08-18
medium CVE-2026-47721 — FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/… vulnerability nvd CVE-2026-47721 ics 2026-08-18
medium CVE-2026-49500 — Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resoluti… vulnerability nvd CVE-2026-49500 2026-08-18
medium CVE-2026-52731 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enab… vulnerability nvd CVE-2026-52731 2026-08-18
medium CVE-2026-52732 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can mon… vulnerability nvd CVE-2026-52732 2026-08-18
medium CVE-2026-52733 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced cha… vulnerability nvd CVE-2026-52733 2026-08-18
medium CVE-2026-52734 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can caus… vulnerability nvd CVE-2026-52734 2026-08-18
medium CVE-2026-52737 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious unauthenticated P2P peer… vulnerability nvd CVE-2026-52737 2026-08-18
medium CVE-2026-52739 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can termi… vulnerability nvd CVE-2026-52739 2026-08-18
medium CVE-2026-71317 — Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did… vulnerability nvd CVE-2026-71317 2026-08-18
medium CVE-2026-71322 — Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePerm… vulnerability nvd CVE-2026-71322 2026-08-18
medium CVE-2026-73529 — Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that… vulnerability nvd CVE-2026-73529 2026-08-18
medium CVE-2026-75876 — A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected… vulnerability nvd CVE-2026-75876 2026-08-18
medium CVE-2026-76032 — Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handl… vulnerability nvd CVE-2026-76032 2026-08-18
medium CVE-2026-12631 — The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscal… vulnerability nvd CVE-2026-12631 2026-08-18
medium CVE-2026-12632 — Zephyr's Precision Time Protocol receive handler ptp_msg_post_recv() in subsys/net/lib/ptp/msg.c tak… vulnerability nvd CVE-2026-12632 2026-08-18
medium CVE-2026-16732 — fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 adde… vulnerability nvd CVE-2026-16732 2026-08-18
medium CVE-2026-18504 — fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are… vulnerability nvd CVE-2026-18504 2026-08-18
medium CVE-2026-41921 — Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in… vulnerability nvd CVE-2026-41921 2026-08-18
medium CVE-2026-52817 — Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems.… vulnerability nvd CVE-2026-52817, CVE-2026-73973 apt 2026-08-18
medium CVE-2026-54543 — Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API comma… vulnerability nvd CVE-2026-54543 2026-08-18
medium CVE-2026-55593 — Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php e… vulnerability nvd CVE-2026-55593 2026-08-18
medium CVE-2026-60589 — Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ… vulnerability nvd CVE-2026-60589, CVE-2026-61308, CVE-2026-70907 2026-08-18
medium CVE-2026-60682 — Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repo… vulnerability nvd CVE-2026-60682 2026-08-18
medium CVE-2026-60830 — Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Suppo… vulnerability nvd CVE-2026-60830 2026-08-18
medium CVE-2026-60884 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Pane… vulnerability nvd CVE-2026-60884 2026-08-18
medium CVE-2026-61139 — Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Su… vulnerability nvd CVE-2026-61139 2026-08-18
medium CVE-2026-61198 — Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Inter… vulnerability nvd CVE-2026-61198 2026-08-18
medium CVE-2026-62475 — Vulnerability in the Oracle Shipping Execution product of Oracle E-Business Suite (component: Intern… vulnerability nvd CVE-2026-62475 2026-08-18
medium CVE-2026-70720 — Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Int… vulnerability nvd CVE-2026-70720 2026-08-18
medium CVE-2026-70726 — Vulnerability in the Oracle Cash Management product of Oracle E-Business Suite (component: Internal… vulnerability nvd CVE-2026-70726 2026-08-18
medium CVE-2026-70732 — Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component:… vulnerability nvd CVE-2026-70732 2026-08-18
medium CVE-2026-70775 — Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: User Inter… vulnerability nvd CVE-2026-70775 2026-08-18
medium CVE-2026-71073 — Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The suppo… vulnerability nvd CVE-2026-71073, CVE-2026-71079, CVE-2026-71084 2026-08-18
medium CVE-2026-71124 — Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authoriza… vulnerability nvd CVE-2026-71124 2026-08-18
medium CVE-2026-76033 — Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attac… vulnerability nvd CVE-2026-76033 2026-08-18
medium CVE-2026-76039 — Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowe… vulnerability nvd CVE-2026-76039 phishing 2026-08-18
medium CVE-2026-76041 — Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to poten… vulnerability nvd CVE-2026-76041 2026-08-18
medium CVE-2026-47699 — Confidential Containers Guest Components provides guest tools and components for confidential contai… vulnerability nvd CVE-2026-47699 2026-08-18
medium CVE-2026-48796 — CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Pr… vulnerability nvd CVE-2026-48796 2026-08-18
medium CVE-2026-52873 — Streambert is a cross-platform Electron Desktop App to stream and download video content. From versi… vulnerability nvd CVE-2026-52873 2026-08-18
medium CVE-2026-53959 — 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any a… vulnerability nvd CVE-2026-53959 phishing 2026-08-18
medium CVE-2026-62289 — libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or… vulnerability nvd CVE-2026-62289 2026-08-18
medium CVE-2026-62291 — libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image s… vulnerability nvd CVE-2026-62291 2026-08-18
medium CVE-2026-62377 — libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF se… vulnerability nvd CVE-2026-62377 2026-08-18
medium CVE-2026-66589 — Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configure… vulnerability nvd CVE-2026-66589 2026-08-18
medium CVE-2025-11729 — The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable… vulnerability nvd CVE-2025-11729 2026-08-19
medium CVE-2026-75978 — A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affe… vulnerability nvd CVE-2026-75978 2026-08-19
medium CVE-2026-75979 — A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function… vulnerability nvd CVE-2026-75979 2026-08-19
medium CVE-2026-15421 — The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable… vulnerability nvd CVE-2026-15421 2026-08-19
medium CVE-2026-13175 — The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule record… vulnerability nvd CVE-2026-13175 2026-08-19
medium CVE-2026-14196 — The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a… vulnerability nvd CVE-2026-14196 2026-08-19
medium CVE-2026-14287 — The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an u… vulnerability nvd CVE-2026-14287 2026-08-19
medium CVE-2026-15253 — The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment tit… vulnerability nvd CVE-2026-15253 2026-08-19
medium CVE-2026-16058 — The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on… vulnerability nvd CVE-2026-16058 2026-08-19
medium CVE-2026-16979 — The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform cap… vulnerability nvd CVE-2026-16979 2026-08-19
medium CVE-2026-18202 — The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types… vulnerability nvd CVE-2026-18202 2026-08-19
medium CVE-2026-18231 — The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one o… vulnerability nvd CVE-2026-18231 2026-08-19
medium CVE-2026-18466 — The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce,… vulnerability nvd CVE-2026-18466 2026-08-19
medium CVE-2026-18777 — The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its… vulnerability nvd CVE-2026-18777, CVE-2026-18779 2026-08-19
medium CVE-2026-19416 — The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appoint… vulnerability nvd CVE-2026-19416 2026-08-19
medium CVE-2026-19417 — The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to t… vulnerability nvd CVE-2026-19417 2026-08-19
medium CVE-2026-19709 — The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer sec… vulnerability nvd CVE-2026-19709 2026-08-19
medium CVE-2026-19782 — The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJA… vulnerability nvd CVE-2026-19782 2026-08-19
medium CVE-2026-8810 — On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker… vulnerability nvd CVE-2026-8810 2026-08-19
medium CVE-2026-15446 — The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data… vulnerability nvd CVE-2026-15446 2026-08-19
medium CVE-2026-75900 — An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The ent… vulnerability nvd CVE-2026-75900 2026-08-19
medium CVE-2026-76166 — A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single… vulnerability nvd CVE-2026-76166 2026-08-19
medium CVE-2026-73363 — Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions. vulnerability nvd CVE-2026-73363 2026-08-19
medium CVE-2026-70423 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML Externa… vulnerability nvd CVE-2026-70423 2026-08-19
medium CVE-2026-70424 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname t… vulnerability nvd CVE-2026-70424 2026-08-19
medium CVE-2026-75148 — cgltf through 1.15 contains an integer overflow vulnerability in the non-sparse accessor bounds chec… vulnerability nvd CVE-2026-75148 2026-08-19
medium CVE-2026-75919 — phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows… vulnerability nvd CVE-2026-75919 2026-08-19
medium CVE-2026-75920 — phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at con… vulnerability nvd CVE-2026-75920 2026-08-19
medium CVE-2026-76206 — phpMyFAQ versions before 4.1.7 fail to validate active status in the PDF export endpoint, allowing u… vulnerability nvd CVE-2026-76206 2026-08-19
medium CVE-2026-76209 — phpMyFAQ versions before v4.1.6 fail to validate the security.enableRegistration setting in API endp… vulnerability nvd CVE-2026-76209 2026-08-19
medium CVE-2026-76210 — phpMyFAQ before 4.1.7 does not adequately sanitize HTML in FAQ answers before generating PDFs via TC… vulnerability nvd CVE-2026-76210 2026-08-19
medium CVE-2026-76211 — phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endp… vulnerability nvd CVE-2026-76211 2026-08-19
medium CVE-2026-76212 — phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the native pgsql PHP extension, declare… vulnerability nvd CVE-2026-76212 2026-08-19
medium CVE-2026-76215 — phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks before returning child resources i… vulnerability nvd CVE-2026-76215 2026-08-19
medium CVE-2026-76217 — GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands… vulnerability nvd CVE-2026-76217 2026-08-19
medium CVE-2026-76226 — Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in baz… vulnerability nvd CVE-2026-76226 rce 2026-08-19
medium CVE-2026-76227 — Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including correspond… vulnerability nvd CVE-2026-76227 2026-08-19
medium CVE-2026-76228 — Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) con… vulnerability nvd CVE-2026-76228 2026-08-19
medium CVE-2026-76229 — Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability… vulnerability nvd CVE-2026-76229 2026-08-19
medium CVE-2026-76230 — Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm m… vulnerability nvd CVE-2026-76230 2026-08-19
medium CVE-2026-76231 — Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the herm… vulnerability nvd CVE-2026-76231 2026-08-19
medium CVE-2026-76232 — Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv… vulnerability nvd CVE-2026-76232 2026-08-19
medium CVE-2026-76233 — Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam… vulnerability nvd CVE-2026-76233 2026-08-19
medium CVE-2026-76239 — Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subsc… vulnerability nvd CVE-2026-76239 2026-08-19
medium CVE-2026-15961 — IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 IBM P… vulnerability nvd CVE-2026-15961 2026-08-19
medium CVE-2026-32802 — Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerabil… vulnerability nvd CVE-2026-32802 2026-08-19
medium CVE-2026-40507 — OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal t… vulnerability nvd CVE-2026-40507 2026-08-19
medium CVE-2026-40508 — OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal temp… vulnerability nvd CVE-2026-40508 2026-08-19
medium CVE-2026-40509 — OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The we… vulnerability nvd CVE-2026-40509 2026-08-19
medium CVE-2026-50149 — Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, whe… vulnerability nvd CVE-2026-50149 2026-08-19
medium CVE-2026-54793 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input Du… vulnerability nvd CVE-2026-54793 2026-08-19
medium CVE-2026-56796 — Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File… vulnerability nvd CVE-2026-56796 2026-08-19
medium CVE-2026-67266 — Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability… vulnerability nvd CVE-2026-67266 2026-08-19
medium CVE-2026-67267 — Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Informat… vulnerability nvd CVE-2026-67267 2026-08-19
medium CVE-2026-67268 — Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External… vulnerability nvd CVE-2026-67268 2026-08-19
medium CVE-2026-76614 — OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. Th… vulnerability nvd CVE-2026-76614 2026-08-19
medium CVE-2026-44253 — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3… vulnerability nvd CVE-2026-44253 2026-08-19
medium CVE-2026-44254 — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1… vulnerability nvd CVE-2026-44254 2026-08-19
medium CVE-2026-53654 — Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a clie… vulnerability nvd CVE-2026-53654 phishing 2026-08-19
medium CVE-2026-61690 — Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Co… vulnerability nvd CVE-2026-61690 2026-08-19
medium CVE-2026-61842 — Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offset… vulnerability nvd CVE-2026-61842 2026-08-19
medium CVE-2026-62670 — Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav… vulnerability nvd CVE-2026-62670 2026-08-19
medium CVE-2026-20177 — A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 S… vulnerability nvd CVE-2026-20177 2026-08-19
medium CVE-2026-20232 — A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series… vulnerability nvd CVE-2026-20232 2026-08-19
medium CVE-2026-20302 — A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker wit… vulnerability nvd CVE-2026-20302 2026-08-19
medium CVE-2026-20314 — A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact… vulnerability nvd CVE-2026-20314 2026-08-19
medium CVE-2026-20327 — A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all… vulnerability nvd CVE-2026-20327 2026-08-19
medium CVE-2026-75145 — FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packe… vulnerability nvd CVE-2026-75145 2026-08-19
medium CVE-2026-18874 — A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malici… vulnerability nvd CVE-2026-18874 2026-08-19
medium CVE-2026-55564 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_ge… vulnerability nvd CVE-2026-55564 ransomware 2026-08-19
medium CVE-2026-63117 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated R… vulnerability nvd CVE-2026-63117 2026-08-19
medium CVE-2026-69159 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.29.0, planar_decompress_… vulnerability nvd CVE-2026-69159 2026-08-19
medium CVE-2026-18681 — IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.0… vulnerability nvd CVE-2026-18681 2026-08-19
medium CVE-2026-49870 — Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limi… vulnerability nvd CVE-2026-49870 2026-08-19
medium CVE-2026-49976 — Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission… vulnerability nvd CVE-2026-49976 2026-08-19
medium CVE-2026-50550 — Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users c… vulnerability nvd CVE-2026-50550 2026-08-19
medium CVE-2026-55482 — Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http… vulnerability nvd CVE-2026-55482 2026-08-19
medium CVE-2026-55519 — Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generi… vulnerability nvd CVE-2026-55519 2026-08-19
medium CVE-2026-55703 — Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request… vulnerability nvd CVE-2026-55703 2026-08-19
medium CVE-2026-16724 — IBM Virtualization Management Interface FW1110.00 through FW1110.30, FW1120.00 through FW1120.00, an… vulnerability nvd CVE-2026-16724 2026-08-19
medium CVE-2026-16833 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to disclose kernel memor… vulnerability nvd CVE-2026-16833 2026-08-19
medium CVE-2026-16883 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive infor… vulnerability nvd CVE-2026-16883, CVE-2026-16890, CVE-2026-16891, CVE-2026-17007 2026-08-19
medium CVE-2026-55086 — Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and… vulnerability nvd CVE-2026-55086 transport 2026-08-19
medium CVE-2026-55087 — Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-con… vulnerability nvd CVE-2026-55087 2026-08-19
medium CVE-2026-55088 — Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/expr… vulnerability nvd CVE-2026-55088 2026-08-19
medium CVE-2026-63187 — Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0,… vulnerability nvd CVE-2026-63187 2026-08-19
medium CVE-2026-67189 — pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnera… vulnerability nvd CVE-2026-67189 2026-08-19
medium CVE-2026-68559 — Wekan is open source kanban built with Meteor. From 9.57 until 9.74, the /api/boards/:boardId/export… vulnerability nvd CVE-2026-68559 2026-08-19
medium CVE-2026-68901 — Wekan is open source kanban built with Meteor. Prior to 10.38, the /api/boards/:boardId/export, /api… vulnerability nvd CVE-2026-68901 2026-08-19
medium CVE-2026-76572 — A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is… vulnerability nvd CVE-2026-76572 2026-08-19
medium CVE-2026-12634 — The NVS backend of the Zephyr settings subsystem (subsys/settings/src/settings_nvs.c) reads stored s… vulnerability nvd CVE-2026-12634 2026-08-19
medium CVE-2026-14514 — IBM Reliable Scalable Cluster Technology (RSCT) 3.0 could allow a remote attacker to cause a denial… vulnerability nvd CVE-2026-14514 2026-08-19
medium CVE-2026-14978 — HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclu… vulnerability nvd CVE-2026-14978 2026-08-19
medium CVE-2026-17015 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of servic… vulnerability nvd CVE-2026-17015 2026-08-19
medium CVE-2026-18849 — IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update pr… vulnerability nvd CVE-2026-18849 2026-08-19
medium CVE-2026-4936 — IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.0… vulnerability nvd CVE-2026-4936 2026-08-19
medium CVE-2026-4937 — IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 throug… vulnerability nvd CVE-2026-4937 2026-08-19
medium CVE-2026-54738 — Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web… vulnerability nvd CVE-2026-54738 2026-08-19
medium CVE-2026-54739 — Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, Lemmy's l… vulnerability nvd CVE-2026-54739 phishing 2026-08-19
medium CVE-2026-54740 — Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, a lower… vulnerability nvd CVE-2026-54740 2026-08-19
medium CVE-2026-68552 — Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthentic… vulnerability nvd CVE-2026-68552 2026-08-19
medium CVE-2026-68555 — Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TUR… vulnerability nvd CVE-2026-68555 2026-08-19
medium CVE-2026-76576 — A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. This impacts the function fileDown… vulnerability nvd CVE-2026-76576 2026-08-19
medium CVE-2026-76827 — A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed… vulnerability nvd CVE-2026-76827 2026-08-19
medium CVE-2026-59992 — Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0… vulnerability nvd CVE-2026-59992 2026-08-19
medium CVE-2026-63123 — Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev ser… vulnerability nvd CVE-2026-63123 2026-08-19
medium CVE-2026-69550 — Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information… vulnerability nvd CVE-2026-69550 2026-08-19
medium CVE-2026-76252 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.13, an unauthenticated user who… vulnerability nvd CVE-2026-76252 phishing 2026-08-19
