| unknown |
CVE-2026-58647 Microsoft PowerBI Report Server Spoofing Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
CVE-2026-49798 Windows Kernel Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
CVE-2026-50383 Windows Print Spooler Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
CVE-2026-65675 CoPilot Chat Security Feature Bypass Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| critical |
CVE-2026-65811 Power BI Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-19 |
| unknown |
CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| medium |
https://malbearlabs.com/shadow-hvnc-and-shadow-loader-the-kit-that-protects-its-license-better-than-its-customers-dd99520b6af3 |
threat-intel |
otx |
212.162.150.121 | f65bdff0bf9c807c…, 5ccd6c0dba9ad2ab… |
|
2026-08-19 |
| high |
CVE-2026-76235 — A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every… |
vulnerability |
nvd |
CVE-2026-76235 |
|
2026-08-19 |
| high |
CVE-2026-73394 — Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions. |
vulnerability |
nvd |
CVE-2026-73394 |
|
2026-08-19 |
| critical |
CVE-2026-73391 — Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. |
vulnerability |
nvd |
CVE-2026-73391 |
|
2026-08-19 |
| critical |
CVE-2026-73390 — Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. |
vulnerability |
nvd |
CVE-2026-73390 |
|
2026-08-19 |
| critical |
CVE-2026-73389 — Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. |
vulnerability |
nvd |
CVE-2026-73389 |
|
2026-08-19 |
| critical |
CVE-2026-73388 — Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. |
vulnerability |
nvd |
CVE-2026-73388 |
|
2026-08-19 |
| high |
CVE-2026-73387 — Unauthenticated Local File Inclusion in Resido <= 1.5 versions. |
vulnerability |
nvd |
CVE-2026-73387 |
|
2026-08-19 |
| high |
CVE-2026-73386 — Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2… |
vulnerability |
nvd |
CVE-2026-73386 |
|
2026-08-19 |
| high |
CVE-2026-73385 — Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions. |
vulnerability |
nvd |
CVE-2026-73385 |
|
2026-08-19 |
| high |
CVE-2026-73384 — Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions. |
vulnerability |
nvd |
CVE-2026-73384 |
|
2026-08-19 |
| critical |
CVE-2026-73364 — Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. |
vulnerability |
nvd |
CVE-2026-73364 |
|
2026-08-19 |
| medium |
CVE-2026-73363 — Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions. |
vulnerability |
nvd |
CVE-2026-73363 |
|
2026-08-19 |
| high |
CVE-2026-73354 — Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions. |
vulnerability |
nvd |
CVE-2026-73354 |
|
2026-08-19 |
| critical |
CVE-2026-73347 — Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. |
vulnerability |
nvd |
CVE-2026-73347 |
|
2026-08-19 |
| critical |
CVE-2026-73185 — Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. |
vulnerability |
nvd |
CVE-2026-73185 |
|
2026-08-19 |
| high |
CVE-2026-73184 — Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions. |
vulnerability |
nvd |
CVE-2026-73184 |
|
2026-08-19 |
| critical |
CVE-2026-73183 — Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. |
vulnerability |
nvd |
CVE-2026-73183 |
|
2026-08-19 |
| high |
CVE-2026-73182 — Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions. |
vulnerability |
nvd |
CVE-2026-73182 |
|
2026-08-19 |
| unknown |
CVE-2026-67364 — Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / C… |
vulnerability |
nvd |
CVE-2026-67364 |
|
2026-08-19 |
| unknown |
CVE-2026-67363 — Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The… |
vulnerability |
nvd |
CVE-2026-67363 |
|
2026-08-19 |
| high |
CVE-2026-66668 — Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions. |
vulnerability |
nvd |
CVE-2026-66668 |
|
2026-08-19 |
| critical |
CVE-2026-66613 — Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions. |
vulnerability |
nvd |
CVE-2026-66613 |
rce |
2026-08-19 |
| high |
CVE-2026-66596 — Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions. |
vulnerability |
nvd |
CVE-2026-66596 |
|
2026-08-19 |
| high |
CVE-2026-61986 — Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions. |
vulnerability |
nvd |
CVE-2026-61986 |
|
2026-08-19 |
| high |
CVE-2026-32552 — Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. |
vulnerability |
nvd |
CVE-2026-32552 |
|
2026-08-19 |
| unknown |
CVE-2026-19489 — Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.3… |
vulnerability |
nvd |
CVE-2026-19489, CVE-2026-19490 |
|
2026-08-19 |
| critical |
CVE-2026-18372 — CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault adminis… |
vulnerability |
nvd |
CVE-2026-18372 |
ransomware |
2026-08-19 |
| critical |
CVE-2026-18371 — HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to… |
vulnerability |
nvd |
CVE-2026-18371 |
ransomware |
2026-08-19 |
| unknown |
OpenAI Tightens AI Safeguards Following Hugging Face Incident |
news |
general-news |
|
|
2026-08-19 |
| high |
Defending Against an Active Threat to Siemens S7 Series PLCs |
advisory |
cisa-advisories |
|
ics, supply-chain |
2026-08-19 |
| unknown |
Senators introduce bipartisan Quantum-GUARD Act to boost US electric grid against emerging quantum cyber threats |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P |
news |
general-news |
|
|
2026-08-19 |
| medium |
Phishing 3.0: The Fight Moves to Agent Versus Agent |
news |
general-news |
|
phishing |
2026-08-19 |
| unknown |
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data |
news |
general-news |
|
|
2026-08-19 |
| medium |
From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel |
threat-intel |
otx |
519d5f0350f78805… |
legionloader, modular architecture, maas, lummastealer, clickfix, rat, tor, cryptocurrency theft, nodejs, grpc, botnet, infostealer |
2026-08-19 |
| unknown |
CVE-2026-16440 — In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations causes a… |
vulnerability |
nvd |
CVE-2026-16440 |
|
2026-08-19 |
| unknown |
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation |
news |
general-news |
|
|
2026-08-19 |
| critical |
Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware |
news |
general-news |
|
ransomware |
2026-08-19 |
| medium |
CVE-2026-76166 — A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single… |
vulnerability |
nvd |
CVE-2026-76166 |
|
2026-08-19 |
| unknown |
Describing attacks with crime script analysis |
advisory |
vendor-blogs |
|
|
2026-08-19 |
| unknown |
CVE-2026-76164 — AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission… |
vulnerability |
nvd |
CVE-2026-76164 |
|
2026-08-19 |
| medium |
CVE-2026-75900 — An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The ent… |
vulnerability |
nvd |
CVE-2026-75900 |
|
2026-08-19 |