| unknown |
CVE-2026-11817 — This vulnerability only affects Grafana stacks configured with multiple organizations; single-organi… |
vulnerability |
nvd |
CVE-2026-11817 |
|
2026-08-17 |
| medium |
CVE-2026-10080 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSoc… |
vulnerability |
nvd |
CVE-2026-10080 |
|
2026-08-17 |
| unknown |
Video Call Exploit Chains Two Flaws in Unisoc Modems |
news |
general-news |
|
|
2026-08-17 |
| unknown |
CVE-2026-75531 — Pandora contains a stored cross-site scripting (XSS) vulnerability in the rendering of URL observabl… |
vulnerability |
nvd |
CVE-2026-75531 |
|
2026-08-17 |
| unknown |
CVE-2026-75529 — Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality… |
vulnerability |
nvd |
CVE-2026-75529 |
|
2026-08-17 |
| low |
CVE-2026-75483 — powerlevel10k fails to neutralize control characters in the package.json version field when renderin… |
vulnerability |
nvd |
CVE-2026-75483 |
|
2026-08-17 |
| high |
CVE-2026-75482 — SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that j… |
vulnerability |
nvd |
CVE-2026-75482 |
|
2026-08-17 |
| high |
CVE-2026-75481 — SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when u… |
vulnerability |
nvd |
CVE-2026-75481 |
|
2026-08-17 |
| medium |
CVE-2026-75480 — OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-lev… |
vulnerability |
nvd |
CVE-2026-75480 |
|
2026-08-17 |
| high |
CVE-2026-75479 — JimuReport contains an authentication bypass vulnerability in the report folder template listing end… |
vulnerability |
nvd |
CVE-2026-75479 |
|
2026-08-17 |
| high |
CVE-2026-75111 — Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoi… |
vulnerability |
nvd |
CVE-2026-75111 |
|
2026-08-17 |
| critical |
CVE-2026-75110 — MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is en… |
vulnerability |
nvd |
CVE-2026-75110 |
|
2026-08-17 |
| high |
CVE-2026-75109 — Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the… |
vulnerability |
nvd |
CVE-2026-75109 |
|
2026-08-17 |
| medium |
CVE-2026-75108 — Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN end… |
vulnerability |
nvd |
CVE-2026-75108 |
ransomware |
2026-08-17 |
| critical |
CVE-2026-75106 — OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an em… |
vulnerability |
nvd |
CVE-2026-75106 |
|
2026-08-17 |
| high |
CVE-2026-75105 — phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary… |
vulnerability |
nvd |
CVE-2026-75105 |
|
2026-08-17 |
| medium |
CVE-2026-75104 — Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing atta… |
vulnerability |
nvd |
CVE-2026-75104 |
|
2026-08-17 |
| high |
CVE-2026-75103 — Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allow… |
vulnerability |
nvd |
CVE-2026-75103 |
|
2026-08-17 |
| medium |
CVE-2026-73560 — vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMu… |
vulnerability |
nvd |
CVE-2026-73560 |
|
2026-08-17 |
| high |
CVE-2026-73410 — Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outbo… |
vulnerability |
nvd |
CVE-2026-73410 |
|
2026-08-17 |
| high |
CVE-2026-71518 — Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download rou… |
vulnerability |
nvd |
CVE-2026-71518 |
|
2026-08-17 |
| medium |
CVE-2026-68765 — hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePas… |
vulnerability |
nvd |
CVE-2026-68765 |
|
2026-08-17 |
| critical |
CVE-2026-67967 — Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary… |
vulnerability |
nvd |
CVE-2026-67967 |
|
2026-08-17 |
| critical |
CVE-2026-67966 — Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activ… |
vulnerability |
nvd |
CVE-2026-67966 |
|
2026-08-17 |
| critical |
CVE-2026-67965 — An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the… |
vulnerability |
nvd |
CVE-2026-67965 |
|
2026-08-17 |
| critical |
CVE-2026-67926 — An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Param… |
vulnerability |
nvd |
CVE-2026-67926 |
|
2026-08-17 |
| medium |
CVE-2026-67925 — Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrar… |
vulnerability |
nvd |
CVE-2026-67925 |
|
2026-08-17 |
| critical |
CVE-2026-67917 — zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup res… |
vulnerability |
nvd |
CVE-2026-67917 |
|
2026-08-17 |
| critical |
CVE-2026-66795 — A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto… |
vulnerability |
nvd |
CVE-2026-66795 |
|
2026-08-17 |
| medium |
CVE-2026-65976 — Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a conne… |
vulnerability |
nvd |
CVE-2026-65976 |
|
2026-08-17 |
| critical |
CVE-2026-65974 — ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0,… |
vulnerability |
nvd |
CVE-2026-65974 |
rce |
2026-08-17 |
| high |
CVE-2026-65832 — Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthe… |
vulnerability |
nvd |
CVE-2026-65832 |
|
2026-08-17 |
| high |
CVE-2026-65822 — ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0,… |
vulnerability |
nvd |
CVE-2026-65822 |
|
2026-08-17 |
| critical |
CVE-2026-65640 — WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file uploa… |
vulnerability |
nvd |
CVE-2026-65640 |
rce |
2026-08-17 |
| high |
CVE-2026-64657 — Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector… |
vulnerability |
nvd |
CVE-2026-64657 |
|
2026-08-17 |
| high |
CVE-2026-63409 — Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malic… |
vulnerability |
nvd |
CVE-2026-63409 |
|
2026-08-17 |
| high |
CVE-2026-54356 — Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/u… |
vulnerability |
nvd |
CVE-2026-54356 |
|
2026-08-17 |
| medium |
CVE-2026-54336 — JumpServer is an open source bastion host and an operation and maintenance security audit system. Fr… |
vulnerability |
nvd |
CVE-2026-54336 |
|
2026-08-17 |
| critical |
CVE-2026-47698 — vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.j… |
vulnerability |
nvd |
CVE-2026-47698 |
|
2026-08-17 |
| critical |
CVE-2026-47686 — vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbo… |
vulnerability |
nvd |
CVE-2026-47686 |
|
2026-08-17 |
| unknown |
CVE-2026-47683 — vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in l… |
vulnerability |
nvd |
CVE-2026-47683 |
|
2026-08-17 |
| medium |
CVE-2026-44845 — JumpServer is an open source bastion host and an operation and maintenance security audit system. Pr… |
vulnerability |
nvd |
CVE-2026-44845, CVE-2026-44846 |
ransomware |
2026-08-17 |
| medium |
CVE-2026-40506 — OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php inter… |
vulnerability |
nvd |
CVE-2026-40506 |
|
2026-08-17 |
| critical |
CVE-2026-39254 — Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execut… |
vulnerability |
nvd |
CVE-2026-39254, CVE-2026-39255 |
|
2026-08-17 |
| unknown |
CVE-2026-35219 — Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/s… |
vulnerability |
nvd |
CVE-2026-35219 |
|
2026-08-17 |
| high |
CVE-2026-34789 — FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/Prope… |
vulnerability |
nvd |
CVE-2026-34789 |
|
2026-08-17 |
| high |
CVE-2026-34399 — FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCA… |
vulnerability |
nvd |
CVE-2026-34399 |
|
2026-08-17 |
| high |
CVE-2026-34398 — FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mo… |
vulnerability |
nvd |
CVE-2026-34398 |
|
2026-08-17 |
| high |
CVE-2026-19589 — Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow uni… |
vulnerability |
nvd |
CVE-2026-19589 |
|
2026-08-17 |
| unknown |
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects |
news |
general-news |
|
|
2026-08-17 |