medium CVE-2026-76255 — In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.8, and 9.4.13, a user who does not hold the… vulnerability nvd CVE-2026-76255 phishing 2026-08-19
medium CVE-2026-76322 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "user"… vulnerability nvd CVE-2026-76322 phishing 2026-08-19
medium CVE-2026-76328 — In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power"… vulnerability nvd CVE-2026-76328 phishing 2026-08-19
medium CVE-2026-76340 — In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could cause Splunk Enterpri… vulnerability nvd CVE-2026-76340 2026-08-19
medium CVE-2026-76345 — In Splunk Enterprise versions below 10.4.2, a user with a high-privilege Splunk role that can manage… vulnerability nvd CVE-2026-76345 rce 2026-08-19
medium CVE-2026-76349 — In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick… vulnerability nvd CVE-2026-76349 phishing 2026-08-19
medium CVE-2026-76358 — In Splunk SOAR versions below 8.6.0, a user with app-install privileges could use path traversal dur… vulnerability nvd CVE-2026-76358 2026-08-19
medium CVE-2026-76359 — In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversa… vulnerability nvd CVE-2026-76359 2026-08-19
medium CVE-2026-76360 — In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest… vulnerability nvd CVE-2026-76360 2026-08-19
medium CVE-2026-76363 — In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run arbit… vulnerability nvd CVE-2026-76363 ransomware 2026-08-19
medium CVE-2026-76364 — In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role cou… vulnerability nvd CVE-2026-76364, CVE-2026-76365 2026-08-19
medium CVE-2026-76366 — In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representatio… vulnerability nvd CVE-2026-76366 ransomware 2026-08-19
medium CVE-2026-76367 — In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Commander" Splunk SOAR role coul… vulnerability nvd CVE-2026-76367 phishing 2026-08-19
medium CVE-2026-76370 — In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use t… vulnerability nvd CVE-2026-76370 2026-08-19
medium CVE-2026-76372 — In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run playboo… vulnerability nvd CVE-2026-76372 ransomware 2026-08-19
medium CVE-2026-76373 — In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission… vulnerability nvd CVE-2026-76373, CVE-2026-76374, CVE-2026-76375 2026-08-19
medium CVE-2026-76376 — In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who holds a role with permission… vulnerability nvd CVE-2026-76376 2026-08-19
medium CVE-2026-76377 — In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with perm… vulnerability nvd CVE-2026-76377 2026-08-19
medium CVE-2026-76378 — In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds… vulnerability nvd CVE-2026-76378 2026-08-19
medium CVE-2026-76379 — In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permiss… vulnerability nvd CVE-2026-76379 2026-08-19
medium CVE-2026-76380 — In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role wi… vulnerability nvd CVE-2026-76380 2026-08-19
medium CVE-2026-76381 — In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a… vulnerability nvd CVE-2026-76381 2026-08-19
medium CVE-2026-76382 — In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with permission… vulnerability nvd CVE-2026-76382 2026-08-19
medium CVE-2026-76383 — In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who ho… vulnerability nvd CVE-2026-76383 2026-08-19
medium CVE-2026-76384 — In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a… vulnerability nvd CVE-2026-76384 2026-08-19
medium CVE-2026-76385 — In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission t… vulnerability nvd CVE-2026-76385 2026-08-19
medium CVE-2026-76386 — In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to… vulnerability nvd CVE-2026-76386 2026-08-19
medium CVE-2026-76390 — In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated u… vulnerability nvd CVE-2026-76390 2026-08-19
medium CVE-2026-76393 — In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model bein… vulnerability nvd CVE-2026-76393 2026-08-19
medium CVE-2026-76398 — In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk ro… vulnerability nvd CVE-2026-76398 2026-08-19
medium CVE-2026-76405 — In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the… vulnerability nvd CVE-2026-76405 2026-08-19
medium CVE-2026-76881 — CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service vulnerability nvd CVE-2026-76881, CVE-2026-76921 2026-08-19
medium CVE-2026-76882 — Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of… vulnerability nvd CVE-2026-76882 2026-08-19
medium CVE-2026-76883 — Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service vulnerability nvd CVE-2026-76883 2026-08-19
medium CVE-2026-76889 — UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service vulnerability nvd CVE-2026-76889 2026-08-19
medium CVE-2026-76917 — Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial… vulnerability nvd CVE-2026-76917 2026-08-19
medium CVE-2026-76918 — SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service vulnerability nvd CVE-2026-76918 2026-08-19
medium CVE-2026-76919 — ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service vulnerability nvd CVE-2026-76919 2026-08-19
medium CVE-2026-76920 — 3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service vulnerability nvd CVE-2026-76920 2026-08-19
medium CVE-2026-76922 — Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of… vulnerability nvd CVE-2026-76922 2026-08-19
medium CVE-2026-76923 — Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial o… vulnerability nvd CVE-2026-76923 2026-08-19
medium CVE-2026-76924 — Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service vulnerability nvd CVE-2026-76924 2026-08-19
medium CVE-2026-76927 — H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service vulnerability nvd CVE-2026-76927 2026-08-19
medium CVE-2026-76929 — Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service vulnerability nvd CVE-2026-76929 2026-08-19
medium CVE-2026-76785 — A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Aff… vulnerability nvd CVE-2026-76785 2026-08-20
medium CVE-2026-76799 — A weakness has been identified in code-projects Login Registration System 1.0. This affects an unkno… vulnerability nvd CVE-2026-76799 2026-08-20
medium CVE-2026-76800 — A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of th… vulnerability nvd CVE-2026-76800 2026-08-20
medium CVE-2026-76956 — In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to ins… vulnerability nvd CVE-2026-76956 2026-08-20
medium CVE-2026-76957 — libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-… vulnerability nvd CVE-2026-76957 2026-08-20
medium CVE-2026-13405 — The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom w… vulnerability nvd CVE-2026-13405 ransomware 2026-08-20
medium CVE-2026-17153 — The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all version… vulnerability nvd CVE-2026-17153 2026-08-20
medium CVE-2026-19615 — The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG f… vulnerability nvd CVE-2026-19615 2026-08-20
medium CVE-2026-19697 — The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload… vulnerability nvd CVE-2026-19697 2026-08-20
medium CVE-2026-74992 — The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives u… vulnerability nvd CVE-2026-74992 rce 2026-08-20
medium CVE-2026-14949 — A low privileged remote attacker with a valid session can submit a request to the user creation func… vulnerability nvd CVE-2026-14949 2026-08-20
medium CVE-2026-14953 — A low-privileged remote attacker can enumerate all configured users and identify which accounts hold… vulnerability nvd CVE-2026-14953 2026-08-20
medium CVE-2026-77014 — A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator… vulnerability nvd CVE-2026-77014 2026-08-20
medium CVE-2026-73196 — A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by su… vulnerability nvd CVE-2026-73196 2026-08-20
medium CVE-2026-73199 — A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a n… vulnerability nvd CVE-2026-73199 2026-08-20
medium CVE-2026-77066 — The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplie… vulnerability nvd CVE-2026-77066 2026-08-20
medium CVE-2026-77067 — The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied ur… vulnerability nvd CVE-2026-77067 2026-08-20
medium CVE-2025-53999 — Unauthenticated Broken Access Control in Altair <= 5.2.2 versions. vulnerability nvd CVE-2025-53999 2026-08-20
medium CVE-2025-62307 — HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weak… vulnerability nvd CVE-2025-62307 2026-08-20
medium CVE-2026-66586 — Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions. vulnerability nvd CVE-2026-66586 2026-08-20
medium CVE-2026-66595 — Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions. vulnerability nvd CVE-2026-66595 2026-08-20
medium CVE-2026-66601 — Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions. vulnerability nvd CVE-2026-66601 2026-08-20
medium CVE-2026-66647 — Subscriber Broken Access Control in Homlisti <= 3.1.2 versions. vulnerability nvd CVE-2026-66647 2026-08-20
medium CVE-2026-73402 — Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions. vulnerability nvd CVE-2026-73402 2026-08-20
medium CVE-2025-62299 — HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow… vulnerability nvd CVE-2025-62299 2026-08-20
medium CVE-2025-62300 — HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur w… vulnerability nvd CVE-2025-62300 2026-08-20
medium CVE-2025-62306 — HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information b… vulnerability nvd CVE-2025-62306 2026-08-20
medium CVE-2026-21784 — HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security heade… vulnerability nvd CVE-2026-21784 2026-08-20
medium CVE-2026-28163 — Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configu… vulnerability nvd CVE-2026-28163 2026-08-20
medium CVE-2026-76988 — A weakness has been identified in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This… vulnerability nvd CVE-2026-76988 2026-08-20
medium CVE-2026-76989 — A security vulnerability has been detected in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13… vulnerability nvd CVE-2026-76989 2026-08-20
medium CVE-2026-76634 — WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profil… vulnerability nvd CVE-2026-76634 2026-08-20
medium CVE-2026-44725 — EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to vers… vulnerability nvd CVE-2026-44725 transport 2026-08-20
medium CVE-2026-55558 — aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_t… vulnerability nvd CVE-2026-55558 2026-08-20
medium CVE-2026-76991 — A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown pa… vulnerability nvd CVE-2026-76991 2026-08-20
medium CVE-2026-76993 — A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown… vulnerability nvd CVE-2026-76993 2026-08-20
medium CVE-2026-76995 — A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue… vulnerability nvd CVE-2026-76995 2026-08-20
medium CVE-2026-63015 — Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons c… vulnerability nvd CVE-2026-63015 2026-08-20
medium CVE-2026-63016 — Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational con… vulnerability nvd CVE-2026-63016 2026-08-20
medium CVE-2026-76997 — A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affecte… vulnerability nvd CVE-2026-76997 2026-08-20
medium CVE-2026-76999 — A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analy… vulnerability nvd CVE-2026-76999 2026-08-20
medium CVE-2026-54770 — WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_abs… vulnerability nvd CVE-2026-54770 phishing 2026-08-20
medium CVE-2026-55586 — SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, a crafted CHM file can supply… vulnerability nvd CVE-2026-55586 2026-08-20
medium CVE-2026-61625 — VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.… vulnerability nvd CVE-2026-61625 2026-08-20
medium CVE-2026-77025 — A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unkno… vulnerability nvd CVE-2026-77025 2026-08-20
medium CVE-2026-54625 — django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the djan… vulnerability nvd CVE-2026-54625 2026-08-20
medium CVE-2026-72844 — The Lean 4 kernel does not verify that the structure named in a projection expression matches the ty… vulnerability nvd CVE-2026-72844 2026-08-20
medium CVE-2026-72847 — broot renders each file and directory name in its interactive tree view exactly as read from the fil… vulnerability nvd CVE-2026-72847 2026-08-20
medium CVE-2026-73254 — Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a… vulnerability nvd CVE-2026-73254 2026-08-20
medium CVE-2026-73255 — Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control a… vulnerability nvd CVE-2026-73255 2026-08-20
medium CVE-2026-73258 — Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a… vulnerability nvd CVE-2026-73258 2026-08-20
medium CVE-2026-73259 — Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a… vulnerability nvd CVE-2026-73259 2026-08-20
medium CVE-2026-77036 — A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailCon… vulnerability nvd CVE-2026-77036 2026-08-20
medium CVE-2026-43678 — An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingb… vulnerability nvd CVE-2026-43678 2026-08-20
medium CVE-2026-64777 — A malicious builder peer may be able to request an in-context file by name from the host and receive… vulnerability nvd CVE-2026-64777 2026-08-20
medium CVE-2026-72854 — msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_… vulnerability nvd CVE-2026-72854 2026-08-20
medium CVE-2026-75514 — BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklis… vulnerability nvd CVE-2026-75514 2026-08-20
medium CVE-2026-72861 — The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inv… vulnerability nvd CVE-2026-72861 2026-08-20
medium CVE-2026-75910 — Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Fede… vulnerability nvd CVE-2026-75910 2026-08-20
medium CVE-2026-67445 — Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP command… vulnerability nvd CVE-2026-67445 2026-08-20
medium CVE-2026-67446 — Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-s… vulnerability nvd CVE-2026-67446 2026-08-20
medium CVE-2026-68921 — DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpola… vulnerability nvd CVE-2026-68921 2026-08-20
medium CVE-2026-76018 — Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker lev… vulnerability nvd CVE-2026-76018 phishing 2026-08-20
medium CVE-2026-76019 — Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacke… vulnerability nvd CVE-2026-76019 phishing 2026-08-20
medium CVE-2026-77506 — Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS. vulnerability nvd CVE-2026-77506 2026-08-20
medium CVE-2026-77587 — Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object whe… vulnerability nvd CVE-2026-77587 2026-08-20
medium CVE-2026-77639 — Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many g… vulnerability nvd CVE-2026-77639 2026-08-20
medium CVE-2026-77641 — tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. Th… vulnerability nvd CVE-2026-77641 2026-08-20
medium CVE-2026-16951 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute… vulnerability nvd CVE-2026-16951 2026-08-20
medium CVE-2026-16964 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages an… vulnerability nvd CVE-2026-16964 2026-08-20
medium CVE-2026-16973 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to disclose sensitive ker… vulnerability nvd CVE-2026-16973 2026-08-20
medium CVE-2026-17424 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restr… vulnerability nvd CVE-2026-17424 2026-08-20
medium CVE-2026-19448 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the… vulnerability nvd CVE-2026-19448 2026-08-20
medium CVE-2026-19783 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory co… vulnerability nvd CVE-2026-19783 2026-08-20
medium CVE-2026-49244 — SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public we… vulnerability nvd CVE-2026-49244 2026-08-20
medium CVE-2026-54389 — Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser t… vulnerability nvd CVE-2026-54389 2026-08-20
medium CVE-2026-54509 — TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link… vulnerability nvd CVE-2026-54509 2026-08-20
medium CVE-2026-55015 — Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny servic… vulnerability nvd CVE-2026-55015 2026-08-20
medium CVE-2026-55489 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could s… vulnerability nvd CVE-2026-55489 2026-08-20
medium CVE-2026-55491 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape m… vulnerability nvd CVE-2026-55491 ransomware 2026-08-20
medium CVE-2026-62945 — TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions a… vulnerability nvd CVE-2026-62945 2026-08-20
medium CVE-2026-67447 — Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's interna… vulnerability nvd CVE-2026-67447 2026-08-20
medium CVE-2026-67448 — Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/… vulnerability nvd CVE-2026-67448 2026-08-20
medium CVE-2026-70105 — Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose infor… vulnerability nvd CVE-2026-70105 2026-08-20
medium CVE-2026-72846 — Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendW… vulnerability nvd CVE-2026-72846 2026-08-20
medium CVE-2026-77643 — A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core… vulnerability nvd CVE-2026-77643 2026-08-20
medium CVE-2026-77391 — A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS,… vulnerability nvd CVE-2026-77391 2026-08-21
medium CVE-2026-77392 — A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and… vulnerability nvd CVE-2026-77392 2026-08-21
medium payload: undefined threat-intel threatfox elf, IoT, ClearFake, ClickFix, etherhiding, majinahanashi, Ransomware, ErrTraffic, DPRK, kimsuky, MoonPeak, Stella, golang, zimbra, zimbra-exfil, ZMBX, ransomware, apt, botnet 2026-08-20
medium BRIDGEHEAD: An npm typosquatting campaign that crosses from WSL into Windows to plant a crypto-wallet stealer threat-intel otx 6888d4c54ef2b5bf… rust, github-hosted-payload, browser-credentials, wsl, telegram, npm, cryptocurrency-stealer, typosquatting, in-memory-execution, supply-chain, botnet 2026-08-20
medium How Peer2Profit and Astroproxy Turn Your Bandwidth Into Someone Else's Product threat-intel otx c85c7436fdb71cf5… backconnect infrastructure, bandwidth-sharing, internal network exposure, privateloader, sdk analysis, proxy enumeration, peer2profit, residential proxies, astroproxy 2026-08-20
medium N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it threat-intel otx CVE-2023-48022, CVE-2026-26220, CVE-2026-27944, CVE-2026-33032, CVE-2026-39987 | e09ac5e8c23a768a…, b8e66803519f9376… n4d mesh controller, cve-2023-48022, cve-2026-26220, linux malware, go-titan, cve-2026-27944, ray dashboard, cve-2026-33032, n4d, cve-2026-39987, mcp exploitation, lateral movement, ai infrastructure targeting, cloudflare tunnels, credential theft, lightllm, botnet 2026-08-20
medium Blend between Banking Malware & Spyware threat-intel otx feea425cde1223fe…, 2b24e1e154eb93e5… wi-fi mesh relay, ukraine targeted, android, spyware, device takeover, manic, banking trojan, cryptocurrency theft, botnet, infostealer 2026-08-20
medium Back-to-School Cyber Risks Surge as Education Remains the World's Most Attacked Sector threat-intel otx 6d0bd9615d730b0b… student targeting, education sector, phishing campaigns, back-to-school, credential theft, domain registration, apac attacks, phishing 2026-08-20
medium Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign threat-intel otx fad1e9d507c7021a…, f1aed8cf2adafa86… sandbox evasion, grandoreiro, mexico, dll sideloading, anti-analysis, delphi, banking trojan, latin america, botnet 2026-08-19
medium Backdoor delivered through software updates threat-intel otx cefd8928fd7411b4… download studio, cryptocurrency mining, software update abuse, xmrig, supply chain attack, backdoor, adblocker, torrent client, qt framework, fakembam, botnet, supply-chain 2026-08-19
medium Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware threat-intel otx e276bf8744f29c54…, f4769ba9e8065727… black hat, conference phishing, cryptocurrency theft, def con, atomic macos stealer, netsupport rat, clickfix, netsupport manager, google apps script, amos, phishing, infostealer 2026-08-19
medium Scammers are using fake crypto AML checkers to drain your wallet threat-intel otx fake aml checker, social engineering, crypto scam, wallet draining, fraudulent website, phishing, cryptocurrency, token theft, ghostdesk, ransomware 2026-08-19
