| unknown |
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0 |
news |
general-news |
|
|
2026-08-21 |
| high |
Rust Supply Chain Attack Linked to North Korean Hackers |
news |
general-news |
|
supply-chain |
2026-08-21 |
| unknown |
CVE-2026-77710 — A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MIS… |
vulnerability |
nvd |
CVE-2026-77710 |
|
2026-08-21 |
| medium |
CVE-2026-74866 — @fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits… |
vulnerability |
nvd |
CVE-2026-74866 |
|
2026-08-21 |
| unknown |
CVE-2026-68745 — Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on… |
vulnerability |
nvd |
CVE-2026-68745 |
|
2026-08-21 |
| unknown |
CVE-2026-66797 — Improper access control in CloudStack's annotation functionality allows unauthorized comment creatio… |
vulnerability |
nvd |
CVE-2026-66797 |
|
2026-08-21 |
| unknown |
CVE-2026-66722 — Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain… |
vulnerability |
nvd |
CVE-2026-66722 |
|
2026-08-21 |
| unknown |
CVE-2026-66721 — Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domai… |
vulnerability |
nvd |
CVE-2026-66721 |
|
2026-08-21 |
| unknown |
CVE-2026-65613 — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webh… |
vulnerability |
nvd |
CVE-2026-65613 |
|
2026-08-21 |
| unknown |
CVE-2026-63046 — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in… |
vulnerability |
nvd |
CVE-2026-63046 |
|
2026-08-21 |
| unknown |
CVE-2026-62440 — Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowi… |
vulnerability |
nvd |
CVE-2026-62440 |
|
2026-08-21 |
| unknown |
CVE-2026-61422 — Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration… |
vulnerability |
nvd |
CVE-2026-61422 |
|
2026-08-21 |
| unknown |
CVE-2026-61400 — Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in… |
vulnerability |
nvd |
CVE-2026-61400 |
|
2026-08-21 |
| unknown |
CVE-2026-61399 — Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock Use… |
vulnerability |
nvd |
CVE-2026-61399 |
|
2026-08-21 |
| unknown |
CVE-2026-61398 — Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance… |
vulnerability |
nvd |
CVE-2026-61398 |
|
2026-08-21 |
| unknown |
CVE-2026-59799 — Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin… |
vulnerability |
nvd |
CVE-2026-59799 |
|
2026-08-21 |
| unknown |
CVE-2026-59780 — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP… |
vulnerability |
nvd |
CVE-2026-59780 |
|
2026-08-21 |
| unknown |
CVE-2026-59657 — Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage… |
vulnerability |
nvd |
CVE-2026-59657 |
|
2026-08-21 |
| unknown |
CVE-2026-59655 — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAut… |
vulnerability |
nvd |
CVE-2026-59655, CVE-2026-61397 |
|
2026-08-21 |
| unknown |
CVE-2026-59085 — Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable… |
vulnerability |
nvd |
CVE-2026-59085 |
|
2026-08-21 |
| unknown |
CVE-2026-50222 — Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A… |
vulnerability |
nvd |
CVE-2026-50222 |
|
2026-08-21 |
| high |
CVE-2026-50112 — SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to… |
vulnerability |
nvd |
CVE-2026-50112 |
rce |
2026-08-21 |
| unknown |
CVE-2026-47359 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi… |
vulnerability |
nvd |
CVE-2026-47359 |
|
2026-08-21 |
| critical |
CVE-2026-77264 — The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin fo… |
vulnerability |
nvd |
CVE-2026-77264 |
|
2026-08-21 |
| critical |
CVE-2026-73537 — Cross-site scripting vulnerability exists in Miraikan Assist App. If this vulnerability is exploited… |
vulnerability |
nvd |
CVE-2026-73537 |
ransomware, botnet |
2026-08-21 |
| medium |
CVE-2026-19441 — Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake… |
vulnerability |
nvd |
CVE-2026-19441 |
|
2026-08-21 |
| high |
CVE-2026-16323 — Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectP… |
vulnerability |
nvd |
CVE-2026-16323 |
|
2026-08-21 |
| unknown |
Microsoft Patches Exploited Entra ID Vulnerability |
news |
general-news |
|
|
2026-08-21 |
| unknown |
Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) |
news |
general-news |
|
|
2026-08-21 |
| high |
Head Mare APT Group exploits vulnerabilities in unpatched TrueConf server to deliver PhantomCore malware to conference participants |
threat-intel |
otx |
194.87.239.71, 194.87.93.153, 31.59.102.61, 38.244.205.244, 81.177.32.12 | ceea2f175eaa0291…, 4333f52668996c0f… |
trueconf, supply chain attack, backdoor, phantomgraph, head mare, phantomcore, web shell, video conferencing, zero-day exploitation, apt, zeroday, botnet, supply-chain |
2026-08-21 |
| unknown |
CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities |
news |
general-news |
|
|
2026-08-21 |
| high |
CVE-2026-75796 — The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized t… |
vulnerability |
nvd |
CVE-2026-75796 |
|
2026-08-21 |
| low |
CVE-2026-19435 — The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before retur… |
vulnerability |
nvd |
CVE-2026-19435 |
|
2026-08-21 |
| low |
CVE-2026-19085 — The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of… |
vulnerability |
nvd |
CVE-2026-19085 |
|
2026-08-21 |
| high |
CVE-2026-18781 — The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not v… |
vulnerability |
nvd |
CVE-2026-18781 |
|
2026-08-21 |
| medium |
CVE-2026-16962 — The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any… |
vulnerability |
nvd |
CVE-2026-16962 |
|
2026-08-21 |
| medium |
CVE-2026-16959 — The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before… |
vulnerability |
nvd |
CVE-2026-16959 |
|
2026-08-21 |
| high |
CVE-2026-16575 — The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 do… |
vulnerability |
nvd |
CVE-2026-16575, CVE-2026-16576, CVE-2026-16577 |
|
2026-08-21 |
| medium |
CVE-2026-14601 — The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a paramete… |
vulnerability |
nvd |
CVE-2026-14601 |
|
2026-08-21 |
| low |
CVE-2026-14325 — The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not e… |
vulnerability |
nvd |
CVE-2026-14325 |
|
2026-08-21 |
| medium |
CVE-2026-13736 — The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only… |
vulnerability |
nvd |
CVE-2026-13736 |
|
2026-08-21 |
| medium |
CVE-2025-15671 — The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on… |
vulnerability |
nvd |
CVE-2025-15671 |
|
2026-08-21 |
| unknown |
GitLab 19.3 helps enterprises scale agentic development securely |
news |
general-news |
|
|
2026-08-21 |
| unknown |
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure |
news |
general-news |
|
|
2026-08-21 |
| critical |
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution |
news |
general-news |
|
rce |
2026-08-21 |
| unknown |
Nearly half of enterprises have no one leading PQC migration |
news |
general-news |
|
|
2026-08-21 |
| unknown |
CVE-2026-65645 — Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15,… |
vulnerability |
nvd |
CVE-2026-65645 |
|
2026-08-21 |
| medium |
CVE-2026-65644 — Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 h… |
vulnerability |
nvd |
CVE-2026-65644 |
phishing |
2026-08-21 |
| unknown |
CVE-2026-45202 — Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU mem… |
vulnerability |
nvd |
CVE-2026-45202 |
|
2026-08-21 |
| unknown |
CVE-2026-45201 — Software installed and run as a non-privileged user may conduct improper GPU system calls to pass in… |
vulnerability |
nvd |
CVE-2026-45201 |
|
2026-08-21 |