| medium |
CVE-2026-76228 — Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) con… |
vulnerability |
nvd |
CVE-2026-76228 |
|
2026-08-19 |
| medium |
CVE-2026-76227 — Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including correspond… |
vulnerability |
nvd |
CVE-2026-76227 |
|
2026-08-19 |
| medium |
CVE-2026-76226 — Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in baz… |
vulnerability |
nvd |
CVE-2026-76226 |
rce |
2026-08-19 |
| high |
CVE-2026-76225 — ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD C… |
vulnerability |
nvd |
CVE-2026-76225 |
|
2026-08-19 |
| high |
CVE-2026-76224 — ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulne… |
vulnerability |
nvd |
CVE-2026-76224 |
rce |
2026-08-19 |
| high |
CVE-2026-76223 — ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission che… |
vulnerability |
nvd |
CVE-2026-76223 |
|
2026-08-19 |
| high |
CVE-2026-76222 — GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers… |
vulnerability |
nvd |
CVE-2026-76222 |
|
2026-08-19 |
| high |
CVE-2026-76221 — GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator… |
vulnerability |
nvd |
CVE-2026-76221 |
rce |
2026-08-19 |
| high |
CVE-2026-76220 — GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard… |
vulnerability |
nvd |
CVE-2026-76220 |
|
2026-08-19 |
| high |
CVE-2026-76219 — GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from… |
vulnerability |
nvd |
CVE-2026-76219 |
|
2026-08-19 |
| high |
CVE-2026-76218 — GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards un… |
vulnerability |
nvd |
CVE-2026-76218 |
rce |
2026-08-19 |
| medium |
CVE-2026-76217 — GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands… |
vulnerability |
nvd |
CVE-2026-76217 |
|
2026-08-19 |
| high |
CVE-2026-76216 — Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals… |
vulnerability |
nvd |
CVE-2026-76216 |
|
2026-08-19 |
| medium |
CVE-2026-76215 — phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks before returning child resources i… |
vulnerability |
nvd |
CVE-2026-76215 |
|
2026-08-19 |
| high |
CVE-2026-76214 — phpMyFAQ before 4.1.7 fails to persist the WebAuthn login challenge generated by prepareForLogin, be… |
vulnerability |
nvd |
CVE-2026-76214 |
ransomware |
2026-08-19 |
| high |
CVE-2026-76213 — phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step whe… |
vulnerability |
nvd |
CVE-2026-76213 |
|
2026-08-19 |
| medium |
CVE-2026-76212 — phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the native pgsql PHP extension, declare… |
vulnerability |
nvd |
CVE-2026-76212 |
|
2026-08-19 |
| medium |
CVE-2026-76211 — phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endp… |
vulnerability |
nvd |
CVE-2026-76211 |
|
2026-08-19 |
| medium |
CVE-2026-76210 — phpMyFAQ before 4.1.6 does not adequately sanitize HTML in FAQ answers before generating PDFs via TC… |
vulnerability |
nvd |
CVE-2026-76210 |
|
2026-08-19 |
| medium |
CVE-2026-76209 — phpMyFAQ versions before v4.1.6 fail to validate the security.enableRegistration setting in API endp… |
vulnerability |
nvd |
CVE-2026-76209 |
|
2026-08-19 |
| high |
CVE-2026-76208 — phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::cr… |
vulnerability |
nvd |
CVE-2026-76208 |
|
2026-08-19 |
| high |
CVE-2026-76207 — phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me to… |
vulnerability |
nvd |
CVE-2026-76207 |
ransomware |
2026-08-19 |
| medium |
CVE-2026-76206 — phpMyFAQ versions before 4.1.7 fail to validate active status in the PDF export endpoint, allowing u… |
vulnerability |
nvd |
CVE-2026-76206 |
|
2026-08-19 |
| high |
CVE-2026-76205 — phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpo… |
vulnerability |
nvd |
CVE-2026-76205 |
|
2026-08-19 |
| medium |
CVE-2026-75920 — phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at con… |
vulnerability |
nvd |
CVE-2026-75920 |
|
2026-08-19 |
| medium |