medium 77 Firefox Extensions Linked to Crypto Wallet and Credential Theft threat-intel otx 77.91.100.175 | b65143df86edd606… browser extension campaign, credential stealing, supabase abuse, cloudflare workers, firefox extensions, phishing, web3 impersonation, cryptocurrency wallet theft, botnet, infostealer 2026-08-20
medium 41 deceptive download sites show a real link, then send you somewhere else threat-intel otx 9a3f6e69c12cb814…, c0ecbd201cc92afd… affiliate fraud, deceptive downloads, fake software sites, bait-and-switch, grand media, download studio, javascript redirection, fakembam, ransomware 2026-08-20
medium https://malbearlabs.com/shadow-hvnc-and-shadow-loader-the-kit-that-protects-its-license-better-than-its-customers-dd99520b6af3 threat-intel otx 212.162.150.121 | f65bdff0bf9c807c…, 5ccd6c0dba9ad2ab… 2026-08-19
medium From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel threat-intel otx 519d5f0350f78805… legionloader, modular architecture, maas, lummastealer, clickfix, rat, tor, cryptocurrency theft, nodejs, grpc, botnet, infostealer 2026-08-19
medium Beware of Phishing Emails Disguised as Quote Confirmation Requests (PhantomStealer) threat-intel otx 05aa847cdfc69a78…, c155a21bec649260… clipper, uac bypass, cryptocurrency stealer, byovd, injector, phantomstealer, credential theft, process hollowing, phishing, infostealer 2026-08-19
medium Signed Overwolf Binary Sideloads ValleyRAT Malware in India threat-intel otx 103.240.196.115 | 2d2a251a88632f01…, 315bda377beafb74… india taxation phishing, upx packing, valleyrat, astral-pe, overwolf abuse, reflective loading, process hollowing, dll sideloading, phishing, botnet 2026-08-18
medium Beware of Phishing Emails Disguised as Transaction Receipts threat-intel otx 82a7410b7c56f538…, ab707764ad3fc261… pdf attachment, remote access, vbs script, transaction receipt lure, living-off-the-land, phishing campaign, screenconnect abuse, screenconnect, ransomware, phishing 2026-08-18
medium Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor threat-intel otx 38.60.244.141 | daeac66441b88ba2…, b9622eb982f7c8b9… vhd file, quic protocol, cloudflare workers, china-nexus, quicagent, operation quicsilver, go backdoor, myanmar diplomats, botnet 2026-08-17
medium Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline threat-intel otx ba9d459169a30306… vishing, electron-malware, account-enumeration, jailbreak-prompt, telegram-exfiltration, phishing, cryptocurrency, wallet-theft, ai-assisted-development, seed-phrase-exfiltration 2026-08-18
medium New Mirai-Based Linux Botnet 'Evooo1Bot' Turns Victims Into Proxies threat-intel otx, general-news CVE-2016-6277, CVE-2007-3010, CVE-2018-14558, CVE-2019-14931, CVE-2020-10987, CVE-2021-46422, CVE-2022-37055, CVE-2024-29269, CVE-2025-10123, CVE-2025-55583 | 91.92.40.118 edge devices, cve-2007-3010, iot exploitation, cve-2022-37055, cve-2025-55583, cve-2020-10987, mirai variant, cve-2025-10123, cve-2021-46422, cve-2024-29269, cve-2018-14558, cve-2019-14931, ddos attacks, linux botnet, evooo1bot, cve-2016-6277, socks proxy, encrypted c2, mirai, botnet 2026-08-14
medium Hackers poison arrayref Rust crate to push infostealer malware news general-news infostealer 2026-08-20
medium How MSPs can catch phishing attacks email filters miss news general-news phishing 2026-08-20
medium Phishing 3.0: The Fight Moves to Agent Versus Agent news general-news phishing 2026-08-19
medium SilkParasite Threatens Central Asian Orgs With Flurry of RATs news general-news phishing 2026-08-19
medium Def Con Attendees Targeted by Persistent Phishing Campaign news general-news phishing 2026-08-20
medium Infostealers Harvest 1.7 Billion Credentials in Six Months news general-news infostealer 2026-08-17
medium Fake Gemini installer delivers Vidar infostealer via Google Colab lure news general-news infostealer 2026-08-20
low CVE-2026-19835 — A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an u… vulnerability nvd CVE-2026-19835 2026-08-14
low CVE-2026-19837 — A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the fi… vulnerability nvd CVE-2026-19837 2026-08-14
low CVE-2026-19841 — A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /e… vulnerability nvd CVE-2026-19841 2026-08-14
low CVE-2026-73844 — CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect… vulnerability nvd CVE-2026-73844 2026-08-14
low CVE-2026-19891 — A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02. This affects an unknown function of t… vulnerability nvd CVE-2026-19891 2026-08-15
low CVE-2026-19893 — A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the f… vulnerability nvd CVE-2026-19893 2026-08-15
low CVE-2026-19895 — A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects th… vulnerability nvd CVE-2026-19895 2026-08-15
low CVE-2026-19896 — A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_… vulnerability nvd CVE-2026-19896 2026-08-15
low CVE-2026-19897 — A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login… vulnerability nvd CVE-2026-19897 2026-08-15
low CVE-2026-19898 — A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler… vulnerability nvd CVE-2026-19898 2026-08-15
low CVE-2026-19904 — A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects… vulnerability nvd CVE-2026-19904 2026-08-15
low CVE-2026-19906 — A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the func… vulnerability nvd CVE-2026-19906 2026-08-15
low CVE-2026-19916 — A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is… vulnerability nvd CVE-2026-19916 2026-08-15
low CVE-2026-19922 — A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this is… vulnerability nvd CVE-2026-19922 2026-08-16
low CVE-2026-74797 — OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command w… vulnerability nvd CVE-2026-74797 2026-08-16
low CVE-2026-19955 — A vulnerability was detected in TrailDB 0.6. Impacted is the function tdb_open of the file /src/tdb.… vulnerability nvd CVE-2026-19955 2026-08-16
low CVE-2026-19965 — A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the functi… vulnerability nvd CVE-2026-19965 2026-08-17
low CVE-2026-19975 — A weakness has been identified in Azuriom CMS up to 1.2.12. This issue affects the function transfer… vulnerability nvd CVE-2026-19975 2026-08-17
low CVE-2026-19992 — A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up… vulnerability nvd CVE-2026-19992 2026-08-17
low CVE-2026-19995 — A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the fi… vulnerability nvd CVE-2026-19995 2026-08-17
low CVE-2026-49306 — UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerab… vulnerability nvd CVE-2026-49306 2026-08-17
low CVE-2026-74870 — openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm… vulnerability nvd CVE-2026-74870 2026-08-17
low CVE-2026-74885 — openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs mo… vulnerability nvd CVE-2026-74885 2026-08-17
low CVE-2026-74887 — openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PR… vulnerability nvd CVE-2026-74887 2026-08-17
low CVE-2026-70412 — Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a… vulnerability nvd CVE-2026-70412 2026-08-17
low CVE-2026-75052 — In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content wa… vulnerability nvd CVE-2026-75052 2026-08-17
low CVE-2026-75483 — powerlevel10k fails to neutralize control characters in the package.json version field when renderin… vulnerability nvd CVE-2026-75483 2026-08-17
low CVE-2026-64779 — A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari… vulnerability nvd CVE-2026-64779, CVE-2026-64782 2026-08-17
low CVE-2026-75587 — Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a d… vulnerability nvd CVE-2026-75587 2026-08-17
low CVE-2026-9693 — Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membersh… vulnerability nvd CVE-2026-9693 2026-08-17
low CVE-2026-75773 — A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the functio… vulnerability nvd CVE-2026-75773 2026-08-18
low CVE-2026-75774 — A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unk… vulnerability nvd CVE-2026-75774 2026-08-18
low CVE-2026-63632 — Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From… vulnerability nvd CVE-2026-63632 2026-08-18
low CVE-2026-45126 — MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Security Questions module… vulnerability nvd CVE-2026-45126 2026-08-18
low CVE-2026-45127 — MyBB is free and open source forum software. Prior to 1.8.40, the ACP Mass Mail module does not vali… vulnerability nvd CVE-2026-45127 2026-08-18
low CVE-2026-45128 — MyBB is free and open source forum software. Prior to 1.8.40, the ACP Users View Manager module does… vulnerability nvd CVE-2026-45128 2026-08-18
low CVE-2026-62684 — File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing… vulnerability nvd CVE-2026-62684 2026-08-18
low CVE-2026-75904 — libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The… vulnerability nvd CVE-2026-75904 ransomware 2026-08-18
low CVE-2026-68927 — MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities i… vulnerability nvd CVE-2026-68927 2026-08-18
low CVE-2026-67442 — FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /ap… vulnerability nvd CVE-2026-67442 ics 2026-08-18
low CVE-2026-76042 — Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attac… vulnerability nvd CVE-2026-76042 2026-08-18
low CVE-2026-76014 — A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of t… vulnerability nvd CVE-2026-76014 2026-08-19
low CVE-2026-13173 — The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit oth… vulnerability nvd CVE-2026-13173 2026-08-19
low CVE-2026-14825 — The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object owners… vulnerability nvd CVE-2026-14825, CVE-2026-14826 2026-08-19
low CVE-2026-19406 — The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing… vulnerability nvd CVE-2026-19406 2026-08-19
low CVE-2026-75583 — keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) g… vulnerability nvd CVE-2026-75583 2026-08-19
low CVE-2026-11617 — Tanium addressed a compression bomb vulnerability in Findings. vulnerability nvd CVE-2026-11617 2026-08-19
low CVE-2026-18102 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memor… vulnerability nvd CVE-2026-18102 2026-08-19
low CVE-2026-75476 — Tanium addressed a compression bomb vulnerability in Threat Response. vulnerability nvd CVE-2026-75476 2026-08-19
low CVE-2026-76348 — In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk ro… vulnerability nvd CVE-2026-76348 2026-08-19
low CVE-2026-76361 — In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/suppor… vulnerability nvd CVE-2026-76361 2026-08-19
low CVE-2026-76368 — In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permis… vulnerability nvd CVE-2026-76368 ransomware 2026-08-19
low CVE-2026-76369 — In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outsi… vulnerability nvd CVE-2026-76369 2026-08-19
low CVE-2026-76371 — In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in… vulnerability nvd CVE-2026-76371 ransomware 2026-08-19
low CVE-2026-76884 — ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service vulnerability nvd CVE-2026-76884 2026-08-19
low CVE-2026-76885 — Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service vulnerability nvd CVE-2026-76885 2026-08-19
low CVE-2026-76887 — Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of serv… vulnerability nvd CVE-2026-76887 2026-08-19
low CVE-2026-76888 — RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service vulnerability nvd CVE-2026-76888 2026-08-19
low CVE-2026-76890 — Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service vulnerability nvd CVE-2026-76890, CVE-2026-76891 2026-08-19
low CVE-2026-76926 — BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service vulnerability nvd CVE-2026-76926 2026-08-19
low CVE-2026-19699 — The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of it… vulnerability nvd CVE-2026-19699 2026-08-20
low CVE-2026-73542 — Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle at… vulnerability nvd CVE-2026-73542 2026-08-20
low CVE-2026-64846 — Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation e… vulnerability nvd CVE-2026-64846 2026-08-20
low CVE-2026-49996 — SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle s… vulnerability nvd CVE-2026-49996 2026-08-20
low CVE-2026-77151 — A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the func… vulnerability nvd CVE-2026-77151 2026-08-20
low CVE-2026-77640 — tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream wit… vulnerability nvd CVE-2026-77640 2026-08-20
low CVE-2026-49245 — SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline qu… vulnerability nvd CVE-2026-49245 phishing 2026-08-20
low CVE-2026-77648 — In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_f… vulnerability nvd CVE-2026-77648 2026-08-20
unknown CISA Adds Two Known Exploited Vulnerabilities to Catalog advisory cisa-advisories 2026-08-20
unknown CISA Adds One Known Exploited Vulnerability to Catalog advisory cisa-advisories 2026-08-19
unknown CISA Adds Four Known Exploited Vulnerabilities to Catalog advisory cisa-advisories 2026-08-18
unknown CVE-2026-19871 — Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.… vulnerability nvd CVE-2026-19871 2026-08-14
unknown CVE-2026-19880 — Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows… vulnerability nvd CVE-2026-19880 2026-08-14
unknown CVE-2026-13196 — Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image ma… vulnerability nvd CVE-2026-13196 2026-08-14
unknown CVE-2026-13197 — Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper… vulnerability nvd CVE-2026-13197, CVE-2026-13198 2026-08-14
unknown CVE-2026-19884 — In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integra… vulnerability nvd CVE-2026-19884 2026-08-14
unknown CVE-2026-57469 — Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the we… vulnerability nvd CVE-2026-57469 2026-08-14
unknown CVE-2026-57471 — Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Director… vulnerability nvd CVE-2026-57471, CVE-2026-57472 2026-08-14
unknown CVE-2026-47191 — kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git c… vulnerability nvd CVE-2026-47191 2026-08-14
unknown CVE-2026-47192 — kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, ka… vulnerability nvd CVE-2026-47192 2026-08-14
unknown CVE-2026-49986 — The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to vers… vulnerability nvd CVE-2026-49986 2026-08-14
unknown CVE-2026-49989 — CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can… vulnerability nvd CVE-2026-49989 2026-08-14
unknown CVE-2026-73107 — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. vulnerability nvd CVE-2026-73107, CVE-2026-39925, CVE-2026-18932, CVE-2026-72044, CVE-2026-72246, CVE-2026-74511, CVE-2026-60106, CVE-2026-60107, CVE-2026-54385, CVE-2026-73692, CVE-2026-73103, CVE-2026-73104, CVE-2026-73105, CVE-2026-73106, CVE-2026-73111, CVE-2026-73112, CVE-2026-74226, CVE-2026-74227, CVE-2026-74228, CVE-2026-18502, CVE-2026-18862, CVE-2026-19561, CVE-2026-19562, CVE-2026-19563, CVE-2026-76632, CVE-2026-72845, CVE-2026-46533, CVE-2026-46534, CVE-2026-46535, CVE-2026-46536, CVE-2026-46537, CVE-2026-53993, CVE-2026-6260, CVE-2026-6822, CVE-2026-8717, CVE-2026-63723, CVE-2026-72858 2026-08-14
unknown CVE-2026-49263 — Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend a… vulnerability nvd CVE-2026-49263 2026-08-14
unknown CVE-2026-63361 — LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerab… vulnerability nvd CVE-2026-63361 2026-08-14
unknown CVE-2026-73850 — Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vul… vulnerability nvd CVE-2026-73850 2026-08-14
unknown CVE-2026-18403 — LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Cent… vulnerability nvd CVE-2026-18403 2026-08-14
unknown CVE-2026-19908 — PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows networ… vulnerability nvd CVE-2026-19908 2026-08-14
unknown CVE-2026-27871 — Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 all… vulnerability nvd CVE-2026-27871 2026-08-14
unknown CVE-2026-34492 — External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipu… vulnerability nvd CVE-2026-34492 2026-08-14
unknown CVE-2026-64887 — Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic… vulnerability nvd CVE-2026-64887 2026-08-14
unknown CVE-2026-67365 — Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthe… vulnerability nvd CVE-2026-67365 2026-08-14
unknown CVE-2026-71571 — Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagen… vulnerability nvd CVE-2026-71571 2026-08-14
unknown CVE-2026-67366 — Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 -… vulnerability nvd CVE-2026-67366 2026-08-14
unknown CVE-2026-71570 — Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A… vulnerability nvd CVE-2026-71570 2026-08-14
unknown CVE-2026-73682 — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. CVE-2026… vulnerability nvd CVE-2026-73682 2026-08-14
unknown CVE-2026-63649 — The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows… vulnerability nvd CVE-2026-63649 2026-08-14
unknown CVE-2026-63650 — OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified… vulnerability nvd CVE-2026-63650 2026-08-14
unknown CVE-2026-16007 — AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with… vulnerability nvd CVE-2026-16007 2026-08-15
unknown CVE-2026-68455 — In the Linux kernel, the following vulnerability has been resolved: liveupdate: validate session typ… vulnerability nvd CVE-2026-68455 2026-08-15
unknown CVE-2026-68456 — In the Linux kernel, the following vulnerability has been resolved: usb: atm: ueagle-atm: wait for p… vulnerability nvd CVE-2026-68456 2026-08-15
unknown CVE-2026-68459 — In the Linux kernel, the following vulnerability has been resolved: f2fs: fix potential deadlock in… vulnerability nvd CVE-2026-68459, CVE-2026-68460 2026-08-15
unknown CVE-2026-68463 — In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-esdhc-imx: use pm_run… vulnerability nvd CVE-2026-68463 2026-08-15
unknown CVE-2026-68464 — In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-esdhc-imx: disable ir… vulnerability nvd CVE-2026-68464 2026-08-15
unknown CVE-2026-68465 — In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-esdhc-imx: fix esdhc_… vulnerability nvd CVE-2026-68465 2026-08-15
unknown CVE-2026-68468 — In the Linux kernel, the following vulnerability has been resolved: mtd: virt-concat: free duplicate… vulnerability nvd CVE-2026-68468 2026-08-15
unknown CVE-2026-68469 — In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: fix permanently b… vulnerability nvd CVE-2026-68469 2026-08-15
unknown CVE-2026-68475 — In the Linux kernel, the following vulnerability has been resolved: reset: sunxi: fix memory region… vulnerability nvd CVE-2026-68475 2026-08-15
unknown CVE-2026-68478 — In the Linux kernel, the following vulnerability has been resolved: memstick: ms_block: reject a car… vulnerability nvd CVE-2026-68478 2026-08-15
unknown CVE-2026-72004 — In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix memory leak… vulnerability nvd CVE-2026-72004 2026-08-15
unknown CVE-2026-72006 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5: free mlx5_st_idx_data… vulnerability nvd CVE-2026-72006 2026-08-15
unknown CVE-2026-72007 — In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx: Fix i.MX8MP VC800… vulnerability nvd CVE-2026-72007 2026-08-15
unknown CVE-2026-72008 — In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: Fix possible… vulnerability nvd CVE-2026-72008 2026-08-15
unknown CVE-2026-72010 — In the Linux kernel, the following vulnerability has been resolved: cgroup/cpuset: rebind mm mempoli… vulnerability nvd CVE-2026-72010 2026-08-15
unknown CVE-2026-72011 — In the Linux kernel, the following vulnerability has been resolved: s390/diag: Add missing array_ind… vulnerability nvd CVE-2026-72011 2026-08-15
unknown CVE-2026-72013 — In the Linux kernel, the following vulnerability has been resolved: riscv: Prevent NULL pointer dere… vulnerability nvd CVE-2026-72013 2026-08-15
unknown CVE-2026-72015 — In the Linux kernel, the following vulnerability has been resolved: fs/resctrl: Fix double-add of ps… vulnerability nvd CVE-2026-72015 2026-08-15
unknown CVE-2026-72016 — In the Linux kernel, the following vulnerability has been resolved: cpu/hotplug: Fix NULL kobject wa… vulnerability nvd CVE-2026-72016 2026-08-15
unknown CVE-2026-72017 — In the Linux kernel, the following vulnerability has been resolved: net: macb: drop in-flight Tx SKB… vulnerability nvd CVE-2026-72017 2026-08-15
