| medium |
CVE-2026-47720 — FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengi… |
vulnerability |
nvd |
CVE-2026-47720 |
ics |
2026-08-18 |
| high |
CVE-2026-47719 — FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE… |
vulnerability |
nvd |
CVE-2026-47719 |
ics |
2026-08-18 |
| medium |
CVE-2026-19671 — Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth,… |
vulnerability |
nvd |
CVE-2026-19671 |
|
2026-08-18 |
| medium |
CVE-2026-19670 — Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may… |
vulnerability |
nvd |
CVE-2026-19670 |
|
2026-08-18 |
| medium |
CVE-2026-12520 — The Sierra Wireless HL7800 cellular modem driver (drivers/modem/vendor_standalone/hl7800.c, located… |
vulnerability |
nvd |
CVE-2026-12520 |
|
2026-08-18 |
| high |
MacSync Stealer: C2 Infrastructure Rotation |
threat-intel |
otx |
7980485fb1e0b1b1…, 277acd8e241c1341… |
macsync stealer, c2 infrastructure, macos, mac.c, clickfix, credential theft, cryptocurrency wallet, macsync, malware-as-a-service, infostealer, botnet |
2026-08-18 |
| medium |
CVE-2026-70667 — Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificat… |
vulnerability |
nvd |
CVE-2026-70667 |
|
2026-08-18 |
| medium |
CVE-2026-65959 — Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /… |
vulnerability |
nvd |
CVE-2026-65959 |
|
2026-08-18 |
| critical |
CVE-2026-55166 — Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME… |
vulnerability |
nvd |
CVE-2026-55166 |
|
2026-08-18 |
| medium |
CVE-2026-55165 — Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifier in lemur/auth/service.py:13… |
vulnerability |
nvd |
CVE-2026-55165 |
|
2026-08-18 |
| medium |
CVE-2026-55164 — Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replac… |
vulnerability |
nvd |
CVE-2026-55164 |
|
2026-08-18 |
| medium |
CVE-2026-55163 — Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:29… |
vulnerability |
nvd |
CVE-2026-55163 |
|
2026-08-18 |
| medium |
CVE-2026-55162 — Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certificates/verify.py accepted CRL Di… |
vulnerability |
nvd |
CVE-2026-55162 |
|
2026-08-18 |
| high |
CVE-2026-47629 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause impr… |
vulnerability |
nvd |
CVE-2026-47629 |
|
2026-08-18 |
| critical |
CVE-2026-47627 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path… |
vulnerability |
nvd |
CVE-2026-47627 |
|
2026-08-18 |
| high |
CVE-2026-47606 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an a… |
vulnerability |
nvd |
CVE-2026-47606, CVE-2026-47628, CVE-2026-47630 |
|
2026-08-18 |
| high |
CVE-2026-24185 — NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configura… |
vulnerability |
nvd |
CVE-2026-24185 |
|
2026-08-18 |
| high |
CVE-2026-24184 — NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon com… |
vulnerability |
nvd |
CVE-2026-24184 |
|
2026-08-18 |
| high |
CVE-2026-24183 — NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivilege… |
vulnerability |
nvd |
CVE-2026-24183 |
|
2026-08-18 |
| unknown |
CVE-2026-17106 — The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and th… |
vulnerability |
nvd |
CVE-2026-17106 |
|
2026-08-18 |
| medium |
CVE-2025-9211 — Unescaped stored values in application security page in Otalio Ship Property Management System versi… |
vulnerability |
nvd |
CVE-2025-9211 |
|
2026-08-18 |
| high |
CVE-2025-9210 — Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions b… |
vulnerability |
nvd |
CVE-2025-9210 |
|
2026-08-18 |
| unknown |
The 'Industrial Accidents' Behind Rogue AI Agent Attacks — and the Sandbox Failures Exposed |
news |
general-news |
|
|
2026-08-18 |
| critical |
CVE-2026-75625 — Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest be… |
vulnerability |
nvd |
CVE-2026-75625 |
|
2026-08-18 |
| critical |
