| critical |
CVE-2026-50772 — An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via… |
vulnerability |
nvd |
CVE-2026-50772 |
|
2026-08-17 |
| medium |
CVE-2026-50771 — Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to… |
vulnerability |
nvd |
CVE-2026-50771 |
|
2026-08-17 |
| critical |
CVE-2026-50770 — An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges… |
vulnerability |
nvd |
CVE-2026-50770 |
|
2026-08-17 |
| critical |
CVE-2026-50769 — The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Inj… |
vulnerability |
nvd |
CVE-2026-50769 |
|
2026-08-17 |
| critical |
CVE-2026-50768 — File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a r… |
vulnerability |
nvd |
CVE-2026-50768 |
|
2026-08-17 |
| medium |
CVE-2026-48053 — Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoin… |
vulnerability |
nvd |
CVE-2026-48053 |
|
2026-08-17 |
| high |
CVE-2026-46345 — compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 a… |
vulnerability |
nvd |
CVE-2026-46345 |
|
2026-08-17 |
| high |
CVE-2026-33437 — Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. P… |
vulnerability |
nvd |
CVE-2026-33437, CVE-2026-57485 |
|
2026-08-17 |
| high |
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic |
news |
general-news |
|
botnet |
2026-08-17 |
| high |
CVE-2026-9771 — The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On bu… |
vulnerability |
nvd |
CVE-2026-9771 |
|
2026-08-17 |
| unknown |
CVE-2026-68518 — Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_… |
vulnerability |
nvd |
CVE-2026-68518 |
|
2026-08-17 |
| medium |
CVE-2026-68517 — Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins gu… |
vulnerability |
nvd |
CVE-2026-68517 |
|
2026-08-17 |
| unknown |
CVE-2026-61666 — websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driv… |
vulnerability |
nvd |
CVE-2026-61666 |
|
2026-08-17 |
| unknown |
CVE-2026-40145 — A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deploymen… |
vulnerability |
nvd |
CVE-2026-40145 |
|
2026-08-17 |
| medium |
CVE-2026-12630 — Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression code contains an out-of-bounds read in g… |
vulnerability |
nvd |
CVE-2026-12630 |
|
2026-08-17 |
| medium |
CVE-2026-12629 — The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails to acknowledge receive error interrup… |
vulnerability |
nvd |
CVE-2026-12629 |
|
2026-08-17 |
| medium |
CVE-2026-12519 — The WNC-M14A2A LTE-M modem driver mishandles unsolicited %NOTIFYEV: events in on_cmd_socknotifyev()… |
vulnerability |
nvd |
CVE-2026-12519 |
|
2026-08-17 |
| high |
CVE-2026-75060 — In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP too… |
vulnerability |
nvd |
CVE-2026-75060 |
|
2026-08-17 |
| medium |
CVE-2026-75059 — In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible |
vulnerability |
nvd |
CVE-2026-75059 |
|
2026-08-17 |
| medium |
CVE-2026-75058 — In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers |
vulnerability |
nvd |
CVE-2026-75058 |
|
2026-08-17 |
| medium |
CVE-2026-75057 — In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log |
vulnerability |
nvd |
CVE-2026-75057 |
|
2026-08-17 |
| high |
CVE-2026-75056 — In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible |
vulnerability |
nvd |
CVE-2026-75056 |
rce |
2026-08-17 |
| medium |
CVE-2026-75055 — In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE |
vulnerability |
nvd |
CVE-2026-75055 |
|
2026-08-17 |
| medium |
CVE-2026-75054 — In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrus… |
vulnerability |
nvd |
CVE-2026-75054 |
|
2026-08-17 |
| medium |
CVE-2026-75053 — In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint |
vulnerability |
nvd |
CVE-2026-75053 |
|
2026-08-17 |
| low |
CVE-2026-75052 — In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content wa… |
vulnerability |
nvd |
CVE-2026-75052 |
|
2026-08-17 |
| high |
CVE-2026-75051 — In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was po… |
vulnerability |
nvd |
CVE-2026-75051 |
|
2026-08-17 |
| high |
CVE-2026-75050 — In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type par… |
vulnerability |
nvd |
CVE-2026-75050 |
|
2026-08-17 |
| medium |
CVE-2026-75049 — In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted… |
vulnerability |
nvd |
CVE-2026-75049 |
|
2026-08-17 |
| high |
CVE-2026-75048 — In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was po… |
vulnerability |
nvd |
CVE-2026-75048 |
|
2026-08-17 |
| medium |
CVE-2026-75047 — In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the im… |
vulnerability |
nvd |
CVE-2026-75047 |
|
2026-08-17 |
| medium |
CVE-2026-75046 — In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the use… |
vulnerability |
nvd |
CVE-2026-75046 |
|
2026-08-17 |
| critical |
CVE-2026-75045 — In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker c… |
vulnerability |
nvd |
CVE-2026-75045 |
|
2026-08-17 |
| high |
CVE-2026-75044 — In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed… |
vulnerability |
nvd |
CVE-2026-75044 |
|
2026-08-17 |
| medium |
CVE-2026-74858 — A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_ur… |
vulnerability |
nvd |
CVE-2026-74858 |
|
2026-08-17 |
| high |
CVE-2026-73646 — PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rul… |
vulnerability |
nvd |
CVE-2026-73646 |
|
2026-08-17 |
| medium |
CVE-2026-68762 — In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible |
vulnerability |
nvd |
CVE-2026-68762 |
|
2026-08-17 |
| critical |
CVE-2026-64859 — New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management sys… |
vulnerability |
nvd |
CVE-2026-64859, CVE-2026-64865, CVE-2026-64866, CVE-2026-64868, CVE-2026-71479 |
|
2026-08-17 |
| medium |
CVE-2026-59829 — Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1… |
vulnerability |
nvd |
CVE-2026-59829 |
|
2026-08-17 |
| medium |
CVE-2026-55704 — Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0,… |
vulnerability |
nvd |
CVE-2026-55704 |
|
2026-08-17 |
| critical |
CVE-2026-53960 — Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0… |
vulnerability |
nvd |
CVE-2026-53960, CVE-2026-55674 |
|
2026-08-17 |
| unknown |
CVE-2026-40144 — A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privileg… |
vulnerability |
nvd |
CVE-2026-40144 |
|
2026-08-17 |
| unknown |
CVE-2025-27621 — UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.… |
vulnerability |
nvd |
CVE-2025-27621, CVE-2025-27770, CVE-2025-27771, CVE-2025-27772 |
|
2026-08-17 |
| high |
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS |
news |
general-news |
|
botnet |
2026-08-17 |
| unknown |
CVE-2026-73851 — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who co… |
vulnerability |
nvd |
CVE-2026-73851 |
|
2026-08-17 |
| high |
CVE-2026-71567 — In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variable… |
vulnerability |
nvd |
CVE-2026-71567 |
|
2026-08-17 |
| critical |
CVE-2026-71566 — FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware… |
vulnerability |
nvd |
CVE-2026-71566 |
|
2026-08-17 |
| medium |
CVE-2026-16049 — Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify c… |
vulnerability |
nvd |
CVE-2026-16049 |
|
2026-08-17 |
| medium |
CVE-2026-16048 — Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel… |
vulnerability |
nvd |
CVE-2026-16048 |
|
2026-08-17 |
| medium |
CVE-2026-16047 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate that us… |
vulnerability |
nvd |
CVE-2026-16047 |
|
2026-08-17 |