unknown CVE-2026-72022 — In the Linux kernel, the following vulnerability has been resolved: llc: fix SAP refcount leak in ll… vulnerability nvd CVE-2026-72022 2026-08-15
unknown CVE-2026-72023 — In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix SQB pointer le… vulnerability nvd CVE-2026-72023 2026-08-15
unknown CVE-2026-72025 — In the Linux kernel, the following vulnerability has been resolved: s390/monwriter: Reject buffer re… vulnerability nvd CVE-2026-72025 2026-08-15
unknown CVE-2026-72026 — In the Linux kernel, the following vulnerability has been resolved: irqchip/irq-riscv-imsic-early: F… vulnerability nvd CVE-2026-72026 2026-08-15
unknown CVE-2026-72028 — In the Linux kernel, the following vulnerability has been resolved: riscv: probes: save original sp… vulnerability nvd CVE-2026-72028 2026-08-15
unknown CVE-2026-72030 — In the Linux kernel, the following vulnerability has been resolved: ata: libata-core: Reject an inva… vulnerability nvd CVE-2026-72030 2026-08-15
unknown CVE-2026-72031 — In the Linux kernel, the following vulnerability has been resolved: ata: libata-core: Add NOLPM quir… vulnerability nvd CVE-2026-72031 2026-08-15
unknown CVE-2026-72032 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, fix matcher leak… vulnerability nvd CVE-2026-72032 2026-08-15
unknown CVE-2026-72037 — In the Linux kernel, the following vulnerability has been resolved: net: lan743x: Initialize eth_sys… vulnerability nvd CVE-2026-72037 2026-08-15
unknown CVE-2026-72038 — In the Linux kernel, the following vulnerability has been resolved: net: liquidio: fix BAR resource… vulnerability nvd CVE-2026-72038 2026-08-15
unknown CVE-2026-72039 — In the Linux kernel, the following vulnerability has been resolved: bnx2x: fix potential memory leak… vulnerability nvd CVE-2026-72039 2026-08-15
unknown CVE-2026-72040 — In the Linux kernel, the following vulnerability has been resolved: ipmi: fix refcount leak in i_ipm… vulnerability nvd CVE-2026-72040 2026-08-15
unknown CVE-2026-72047 — In the Linux kernel, the following vulnerability has been resolved: ieee802154: ca8210: fix pointer… vulnerability nvd CVE-2026-72047 2026-08-15
unknown CVE-2026-72048 — In the Linux kernel, the following vulnerability has been resolved: ieee802154: ca8210: fix cas_ctl… vulnerability nvd CVE-2026-72048 2026-08-15
unknown CVE-2026-72050 — In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Free BPID bitmap o… vulnerability nvd CVE-2026-72050 2026-08-15
unknown CVE-2026-72056 — In the Linux kernel, the following vulnerability has been resolved: net: ena: clean up XDP TX queues… vulnerability nvd CVE-2026-72056 2026-08-15
unknown CVE-2026-72058 — In the Linux kernel, the following vulnerability has been resolved: net: ixp4xx_hss: fix duplicate H… vulnerability nvd CVE-2026-72058 2026-08-15
unknown CVE-2026-72059 — In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: destroy DMA poo… vulnerability nvd CVE-2026-72059 2026-08-15
unknown CVE-2026-72060 — In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: icssg: guard… vulnerability nvd CVE-2026-72060 2026-08-15
unknown CVE-2026-72062 — In the Linux kernel, the following vulnerability has been resolved: gpio: mt7621: avoid corruption o… vulnerability nvd CVE-2026-72062 2026-08-15
unknown CVE-2026-72063 — In the Linux kernel, the following vulnerability has been resolved: gpio: tegra: do not call pinctrl… vulnerability nvd CVE-2026-72063 2026-08-15
unknown CVE-2026-72068 — In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Use u64 multip… vulnerability nvd CVE-2026-72068 2026-08-15
unknown CVE-2026-72070 — In the Linux kernel, the following vulnerability has been resolved: wifi: libertas_tf: fix use-after… vulnerability nvd CVE-2026-72070 2026-08-15
unknown CVE-2026-72073 — In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: fix use-after-free… vulnerability nvd CVE-2026-72073 2026-08-15
unknown CVE-2026-72074 — In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix type confus… vulnerability nvd CVE-2026-72074 2026-08-15
unknown CVE-2026-72075 — In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix race condit… vulnerability nvd CVE-2026-72075 2026-08-15
unknown CVE-2026-72076 — In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix out-of-boun… vulnerability nvd CVE-2026-72076 2026-08-15
unknown CVE-2026-72077 — In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix firmware le… vulnerability nvd CVE-2026-72077 2026-08-15
unknown CVE-2026-72078 — In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - validate contro… vulnerability nvd CVE-2026-72078 2026-08-15
unknown CVE-2026-72079 — In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix use-after-f… vulnerability nvd CVE-2026-72079 2026-08-15
unknown CVE-2026-72081 — In the Linux kernel, the following vulnerability has been resolved: scsi: elx: efct: Fix I/O leak on… vulnerability nvd CVE-2026-72081 2026-08-15
unknown CVE-2026-72082 — In the Linux kernel, the following vulnerability has been resolved: scsi: elx: efct: Fix refcount le… vulnerability nvd CVE-2026-72082 2026-08-15
unknown CVE-2026-72086 — In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Free the co… vulnerability nvd CVE-2026-72086 2026-08-15
unknown CVE-2026-72087 — In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix memory leak in l… vulnerability nvd CVE-2026-72087 2026-08-15
unknown CVE-2026-72088 — In the Linux kernel, the following vulnerability has been resolved: scsi: hpsa: Fix DMA mapping leak… vulnerability nvd CVE-2026-72088 2026-08-15
unknown CVE-2026-72091 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: reject user comma… vulnerability nvd CVE-2026-72091 2026-08-15
unknown CVE-2026-72092 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: reject command su… vulnerability nvd CVE-2026-72092 2026-08-15
unknown CVE-2026-72094 — In the Linux kernel, the following vulnerability has been resolved: dma-buf: dma-fence: Fix potentia… vulnerability nvd CVE-2026-72094 2026-08-15
unknown CVE-2026-72096 — In the Linux kernel, the following vulnerability has been resolved: dm-verity: make error counter at… vulnerability nvd CVE-2026-72096 2026-08-15
unknown CVE-2026-72097 — In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix a possible NULL p… vulnerability nvd CVE-2026-72097 2026-08-15
unknown CVE-2026-72101 — In the Linux kernel, the following vulnerability has been resolved: dm-integrity: fix leaking uninit… vulnerability nvd CVE-2026-72101 2026-08-15
unknown CVE-2026-72104 — In the Linux kernel, the following vulnerability has been resolved: dm-pcache: reject option groups… vulnerability nvd CVE-2026-72104 2026-08-15
unknown CVE-2026-72106 — In the Linux kernel, the following vulnerability has been resolved: dm-ioctl: fix a possible overflo… vulnerability nvd CVE-2026-72106 2026-08-15
unknown CVE-2026-72117 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix data race on rx_st… vulnerability nvd CVE-2026-72117 2026-08-15
unknown CVE-2026-72118 — In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix CAN frame rx/tx st… vulnerability nvd CVE-2026-72118 2026-08-15
unknown CVE-2026-72128 — In the Linux kernel, the following vulnerability has been resolved: nvmet: fix refcount leak in nvme… vulnerability nvd CVE-2026-72128 2026-08-15
unknown CVE-2026-72131 — In the Linux kernel, the following vulnerability has been resolved: nvme-apple: Prevent shared tags… vulnerability nvd CVE-2026-72131 2026-08-15
unknown CVE-2026-72132 — In the Linux kernel, the following vulnerability has been resolved: NFS: Charge unstable writes by r… vulnerability nvd CVE-2026-72132 2026-08-15
unknown CVE-2026-72138 — In the Linux kernel, the following vulnerability has been resolved: xen/gntdev: fix error handling i… vulnerability nvd CVE-2026-72138 2026-08-15
unknown CVE-2026-72140 — In the Linux kernel, the following vulnerability has been resolved: i2c: mlxbf: Fix use-after-free i… vulnerability nvd CVE-2026-72140 2026-08-15
unknown CVE-2026-72145 — In the Linux kernel, the following vulnerability has been resolved: platform/x86/intel/tpmi: use cle… vulnerability nvd CVE-2026-72145 2026-08-15
unknown CVE-2026-72147 — In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma-pcie: Reject… vulnerability nvd CVE-2026-72147 2026-08-15
unknown CVE-2026-72150 — In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix uninitialized xprt_c… vulnerability nvd CVE-2026-72150 2026-08-15
unknown CVE-2026-72152 — In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_tis_spi: Use wait_woken… vulnerability nvd CVE-2026-72152 2026-08-15
unknown CVE-2026-72153 — In the Linux kernel, the following vulnerability has been resolved: irqchip/crossbar: Use correct in… vulnerability nvd CVE-2026-72153 2026-08-15
unknown CVE-2026-72155 — In the Linux kernel, the following vulnerability has been resolved: mtd: spi-nor: swp: Improve locki… vulnerability nvd CVE-2026-72155 2026-08-15
unknown CVE-2026-72156 — In the Linux kernel, the following vulnerability has been resolved: fpga: microchip-spi: fix zero he… vulnerability nvd CVE-2026-72156 2026-08-15
unknown CVE-2026-72158 — In the Linux kernel, the following vulnerability has been resolved: fpga: dfl: add bounds check in d… vulnerability nvd CVE-2026-72158 2026-08-15
unknown CVE-2026-72159 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject non-inline dinodes… vulnerability nvd CVE-2026-72159 2026-08-15
unknown CVE-2026-72161 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: add journal NULL check in… vulnerability nvd CVE-2026-72161 2026-08-15
unknown CVE-2026-72163 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix NULL h_transaction de… vulnerability nvd CVE-2026-72163 2026-08-15
unknown CVE-2026-72166 — In the Linux kernel, the following vulnerability has been resolved: net/9p: fix infinite loop in p9_… vulnerability nvd CVE-2026-72166 2026-08-15
unknown CVE-2026-72167 — In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: pl353: fix probe r… vulnerability nvd CVE-2026-72167 2026-08-15
unknown CVE-2026-72168 — In the Linux kernel, the following vulnerability has been resolved: mtd: maps: vmu-flash: fix fault… vulnerability nvd CVE-2026-72168 2026-08-15
unknown CVE-2026-72169 — In the Linux kernel, the following vulnerability has been resolved: kho: make sure scratch size is a… vulnerability nvd CVE-2026-72169 2026-08-15
unknown CVE-2026-72173 — In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: do not warn on… vulnerability nvd CVE-2026-72173 2026-08-15
unknown CVE-2026-72174 — In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: fix hugetlb se… vulnerability nvd CVE-2026-72174 2026-08-15
unknown CVE-2026-72176 — In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: put stat… vulnerability nvd CVE-2026-72176 2026-08-15
unknown CVE-2026-72177 — In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: fix dir… vulnerability nvd CVE-2026-72177 2026-08-15
unknown CVE-2026-72178 — In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: always put unsucc… vulnerability nvd CVE-2026-72178 2026-08-15
unknown CVE-2026-72179 — In the Linux kernel, the following vulnerability has been resolved: riscv: cacheinfo: Fix node refer… vulnerability nvd CVE-2026-72179 2026-08-15
unknown CVE-2026-72180 — In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: preserve pmd_swp… vulnerability nvd CVE-2026-72180 2026-08-15
unknown CVE-2026-72182 — In the Linux kernel, the following vulnerability has been resolved: power: supply: charger-manager:… vulnerability nvd CVE-2026-72182 2026-08-15
unknown CVE-2026-72184 — In the Linux kernel, the following vulnerability has been resolved: ntfs: fix hole runlist memory le… vulnerability nvd CVE-2026-72184 2026-08-15
unknown CVE-2026-72187 — In the Linux kernel, the following vulnerability has been resolved: ntfs: avoid self-deadlock during… vulnerability nvd CVE-2026-72187 2026-08-15
unknown CVE-2026-72189 — In the Linux kernel, the following vulnerability has been resolved: ntfs: fail attrlist updates when… vulnerability nvd CVE-2026-72189 2026-08-15
unknown CVE-2026-72190 — In the Linux kernel, the following vulnerability has been resolved: ntfs: fix mrec_lock ABBA deadloc… vulnerability nvd CVE-2026-72190 2026-08-15
unknown CVE-2026-72205 — In the Linux kernel, the following vulnerability has been resolved: ntfs: free volume-wide resources… vulnerability nvd CVE-2026-72205 2026-08-15
unknown CVE-2026-72212 — In the Linux kernel, the following vulnerability has been resolved: mm/memory_hotplug: fix incorrect… vulnerability nvd CVE-2026-72212 2026-08-15
unknown CVE-2026-72214 — In the Linux kernel, the following vulnerability has been resolved: power: supply: cpcap-battery: Fi… vulnerability nvd CVE-2026-72214 2026-08-15
unknown CVE-2026-72215 — In the Linux kernel, the following vulnerability has been resolved: MIPS: DEC: Ensure 32-bit stack l… vulnerability nvd CVE-2026-72215 2026-08-15
unknown CVE-2026-72216 — In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom: Fix leak when… vulnerability nvd CVE-2026-72216 2026-08-15
unknown CVE-2026-72218 — In the Linux kernel, the following vulnerability has been resolved: lockd: Plug nlm_file refcount le… vulnerability nvd CVE-2026-72218 2026-08-15
unknown CVE-2026-72219 — In the Linux kernel, the following vulnerability has been resolved: lockd: Plug nlm_file leak when n… vulnerability nvd CVE-2026-72219 2026-08-15
unknown CVE-2026-72223 — In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: Free arena sub-alloc… vulnerability nvd CVE-2026-72223 2026-08-15
unknown CVE-2026-72224 — In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: Free arenas on btt_i… vulnerability nvd CVE-2026-72224 2026-08-15
unknown CVE-2026-72228 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: frag: fix primary_if… vulnerability nvd CVE-2026-72228 2026-08-15
unknown CVE-2026-72229 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: clean untagged VLAN… vulnerability nvd CVE-2026-72229 2026-08-15
unknown CVE-2026-72230 — In the Linux kernel, the following vulnerability has been resolved: batman-adv: frag: free unfragmen… vulnerability nvd CVE-2026-72230 2026-08-15
unknown CVE-2026-72236 — In the Linux kernel, the following vulnerability has been resolved: s390/perf_cpum_cf: Add missing a… vulnerability nvd CVE-2026-72236 2026-08-15
unknown CVE-2026-72237 — In the Linux kernel, the following vulnerability has been resolved: perf/x86/amd/brs: Fix kernel add… vulnerability nvd CVE-2026-72237 2026-08-15
unknown CVE-2026-72238 — In the Linux kernel, the following vulnerability has been resolved: x86/boot: Validate console=uart8… vulnerability nvd CVE-2026-72238 2026-08-15
unknown CVE-2026-72240 — In the Linux kernel, the following vulnerability has been resolved: mfd: sm501: Fix reference leak o… vulnerability nvd CVE-2026-72240 2026-08-15
unknown CVE-2026-72241 — In the Linux kernel, the following vulnerability has been resolved: leds: uleds: Fix potential buffe… vulnerability nvd CVE-2026-72241 2026-08-15
unknown CVE-2026-72245 — In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix device referenc… vulnerability nvd CVE-2026-72245 2026-08-15
unknown CVE-2026-72256 — In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_cluster: reject te… vulnerability nvd CVE-2026-72256 2026-08-15
unknown CVE-2026-72257 — In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: q6apm: fix NULL poin… vulnerability nvd CVE-2026-72257 2026-08-15
unknown CVE-2026-72258 — In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8183: Release… vulnerability nvd CVE-2026-72258 2026-08-15
unknown CVE-2026-72259 — In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8192: Release… vulnerability nvd CVE-2026-72259 2026-08-15
unknown CVE-2026-72260 — In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8192: Check ru… vulnerability nvd CVE-2026-72260 2026-08-15
unknown CVE-2026-72263 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: topology: fix memory… vulnerability nvd CVE-2026-72263 2026-08-15
unknown CVE-2026-72264 — In the Linux kernel, the following vulnerability has been resolved: fbdev: tridentfb: fix potential… vulnerability nvd CVE-2026-72264 2026-08-15
unknown CVE-2026-72265 — In the Linux kernel, the following vulnerability has been resolved: fbdev: nvidia: fix potential mem… vulnerability nvd CVE-2026-72265 2026-08-15
unknown CVE-2026-72266 — In the Linux kernel, the following vulnerability has been resolved: fbdev: vesafb: fix memory leak i… vulnerability nvd CVE-2026-72266 2026-08-15
unknown CVE-2026-72267 — In the Linux kernel, the following vulnerability has been resolved: fbdev: carminefb: fix potential… vulnerability nvd CVE-2026-72267 2026-08-15
unknown CVE-2026-72268 — In the Linux kernel, the following vulnerability has been resolved: fbdev: tdfxfb: fix potential mem… vulnerability nvd CVE-2026-72268 2026-08-15
unknown CVE-2026-72269 — In the Linux kernel, the following vulnerability has been resolved: fbdev: uvesafb: fix potential me… vulnerability nvd CVE-2026-72269 2026-08-15
unknown CVE-2026-72270 — In the Linux kernel, the following vulnerability has been resolved: fbdev: s3fb: fix potential memor… vulnerability nvd CVE-2026-72270 2026-08-15
unknown CVE-2026-72271 — In the Linux kernel, the following vulnerability has been resolved: fbdev: i740fb: fix potential mem… vulnerability nvd CVE-2026-72271 2026-08-15
unknown CVE-2026-72272 — In the Linux kernel, the following vulnerability has been resolved: fbdev: radeon: fix potential mem… vulnerability nvd CVE-2026-72272 2026-08-15
unknown CVE-2026-72273 — In the Linux kernel, the following vulnerability has been resolved: fbdev: efifb: fix memory leak in… vulnerability nvd CVE-2026-72273 2026-08-15
unknown CVE-2026-72274 — In the Linux kernel, the following vulnerability has been resolved: fbdev: hecubafb: fix potential m… vulnerability nvd CVE-2026-72274 2026-08-15
unknown CVE-2026-72275 — In the Linux kernel, the following vulnerability has been resolved: fbdev: broadsheetfb: fix potenti… vulnerability nvd CVE-2026-72275 2026-08-15
unknown CVE-2026-72276 — In the Linux kernel, the following vulnerability has been resolved: fbdev: metronomefb: fix potentia… vulnerability nvd CVE-2026-72276 2026-08-15
unknown CVE-2026-72281 — In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: account pKVM reclaim… vulnerability nvd CVE-2026-72281 2026-08-15
unknown CVE-2026-72290 — In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix GISC refcoun… vulnerability nvd CVE-2026-72290 2026-08-15
unknown CVE-2026-72292 — In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Initialize KVM_S390_G… vulnerability nvd CVE-2026-72292 2026-08-15
unknown CVE-2026-72293 — In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: Add missing rad… vulnerability nvd CVE-2026-72293 2026-08-15
unknown CVE-2026-72300 — In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: topology: validate ve… vulnerability nvd CVE-2026-72300 2026-08-15
unknown CVE-2026-72305 — In the Linux kernel, the following vulnerability has been resolved: VDUSE: avoid leaking information… vulnerability nvd CVE-2026-72305 2026-08-15
unknown CVE-2026-72306 — In the Linux kernel, the following vulnerability has been resolved: vduse: Fix race in vduse_dev_msg… vulnerability nvd CVE-2026-72306 2026-08-15
unknown CVE-2026-72307 — In the Linux kernel, the following vulnerability has been resolved: mlxsw: fix refcount leak in mlxs… vulnerability nvd CVE-2026-72307, CVE-2026-72308 2026-08-15
unknown CVE-2026-72309 — In the Linux kernel, the following vulnerability has been resolved: tracing/remotes: Fix leak in tra… vulnerability nvd CVE-2026-72309 2026-08-15
unknown CVE-2026-72311 — In the Linux kernel, the following vulnerability has been resolved: drm/xe: free madvise VMA array o… vulnerability nvd CVE-2026-72311 2026-08-15
unknown CVE-2026-72316 — In the Linux kernel, the following vulnerability has been resolved: dm era: fix NULL pointer derefer… vulnerability nvd CVE-2026-72316 2026-08-15
unknown CVE-2026-72321 — In the Linux kernel, the following vulnerability has been resolved: ipv4: igmp: Fix potential memory… vulnerability nvd CVE-2026-72321 2026-08-15
unknown CVE-2026-72324 — In the Linux kernel, the following vulnerability has been resolved: gpio: mvebu: free generic chips… vulnerability nvd CVE-2026-72324 2026-08-15
unknown CVE-2026-72325 — In the Linux kernel, the following vulnerability has been resolved: perf/x86/amd/core: Avoid enablin… vulnerability nvd CVE-2026-72325 2026-08-15
unknown CVE-2026-72326 — In the Linux kernel, the following vulnerability has been resolved: net/sched: cake: reject overhead… vulnerability nvd CVE-2026-72326 2026-08-15
