| high |
CVE-2026-75836 — The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.1… |
vulnerability |
nvd |
CVE-2026-75836 |
|
2026-08-18 |
| medium |
CVE-2026-75835 — Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerabili… |
vulnerability |
nvd |
CVE-2026-75835 |
|
2026-08-18 |
| medium |
CVE-2026-75834 — Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss()… |
vulnerability |
nvd |
CVE-2026-75834 |
|
2026-08-18 |
| medium |
CVE-2026-75833 — The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before v… |
vulnerability |
nvd |
CVE-2026-75833 |
phishing |
2026-08-18 |
| medium |
CVE-2026-75832 — The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in… |
vulnerability |
nvd |
CVE-2026-75832 |
|
2026-08-18 |
| high |
CVE-2026-75831 — Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media… |
vulnerability |
nvd |
CVE-2026-75831 |
|
2026-08-18 |
| high |
CVE-2026-75830 — grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path tra… |
vulnerability |
nvd |
CVE-2026-75830 |
|
2026-08-18 |
| high |
CVE-2026-75829 — grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, al… |
vulnerability |
nvd |
CVE-2026-75829 |
|
2026-08-18 |
| high |
CVE-2026-75828 — Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function… |
vulnerability |
nvd |
CVE-2026-75828 |
|
2026-08-18 |
| high |
CVE-2026-75827 — Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare… |
vulnerability |
nvd |
CVE-2026-75827 |
rce |
2026-08-18 |
| low |
CVE-2026-75774 — A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unk… |
vulnerability |
nvd |
CVE-2026-75774 |
|
2026-08-18 |
| medium |
CVE-2026-75107 — Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append… |
vulnerability |
nvd |
CVE-2026-75107 |
|
2026-08-18 |
| medium |
CVE-2026-74908 — Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only… |
vulnerability |
nvd |
CVE-2026-74908 |
|
2026-08-18 |
| medium |
CVE-2026-74907 — Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.p… |
vulnerability |
nvd |
CVE-2026-74907 |
|
2026-08-18 |
| high |
CVE-2026-74906 — SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-… |
vulnerability |
nvd |
CVE-2026-74906 |
|
2026-08-18 |
| high |
CVE-2026-74905 — SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP… |
vulnerability |
nvd |
CVE-2026-74905 |
|
2026-08-18 |
| high |
CVE-2026-74904 — SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kerne… |
vulnerability |
nvd |
CVE-2026-74904 |
|
2026-08-18 |
| medium |
CVE-2026-74903 — SiYuan before v3.7.4 contains an insufficient access control vulnerability in the /api/lute/spinBloc… |
vulnerability |
nvd |
CVE-2026-74903 |
|
2026-08-18 |
| high |
CVE-2026-74902 — SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flo… |
vulnerability |
nvd |
CVE-2026-74902 |
|
2026-08-18 |
| medium |
CVE-2026-5224 — Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technolog… |
vulnerability |
nvd |
CVE-2026-5224 |
|
2026-08-18 |
| high |
CVE-2026-15585 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN… |
vulnerability |
nvd |
CVE-2026-15585 |
|
2026-08-18 |
| unknown |
CISA Adds Four Known Exploited Vulnerabilities to Catalog |
advisory |
cisa-advisories |
|
|
2026-08-18 |
| critical |
Siemens Simcenter Nastran |
advisory |
cisa-advisories, vendor-blogs |
|
ics, rce |
2026-08-18 |
| high |
CISA Malcolm |
advisory |
cisa-advisories, vendor-blogs |
|
phishing, ics |
2026-08-18 |
| unknown |
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025 |
news |
general-news |
|
|
2026-08-18 |
| unknown |
Cyber Incident Disrupts Student Services at UT San Antonio |
news |
general-news |
|
|
2026-08-18 |
| high |
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets |
news |
general-news |
|
supply-chain |
2026-08-18 |
| low |
CVE-2026-75773 — A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the functio… |
vulnerability |
nvd |
CVE-2026-75773 |
|
2026-08-18 |
| critical |
CVE-2026-75627 — Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unaut… |
vulnerability |
nvd |
CVE-2026-75627 |
|
2026-08-18 |
| critical |
CVE-2026-75626 — SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including s… |
vulnerability |
nvd |
CVE-2026-75626 |
|
2026-08-18 |
| medium |
CVE-2026-19608 — A flaw was found in the group policy provider of Keycloak authorization services, which is used to m… |
vulnerability |
nvd |
CVE-2026-19608 |
|
2026-08-18 |
| medium |
CVE-2026-19447 — Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i… |
vulnerability |
nvd |
CVE-2026-19447, CVE-2026-66603, CVE-2026-27365, CVE-2026-66591 |
|
2026-08-18 |
| medium |
Beware of Phishing Emails Disguised as Transaction Receipts |
threat-intel |
otx |
82a7410b7c56f538…, ab707764ad3fc261… |
pdf attachment, remote access, vbs script, transaction receipt lure, living-off-the-land, phishing campaign, screenconnect abuse, screenconnect, ransomware, phishing |
2026-08-18 |
| unknown |
CVE-2026-18929 — Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processi… |
vulnerability |
nvd |
CVE-2026-18929 |
|
2026-08-18 |
| critical |
Three-quarters of Ransomware Attacks Target Mid-Market Firms |
news |
general-news |
|
ransomware |
2026-08-18 |
| unknown |
CVE-2026-43971 — Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directi… |
vulnerability |
nvd |
CVE-2026-43971 |
|
2026-08-18 |
| critical |
CVE-2026-34884 — SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking… |
vulnerability |
nvd |
CVE-2026-34884 |
|
2026-08-18 |
| high |
CVE-2026-15371 — Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the… |
vulnerability |
nvd |
CVE-2026-15371 |
|
2026-08-18 |
| medium |
Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline |
threat-intel |
otx |
ba9d459169a30306… |
vishing, electron-malware, account-enumeration, jailbreak-prompt, telegram-exfiltration, phishing, cryptocurrency, wallet-theft, ai-assisted-development, seed-phrase-exfiltration |
2026-08-18 |
| critical |
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE |
news |
general-news |
|
rce |
2026-08-18 |
| high |
CVE-2026-75091 — The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnera… |
vulnerability |
nvd |
CVE-2026-75091 |
|
2026-08-18 |
| critical |
CVE-2026-15748 — The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up… |
vulnerability |
nvd |
CVE-2026-15748 |
rce |
2026-08-18 |
| medium |
CVE-2026-75151 — A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0.… |
vulnerability |
nvd |
CVE-2026-75151 |
|
2026-08-18 |
| high |
CVE-2026-11801 — The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all… |
vulnerability |
nvd |
CVE-2026-11801 |
|
2026-08-18 |
| critical |
CVE-2026-75094 — A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /… |
vulnerability |
nvd |
CVE-2026-75094 |
|
2026-08-18 |
| medium |
CVE-2026-75093 — A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Te… |
vulnerability |
nvd |
CVE-2026-75093 |
botnet |
2026-08-18 |
| medium |
CVE-2026-75090 — A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. Affected by this issue is the… |
vulnerability |
nvd |
CVE-2026-75090 |
botnet |
2026-08-18 |
| high |
CVE-2026-75089 — A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue… |
vulnerability |
nvd |
CVE-2026-75089 |
|
2026-08-18 |
| medium |
CVE-2026-75088 — A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unkno… |
vulnerability |
nvd |
CVE-2026-75088 |
|
2026-08-18 |
| medium |
CVE-2026-75087 — A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown fu… |
vulnerability |
nvd |
CVE-2026-75087 |
|
2026-08-18 |