| critical |
CVE-2026-65770 — Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed… |
vulnerability |
nvd |
CVE-2026-65770 |
|
2026-08-20 |
| unknown |
CVE-2026-64773 — An attacker that can reach a container's published TCP port may be able to force the host's forwardi… |
vulnerability |
nvd |
CVE-2026-64773 |
|
2026-08-20 |
| critical |
CVE-2026-63509 — Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over… |
vulnerability |
nvd |
CVE-2026-63509 |
|
2026-08-20 |
| medium |
CVE-2026-62945 — TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions a… |
vulnerability |
nvd |
CVE-2026-62945 |
|
2026-08-20 |
| critical |
CVE-2026-62834 — Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attack… |
vulnerability |
nvd |
CVE-2026-62834 |
|
2026-08-20 |
| unknown |
CVE-2026-55893 — Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.… |
vulnerability |
nvd |
CVE-2026-55893, CVE-2026-55894 |
|
2026-08-20 |
| high |
CVE-2026-55765 — CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments.… |
vulnerability |
nvd |
CVE-2026-55765, CVE-2026-55769 |
|
2026-08-20 |
| medium |
CVE-2026-55491 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape m… |
vulnerability |
nvd |
CVE-2026-55491 |
ransomware |
2026-08-20 |
| medium |
CVE-2026-55489 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could s… |
vulnerability |
nvd |
CVE-2026-55489 |
|
2026-08-20 |
| medium |
CVE-2026-55015 — Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny servic… |
vulnerability |
nvd |
CVE-2026-55015 |
|
2026-08-20 |
| high |
CVE-2026-55013 — Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to per… |
vulnerability |
nvd |
CVE-2026-55013 |
|
2026-08-20 |
| medium |
CVE-2026-54509 — TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link… |
vulnerability |
nvd |
CVE-2026-54509 |
|
2026-08-20 |
| unknown |
CVE-2026-54508 — TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before n… |
vulnerability |
nvd |
CVE-2026-54508 |
|
2026-08-20 |
| unknown |
CVE-2026-54505 — TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK int… |
vulnerability |
nvd |
CVE-2026-54505 |
|
2026-08-20 |
| medium |
CVE-2026-54389 — Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser t… |
vulnerability |
nvd |
CVE-2026-54389 |
|
2026-08-20 |
| unknown |
CVE-2026-50192 — Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the… |
vulnerability |
nvd |
CVE-2026-50192 |
|
2026-08-20 |
| high |
CVE-2026-49436 — LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API… |
vulnerability |
nvd |
CVE-2026-49436 |
|
2026-08-20 |
| low |
CVE-2026-49245 — SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline qu… |
vulnerability |
nvd |
CVE-2026-49245 |
phishing |
2026-08-20 |
| medium |
CVE-2026-49244 — SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public we… |
vulnerability |
nvd |
CVE-2026-49244 |
|
2026-08-20 |
| high |
CVE-2026-49217 — Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorizati… |
vulnerability |
nvd |
CVE-2026-49217 |
|
2026-08-20 |
| high |
CVE-2026-46682 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authentica… |
vulnerability |
nvd |
CVE-2026-46682 |
|
2026-08-20 |
| high |
CVE-2026-46355 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebu… |
vulnerability |
nvd |
CVE-2026-46355 |
|
2026-08-20 |
| medium |
CVE-2026-19783 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory co… |
vulnerability |
nvd |
CVE-2026-19783 |
|
2026-08-20 |
| high |
CVE-2026-19449 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unpriv… |
vulnerability |
nvd |
CVE-2026-19449 |
|
2026-08-20 |
| medium |
CVE-2026-19448 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the… |
vulnerability |
nvd |
CVE-2026-19448 |
|
2026-08-20 |
| high |
CVE-2026-19446 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a cr… |
vulnerability |
nvd |
CVE-2026-19446 |
|
2026-08-20 |
| high |
CVE-2026-19442 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtua… |
vulnerability |
nvd |
CVE-2026-19442 |
|
2026-08-20 |
| medium |
CVE-2026-17424 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restr… |
vulnerability |
nvd |
CVE-2026-17424 |
|
2026-08-20 |
| high |
CVE-2026-17171 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary fi… |
vulnerability |
nvd |
CVE-2026-17171 |
|
2026-08-20 |
| high |
CVE-2026-17003 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confid… |
vulnerability |
nvd |
CVE-2026-17003 |
|
2026-08-20 |
| medium |
CVE-2026-16973 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to disclose sensitive ker… |
vulnerability |
nvd |
CVE-2026-16973 |
|
2026-08-20 |
| medium |
CVE-2026-16964 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages an… |
vulnerability |
nvd |
CVE-2026-16964 |
|
2026-08-20 |
| medium |
CVE-2026-16951 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute… |
vulnerability |
nvd |
CVE-2026-16951 |
|
2026-08-20 |
| unknown |
CVE-2025-52182 — The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure… |
vulnerability |
nvd |
CVE-2025-52182 |
|
2026-08-20 |
| medium |
Popular Rust Crates Compromised in Build-Time Supply Chain Attack |
threat-intel |
otx |
cb7778eb6dda9102… |
backdoor, proc-macro1, typosquatting, supply chain attack, proc-macro-en, build-time execution, rust, credential theft, ci/cd compromise, botnet, supply-chain |
2026-08-20 |
| medium |
CVE-2026-77641 — tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. Th… |
vulnerability |
nvd |
CVE-2026-77641 |
|
2026-08-20 |
| low |
CVE-2026-77640 — tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream wit… |
vulnerability |
nvd |
CVE-2026-77640 |
|
2026-08-20 |
| medium |
CVE-2026-77639 — Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many g… |
vulnerability |
nvd |
CVE-2026-77639 |
|
2026-08-20 |
| high |
CVE-2026-77638 — Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous… |
vulnerability |
nvd |
CVE-2026-77638 |
|
2026-08-20 |
| medium |
CVE-2026-77587 — Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object whe… |
vulnerability |
nvd |
CVE-2026-77587 |
|
2026-08-20 |
| high |
CVE-2026-77584 — Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has a… |
vulnerability |
nvd |
CVE-2026-77584 |
|
2026-08-20 |
| medium |
CVE-2026-77506 — Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS. |
vulnerability |
nvd |
CVE-2026-77506 |
|
2026-08-20 |
| unknown |
CVE-2026-76023 — Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed… |
vulnerability |
nvd |
CVE-2026-76023 |
|
2026-08-20 |
| unknown |
CVE-2026-76022 — Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to exe… |
vulnerability |
nvd |
CVE-2026-76022 |
|
2026-08-20 |
| unknown |
CVE-2026-76021 — Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute… |
vulnerability |
nvd |
CVE-2026-76021 |
|
2026-08-20 |
| unknown |
CVE-2026-76020 — Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute a… |
vulnerability |
nvd |
CVE-2026-76020 |
|
2026-08-20 |
| medium |
CVE-2026-76019 — Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacke… |
vulnerability |
nvd |
CVE-2026-76019 |
phishing |
2026-08-20 |
| medium |
CVE-2026-76018 — Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker lev… |
vulnerability |
nvd |
CVE-2026-76018 |
phishing |
2026-08-20 |
| unknown |
CVE-2026-76017 — Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to e… |
vulnerability |
nvd |
CVE-2026-76017 |
|
2026-08-20 |
| unknown |
CVE-2026-75484 — Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows… |
vulnerability |
nvd |
CVE-2026-75484 |
|
2026-08-20 |