unknown CVE-2026-72327 — In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Reject invalid indirect… vulnerability nvd CVE-2026-72327 2026-08-15
unknown CVE-2026-72332 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Prevent PM resume… vulnerability nvd CVE-2026-72332 2026-08-15
unknown CVE-2026-72333 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix tx ident l… vulnerability nvd CVE-2026-72333 2026-08-15
unknown CVE-2026-72336 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: 6lowpan: hold L2CAP c… vulnerability nvd CVE-2026-72336 2026-08-15
unknown CVE-2026-72337 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: 6lowpan: avoid untrac… vulnerability nvd CVE-2026-72337 2026-08-15
unknown CVE-2026-72341 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix publication race… vulnerability nvd CVE-2026-72341 2026-08-15
unknown CVE-2026-72346 — In the Linux kernel, the following vulnerability has been resolved: platform/x86: bitland-mifs-wmi:… vulnerability nvd CVE-2026-72346 2026-08-15
unknown CVE-2026-72349 — In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_rateest: fix u64 t… vulnerability nvd CVE-2026-72349 2026-08-15
unknown CVE-2026-72359 — In the Linux kernel, the following vulnerability has been resolved: drm/xe: fix NPD in bo_meminfo()… vulnerability nvd CVE-2026-72359 2026-08-15
unknown CVE-2026-72361 — In the Linux kernel, the following vulnerability has been resolved: drm/xe/hw_engine: Fix double-fre… vulnerability nvd CVE-2026-72361 2026-08-15
unknown CVE-2026-72362 — In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: Fix NULL pointer dere… vulnerability nvd CVE-2026-72362 2026-08-15
unknown CVE-2026-72363 — In the Linux kernel, the following vulnerability has been resolved: netfs: Fix folio state after ENO… vulnerability nvd CVE-2026-72363 2026-08-15
unknown CVE-2026-72365 — In the Linux kernel, the following vulnerability has been resolved: netfs: Fix writethrough to use c… vulnerability nvd CVE-2026-72365 2026-08-15
unknown CVE-2026-72370 — In the Linux kernel, the following vulnerability has been resolved: iomap: release pages on atomic d… vulnerability nvd CVE-2026-72370 2026-08-15
unknown CVE-2026-72376 — In the Linux kernel, the following vulnerability has been resolved: afs: Fix misplaced inc of net->c… vulnerability nvd CVE-2026-72376 2026-08-15
unknown CVE-2026-72377 — In the Linux kernel, the following vulnerability has been resolved: afs: Remove setting of AS_RELEAS… vulnerability nvd CVE-2026-72377 2026-08-15
unknown CVE-2026-72379 — In the Linux kernel, the following vulnerability has been resolved: fs: refuse O_TMPFILE creation wi… vulnerability nvd CVE-2026-72379 2026-08-15
unknown CVE-2026-72384 — In the Linux kernel, the following vulnerability has been resolved: irqchip/ts4800: Fix missing chai… vulnerability nvd CVE-2026-72384 2026-08-15
unknown CVE-2026-72385 — In the Linux kernel, the following vulnerability has been resolved: tracing/fprobe: Fix NULL pointer… vulnerability nvd CVE-2026-72385 2026-08-15
unknown CVE-2026-72386 — In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix a leak when a g… vulnerability nvd CVE-2026-72386 2026-08-15
unknown CVE-2026-72387 — In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix potential inval… vulnerability nvd CVE-2026-72387 2026-08-15
unknown CVE-2026-72388 — In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Always use the IRQ-… vulnerability nvd CVE-2026-72388 2026-08-15
unknown CVE-2026-72391 — In the Linux kernel, the following vulnerability has been resolved: net: phy: sfp: free mii_bus in s… vulnerability nvd CVE-2026-72391 2026-08-15
unknown CVE-2026-72392 — In the Linux kernel, the following vulnerability has been resolved: ipv6: fib6: fix NULL deref in fi… vulnerability nvd CVE-2026-72392 2026-08-15
unknown CVE-2026-72394 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (aspeed-g6-pwm-tach) Guar… vulnerability nvd CVE-2026-72394 2026-08-15
unknown CVE-2026-72396 — In the Linux kernel, the following vulnerability has been resolved: hwmon: adm1275: Prevent reading… vulnerability nvd CVE-2026-72396 2026-08-15
unknown CVE-2026-72401 — In the Linux kernel, the following vulnerability has been resolved: bpf: Fix insn_aux_data leak on v… vulnerability nvd CVE-2026-72401 2026-08-15
unknown CVE-2026-72402 — In the Linux kernel, the following vulnerability has been resolved: bpf: Mask pseudo pointer values… vulnerability nvd CVE-2026-72402 2026-08-15
unknown CVE-2026-72403 — In the Linux kernel, the following vulnerability has been resolved: ALSA: FCP: Fix NULL pointer dere… vulnerability nvd CVE-2026-72403 2026-08-15
unknown CVE-2026-72413 — In the Linux kernel, the following vulnerability has been resolved: sctp: fix err_chunk memory leaks… vulnerability nvd CVE-2026-72413 2026-08-15
unknown CVE-2026-72414 — In the Linux kernel, the following vulnerability has been resolved: net: dsa: sja1105: round up PTP… vulnerability nvd CVE-2026-72414 2026-08-15
unknown CVE-2026-72424 — In the Linux kernel, the following vulnerability has been resolved: rtc: msc313: fix NULL deref in s… vulnerability nvd CVE-2026-72424 2026-08-15
unknown CVE-2026-72428 — In the Linux kernel, the following vulnerability has been resolved: bpf: Fix stack slot index in nos… vulnerability nvd CVE-2026-72428 2026-08-15
unknown CVE-2026-72430 — In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix nf_connla… vulnerability nvd CVE-2026-72430 2026-08-15
unknown CVE-2026-72431 — In the Linux kernel, the following vulnerability has been resolved: alloc_tag: fix use-after-free in… vulnerability nvd CVE-2026-72431 2026-08-15
unknown CVE-2026-72432 — In the Linux kernel, the following vulnerability has been resolved: tpm_crb: Check ACPI_COMPANION()… vulnerability nvd CVE-2026-72432 2026-08-15
unknown CVE-2026-72433 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_meta_bridge: fix… vulnerability nvd CVE-2026-72433 2026-08-15
unknown CVE-2026-72437 — In the Linux kernel, the following vulnerability has been resolved: md/raid1: free r1_bio when REQ_N… vulnerability nvd CVE-2026-72437 2026-08-15
unknown CVE-2026-72439 — In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix writes_pending le… vulnerability nvd CVE-2026-72439 2026-08-15
unknown CVE-2026-72441 — In the Linux kernel, the following vulnerability has been resolved: ieee802154: fix kernel-infoleak… vulnerability nvd CVE-2026-72441 2026-08-15
unknown CVE-2026-72443 — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Kill MIDI 2.0 U… vulnerability nvd CVE-2026-72443 2026-08-15
unknown CVE-2026-72445 — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: qcom: clear ope… vulnerability nvd CVE-2026-72445 2026-08-15
unknown CVE-2026-72447 — In the Linux kernel, the following vulnerability has been resolved: sctp: hold socket lock when dump… vulnerability nvd CVE-2026-72447 2026-08-15
unknown CVE-2026-72448 — In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix leak of SQ tim… vulnerability nvd CVE-2026-72448 2026-08-15
unknown CVE-2026-72453 — In the Linux kernel, the following vulnerability has been resolved: regcache: Do not overwrite error… vulnerability nvd CVE-2026-72453 2026-08-15
unknown CVE-2026-72456 — In the Linux kernel, the following vulnerability has been resolved: apparmor: release exe file resou… vulnerability nvd CVE-2026-72456 2026-08-15
unknown CVE-2026-72457 — In the Linux kernel, the following vulnerability has been resolved: apparmor: fail policy unpack on… vulnerability nvd CVE-2026-72457 2026-08-15
unknown CVE-2026-72458 — In the Linux kernel, the following vulnerability has been resolved: apparmor: fix NULL pointer deref… vulnerability nvd CVE-2026-72458 2026-08-15
unknown CVE-2026-72467 — In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Check frwr_wp_create()… vulnerability nvd CVE-2026-72467 2026-08-15
unknown CVE-2026-72468 — In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Initialize re_id befor… vulnerability nvd CVE-2026-72468 2026-08-15
unknown CVE-2026-72474 — In the Linux kernel, the following vulnerability has been resolved: dmaengine: dma-axi-dmac: use DMA… vulnerability nvd CVE-2026-72474 2026-08-15
unknown CVE-2026-72475 — In the Linux kernel, the following vulnerability has been resolved: dmaengine: dma-axi-dmac: Properl… vulnerability nvd CVE-2026-72475 2026-08-15
unknown CVE-2026-72479 — In the Linux kernel, the following vulnerability has been resolved: iio: accel: mma8452: handle I2C… vulnerability nvd CVE-2026-72479 2026-08-15
unknown CVE-2026-72481 — In the Linux kernel, the following vulnerability has been resolved: iio: magnetometer: ak8975: fix p… vulnerability nvd CVE-2026-72481 2026-08-15
unknown CVE-2026-72484 — In the Linux kernel, the following vulnerability has been resolved: staging: most: video: avoid doub… vulnerability nvd CVE-2026-72484 2026-08-15
unknown CVE-2026-72486 — In the Linux kernel, the following vulnerability has been resolved: mailbox: mtk-adsp: fix UAF durin… vulnerability nvd CVE-2026-72486 2026-08-15
unknown CVE-2026-72490 — In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix stainfo… vulnerability nvd CVE-2026-72490 2026-08-15
unknown CVE-2026-72501 — In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Initialize dpi var… vulnerability nvd CVE-2026-72501 2026-08-15
unknown CVE-2026-74261 — In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: avoid stale FIFO cell… vulnerability nvd CVE-2026-74261 2026-08-15
unknown CVE-2026-74263 — In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: check skb_clone… vulnerability nvd CVE-2026-74263 2026-08-15
unknown CVE-2026-74265 — In the Linux kernel, the following vulnerability has been resolved: net: mana: initialize gdma queue… vulnerability nvd CVE-2026-74265 2026-08-15
unknown CVE-2026-74271 — In the Linux kernel, the following vulnerability has been resolved: power: supply: core: fix supplie… vulnerability nvd CVE-2026-74271 2026-08-15
unknown CVE-2026-74272 — In the Linux kernel, the following vulnerability has been resolved: cxl/region: Resolve region delet… vulnerability nvd CVE-2026-74272 2026-08-15
unknown CVE-2026-74273 — In the Linux kernel, the following vulnerability has been resolved: cxl/region: Block region delete… vulnerability nvd CVE-2026-74273 2026-08-15
unknown CVE-2026-74274 — In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fill first free targ… vulnerability nvd CVE-2026-74274 2026-08-15
unknown CVE-2026-74276 — In the Linux kernel, the following vulnerability has been resolved: spi: xilinx: use FIFO occupancy… vulnerability nvd CVE-2026-74276 2026-08-15
unknown CVE-2026-74278 — In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: Fix kernel heap addre… vulnerability nvd CVE-2026-74278 2026-08-15
unknown CVE-2026-74284 — In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_hfsc: Don't make… vulnerability nvd CVE-2026-74284 2026-08-15
unknown CVE-2026-74286 — In the Linux kernel, the following vulnerability has been resolved: net: pfcp: allocate per-cpu tsta… vulnerability nvd CVE-2026-74286 2026-08-15
unknown CVE-2026-74290 — In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_flow: Dont expose… vulnerability nvd CVE-2026-74290 2026-08-15
unknown CVE-2026-74291 — In the Linux kernel, the following vulnerability has been resolved: ASoC: topology: Check PCM and DA… vulnerability nvd CVE-2026-74291 2026-08-15
unknown CVE-2026-74298 — In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix FRMR set pinned p… vulnerability nvd CVE-2026-74298 2026-08-15
unknown CVE-2026-74299 — In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix FRMR aging push t… vulnerability nvd CVE-2026-74299 2026-08-15
unknown CVE-2026-74301 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtk: fix URB leak i… vulnerability nvd CVE-2026-74301 2026-08-15
unknown CVE-2026-74303 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_qca: fix NULL poi… vulnerability nvd CVE-2026-74303, CVE-2026-74304 2026-08-15
unknown CVE-2026-74307 — In the Linux kernel, the following vulnerability has been resolved: ext4: validate donor file superb… vulnerability nvd CVE-2026-74307 2026-08-15
unknown CVE-2026-74308 — In the Linux kernel, the following vulnerability has been resolved: ext4: fix kernel BUG in ext4_wri… vulnerability nvd CVE-2026-74308 2026-08-15
unknown CVE-2026-74318 — In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock cloning inli… vulnerability nvd CVE-2026-74318 2026-08-15
unknown CVE-2026-74319 — In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix deadlock waiti… vulnerability nvd CVE-2026-74319 2026-08-15
unknown CVE-2026-74320 — In the Linux kernel, the following vulnerability has been resolved: fbdev: sm501fb: Fix buffer error… vulnerability nvd CVE-2026-74320 2026-08-15
unknown CVE-2026-74324 — In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: validate skb… vulnerability nvd CVE-2026-74324 2026-08-15
unknown CVE-2026-74326 — In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix resource… vulnerability nvd CVE-2026-74326 2026-08-15
unknown CVE-2026-74327 — In the Linux kernel, the following vulnerability has been resolved: vmalloc: fix NULL pointer derefe… vulnerability nvd CVE-2026-74327 2026-08-15
unknown CVE-2026-74329 — In the Linux kernel, the following vulnerability has been resolved: watchdog: unregister PM notifier… vulnerability nvd CVE-2026-74329 2026-08-15
unknown CVE-2026-74331 — In the Linux kernel, the following vulnerability has been resolved: firmware_loader: Fix recursive l… vulnerability nvd CVE-2026-74331 2026-08-15
unknown CVE-2026-74335 — In the Linux kernel, the following vulnerability has been resolved: bpf: Fix NULL pointer dereferenc… vulnerability nvd CVE-2026-74335 2026-08-15
unknown CVE-2026-74336 — In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bound S1G TIM PV… vulnerability nvd CVE-2026-74336 2026-08-15
unknown CVE-2026-74337 — In the Linux kernel, the following vulnerability has been resolved: bpf: Fix NMI/tracepoint re-entry… vulnerability nvd CVE-2026-74337 2026-08-15
unknown CVE-2026-74339 — In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: Clear variable event… vulnerability nvd CVE-2026-74339 2026-08-15
unknown CVE-2026-74342 — In the Linux kernel, the following vulnerability has been resolved: kernfs: link kn to its parent be… vulnerability nvd CVE-2026-74342 2026-08-15
unknown CVE-2026-74346 — In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix OOB read during… vulnerability nvd CVE-2026-74346 2026-08-15
unknown CVE-2026-74348 — In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: require a ref for loc… vulnerability nvd CVE-2026-74348 2026-08-15
unknown CVE-2026-74351 — In the Linux kernel, the following vulnerability has been resolved: ocfs2: rebase copied fsdlm LVB p… vulnerability nvd CVE-2026-74351 2026-08-15
unknown CVE-2026-74352 — In the Linux kernel, the following vulnerability has been resolved: of: reserved_mem: avoid post-ini… vulnerability nvd CVE-2026-74352 2026-08-15
unknown CVE-2026-74353 — In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: always resume_all af… vulnerability nvd CVE-2026-74353 2026-08-15
unknown CVE-2026-74358 — In the Linux kernel, the following vulnerability has been resolved: ext4: fix fast commit wait/wake… vulnerability nvd CVE-2026-74358 2026-08-15
unknown CVE-2026-74360 — In the Linux kernel, the following vulnerability has been resolved: bpf: Reject exclusive maps for b… vulnerability nvd CVE-2026-74360 2026-08-15
unknown CVE-2026-74362 — In the Linux kernel, the following vulnerability has been resolved: ext2: fix ignored return value o… vulnerability nvd CVE-2026-74362 2026-08-15
unknown CVE-2026-74366 — In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix NULL deref in… vulnerability nvd CVE-2026-74366 2026-08-15
unknown CVE-2026-74368 — In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in… vulnerability nvd CVE-2026-74368 2026-08-15
unknown CVE-2026-74369 — In the Linux kernel, the following vulnerability has been resolved: liveupdate: fix u-a-f in luo_fil… vulnerability nvd CVE-2026-74369 2026-08-15
unknown CVE-2026-74370 — In the Linux kernel, the following vulnerability has been resolved: liveupdate: fix TOCTOU race in l… vulnerability nvd CVE-2026-74370 2026-08-15
unknown CVE-2026-74372 — In the Linux kernel, the following vulnerability has been resolved: raid1: fix nr_pending leak in RE… vulnerability nvd CVE-2026-74372 2026-08-15
unknown CVE-2026-74373 — In the Linux kernel, the following vulnerability has been resolved: md/raid1,raid10: fix bio account… vulnerability nvd CVE-2026-74373 2026-08-15
unknown CVE-2026-74375 — In the Linux kernel, the following vulnerability has been resolved: md/raid1,raid10: fix deadlock in… vulnerability nvd CVE-2026-74375 2026-08-15
unknown CVE-2026-74379 — In the Linux kernel, the following vulnerability has been resolved: dax/kmem: account for partial di… vulnerability nvd CVE-2026-74379 2026-08-15
unknown CVE-2026-74381 — In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Allow entries in BO… vulnerability nvd CVE-2026-74381 2026-08-15
unknown CVE-2026-74382 — In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_bpf: prevent unbo… vulnerability nvd CVE-2026-74382 2026-08-15
unknown CVE-2026-74386 — In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix page fragment cac… vulnerability nvd CVE-2026-74386 2026-08-15
unknown CVE-2026-74389 — In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix log flood after cm… vulnerability nvd CVE-2026-74389 2026-08-15
unknown CVE-2026-74391 — In the Linux kernel, the following vulnerability has been resolved: tracing: Bound synthetic-field s… vulnerability nvd CVE-2026-74391 2026-08-15
unknown CVE-2026-74392 — In the Linux kernel, the following vulnerability has been resolved: dm: limit target bio polling to… vulnerability nvd CVE-2026-74392 2026-08-15
unknown CVE-2026-74393 — In the Linux kernel, the following vulnerability has been resolved: drm/syncobj: Fix memory leak in… vulnerability nvd CVE-2026-74393 2026-08-15
unknown CVE-2026-74395 — In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix devx subscribe-ev… vulnerability nvd CVE-2026-74395 2026-08-15
unknown CVE-2026-74399 — In the Linux kernel, the following vulnerability has been resolved: evm: terminate and bound the evm… vulnerability nvd CVE-2026-74399 2026-08-15
unknown CVE-2026-74400 — In the Linux kernel, the following vulnerability has been resolved: bpf: fix crash in bpf_[set|remov… vulnerability nvd CVE-2026-74400 2026-08-15
unknown CVE-2026-74402 — In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-sha204a - fix bloc… vulnerability nvd CVE-2026-74402 2026-08-15
unknown CVE-2026-74414 — In the Linux kernel, the following vulnerability has been resolved: hfsplus: Remove the duplicate at… vulnerability nvd CVE-2026-74414 2026-08-15
unknown CVE-2026-74415 — In the Linux kernel, the following vulnerability has been resolved: spi: atcspi200: fix use-after-fr… vulnerability nvd CVE-2026-74415 2026-08-15
unknown CVE-2026-74416 — In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix memory leak in r… vulnerability nvd CVE-2026-74416 2026-08-15
unknown CVE-2026-74418 — In the Linux kernel, the following vulnerability has been resolved: dma-fence: Fix potential tracepo… vulnerability nvd CVE-2026-74418 2026-08-15
unknown CVE-2026-74420 — In the Linux kernel, the following vulnerability has been resolved: drm/gpusvm: Reject VMAs with VM_… vulnerability nvd CVE-2026-74420 2026-08-15
unknown CVE-2026-74421 — In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: dw_dp: Switch to d… vulnerability nvd CVE-2026-74421 2026-08-15
unknown CVE-2026-74422 — In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: inno-hdmi: Switch… vulnerability nvd CVE-2026-74422 2026-08-15
unknown CVE-2026-74423 — In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix leak when pin… vulnerability nvd CVE-2026-74423 2026-08-15
unknown CVE-2026-74426 — In the Linux kernel, the following vulnerability has been resolved: afs: fix NULL pointer dereferenc… vulnerability nvd CVE-2026-74426 2026-08-15
unknown CVE-2026-74432 — In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix leak of released call… vulnerability nvd CVE-2026-74432 2026-08-15
unknown CVE-2026-74437 — In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix deadlock if… vulnerability nvd CVE-2026-74437 2026-08-15
unknown CVE-2026-74441 — In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Fix race condi… vulnerability nvd CVE-2026-74441 2026-08-15