CVE-2026-75130 — Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute ma… |
vulnerability |
nvd |
CVE-2026-75130 |
|
2026-08-18 |
| medium |
CVE-2026-74046 — Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() func… |
vulnerability |
nvd |
CVE-2026-74046 |
|
2026-08-18 |
| medium |
CVE-2026-74044 — Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster… |
vulnerability |
nvd |
CVE-2026-74044 |
|
2026-08-18 |
| medium |
CVE-2026-74039 — Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows auth… |
vulnerability |
nvd |
CVE-2026-74039 |
|
2026-08-18 |
| high |
CVE-2026-74038 — Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote… |
vulnerability |
nvd |
CVE-2026-74038 |
|
2026-08-18 |
| medium |
CVE-2026-73502 — kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.Val… |
vulnerability |
nvd |
CVE-2026-73502 |
|
2026-08-18 |
| unknown |
CVE-2026-71880 — Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions… |
vulnerability |
nvd |
CVE-2026-71880 |
|
2026-08-18 |
| unknown |
CVE-2026-71879 — Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integr… |
vulnerability |
nvd |
CVE-2026-71879 |
|
2026-08-18 |
| unknown |
CVE-2026-71878 — Missing authentication in initial setup functionality left exposed after initial setup is completed… |
vulnerability |
nvd |
CVE-2026-71878 |
|
2026-08-18 |
| high |
CVE-2026-71551 — Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabil… |
vulnerability |
nvd |
CVE-2026-71551 |
|
2026-08-18 |
| medium |
CVE-2026-69160 — OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and… |
vulnerability |
nvd |
CVE-2026-69160 |
|
2026-08-18 |
| low |
CVE-2026-68927 — MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities i… |
vulnerability |
nvd |
CVE-2026-68927 |
|
2026-08-18 |
| medium |
CVE-2026-68924 — MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobs… |
vulnerability |
nvd |
CVE-2026-68924 |
|
2026-08-18 |
| medium |
CVE-2026-68923 — MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py pl… |
vulnerability |
nvd |
CVE-2026-68923 |
|
2026-08-18 |
| medium |
CVE-2026-68922 — MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobs… |
vulnerability |
nvd |
CVE-2026-68922 |
|
2026-08-18 |
| critical |
CVE-2026-67921 — Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the Cor… |
vulnerability |
nvd |
CVE-2026-67921 |
|
2026-08-18 |
| high |
CVE-2026-67920 — An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migr… |
vulnerability |
nvd |
CVE-2026-67920 |
|
2026-08-18 |
| high |
CVE-2026-67846 — Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a pote… |
vulnerability |
nvd |
CVE-2026-67846 |
|
2026-08-18 |
| high |
CVE-2026-67262 — Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped… |
vulnerability |
nvd |
CVE-2026-67262 |
|
2026-08-18 |
| critical |
CVE-2026-66780 — A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, whi… |
vulnerability |
nvd |
CVE-2026-66780 |
|
2026-08-18 |
| unknown |
CVE-2026-63643 — MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR hand… |
vulnerability |
nvd |
CVE-2026-63643 |
|
2026-08-18 |
| unknown |
CVE-2026-63642 — MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in de… |
vulnerability |
nvd |
CVE-2026-63642 |
|
2026-08-18 |
| unknown |
CVE-2026-63641 — MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies i… |
vulnerability |
nvd |
CVE-2026-63641 |
|
2026-08-18 |
| medium |
CVE-2026-63640 — MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecret… |
vulnerability |
nvd |
CVE-2026-63640 |
|
2026-08-18 |
| medium |
CVE-2026-61696 — Forem is open source software for building communities. In versions before commit 92eacd16a82cf9007b… |
vulnerability |
nvd |
CVE-2026-61696 |
|
2026-08-18 |
| medium |
CVE-2026-54570 — AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnota… |
vulnerability |
nvd |
CVE-2026-54570 |
|
2026-08-18 |