| unknown |
'Turf War' Between Claude Agents Leads to Self-Replicating Malware |
news |
general-news |
|
|
2026-08-17 |
| high |
CVE-2026-75014 — A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability aff… |
vulnerability |
nvd |
CVE-2026-75014 |
|
2026-08-17 |
| medium |
CVE-2026-75013 — A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function se… |
vulnerability |
nvd |
CVE-2026-75013 |
|
2026-08-17 |
| medium |
CVE-2026-75012 — A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by th… |
vulnerability |
nvd |
CVE-2026-75012 |
|
2026-08-17 |
| high |
CVE-2026-74234 — Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achi… |
vulnerability |
nvd |
CVE-2026-74234 |
|
2026-08-17 |
| unknown |
CVE-2026-71858 — Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attack… |
vulnerability |
nvd |
CVE-2026-71858 |
|
2026-08-17 |
| unknown |
CVE-2026-71553 — ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api… |
vulnerability |
nvd |
CVE-2026-71553 |
|
2026-08-17 |
| medium |
CVE-2026-71486 — vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completi… |
vulnerability |
nvd |
CVE-2026-71486 |
|
2026-08-17 |
| critical |
CVE-2026-71472 — A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such a… |
vulnerability |
nvd |
CVE-2026-71472 |
|
2026-08-17 |
| high |
CVE-2026-70495 — A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad pe… |
vulnerability |
nvd |
CVE-2026-70495 |
|
2026-08-17 |
| high |
CVE-2026-68005 — An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via… |
vulnerability |
nvd |
CVE-2026-68005 |
|
2026-08-17 |
| critical |
CVE-2026-68004 — An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitra… |
vulnerability |
nvd |
CVE-2026-68004 |
|
2026-08-17 |
| critical |
CVE-2026-67678 — File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute ar… |
vulnerability |
nvd |
CVE-2026-67678 |
|
2026-08-17 |
| medium |
CVE-2026-63670 — ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() c… |
vulnerability |
nvd |
CVE-2026-63670 |
|
2026-08-17 |
| medium |
CVE-2026-63669 — ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module'… |
vulnerability |
nvd |
CVE-2026-63669 |
|
2026-08-17 |
| medium |
CVE-2026-63667 — ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export… |
vulnerability |
nvd |
CVE-2026-63667 |
|
2026-08-17 |
| high |
CVE-2026-57233 — Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress functi… |
vulnerability |
nvd |
CVE-2026-57233 |
|
2026-08-17 |
| high |
CVE-2026-54758 — Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the expandNppEnvironmentStrs… |
vulnerability |
nvd |
CVE-2026-54758 |
|
2026-08-17 |
| unknown |
CVE-2026-52886 — Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the back… |
vulnerability |
nvd |
CVE-2026-52886 |
|
2026-08-17 |
| critical |
CVE-2026-19478 — GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.… |
vulnerability |
nvd |
CVE-2026-19478, CVE-2026-19650 |
|
2026-08-17 |
| unknown |
Hugging Face Breach Raises Big Questions About AI Security Controls |
news |
general-news |
|
|
2026-08-17 |
| medium |
CVE-2026-75011 — A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the function execAsync of the fil… |
vulnerability |
nvd |
CVE-2026-75011 |
|
2026-08-17 |
| high |
CVE-2026-74238 — TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpac… |
vulnerability |
nvd |
CVE-2026-74238 |
|
2026-08-17 |
| unknown |
CVE-2026-71693 — Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by… |
vulnerability |
nvd |
CVE-2026-71693 |
|
2026-08-17 |
| critical |
CVE-2026-66792 — A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a use… |
vulnerability |
nvd |
CVE-2026-66792 |
|
2026-08-17 |
| high |
CVE-2026-50776 — Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote atta… |
vulnerability |
nvd |
CVE-2026-50776 |
|
2026-08-17 |
| critical |
CVE-2026-50775 — A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the… |
vulnerability |
nvd |
CVE-2026-50775 |
|
2026-08-17 |
| critical |
CVE-2026-50774 — An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Ma… |
vulnerability |
nvd |
CVE-2026-50774 |
|
2026-08-17 |
| high |
CVE-2026-50773 — An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to ex… |
vulnerability |
nvd |
CVE-2026-50773 |
|
2026-08-17 |
| high |
CVE-2026-45698 — Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.… |
vulnerability |
nvd |
CVE-2026-45698 |
|
2026-08-17 |
| unknown |
CVE-2026-17639 — Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condi… |
vulnerability |
nvd |
CVE-2026-17639 |
|
2026-08-17 |
| unknown |
CVE-2026-12553 — HP has identified a potential vulnerability in HP Web Jetadmin (WJA) that may allow an unauthenticat… |
vulnerability |
nvd |
CVE-2026-12553 |
|
2026-08-17 |
| unknown |
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection |
news |
general-news |
|
|
2026-08-17 |
| critical |
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads |
news |
general-news |
|
rce |
2026-08-17 |
| unknown |
CVE-2026-74254 — Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Pag… |
vulnerability |
nvd |
CVE-2026-74254 |
|
2026-08-17 |
| critical |
CVE-2026-74253 — Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in… |
vulnerability |
nvd |
CVE-2026-74253 |
rce |
2026-08-17 |
| high |
CVE-2026-73523 — COVESA Open1722 through 0.9.2 contains an integer truncation vulnerability in acf-can-listener.c tha… |
vulnerability |
nvd |
CVE-2026-73523 |
|
2026-08-17 |
| high |
CVE-2026-73522 — COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthentic… |
vulnerability |
nvd |
CVE-2026-73522 |
|
2026-08-17 |
| medium |
CVE-2026-73424 — Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel ada… |
vulnerability |
nvd |
CVE-2026-73424 |
|
2026-08-17 |
| high |
CVE-2026-71980 — Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the d… |
vulnerability |
nvd |
CVE-2026-71980 |
|
2026-08-17 |
| high |
CVE-2026-71979 — INDI (Instrument Neutral Distributed Interface) indiserver through 2.2.4.2, fixed in commit 96bbd7f,… |
vulnerability |
nvd |
CVE-2026-71979 |
|
2026-08-17 |
| unknown |
CVE-2026-71491 — sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlpars… |
vulnerability |
nvd |
CVE-2026-71491 |
|
2026-08-17 |
| medium |
CVE-2026-68520 — Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in… |
vulnerability |
nvd |
CVE-2026-68520 |
|
2026-08-17 |
| unknown |
CVE-2026-68519 — Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run(… |
vulnerability |
nvd |
CVE-2026-68519 |
|
2026-08-17 |
| high |
CVE-2026-62982 — Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_m… |
vulnerability |
nvd |
CVE-2026-62982 |
|
2026-08-17 |
| high |
CVE-2026-59902 — Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2… |
vulnerability |
nvd |
CVE-2026-59902, CVE-2026-59903, CVE-2026-75596 |
|
2026-08-17 |
| unknown |
CVE-2026-59894 — sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.p… |
vulnerability |
nvd |
CVE-2026-59894 |
|
2026-08-17 |
| high |
CVE-2026-59893 — sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/key… |
vulnerability |
nvd |
CVE-2026-59893 |
|
2026-08-17 |
| unknown |
CVE-2026-54284 — sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction an… |
vulnerability |
nvd |
CVE-2026-54284 |
|
2026-08-17 |
| critical |
CVE-2026-51346 — SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote att… |
vulnerability |
nvd |
CVE-2026-51346 |
|
2026-08-17 |