unknown CVE-2026-74442 — In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: avoid destroy_workqu… vulnerability nvd CVE-2026-74442 2026-08-15
unknown CVE-2026-74445 — In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: reject DX_BIND_QUERY… vulnerability nvd CVE-2026-74445 2026-08-15
unknown CVE-2026-74448 — In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix QID bit leak in… vulnerability nvd CVE-2026-74448 2026-08-15
unknown CVE-2026-74455 — In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: validate uCAN rec… vulnerability nvd CVE-2026-74455 2026-08-15
unknown CVE-2026-74457 — In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: add bounds check… vulnerability nvd CVE-2026-74457 2026-08-15
unknown CVE-2026-74458 — In the Linux kernel, the following vulnerability has been resolved: can: kvaser_usb_leaf: kvaser_usb… vulnerability nvd CVE-2026-74458 2026-08-15
unknown CVE-2026-74459 — In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_read_bulk… vulnerability nvd CVE-2026-74459 2026-08-15
unknown CVE-2026-74460 — In the Linux kernel, the following vulnerability has been resolved: can: ems_usb: validate CPC messa… vulnerability nvd CVE-2026-74460 2026-08-15
unknown CVE-2026-74462 — In the Linux kernel, the following vulnerability has been resolved: i2c: imx: mark I2C adapter when… vulnerability nvd CVE-2026-74462 2026-08-15
unknown CVE-2026-74463 — In the Linux kernel, the following vulnerability has been resolved: i2c: jz4780: Cache host clock ra… vulnerability nvd CVE-2026-74463 2026-08-15
unknown CVE-2026-74464 — In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix skb leak o… vulnerability nvd CVE-2026-74464 2026-08-15
unknown CVE-2026-74466 — In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Close speculative m… vulnerability nvd CVE-2026-74466 2026-08-15
unknown CVE-2026-74468 — In the Linux kernel, the following vulnerability has been resolved: gpio: pch: use raw_spinlock_t fo… vulnerability nvd CVE-2026-74468 2026-08-15
unknown CVE-2026-74472 — In the Linux kernel, the following vulnerability has been resolved: ublk: reset kernel-owned dev_inf… vulnerability nvd CVE-2026-74472 2026-08-15
unknown CVE-2026-74477 — In the Linux kernel, the following vulnerability has been resolved: uprobes: Fix NULL pointer derefe… vulnerability nvd CVE-2026-74477 2026-08-15
unknown CVE-2026-74483 — In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: don't leak the user… vulnerability nvd CVE-2026-74483 2026-08-15
unknown CVE-2026-74484 — In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: don't let an 'F' en… vulnerability nvd CVE-2026-74484 2026-08-15
unknown CVE-2026-74487 — In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: restore write acces… vulnerability nvd CVE-2026-74487 2026-08-15
unknown CVE-2026-74491 — In the Linux kernel, the following vulnerability has been resolved: of/address: Fix NULL bus derefer… vulnerability nvd CVE-2026-74491 2026-08-15
unknown CVE-2026-74494 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject repeated SMB2 NEGO… vulnerability nvd CVE-2026-74494 2026-08-15
unknown CVE-2026-74498 — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix DMA buffer… vulnerability nvd CVE-2026-74498 2026-08-15
unknown CVE-2026-74499 — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write i… vulnerability nvd CVE-2026-74499 2026-08-15
unknown CVE-2026-74500 — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix stack info… vulnerability nvd CVE-2026-74500 2026-08-15
unknown CVE-2026-74501 — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix use-after-f… vulnerability nvd CVE-2026-74501 2026-08-15
unknown CVE-2026-74502 — In the Linux kernel, the following vulnerability has been resolved: ALSA: ump: fix double free of ou… vulnerability nvd CVE-2026-74502 2026-08-15
unknown CVE-2026-74504 — In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: Fix division by zero… vulnerability nvd CVE-2026-74504 2026-08-15
unknown CVE-2026-74505 — In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire: Fix UAF at error ha… vulnerability nvd CVE-2026-74505 2026-08-15
unknown CVE-2026-74514 — In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix memory accou… vulnerability nvd CVE-2026-74514 2026-08-15
unknown CVE-2026-74524 — In the Linux kernel, the following vulnerability has been resolved: riscv: mm: Fix out-of-bounds pag… vulnerability nvd CVE-2026-74524 2026-08-15
unknown CVE-2026-74525 — In the Linux kernel, the following vulnerability has been resolved: net: sxgbe: free TX rings on RX… vulnerability nvd CVE-2026-74525 2026-08-15
unknown CVE-2026-74526 — In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix potential dead… vulnerability nvd CVE-2026-74526 2026-08-15
unknown CVE-2026-74532 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: Validate len… vulnerability nvd CVE-2026-74532 2026-08-15
unknown CVE-2026-74536 — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix leaking sk a… vulnerability nvd CVE-2026-74536 2026-08-15
unknown CVE-2026-74542 — In the Linux kernel, the following vulnerability has been resolved: netfs: Fix folio_queue ENOMEM in… vulnerability nvd CVE-2026-74542 2026-08-15
unknown CVE-2026-74543 — In the Linux kernel, the following vulnerability has been resolved: net: udp_tunnel: fix memory leak… vulnerability nvd CVE-2026-74543 2026-08-15
unknown CVE-2026-74546 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (adt7470) Fix divide-by-z… vulnerability nvd CVE-2026-74546 2026-08-15
unknown CVE-2026-74547 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (adt7470) Fix busy-loop a… vulnerability nvd CVE-2026-74547 2026-08-15
unknown CVE-2026-74552 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Only report alarms… vulnerability nvd CVE-2026-74552 2026-08-15
unknown CVE-2026-74553 — In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct6775-core) Fix number… vulnerability nvd CVE-2026-74553 2026-08-15
unknown CVE-2026-74555 — In the Linux kernel, the following vulnerability has been resolved: scsi: libsas: Fix HA resume dead… vulnerability nvd CVE-2026-74555 2026-08-15
unknown CVE-2026-74558 — In the Linux kernel, the following vulnerability has been resolved: xsk: reclaim invalid Tx descript… vulnerability nvd CVE-2026-74558 2026-08-15
unknown CVE-2026-74559 — In the Linux kernel, the following vulnerability has been resolved: xsk: drain continuation descs af… vulnerability nvd CVE-2026-74559 2026-08-15
unknown CVE-2026-74566 — In the Linux kernel, the following vulnerability has been resolved: keys: make keyring key-chunk byt… vulnerability nvd CVE-2026-74566 2026-08-15
unknown CVE-2026-74571 — In the Linux kernel, the following vulnerability has been resolved: btrfs: skip global block reserve… vulnerability nvd CVE-2026-74571 2026-08-15
unknown CVE-2026-74577 — In the Linux kernel, the following vulnerability has been resolved: net: mpls: initialize rtm_tos in… vulnerability nvd CVE-2026-74577 2026-08-15
unknown CVE-2026-74764 — Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When pr… vulnerability nvd CVE-2026-74764 2026-08-15
unknown CVE-2026-74767 — Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) fi… vulnerability nvd CVE-2026-74767 2026-08-15
unknown CVE-2026-74251 — Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0… vulnerability nvd CVE-2026-74251 2026-08-16
unknown CVE-2026-74784 — Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that… vulnerability nvd CVE-2026-74784 2026-08-16
unknown CVE-2026-50601 — A security vulnerability has been identified in the Planet9 desktop application where a hardcoded re… vulnerability nvd CVE-2026-50601 2026-08-17
unknown CVE-2026-50602 — A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned t… vulnerability nvd CVE-2026-50602 2026-08-17
unknown CVE-2026-74579 — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: fix mask… vulnerability nvd CVE-2026-74579 2026-08-17
unknown CVE-2026-15623 — A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chroni… vulnerability nvd CVE-2026-15623 2026-08-17
unknown CVE-2026-22072 — Loading arbitrary external URLs through WebView components introduces malicious JS code that can ste… vulnerability nvd CVE-2026-22072 2026-08-17
unknown CVE-2026-40126 — OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be… vulnerability nvd CVE-2026-40126 2026-08-17
unknown CVE-2026-18674 — On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attribu… vulnerability nvd CVE-2026-18674 2026-08-17
unknown CVE-2026-13202 — A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue a… vulnerability nvd CVE-2026-13202 2026-08-17
unknown CVE-2026-73851 — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who co… vulnerability nvd CVE-2026-73851 2026-08-17
unknown CVE-2025-27621 — UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.… vulnerability nvd CVE-2025-27621, CVE-2025-27770, CVE-2025-27771, CVE-2025-27772 2026-08-17
unknown CVE-2026-40144 — A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privileg… vulnerability nvd CVE-2026-40144 2026-08-17
unknown CVE-2026-40145 — A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deploymen… vulnerability nvd CVE-2026-40145 2026-08-17
unknown CVE-2026-61666 — websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driv… vulnerability nvd CVE-2026-61666 2026-08-17
unknown CVE-2026-68518 — Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_… vulnerability nvd CVE-2026-68518 2026-08-17
unknown CVE-2026-54284 — sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction an… vulnerability nvd CVE-2026-54284 2026-08-17
unknown CVE-2026-59894 — sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.p… vulnerability nvd CVE-2026-59894 2026-08-17
unknown CVE-2026-68519 — Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run(… vulnerability nvd CVE-2026-68519 2026-08-17
unknown CVE-2026-71491 — sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlpars… vulnerability nvd CVE-2026-71491 2026-08-17
unknown CVE-2026-74254 — Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Pag… vulnerability nvd CVE-2026-74254 2026-08-17
unknown CVE-2026-12553 — HP has identified a potential vulnerability in HP Web Jetadmin (WJA) that may allow an unauthenticat… vulnerability nvd CVE-2026-12553 2026-08-17
unknown CVE-2026-17639 — Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condi… vulnerability nvd CVE-2026-17639 2026-08-17
unknown CVE-2026-71693 — Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by… vulnerability nvd CVE-2026-71693 2026-08-17
unknown CVE-2026-52886 — Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the back… vulnerability nvd CVE-2026-52886 2026-08-17
unknown CVE-2026-71553 — ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api… vulnerability nvd CVE-2026-71553 2026-08-17
unknown CVE-2026-71858 — Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attack… vulnerability nvd CVE-2026-71858 2026-08-17
unknown CVE-2026-35219 — Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/s… vulnerability nvd CVE-2026-35219 2026-08-17
unknown CVE-2026-47683 — vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in l… vulnerability nvd CVE-2026-47683 2026-08-17
unknown CVE-2026-75529 — Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality… vulnerability nvd CVE-2026-75529 2026-08-17
unknown CVE-2026-75531 — Pandora contains a stored cross-site scripting (XSS) vulnerability in the rendering of URL observabl… vulnerability nvd CVE-2026-75531 2026-08-17
unknown CVE-2026-11817 — This vulnerability only affects Grafana stacks configured with multiple organizations; single-organi… vulnerability nvd CVE-2026-11817 2026-08-17
unknown CVE-2026-43971 — Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directi… vulnerability nvd CVE-2026-43971 2026-08-18
unknown CVE-2026-18929 — Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processi… vulnerability nvd CVE-2026-18929 2026-08-18
unknown CVE-2026-75838 — DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where… vulnerability nvd CVE-2026-75838 2026-08-18
unknown CVE-2026-18751 — External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue aff… vulnerability nvd CVE-2026-18751 2026-08-18
unknown CVE-2026-1199 — Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests… vulnerability nvd CVE-2026-1199 2026-08-18
unknown CVE-2026-23922 — The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak… vulnerability nvd CVE-2026-23922 2026-08-18
unknown CVE-2026-23929 — Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps.… vulnerability nvd CVE-2026-23929 2026-08-18
unknown CVE-2026-23930 — An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by send… vulnerability nvd CVE-2026-23930 2026-08-18
unknown CVE-2026-23931 — The frontend validatate.api.exists action can be exploited by authenticated users to extract plainte… vulnerability nvd CVE-2026-23931 2026-08-18
unknown CVE-2026-23933 — In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written… vulnerability nvd CVE-2026-23933 2026-08-18
unknown CVE-2026-23934 — An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sendin… vulnerability nvd CVE-2026-23934 2026-08-18
unknown CVE-2026-23935 — A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/prepr… vulnerability nvd CVE-2026-23935 2026-08-18
unknown CVE-2026-23937 — The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key l… vulnerability nvd CVE-2026-23937 2026-08-18
unknown CVE-2026-23938 — An authenticated administrator is able to crash Zabbix server or proxy by creating specifically craf… vulnerability nvd CVE-2026-23938 2026-08-18
unknown CVE-2026-45532 — DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a pa… vulnerability nvd CVE-2026-45532 2026-08-18
unknown CVE-2026-59781 — When Zabbix Agent was installed on Windows into a custom installation directory, the installer did n… vulnerability nvd CVE-2026-59781 2026-08-18
unknown CVE-2026-74934 — Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox… vulnerability nvd CVE-2026-74934 2026-08-18
unknown CVE-2026-74945 — Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154,… vulnerability nvd CVE-2026-74945 2026-08-18
unknown CVE-2026-74948 — Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firef… vulnerability nvd CVE-2026-74948 2026-08-18
unknown CVE-2026-74957 — Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firef… vulnerability nvd CVE-2026-74957 2026-08-18
unknown CVE-2026-74959 — Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154,… vulnerability nvd CVE-2026-74959 2026-08-18
unknown CVE-2026-74960 — Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Fi… vulnerability nvd CVE-2026-74960 2026-08-18
unknown CVE-2026-17084 — The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the lat… vulnerability nvd CVE-2026-17084 2026-08-18
unknown CVE-2026-68939 — Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-… vulnerability nvd CVE-2026-68939 2026-08-18
unknown CVE-2026-71539 — n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git n… vulnerability nvd CVE-2026-71539 2026-08-18
unknown CVE-2026-75872 — HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticat… vulnerability nvd CVE-2026-75872 2026-08-18
unknown CVE-2026-75890 — Rejected reason: Duplicate of CVE-2026-50236. This CVE ID was reserved in error for a finding that a… vulnerability nvd CVE-2026-75890 2026-08-18
unknown CVE-2026-15806 — The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWit… vulnerability nvd CVE-2026-15806 2026-08-18
unknown CVE-2026-19501 — CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize sprea… vulnerability nvd CVE-2026-19501 2026-08-18
unknown CVE-2026-62357 — Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.IN… vulnerability nvd CVE-2026-62357 2026-08-18
unknown CVE-2026-63328 — Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager… vulnerability nvd CVE-2026-63328 2026-08-18
unknown CVE-2026-71574 — Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.… vulnerability nvd CVE-2026-71574 2026-08-18
unknown CVE-2026-72532 — Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.… vulnerability nvd CVE-2026-72532 2026-08-18
unknown CVE-2026-73073 — Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autol… vulnerability nvd CVE-2026-73073 2026-08-18
unknown CVE-2026-73337 — Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insuff… vulnerability nvd CVE-2026-73337 2026-08-18
unknown CVE-2026-73371 — Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-… vulnerability nvd CVE-2026-73371 2026-08-18
unknown CVE-2026-73373 — Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 -… vulnerability nvd CVE-2026-73373 2026-08-18
unknown CVE-2026-19869 — @neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication ru… vulnerability nvd CVE-2026-19869 2026-08-18
unknown CVE-2026-54730 — authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google… vulnerability nvd CVE-2026-54730 2026-08-18
unknown CVE-2026-57580 — authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Sourc… vulnerability nvd CVE-2026-57580 2026-08-18
unknown CVE-2026-61634 — The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact w… vulnerability nvd CVE-2026-61634, CVE-2026-63335, CVE-2026-63336, CVE-2026-63337, CVE-2026-69219, CVE-2026-69220 2026-08-18
unknown CVE-2026-71572 — Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0… vulnerability nvd CVE-2026-71572 2026-08-18
unknown CVE-2026-71573 — Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An… vulnerability nvd CVE-2026-71573 2026-08-18
unknown CVE-2026-72531 — Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0… vulnerability nvd CVE-2026-72531 2026-08-18
unknown CVE-2026-73336 — Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Impr… vulnerability nvd CVE-2026-73336 2026-08-18
unknown CVE-2026-73372 — Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1… vulnerability nvd CVE-2026-73372 2026-08-18
unknown CVE-2026-18392 — Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in… vulnerability nvd CVE-2026-18392 2026-08-18
unknown CVE-2026-50161 — libre is a generic library for real-time communications with asynchronous input and output support.… vulnerability nvd CVE-2026-50161 2026-08-18
unknown CVE-2026-50167 — Kurrier is a modern, self-hosted workspace for email, calendar, contacts, and storage. Prior to 1.2.… vulnerability nvd CVE-2026-50167 2026-08-18
unknown CVE-2026-53533 — aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rc… vulnerability nvd CVE-2026-53533 2026-08-18
unknown CVE-2026-63641 — MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies i… vulnerability nvd CVE-2026-63641 2026-08-18
unknown CVE-2026-63642 — MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in de… vulnerability nvd CVE-2026-63642 2026-08-18
unknown CVE-2026-63643 — MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR hand… vulnerability nvd CVE-2026-63643 2026-08-18
unknown CVE-2026-67846 — Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a pote… vulnerability nvd CVE-2026-67846 2026-08-18
unknown CVE-2026-71878 — Missing authentication in initial setup functionality left exposed after initial setup is completed… vulnerability nvd CVE-2026-71878 2026-08-18
unknown CVE-2026-71879 — Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integr… vulnerability nvd CVE-2026-71879 2026-08-18
unknown CVE-2026-71880 — Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions… vulnerability nvd CVE-2026-71880 2026-08-18
unknown CVE-2026-17106 — The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and th… vulnerability nvd CVE-2026-17106 2026-08-18
unknown CVE-2026-52735 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd… vulnerability nvd CVE-2026-52735 2026-08-18
unknown CVE-2026-52736 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer ca… vulnerability nvd CVE-2026-52736 2026-08-18
unknown CVE-2026-52738 — ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a consensus-valid block containing a… vulnerability nvd CVE-2026-52738 2026-08-18
unknown CVE-2026-53453 — Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.… vulnerability nvd CVE-2026-53453, CVE-2026-53454, CVE-2026-53455, CVE-2026-53456, CVE-2026-53457, CVE-2026-53458 2026-08-18
unknown CVE-2026-56867 — Rejected reason: reserved but not needed vulnerability nvd CVE-2026-56867, CVE-2026-56868, CVE-2026-56869, CVE-2026-56870, CVE-2026-56871, CVE-2026-56872, CVE-2026-56873, CVE-2026-56874 2026-08-18
unknown CVE-2026-21580 — This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vul… vulnerability nvd CVE-2026-21580 2026-08-18
unknown CVE-2026-21582 — This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026… vulnerability nvd CVE-2026-21582 2026-08-18
unknown CVE-2026-21584 — This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 1… vulnerability nvd CVE-2026-21584 2026-08-18
