| high |
CVE-2026-24184 — NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon com… |
vulnerability |
nvd |
CVE-2026-24184 |
|
2026-08-18 |
| high |
CVE-2026-24183 — NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivilege… |
vulnerability |
nvd |
CVE-2026-24183 |
|
2026-08-18 |
| unknown |
CVE-2026-17106 — The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and th… |
vulnerability |
nvd |
CVE-2026-17106 |
|
2026-08-18 |
| medium |
CVE-2025-9211 — Unescaped stored values in application security page in Otalio Ship Property Management System versi… |
vulnerability |
nvd |
CVE-2025-9211 |
|
2026-08-18 |
| high |
CVE-2025-9210 — Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions b… |
vulnerability |
nvd |
CVE-2025-9210 |
|
2026-08-18 |
| unknown |
The 'Industrial Accidents' Behind Rogue AI Agent Attacks — and the Sandbox Failures Exposed |
news |
general-news |
|
|
2026-08-18 |
| critical |
CVE-2026-75625 — Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest be… |
vulnerability |
nvd |
CVE-2026-75625 |
|
2026-08-18 |
| critical |
CVE-2026-75130 — Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute ma… |
vulnerability |
nvd |
CVE-2026-75130 |
|
2026-08-18 |
| medium |
CVE-2026-74046 — Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() func… |
vulnerability |
nvd |
CVE-2026-74046 |
|
2026-08-18 |
| medium |
CVE-2026-74044 — Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster… |
vulnerability |
nvd |
CVE-2026-74044 |
|
2026-08-18 |
| medium |
CVE-2026-74039 — Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows auth… |
vulnerability |
nvd |
CVE-2026-74039 |
|
2026-08-18 |
| high |
CVE-2026-74038 — Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote… |
vulnerability |
nvd |
CVE-2026-74038 |
|
2026-08-18 |
| medium |
CVE-2026-73502 — kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.Val… |
vulnerability |
nvd |
CVE-2026-73502 |
|
2026-08-18 |
| unknown |
CVE-2026-71880 — Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions… |
vulnerability |
nvd |
CVE-2026-71880 |
|
2026-08-18 |
| unknown |
CVE-2026-71879 — Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integr… |
vulnerability |
nvd |
CVE-2026-71879 |
|
2026-08-18 |
| unknown |
CVE-2026-71878 — Missing authentication in initial setup functionality left exposed after initial setup is completed… |
vulnerability |
nvd |
CVE-2026-71878 |
|
2026-08-18 |
| high |
CVE-2026-71551 — Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabil… |
vulnerability |
nvd |
CVE-2026-71551 |
|
2026-08-18 |
| medium |
CVE-2026-69160 — OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and… |
vulnerability |
nvd |
CVE-2026-69160 |
|
2026-08-18 |
| low |
CVE-2026-68927 — MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities i… |
vulnerability |
nvd |
CVE-2026-68927 |
|
2026-08-18 |
| medium |
CVE-2026-68924 — MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobs… |
vulnerability |
nvd |
CVE-2026-68924 |
|
2026-08-18 |
| medium |
CVE-2026-68923 — MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py pl… |
vulnerability |
nvd |
CVE-2026-68923 |
|
2026-08-18 |
| medium |
CVE-2026-68922 — MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobs… |
vulnerability |
nvd |
CVE-2026-68922 |
|
2026-08-18 |
| critical |
CVE-2026-67921 — Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the Cor… |
vulnerability |
nvd |
CVE-2026-67921 |
|
2026-08-18 |
| high |
CVE-2026-67920 — An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migr… |
vulnerability |
nvd |
CVE-2026-67920 |
|
2026-08-18 |
| high |
CVE-2026-67846 — Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a pote… |
vulnerability |
nvd |
CVE-2026-67846 |
|
2026-08-18 |
| high |
CVE-2026-67262 — Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped… |
vulnerability |
nvd |
CVE-2026-67262 |
|
2026-08-18 |
| critical |
CVE-2026-66780 — A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, whi… |
vulnerability |
nvd |
CVE-2026-66780 |
|
2026-08-18 |
| unknown |
CVE-2026-63643 — MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR hand… |
vulnerability |
nvd |
CVE-2026-63643 |
|
2026-08-18 |
| unknown |
CVE-2026-63642 — MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in de… |
vulnerability |
nvd |
CVE-2026-63642 |
|
2026-08-18 |
| unknown |
CVE-2026-63641 — MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies i… |
vulnerability |
nvd |
CVE-2026-63641 |
|
2026-08-18 |
| medium |
CVE-2026-63640 — MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecret… |
vulnerability |
nvd |
CVE-2026-63640 |
|
2026-08-18 |
| medium |
CVE-2026-61696 — Forem is open source software for building communities. In versions before commit 92eacd16a82cf9007b… |
vulnerability |
nvd |
CVE-2026-61696 |
|
2026-08-18 |
| medium |
CVE-2026-54570 — AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnota… |
vulnerability |
nvd |
CVE-2026-54570 |
|
2026-08-18 |
| high |
CVE-2026-54552 — sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplet… |
vulnerability |
nvd |
CVE-2026-54552 |
|
2026-08-18 |
| unknown |
CVE-2026-53533 — aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rc… |
vulnerability |
nvd |
CVE-2026-53533 |
|
2026-08-18 |
| critical |
CVE-2026-52610 — An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote at… |
vulnerability |
nvd |
CVE-2026-52610 |
|
2026-08-18 |
| critical |
CVE-2026-52608 — An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attack… |
vulnerability |
nvd |
CVE-2026-52608 |
rce |
2026-08-18 |
| medium |
CVE-2026-52607 — A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or e… |
vulnerability |
nvd |
CVE-2026-52607 |
|
2026-08-18 |
| unknown |
CVE-2026-50167 — Kurrier is a modern, self-hosted workspace for email, calendar, contacts, and storage. Prior to 1.2.… |
vulnerability |
nvd |
CVE-2026-50167 |
|
2026-08-18 |
| unknown |
CVE-2026-50161 — libre is a generic library for real-time communications with asynchronous input and output support.… |
vulnerability |
nvd |
CVE-2026-50161 |
|
2026-08-18 |
| high |
CVE-2026-50143 — The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, craw… |
vulnerability |
nvd |
CVE-2026-50143 |
|
2026-08-18 |
| medium |
CVE-2026-49452 — WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped… |
vulnerability |
nvd |
CVE-2026-49452 |
|
2026-08-18 |
| high |
CVE-2026-48508 — Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPer… |
vulnerability |
nvd |
CVE-2026-48508 |
|
2026-08-18 |
| high |
CVE-2026-44472 — Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account ac… |
vulnerability |
nvd |
CVE-2026-44472 |
|
2026-08-18 |
| high |
CVE-2026-32657 — Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRai… |
vulnerability |
nvd |
CVE-2026-32657 |
|
2026-08-18 |
| unknown |
CVE-2026-18392 — Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in… |
vulnerability |
nvd |
CVE-2026-18392 |
|
2026-08-18 |
| high |
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets |
news |
general-news |
|
ics |
2026-08-18 |
| critical |
Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics |
news |
general-news |
|
ransomware |
2026-08-18 |
| high |
CVE-2026-75924 — A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole… |
vulnerability |
nvd |
CVE-2026-75924 |
|
2026-08-18 |
| high |
CVE-2026-75897 — Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of t… |
vulnerability |
nvd |
CVE-2026-75897 |
|
2026-08-18 |