| high |
CVE-2026-74893 — openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py tha… |
vulnerability |
nvd |
CVE-2026-74893 |
|
2026-08-17 |
| high |
CVE-2026-74892 — openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telem… |
vulnerability |
nvd |
CVE-2026-74892 |
|
2026-08-17 |
| critical |
CVE-2026-74891 — openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server co… |
vulnerability |
nvd |
CVE-2026-74891 |
|
2026-08-17 |
| medium |
CVE-2026-74890 — openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCiph… |
vulnerability |
nvd |
CVE-2026-74890 |
|
2026-08-17 |
| critical |
CVE-2026-74889 — openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normali… |
vulnerability |
nvd |
CVE-2026-74889 |
|
2026-08-17 |
| high |
CVE-2026-74888 — openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with ite… |
vulnerability |
nvd |
CVE-2026-74888 |
|
2026-08-17 |
| low |
CVE-2026-74887 — openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PR… |
vulnerability |
nvd |
CVE-2026-74887 |
|
2026-08-17 |
| critical |
CVE-2026-74886 — openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the Plugin… |
vulnerability |
nvd |
CVE-2026-74886 |
|
2026-08-17 |
| low |
CVE-2026-74885 — openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs mo… |
vulnerability |
nvd |
CVE-2026-74885 |
|
2026-08-17 |
| high |
CVE-2026-74884 — openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path me… |
vulnerability |
nvd |
CVE-2026-74884 |
|
2026-08-17 |
| high |
CVE-2026-74883 — openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbo… |
vulnerability |
nvd |
CVE-2026-74883 |
|
2026-08-17 |
| high |
CVE-2026-74882 — openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the enti… |
vulnerability |
nvd |
CVE-2026-74882 |
|
2026-08-17 |
| medium |
CVE-2026-74881 — openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_cr… |
vulnerability |
nvd |
CVE-2026-74881 |
|
2026-08-17 |
| critical |
CVE-2026-74880 — openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and… |
vulnerability |
nvd |
CVE-2026-74880 |
|
2026-08-17 |
| high |
CVE-2026-74879 — openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready… |
vulnerability |
nvd |
CVE-2026-74879 |
|
2026-08-17 |
| critical |
CVE-2026-74878 — openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection… |
vulnerability |
nvd |
CVE-2026-74878 |
|
2026-08-17 |
| high |
CVE-2026-74877 — openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the… |
vulnerability |
nvd |
CVE-2026-74877 |
|
2026-08-17 |
| critical |
CVE-2026-74876 — openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that cr… |
vulnerability |
nvd |
CVE-2026-74876 |
|
2026-08-17 |
| critical |
CVE-2026-74875 — openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema libra… |
vulnerability |
nvd |
CVE-2026-74875 |
|
2026-08-17 |
| high |
CVE-2026-74874 — openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographi… |
vulnerability |
nvd |
CVE-2026-74874 |
|
2026-08-17 |
| medium |
CVE-2026-74873 — openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in pro… |
vulnerability |
nvd |
CVE-2026-74873 |
|
2026-08-17 |
| critical |
CVE-2026-74872 — openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirl… |
vulnerability |
nvd |
CVE-2026-74872 |
|
2026-08-17 |
| medium |
CVE-2026-74871 — openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mo… |
vulnerability |
nvd |
CVE-2026-74871 |
|
2026-08-17 |
| low |
CVE-2026-74870 — openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm… |
vulnerability |
nvd |
CVE-2026-74870 |
|
2026-08-17 |
| high |
CVE-2026-74869 — stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message hand… |
vulnerability |
nvd |
CVE-2026-74869 |
ransomware |
2026-08-17 |
| high |
CVE-2026-74868 — SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service… |
vulnerability |
nvd |
CVE-2026-74868 |
|
2026-08-17 |
| medium |
CVE-2026-74867 — SiYuan versions before 3.7.4 contain a cross-site request forgery vulnerability in the session-cooki… |
vulnerability |
nvd |
CVE-2026-74867 |
|
2026-08-17 |
| medium |
CVE-2026-74842 — A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452.… |
vulnerability |
nvd |
CVE-2026-74842 |
|
2026-08-17 |
| high |
CVE-2026-74802 — SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-onl… |
vulnerability |
nvd |
CVE-2026-74802 |
|
2026-08-17 |
| high |
CVE-2026-74801 — SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-lin… |
vulnerability |
nvd |
CVE-2026-74801 |
|
2026-08-17 |
| critical |
CVE-2026-74800 — SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when servin… |
vulnerability |
nvd |
CVE-2026-74800 |
|
2026-08-17 |
| critical |
CVE-2026-74799 — SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps w… |
vulnerability |
nvd |
CVE-2026-74799 |
|
2026-08-17 |
| high |
CVE-2026-74798 — SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool.… |
vulnerability |
nvd |
CVE-2026-74798 |
|
2026-08-17 |
| critical |
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access |
news |
general-news |
|
rce |
2026-08-17 |
| high |
CVE-2026-74845 — Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulner… |
vulnerability |
nvd |
CVE-2026-74845 |
|
2026-08-17 |
| high |
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies |
news |
general-news |
|
botnet |
2026-08-17 |
| medium |
CVE-2026-58560 — Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vu… |
vulnerability |
nvd |
CVE-2026-58560, CVE-2026-58561 |
|
2026-08-17 |
| medium |
CVE-2026-49308 — Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vu… |
vulnerability |
nvd |
CVE-2026-49308 |
|
2026-08-17 |
| medium |
CVE-2026-49307 — Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of… |
vulnerability |
nvd |
CVE-2026-49307 |
|
2026-08-17 |
| low |
CVE-2026-49306 — UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerab… |
vulnerability |
nvd |
CVE-2026-49306 |
|
2026-08-17 |
| medium |
CVE-2026-49305 — Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of… |
vulnerability |
nvd |
CVE-2026-49305 |
|
2026-08-17 |
| medium |
CVE-2026-49304 — Permission control vulnerability in the device key management module. Impact: Successful exploitatio… |
vulnerability |
nvd |
CVE-2026-49304 |
|
2026-08-17 |
| medium |
CVE-2026-49303 — Permission control vulnerability in the notification module. Impact: Successful exploitation of this… |
vulnerability |
nvd |
CVE-2026-49303 |
|
2026-08-17 |
| medium |
CVE-2026-49302 — Permission control vulnerability in the notification service module. Impact: Successful exploitation… |
vulnerability |
nvd |
CVE-2026-49302 |
|
2026-08-17 |
| medium |
CVE-2026-49301 — Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vuln… |
vulnerability |
nvd |
CVE-2026-49301 |
|
2026-08-17 |
| unknown |
SafePal Data Breach Hits Tens of Thousands of Customers |
news |
general-news |
|
|
2026-08-17 |
| medium |
CVE-2026-20000 — A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is… |
vulnerability |
nvd |
CVE-2026-20000 |
|
2026-08-17 |
| medium |
CVE-2026-19999 — A security vulnerability has been detected in Open Asset Import Library Assimp Assimp 17c12da. The a… |
vulnerability |
nvd |
CVE-2026-19999 |
|
2026-08-17 |
| medium |
CVE-2026-19998 — A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown f… |
vulnerability |
nvd |
CVE-2026-19998 |
|
2026-08-17 |
| critical |
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware |
news |
general-news |
|
ransomware, apt |
2026-08-17 |