unknown CVE-2026-62292 — libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted unco… vulnerability nvd CVE-2026-62292 2026-08-18
unknown CVE-2026-11751 — A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS… vulnerability nvd CVE-2026-11751 2026-08-19
unknown CVE-2026-66358 — A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an a… vulnerability nvd CVE-2026-66358 2026-08-19
unknown CVE-2026-70408 — An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-… vulnerability nvd CVE-2026-70408 2026-08-19
unknown CVE-2026-49421 — The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH fl… vulnerability nvd CVE-2026-49421 2026-08-19
unknown CVE-2026-49426 — When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of… vulnerability nvd CVE-2026-49426 2026-08-19
unknown CVE-2026-49430 — The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a… vulnerability nvd CVE-2026-49430 2026-08-19
unknown CVE-2026-49431 — The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an… vulnerability nvd CVE-2026-49431 2026-08-19
unknown CVE-2026-49423 — When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremen… vulnerability nvd CVE-2026-49423 2026-08-19
unknown CVE-2026-49424 — The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux… vulnerability nvd CVE-2026-49424 2026-08-19
unknown CVE-2026-49425 — The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct… vulnerability nvd CVE-2026-49425 2026-08-19
unknown CVE-2026-58081 — Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the… vulnerability nvd CVE-2026-58081 2026-08-19
unknown CVE-2026-58082 — The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate char… vulnerability nvd CVE-2026-58082 2026-08-19
unknown CVE-2026-58084 — To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the curren… vulnerability nvd CVE-2026-58084 2026-08-19
unknown CVE-2026-58086 — As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was always denied to a jailed… vulnerability nvd CVE-2026-58086 2026-08-19
unknown CVE-2026-72889 — Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verif… vulnerability nvd CVE-2026-72889 2026-08-19
unknown CVE-2026-75589 — Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with… vulnerability nvd CVE-2026-75589 2026-08-19
unknown CVE-2026-76164 — AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission… vulnerability nvd CVE-2026-76164 2026-08-19
unknown CVE-2026-16440 — In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations causes a… vulnerability nvd CVE-2026-16440 2026-08-19
unknown CVE-2026-19489 — Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.3… vulnerability nvd CVE-2026-19489, CVE-2026-19490 2026-08-19
unknown CVE-2026-67363 — Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The… vulnerability nvd CVE-2026-67363 2026-08-19
unknown CVE-2026-67364 — Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / C… vulnerability nvd CVE-2026-67364 2026-08-19
unknown CVE-2026-50719 — The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-cont… vulnerability nvd CVE-2026-50719 2026-08-19
unknown CVE-2026-50720 — The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the… vulnerability nvd CVE-2026-50720 2026-08-19
unknown CVE-2026-51366 — SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to… vulnerability nvd CVE-2026-51366 2026-08-19
unknown CVE-2026-51367 — An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive i… vulnerability nvd CVE-2026-51367 2026-08-19
unknown CVE-2026-65609 — nnn is vulnerable to Out-of-Bound write vulnerability. Due to lack of validation of attacker-control… vulnerability nvd CVE-2026-65609 2026-08-19
unknown CVE-2026-65610 — nnn stores homelen variable as uchar_t, which can only represent values in the range 0-255. An attac… vulnerability nvd CVE-2026-65610 2026-08-19
unknown CVE-2026-65611 — nnn does not sanitize the path variable. An attacker can create a directory on a shared filesystem,… vulnerability nvd CVE-2026-65611 2026-08-19
unknown CVE-2026-65612 — nnn does not sanitize the filename variable. An attacker can place a file with a crafted name on a s… vulnerability nvd CVE-2026-65612 2026-08-19
unknown CVE-2026-71694 — An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b456321217521… vulnerability nvd CVE-2026-71694 2026-08-19
unknown CVE-2026-74803 — Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image… vulnerability nvd CVE-2026-74803 2026-08-19
unknown CVE-2026-74804 — Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo… vulnerability nvd CVE-2026-74804 2026-08-19
unknown CVE-2026-75114 — Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo <… vulnerability nvd CVE-2026-75114 2026-08-19
unknown CVE-2026-76236 — stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw i… vulnerability nvd CVE-2026-76236 2026-08-19
unknown CVE-2026-76237 — stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulner… vulnerability nvd CVE-2026-76237 2026-08-19
unknown CVE-2026-76238 — stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the de… vulnerability nvd CVE-2026-76238 2026-08-19
unknown CVE-2026-76240 — stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defen… vulnerability nvd CVE-2026-76240 2026-08-19
unknown CVE-2026-76241 — stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration f… vulnerability nvd CVE-2026-76241 2026-08-19
unknown CVE-2026-76242 — stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separat… vulnerability nvd CVE-2026-76242 2026-08-19
unknown CVE-2026-76243 — stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-… vulnerability nvd CVE-2026-76243 2026-08-19
unknown CVE-2026-76244 — stigmem-node contains an insecure default configuration vulnerability that allows federation traffic… vulnerability nvd CVE-2026-76244 2026-08-19
unknown CVE-2026-76245 — stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federat… vulnerability nvd CVE-2026-76245 2026-08-19
unknown CVE-2026-18526 — HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerabi… vulnerability nvd CVE-2026-18526 2026-08-19
unknown CVE-2026-18756 — HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space… vulnerability nvd CVE-2026-18756 2026-08-19
unknown CVE-2026-45272 — MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook.… vulnerability nvd CVE-2026-45272 2026-08-19
unknown CVE-2026-45273 — MyBooks is an ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSe… vulnerability nvd CVE-2026-45273 2026-08-19
unknown CVE-2026-45274 — MyBooks is anebook management web server also known as Talebook. In 3.41.2 and earlier, the SignUp.p… vulnerability nvd CVE-2026-45274 2026-08-19
unknown CVE-2026-52792 — Algernon is a small self-contained pure-Go web server. Prior to 1.17.9, Algernon on Windows selects… vulnerability nvd CVE-2026-52792 2026-08-19
unknown CVE-2026-75949 — Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDi… vulnerability nvd CVE-2026-75949 2026-08-19
unknown CVE-2026-75950 — Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory… vulnerability nvd CVE-2026-75950 2026-08-19
unknown CVE-2026-75951 — Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions)… vulnerability nvd CVE-2026-75951 2026-08-19
unknown CVE-2026-75952 — Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Token… vulnerability nvd CVE-2026-75952 2026-08-19
unknown CVE-2026-75953 — Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient addres… vulnerability nvd CVE-2026-75953 2026-08-19
unknown CVE-2026-75954 — Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Se… vulnerability nvd CVE-2026-75954 2026-08-19
unknown CVE-2026-75955 — Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - co… vulnerability nvd CVE-2026-75955 2026-08-19
unknown CVE-2026-75956 — Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirector… vulnerability nvd CVE-2026-75956 2026-08-19
unknown CVE-2026-76203 — Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer… vulnerability nvd CVE-2026-76203 2026-08-19
unknown CVE-2026-18430 — HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notificat… vulnerability nvd CVE-2026-18430 2026-08-19
unknown CVE-2026-19672 — The tarfile module's tar and data extraction filters created directories outside the destination for… vulnerability nvd CVE-2026-19672 2026-08-19
unknown CVE-2026-62672 — Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and func… vulnerability nvd CVE-2026-62672 2026-08-19
unknown CVE-2026-62673 — Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess… vulnerability nvd CVE-2026-62673 2026-08-19
unknown CVE-2026-64850 — Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/… vulnerability nvd CVE-2026-64850 2026-08-19
unknown CVE-2026-64851 — Grav Shortcode Core Plugin allows for the development shortcode plugins that utilize the common form… vulnerability nvd CVE-2026-64851 2026-08-19
unknown CVE-2026-50173 — Flow-Like is a platform for building end-to-end use cases. Prior to version 1.0.4, `GET /api/v1/apps… vulnerability nvd CVE-2026-50173 2026-08-19
unknown CVE-2025-14600 — An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized ad… vulnerability nvd CVE-2025-14600 2026-08-19
unknown CVE-2025-14603 — The application component processes user-supplied parameters insecurely, passing them into SQL queri… vulnerability nvd CVE-2025-14603 2026-08-19
unknown CVE-2026-55191 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients th… vulnerability nvd CVE-2026-55191 2026-08-19
unknown CVE-2026-55192 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP H.264 deco… vulnerability nvd CVE-2026-55192 2026-08-19
unknown CVE-2026-55193 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients us… vulnerability nvd CVE-2026-55193 2026-08-19
unknown CVE-2026-55194 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fr… vulnerability nvd CVE-2026-55194 2026-08-19
unknown CVE-2026-55648 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy… vulnerability nvd CVE-2026-55648 2026-08-19
unknown CVE-2026-63633 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode… vulnerability nvd CVE-2026-63633 2026-08-19
unknown CVE-2026-63652 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv… vulnerability nvd CVE-2026-63652 2026-08-19
unknown CVE-2026-73541 — Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote… vulnerability nvd CVE-2026-73541 2026-08-19
unknown CVE-2026-19198 — Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common BulkAc… vulnerability nvd CVE-2026-19198 2026-08-19
unknown CVE-2026-55483 — Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.… vulnerability nvd CVE-2026-55483 2026-08-19
unknown CVE-2026-55643 — Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS flo… vulnerability nvd CVE-2026-55643 2026-08-19
unknown CVE-2026-55694 — Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /ap… vulnerability nvd CVE-2026-55694 2026-08-19
unknown CVE-2026-61807 — Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier… vulnerability nvd CVE-2026-61807 2026-08-19
unknown CVE-2026-75618 — Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker… vulnerability nvd CVE-2026-75618 2026-08-19
unknown CVE-2026-75619 — Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authen… vulnerability nvd CVE-2026-75619 2026-08-19
unknown CVE-2026-17590 — Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-32475. Reason:… vulnerability nvd CVE-2026-17590 2026-08-19
unknown CVE-2026-19505 — Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirks… vulnerability nvd CVE-2026-19505 2026-08-19
unknown CVE-2026-19506 — Race condition in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attack… vulnerability nvd CVE-2026-19506 2026-08-19
unknown CVE-2026-19507 — Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` all… vulnerability nvd CVE-2026-19507 2026-08-19
unknown CVE-2026-19508 — Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-20… vulnerability nvd CVE-2026-19508 2026-08-19
unknown CVE-2026-19509 — Improper input validation in `ajaxSet_wireless_network_configuration.jst` in RDK-B WebUI `rdkb-2025q… vulnerability nvd CVE-2026-19509 2026-08-19
unknown CVE-2026-54742 — Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.2… vulnerability nvd CVE-2026-54742 2026-08-19
unknown CVE-2026-55090 — Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/Exp… vulnerability nvd CVE-2026-55090 2026-08-19
unknown CVE-2026-61711 — BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and… vulnerability nvd CVE-2026-61711, CVE-2026-61712, CVE-2026-75593 2026-08-19
unknown CVE-2026-63188 — Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto… vulnerability nvd CVE-2026-63188 2026-08-19
unknown CVE-2026-68560 — Wekan is open source kanban built with Meteor. Prior to 9.75, models/fileValidation.js interpolated… vulnerability nvd CVE-2026-68560 2026-08-19
unknown CVE-2026-75112 — A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insuf… vulnerability nvd CVE-2026-75112 2026-08-19
unknown CVE-2026-76647 — Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JS… vulnerability nvd CVE-2026-76647 2026-08-19
unknown CVE-2026-54741 — Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, Lemmy b… vulnerability nvd CVE-2026-54741 2026-08-19
unknown CVE-2026-54743 — Lemmy is a link aggregator and forum for the fediverse. Prior to lemmy-ui 0.19.19-beta.1, LemmyNet/l… vulnerability nvd CVE-2026-54743 2026-08-19
unknown CVE-2026-61556 — LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. From 10.26.0 unt… vulnerability nvd CVE-2026-61556 2026-08-19
unknown CVE-2026-68554 — Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path att… vulnerability nvd CVE-2026-68554 2026-08-19
unknown CVE-2026-75595 — Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.… vulnerability nvd CVE-2026-75595 2026-08-19
unknown CVE-2026-76878 — In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects q… vulnerability nvd CVE-2026-76878 2026-08-19
unknown CVE-2026-8619 — An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150… vulnerability nvd CVE-2026-8619 2026-08-20
unknown CVE-2026-75628 — Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login be… vulnerability nvd CVE-2026-75628 2026-08-20
unknown CVE-2025-14602 — The application generates uploaded file names using a weak and predictable method based on the reque… vulnerability nvd CVE-2025-14602 2026-08-20
unknown CVE-2026-14163 — In affected versions of Octopus Server under certain circumstances it is possible for sensitive vari… vulnerability nvd CVE-2026-14163 2026-08-20
unknown CVE-2026-71368 — F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged… vulnerability nvd CVE-2026-71368 2026-08-20
unknown CVE-2025-14601 — An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative… vulnerability nvd CVE-2025-14601 2026-08-20
unknown CVE-2026-75948 — Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The fronten… vulnerability nvd CVE-2026-75948 2026-08-20
unknown CVE-2026-76564 — Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0… vulnerability nvd CVE-2026-76564 2026-08-20
unknown CVE-2026-76565 — Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Car… vulnerability nvd CVE-2026-76565 2026-08-20
unknown CVE-2026-76569 — Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1… vulnerability nvd CVE-2026-76569 2026-08-20
unknown CVE-2026-76610 — Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment co… vulnerability nvd CVE-2026-76610 2026-08-20
unknown CVE-2026-77026 — Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.… vulnerability nvd CVE-2026-77026 2026-08-20
unknown CVE-2026-77069 — n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential… vulnerability nvd CVE-2026-77069 2026-08-20
unknown CVE-2026-77070 — n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node… vulnerability nvd CVE-2026-77070 2026-08-20
unknown CVE-2026-77071 — n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the S… vulnerability nvd CVE-2026-77071 2026-08-20
unknown CVE-2026-77072 — n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting vulnerability in the… vulnerability nvd CVE-2026-77072 2026-08-20
unknown CVE-2026-77073 — n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_co… vulnerability nvd CVE-2026-77073 2026-08-20
unknown CVE-2026-77074 — n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image n… vulnerability nvd CVE-2026-77074 2026-08-20
unknown CVE-2026-77075 — n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vul… vulnerability nvd CVE-2026-77075 2026-08-20
unknown CVE-2026-77076 — n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in… vulnerability nvd CVE-2026-77076 2026-08-20
unknown CVE-2026-77077 — n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape.… vulnerability nvd CVE-2026-77077 2026-08-20
unknown CVE-2026-77079 — n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (r… vulnerability nvd CVE-2026-77079 2026-08-20
unknown CVE-2026-77080 — n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and… vulnerability nvd CVE-2026-77080 2026-08-20
unknown CVE-2026-77081 — n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in t… vulnerability nvd CVE-2026-77081 2026-08-20
unknown CVE-2026-77082 — n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denia… vulnerability nvd CVE-2026-77082 2026-08-20
unknown CVE-2026-77083 — n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaSc… vulnerability nvd CVE-2026-77083 2026-08-20
unknown CVE-2026-77084 — n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the… vulnerability nvd CVE-2026-77084 2026-08-20
unknown CVE-2026-77085 — n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent t… vulnerability nvd CVE-2026-77085 2026-08-20
unknown CVE-2026-77118 — A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage()… vulnerability nvd CVE-2026-77118 2026-08-20
unknown CVE-2026-7485 — Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all… vulnerability nvd CVE-2026-7485 2026-08-20
unknown CVE-2026-64961 — ATutor is vulnerable to authentication bypass . Although a token validation check is present in the… vulnerability nvd CVE-2026-64961 2026-08-20
unknown CVE-2026-64962 — ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attack… vulnerability nvd CVE-2026-64962 2026-08-20
unknown CVE-2026-64963 — A path traversal vulnerability in ATutor allows an authenticated user to access files from other cou… vulnerability nvd CVE-2026-64963 2026-08-20
unknown CVE-2026-64964 — ATutor generates predictable email confirmation tokens due to the use of insufficiently random value… vulnerability nvd CVE-2026-64964 2026-08-20
unknown CVE-2026-64965 — ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints. A low-pri… vulnerability nvd CVE-2026-64965 2026-08-20
unknown CVE-2026-64967 — A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative p… vulnerability nvd CVE-2026-64967 2026-08-20
unknown CVE-2026-64968 — ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated admi… vulnerability nvd CVE-2026-64968 2026-08-20
unknown CVE-2026-64969 — ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related en… vulnerability nvd CVE-2026-64969 2026-08-20
unknown CVE-2026-64970 — ATutor is vulnerable to Stored Cross Site Scripting in registration functionality. An attacker can r… vulnerability nvd CVE-2026-64970 2026-08-20
unknown CVE-2026-64971 — ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially… vulnerability nvd CVE-2026-64971 2026-08-20
unknown CVE-2026-64972 — ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker… vulnerability nvd CVE-2026-64972 2026-08-20
unknown CVE-2026-70383 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Esto… vulnerability nvd CVE-2026-70383 2026-08-20
unknown CVE-2026-73220 — CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0… vulnerability nvd CVE-2026-73220 2026-08-20
unknown CVE-2026-63040 — Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource per… vulnerability nvd CVE-2026-63040 2026-08-20
unknown CVE-2026-63042 — Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can… vulnerability nvd CVE-2026-63042 2026-08-20
unknown CVE-2026-63043 — Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host file… vulnerability nvd CVE-2026-63043 2026-08-20
unknown CVE-2026-63044 — Server-Side Request Forgery (SSRF) vulnerability in Apache InLong. Any authenticated user (no admin… vulnerability nvd CVE-2026-63044 2026-08-20
unknown CVE-2026-13121 — Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulne… vulnerability nvd CVE-2026-13121, CVE-2026-18262, CVE-2026-18263 2026-08-20
unknown CVE-2026-18267 — Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability. This vulnerability al… vulnerability nvd CVE-2026-18267 2026-08-20
unknown CVE-2026-18268 — Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability. This vuln… vulnerability nvd CVE-2026-18268 2026-08-20
unknown CVE-2026-18269 — Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution Vulnerability. This vulne… vulnerability nvd CVE-2026-18269 2026-08-20