CVE-2026-75919 — phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows… |
vulnerability |
nvd |
CVE-2026-75919 |
|
2026-08-19 |
| high |
CVE-2026-75918 — phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user… |
vulnerability |
nvd |
CVE-2026-75918 |
ransomware |
2026-08-19 |
| high |
CVE-2026-75917 — SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-t… |
vulnerability |
nvd |
CVE-2026-75917 |
|
2026-08-19 |
| high |
CVE-2026-75916 — SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autoc… |
vulnerability |
nvd |
CVE-2026-75916 |
|
2026-08-19 |
| medium |
CVE-2026-75148 — cgltf through 1.15 contains an integer overflow vulnerability in the non-sparse accessor bounds chec… |
vulnerability |
nvd |
CVE-2026-75148 |
|
2026-08-19 |
| unknown |
CVE-2026-75114 — Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo <… |
vulnerability |
nvd |
CVE-2026-75114 |
|
2026-08-19 |
| unknown |
CVE-2026-74804 — Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo… |
vulnerability |
nvd |
CVE-2026-74804 |
|
2026-08-19 |
| unknown |
CVE-2026-74803 — Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image… |
vulnerability |
nvd |
CVE-2026-74803 |
|
2026-08-19 |
| unknown |
CVE-2026-71694 — An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b456321217521… |
vulnerability |
nvd |
CVE-2026-71694 |
|
2026-08-19 |
| medium |
CVE-2026-70424 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname t… |
vulnerability |
nvd |
CVE-2026-70424 |
|
2026-08-19 |
| medium |
CVE-2026-70423 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML Externa… |
vulnerability |
nvd |
CVE-2026-70423 |
|
2026-08-19 |
| high |
CVE-2026-70421 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulne… |
vulnerability |
nvd |
CVE-2026-70421 |
|
2026-08-19 |
| unknown |
CVE-2026-65612 — nnn does not sanitize the filename variable. An attacker can place a file with a crafted name on a s… |
vulnerability |
nvd |
CVE-2026-65612 |
|
2026-08-19 |
| unknown |
CVE-2026-65611 — nnn does not sanitize the path variable. An attacker can create a directory on a shared filesystem,… |
vulnerability |
nvd |
CVE-2026-65611 |
|
2026-08-19 |
| unknown |
CVE-2026-65610 — nnn stores homelen variable as uchar_t, which can only represent values in the range 0-255. An attac… |
vulnerability |
nvd |
CVE-2026-65610 |
|
2026-08-19 |
| unknown |
CVE-2026-65609 — nnn is vulnerable to Out-of-Bound write vulnerability. Due to lack of validation of attacker-control… |
vulnerability |
nvd |
CVE-2026-65609 |
|
2026-08-19 |
| high |
CVE-2026-54795 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special… |
vulnerability |
nvd |
CVE-2026-54795, CVE-2026-54796, CVE-2026-56088, CVE-2026-70422, CVE-2026-71176 |
|
2026-08-19 |
| high |
CVE-2026-54794 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) v… |
vulnerability |
nvd |
CVE-2026-54794 |
|
2026-08-19 |
| unknown |
CVE-2026-51367 — An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive i… |
vulnerability |
nvd |
CVE-2026-51367 |
|
2026-08-19 |
| unknown |
CVE-2026-51366 — SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to… |
vulnerability |
nvd |
CVE-2026-51366 |
|
2026-08-19 |
| unknown |
CVE-2026-50720 — The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the… |
vulnerability |
nvd |
CVE-2026-50720 |
|
2026-08-19 |
| unknown |
CVE-2026-50719 — The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-cont… |
vulnerability |
nvd |
CVE-2026-50719 |
|
2026-08-19 |
| high |
CVE-2026-43961 — A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expressio… |
vulnerability |
nvd |
CVE-2026-43961 |
|
2026-08-19 |
| critical |
CVE-2026-16019 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i… |
vulnerability |
nvd |
CVE-2026-16019, CVE-2026-74011, CVE-2026-63037, CVE-2026-63038, CVE-2026-63039 |
|
2026-08-19 |
| unknown |
CVE-2026-42912 Windows Telephony Service Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-19 |