unknown CVE-2026-18270 — Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability. T… vulnerability nvd CVE-2026-18270 2026-08-20
unknown CVE-2026-18271 — Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerab… vulnerability nvd CVE-2026-18271 2026-08-20
unknown CVE-2026-18272 — Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability. This vulnerability allows phys… vulnerability nvd CVE-2026-18272 2026-08-20
unknown CVE-2026-18273 — Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability. This v… vulnerability nvd CVE-2026-18273 2026-08-20
unknown CVE-2026-18278 — Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability. This v… vulnerability nvd CVE-2026-18278 2026-08-20
unknown CVE-2026-18280 — Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allo… vulnerability nvd CVE-2026-18280 2026-08-20
unknown CVE-2026-18283 — Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physica… vulnerability nvd CVE-2026-18283 2026-08-20
unknown CVE-2026-18284 — Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerability. This… vulnerability nvd CVE-2026-18284 2026-08-20
unknown CVE-2026-40345 — deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects.… vulnerability nvd CVE-2026-40345 2026-08-20
unknown CVE-2026-54136 — Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows an… vulnerability nvd CVE-2026-54136 2026-08-20
unknown CVE-2026-55095 — OpenProject is open-source, web-based project management software. In version 17.5.1 and earlier, an… vulnerability nvd CVE-2026-55095 2026-08-20
unknown CVE-2026-63481 — Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In versio… vulnerability nvd CVE-2026-63481 2026-08-20
unknown CVE-2026-71492 — Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, Dir… vulnerability nvd CVE-2026-71492 2026-08-20
unknown CVE-2026-53425 — Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to… vulnerability nvd CVE-2026-53425 2026-08-20
unknown CVE-2026-63379 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunk… vulnerability nvd CVE-2026-63379 2026-08-20
unknown CVE-2026-63380 — Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid li… vulnerability nvd CVE-2026-63380 2026-08-20
unknown CVE-2026-63381 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after… vulnerability nvd CVE-2026-63381 2026-08-20
unknown CVE-2026-63382 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp pars… vulnerability nvd CVE-2026-63382 2026-08-20
unknown CVE-2026-63383 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond… vulnerability nvd CVE-2026-63383 2026-08-20
unknown CVE-2026-63384 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrec… vulnerability nvd CVE-2026-63384 2026-08-20
unknown CVE-2026-63385 — Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP pa… vulnerability nvd CVE-2026-63385 2026-08-20
unknown CVE-2026-73251 — Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impers… vulnerability nvd CVE-2026-73251 2026-08-20
unknown CVE-2026-73253 — Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network at… vulnerability nvd CVE-2026-73253 2026-08-20
unknown CVE-2026-15743 — Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable… vulnerability nvd CVE-2026-15743 2026-08-20
unknown CVE-2026-19586 — A pre-authentication OS command injection vulnerability has been identified in Omada gateways config… vulnerability nvd CVE-2026-19586 2026-08-20
unknown CVE-2026-19683 — A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During com… vulnerability nvd CVE-2026-19683 2026-08-20
unknown CVE-2026-50190 — Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in… vulnerability nvd CVE-2026-50190 2026-08-20
unknown CVE-2026-53569 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted to… vulnerability nvd CVE-2026-53569 2026-08-20
unknown CVE-2026-62315 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_… vulnerability nvd CVE-2026-62315 2026-08-20
unknown CVE-2026-63654 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted fr… vulnerability nvd CVE-2026-63654 2026-08-20
unknown CVE-2026-66001 — Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and aut… vulnerability nvd CVE-2026-66001 2026-08-20
unknown CVE-2026-66002 — Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-… vulnerability nvd CVE-2026-66002 2026-08-20
unknown CVE-2026-9033 — An unauthenticated attacker with network access to the captive portal service of an affected device… vulnerability nvd CVE-2026-9033 2026-08-20
unknown CVE-2026-19755 — NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing a… vulnerability nvd CVE-2026-19755 2026-08-20
unknown CVE-2026-43798 — A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write… vulnerability nvd CVE-2026-43798 2026-08-20
unknown CVE-2026-52021 — An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remote attacker to obtain sensitiv… vulnerability nvd CVE-2026-52021 2026-08-20
unknown CVE-2026-70651 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips b… vulnerability nvd CVE-2026-70651, CVE-2026-70652 2026-08-20
unknown CVE-2026-70653 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-s… vulnerability nvd CVE-2026-70653 2026-08-20
unknown CVE-2026-70654 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applicati… vulnerability nvd CVE-2026-70654 2026-08-20
unknown CVE-2026-74836 — Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unaut… vulnerability nvd CVE-2026-74836 2026-08-20
unknown CVE-2026-75484 — Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows… vulnerability nvd CVE-2026-75484 2026-08-20
unknown CVE-2026-76017 — Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to e… vulnerability nvd CVE-2026-76017 2026-08-20
unknown CVE-2026-76020 — Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute a… vulnerability nvd CVE-2026-76020 2026-08-20
unknown CVE-2026-76021 — Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute… vulnerability nvd CVE-2026-76021 2026-08-20
unknown CVE-2026-76022 — Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to exe… vulnerability nvd CVE-2026-76022 2026-08-20
unknown CVE-2026-76023 — Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed… vulnerability nvd CVE-2026-76023 2026-08-20
unknown CVE-2025-52182 — The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure… vulnerability nvd CVE-2025-52182 2026-08-20
unknown CVE-2026-50192 — Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the… vulnerability nvd CVE-2026-50192 2026-08-20
unknown CVE-2026-54505 — TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK int… vulnerability nvd CVE-2026-54505 2026-08-20
unknown CVE-2026-54508 — TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before n… vulnerability nvd CVE-2026-54508 2026-08-20
unknown CVE-2026-55893 — Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.… vulnerability nvd CVE-2026-55893, CVE-2026-55894 2026-08-20
unknown CVE-2026-64773 — An attacker that can reach a container's published TCP port may be able to force the host's forwardi… vulnerability nvd CVE-2026-64773 2026-08-20
unknown CVE-2026-77644 — A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliabili… vulnerability nvd CVE-2026-77644 2026-08-20
unknown CVE-2026-77646 — A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PT… vulnerability nvd CVE-2026-77646 2026-08-20
unknown CVE-2026-77113 — Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allow… vulnerability nvd CVE-2026-77113 2026-08-20
unknown CVE-2026-16520 — Improper input validation and Exposure of sensitive information through data queries vulnerability i… vulnerability nvd CVE-2026-16520 2026-08-21
unknown CVE-2026-20679 — The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Son… vulnerability nvd CVE-2026-20679 2026-08-21
unknown CVE-2026-43679 — This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An… vulnerability nvd CVE-2026-43679 2026-08-21
unknown CVE-2026-76155 — Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a rem… vulnerability nvd CVE-2026-76155 2026-08-21
unknown CVE-2026-76156 — OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.… vulnerability nvd CVE-2026-76156 2026-08-21
unknown CVE-2026-76157 — Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management… vulnerability nvd CVE-2026-76157 2026-08-21
unknown CVE-2026-62834 Azure Data Factory Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-68789 Azure SQL Database Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-69519 Azure Stack HCI Information Disclosure Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-69851 Microsoft Entra ID Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-62703 Windows DWM Core Library Information Disclosure Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-62754 Windows Kerberos Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-65786 Desktop Window Manager Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-55015 Microsoft Remote Help Denial of Service Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-55013 Windows Remote Help Defense Spoofing Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-70105 Microsoft Word Information Disclosure Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-63509 Microsoft Fabric Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-65816 Azure Arc Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-66800 Azure Data Factory Information Disclosure Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-69400 Azure Logic Apps Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-69558 Microsoft Partner Center Information Disclosure Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-69543 Azure Virtual Machines Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-69855 Microsoft Copilot in Azure Information Disclosure Vulnerability advisory vendor-blogs 2026-08-20
unknown CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability advisory vendor-blogs 2026-08-19
unknown CVE-2026-62705 Microsoft Brokering File System Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-19
unknown CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-19
unknown CVE-2026-65675 CoPilot Chat Security Feature Bypass Vulnerability advisory vendor-blogs 2026-08-19
unknown CVE-2026-50383 Windows Print Spooler Information Disclosure Vulnerability advisory vendor-blogs 2026-08-19
unknown CVE-2026-49798 Windows Kernel Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-19
unknown CVE-2026-58647 Microsoft PowerBI Report Server Spoofing Vulnerability advisory vendor-blogs 2026-08-19
unknown CVE-2026-42912 Windows Telephony Service Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-19
unknown CVE-2026-24301 Microsoft Copilot Information Disclosure Vulnerability advisory vendor-blogs 2026-08-18
unknown CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-18
unknown CVE-2026-47632 Azure Connected Machine Agent Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-18
unknown CVE-2026-50419 Windows Kernel Information Disclosure Vulnerability advisory vendor-blogs 2026-08-18
unknown CVE-2026-58612 PowerShell Information Disclosure Vulnerability advisory vendor-blogs 2026-08-17
unknown CVE-2026-62886 .NET Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-17
unknown CVE-2026-65769 Microsoft Teams iOS Information Disclosure Vulnerability advisory vendor-blogs 2026-08-16
unknown CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-16
unknown CVE-2026-65767 Microsoft Teams for Android Spoofing Vulnerability advisory vendor-blogs 2026-08-16
unknown CVE-2026-61347 Windows Event Logging Service Information Disclosure Vulnerability advisory vendor-blogs 2026-08-14
unknown CVE-2026-62746 Win32k Information Disclosure Vulnerability advisory vendor-blogs 2026-08-14
unknown CVE-2026-62777 Windows License Manager Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-14
unknown CVE-2026-65671 Remote Access API Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-14
unknown CVE-2026-68821 Windows Package Manager Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-14
unknown Chromium: CVE-2026-19560 Use after free in Blink advisory vendor-blogs 2026-08-14
unknown Chromium: CVE-2026-19559 Use after free in HTML advisory vendor-blogs 2026-08-14
unknown Chromium: CVE-2026-19558 Use after free in Extensions advisory vendor-blogs 2026-08-14
unknown Chromium: CVE-2026-19557 Use after free in TabStrip advisory vendor-blogs 2026-08-14
unknown Chromium: CVE-2026-19556 Use after free in V8 advisory vendor-blogs 2026-08-14
unknown CVE-2026-59126 Windows Event Logging Service Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-14
unknown CVE-2026-59119 PowerShell Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-14
unknown CVE-2026-32153 Windows Speech Runtime Elevation of Privilege Vulnerability advisory vendor-blogs 2026-08-14
unknown Is Cyber missing the Marque? advisory vendor-blogs 2026-08-20
unknown UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations advisory vendor-blogs 2026-08-20
unknown Describing attacks with crime script analysis advisory vendor-blogs 2026-08-19
unknown SD1791 | OTTO® Fleet Manager – Weak Password Hashing Configuration advisory vendor-blogs 2026-08-19
unknown NIST offers resource-constrained BACS operators practical steps to address OT cybersecurity threats and risks advisory vendor-blogs 2026-08-20
unknown Bitdefender traces SilkParasite cyberespionage campaign across Central Asia to seven RAT families, China-nexus tooling advisory vendor-blogs 2026-08-20
unknown Senators introduce bipartisan Quantum-GUARD Act to boost US electric grid against emerging quantum cyber threats advisory vendor-blogs 2026-08-19
unknown Georgia Cyber Resiliency Center aligns rural healthcare cybersecurity, cyber resilience with CMS Rural Health Transformation goals advisory vendor-blogs 2026-08-19
unknown From Hype to Operational Reality: What We Learned at AI in OT Cyber advisory vendor-blogs 2026-08-18
unknown Citrix urges admins to patch new NetScaler flaws as soon as possible news general-news 2026-08-20
unknown CISA warns of hackers exploiting critical MLflow vulnerability news general-news 2026-08-20
unknown New Manic Android malware can exfiltrate data through nearby devices news general-news 2026-08-20
unknown Microsoft says August Windows updates may cause gaming issues news general-news 2026-08-20
unknown Healthtech firm CareCloud data breach impacts 3.7 million patients news general-news 2026-08-19
unknown US warns of AI-powered attacks on Siemens PLCs in critical infrastructure news general-news 2026-08-19
unknown AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure news general-news 2026-08-20
unknown New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data news general-news 2026-08-20
unknown Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers news general-news 2026-08-20
unknown Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments news general-news 2026-08-20
unknown Why "Shady AI" is Security's Next Big Governance Problem news general-news 2026-08-20
unknown CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification news general-news 2026-08-20
unknown Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices news general-news 2026-08-20
unknown NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands news general-news 2026-08-20
unknown ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud news general-news 2026-08-20
unknown Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second news general-news 2026-08-19
unknown OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior news general-news 2026-08-19
unknown Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P news general-news 2026-08-19
unknown StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data news general-news 2026-08-19
unknown Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation news general-news 2026-08-19
unknown Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure news general-news 2026-08-19
unknown One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025 news general-news 2026-08-18
unknown Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects news general-news 2026-08-17
unknown Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection news general-news 2026-08-17
unknown SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch news general-news 2026-08-15
unknown Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner news general-news 2026-08-15
unknown Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware news general-news 2026-08-14
unknown New CUSTODY Framework Constrains AI Agents Inside the Network news general-news 2026-08-20
unknown N-able Bug Exposes Password Vault Master Keys news general-news 2026-08-20
unknown Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks news general-news 2026-08-20
unknown 'Grandoreiro' Malware Resurfaces With Mexico Campaign news general-news 2026-08-20
unknown Agentic AI Presents New Insider Threat Model for Orgs news general-news 2026-08-19
unknown China-Linked Hacker Shows AI Capabilities in APAC Attack news general-news 2026-08-19
unknown Critical GitLab Zero-Click Flaw Poses Mitigation Challenges news general-news 2026-08-18
unknown 'CoSnitch' Attack Tricked Copilot Into Mapping Out Architecture news general-news 2026-08-18
unknown The 'Industrial Accidents' Behind Rogue AI Agent Attacks — and the Sandbox Failures Exposed news general-news 2026-08-18
unknown Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud news general-news 2026-08-18
unknown Video Call Exploit Chains Two Flaws in Unisoc Modems news general-news 2026-08-17
unknown 'Turf War' Between Claude Agents Leads to Self-Replicating Malware news general-news 2026-08-17
unknown Hugging Face Breach Raises Big Questions About AI Security Controls news general-news 2026-08-17
unknown Mission-Driven Security: Inside a Global Bank's Defense news general-news 2026-08-14
unknown Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI news general-news 2026-08-14
unknown Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office news general-news 2026-08-14
unknown Hackers Target Zimbra Servers in Active Exploitation Campaign news general-news 2026-08-20
unknown Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities news general-news 2026-08-20
unknown MLflow Vulnerability Exploited for Cloud Credential Theft news general-news 2026-08-20
unknown OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses news general-news 2026-08-20
unknown Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler news general-news 2026-08-20
unknown Critical GitLab Flaw Exploited Shortly After Disclosure news general-news 2026-08-20
unknown Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps news general-news 2026-08-20
unknown Exclusive: Linux Foundation's Akrites to Go Live in September news general-news 2026-08-19
unknown MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra news general-news 2026-08-19
unknown OpenAI Tightens AI Safeguards Following Hugging Face Incident news general-news 2026-08-19
unknown Enterprise Applications Carry 4.31x More Critical and High Vulnerabilities news general-news 2026-08-18
unknown NASA Ground Control Software Flaw Enables Unauthenticated Commands news general-news 2026-08-18
unknown Cyber Incident Disrupts Student Services at UT San Antonio news general-news 2026-08-18
unknown WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover news general-news 2026-08-17
unknown SafePal Data Breach Hits Tens of Thousands of Customers news general-news 2026-08-17
unknown Corero brings cloud-based AI threat analysis to SmartWall ONE news general-news 2026-08-20
unknown Researchers find a loophole that lets expired credit cards make unauthorized payments news general-news 2026-08-20
unknown 8,539 reasons to rethink how vulnerabilities get patched news general-news 2026-08-20
unknown China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware news general-news 2026-08-20
unknown Electronic health record company CareCloud says 3.7 million people affected by breach news general-news 2026-08-19
unknown NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology news general-news 2026-08-19
unknown Latvian officials resign after cyberattack exposes data on 1.2 million people news general-news 2026-08-19
unknown The push to designate AI as the next critical infrastructure sector news general-news 2026-08-20
unknown AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn news general-news 2026-08-19
unknown Details emerge on BlackFile’s recent attacks on financial companies news general-news 2026-08-17
unknown Irregular says ‘human oversight’ responsible for AI sandbox escape incidents news general-news 2026-08-17