| medium |
CVE-2026-75054 — In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrus… |
vulnerability |
nvd |
CVE-2026-75054 |
|
2026-08-17 |
| medium |
CVE-2026-75053 — In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint |
vulnerability |
nvd |
CVE-2026-75053 |
|
2026-08-17 |
| low |
CVE-2026-75052 — In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content wa… |
vulnerability |
nvd |
CVE-2026-75052 |
|
2026-08-17 |
| high |
CVE-2026-75051 — In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was po… |
vulnerability |
nvd |
CVE-2026-75051 |
|
2026-08-17 |
| high |
CVE-2026-75050 — In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type par… |
vulnerability |
nvd |
CVE-2026-75050 |
|
2026-08-17 |
| medium |
CVE-2026-75049 — In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted… |
vulnerability |
nvd |
CVE-2026-75049 |
|
2026-08-17 |
| high |
CVE-2026-75048 — In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was po… |
vulnerability |
nvd |
CVE-2026-75048 |
|
2026-08-17 |
| medium |
CVE-2026-75047 — In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the im… |
vulnerability |
nvd |
CVE-2026-75047 |
|
2026-08-17 |
| medium |
CVE-2026-75046 — In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the use… |
vulnerability |
nvd |
CVE-2026-75046 |
|
2026-08-17 |
| critical |
CVE-2026-75045 — In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker c… |
vulnerability |
nvd |
CVE-2026-75045 |
|
2026-08-17 |
| high |
CVE-2026-75044 — In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed… |
vulnerability |
nvd |
CVE-2026-75044 |
|
2026-08-17 |
| medium |
CVE-2026-74858 — A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_ur… |
vulnerability |
nvd |
CVE-2026-74858 |
|
2026-08-17 |
| high |
CVE-2026-73646 — PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rul… |
vulnerability |
nvd |
CVE-2026-73646 |
|
2026-08-17 |
| medium |
CVE-2026-68762 — In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible |
vulnerability |
nvd |
CVE-2026-68762 |
|
2026-08-17 |
| critical |
CVE-2026-64859 — New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management sys… |
vulnerability |
nvd |
CVE-2026-64859, CVE-2026-64865, CVE-2026-64866, CVE-2026-64868, CVE-2026-71479 |
|
2026-08-17 |
| medium |
CVE-2026-59829 — Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1… |
vulnerability |
nvd |
CVE-2026-59829 |
|
2026-08-17 |
| medium |
CVE-2026-55704 — Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0,… |
vulnerability |
nvd |
CVE-2026-55704 |
|
2026-08-17 |
| critical |
CVE-2026-53960 — Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0… |
vulnerability |
nvd |
CVE-2026-53960, CVE-2026-55674 |
|
2026-08-17 |
| unknown |
CVE-2026-40144 — A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privileg… |
vulnerability |
nvd |
CVE-2026-40144 |
|
2026-08-17 |
| unknown |
CVE-2025-27621 — UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.… |
vulnerability |
nvd |
CVE-2025-27621, CVE-2025-27770, CVE-2025-27771, CVE-2025-27772 |
|
2026-08-17 |
| high |
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS |
news |
general-news |
|
botnet |
2026-08-17 |
| unknown |
CVE-2026-73851 — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who co… |
vulnerability |
nvd |
CVE-2026-73851 |
|
2026-08-17 |
| high |
CVE-2026-71567 — In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variable… |
vulnerability |
nvd |
CVE-2026-71567 |
|
2026-08-17 |
| critical |
CVE-2026-71566 — FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware… |
vulnerability |
nvd |
CVE-2026-71566 |
|
2026-08-17 |
| medium |
CVE-2026-16049 — Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify c… |
vulnerability |
nvd |
CVE-2026-16049 |
|
2026-08-17 |
| medium |
CVE-2026-16048 — Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel… |
vulnerability |
nvd |
CVE-2026-16048 |
|
2026-08-17 |
| medium |
CVE-2026-16047 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate that us… |
vulnerability |
nvd |
CVE-2026-16047 |
|
2026-08-17 |
| medium |
CVE-2026-16046 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on wr… |
vulnerability |
nvd |
CVE-2026-16046 |
ransomware |
2026-08-17 |
| medium |
CVE-2026-16045 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauth… |
vulnerability |
nvd |
CVE-2026-16045 |
|
2026-08-17 |
| medium |
CVE-2026-16044 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving… |
vulnerability |
nvd |
CVE-2026-16044 |
|
2026-08-17 |
| medium |
CVE-2026-15754 — Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint f… |
vulnerability |
nvd |
CVE-2026-15754 |
|
2026-08-17 |
| unknown |
CVE-2026-13202 — A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue a… |
vulnerability |
nvd |
CVE-2026-13202 |
|
2026-08-17 |
| medium |
CVE-2026-10527 — Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile Schem… |
vulnerability |
nvd |
CVE-2026-10527 |
|
2026-08-17 |
| critical |
Projextor: Abusing Electron in Trojanized Productivity Applications |
threat-intel |
otx |
e7bc36c7345b3894…, b648ec0880e9f542… |
javascript execution, trojanized software, impersonation websites, desktop capture, projextor, productivity applications, tamperedchef, electron framework |
2026-08-17 |
| critical |
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2 |
threat-intel |
otx |
45.158.196.184, 45.158.196.23 | 20675a659c338f72… |
github c2, backdoor, clickfix, oyster, initial access broker, lactrodectus, rust-based, dll sideloading, c2looper, ransomware, botnet |
2026-08-17 |
| medium |
Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor |
threat-intel |
otx |
38.60.244.141 | daeac66441b88ba2…, b9622eb982f7c8b9… |
vhd file, quic protocol, cloudflare workers, china-nexus, quicagent, operation quicsilver, go backdoor, myanmar diplomats, botnet |
2026-08-17 |
| medium |
CVE-2026-59911 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into L… |
vulnerability |
nvd |
CVE-2026-59911 |
|
2026-08-17 |
| high |
CVE-2026-56685 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elemen… |
vulnerability |
nvd |
CVE-2026-56685, CVE-2026-56686, CVE-2026-59910 |
|
2026-08-17 |
| high |
CVE-2026-56090 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerab… |
vulnerability |
nvd |
CVE-2026-56090 |
|
2026-08-17 |
| high |
CVE-2026-56089 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privil… |
vulnerability |
nvd |
CVE-2026-56089, CVE-2026-59909 |
|
2026-08-17 |
| high |
CVE-2026-19693 — extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and nev… |
vulnerability |
nvd |
CVE-2026-19693 |
|
2026-08-17 |
| high |
CVE-2026-16471 — Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Fun… |
vulnerability |
nvd |
CVE-2026-16471 |
|
2026-08-17 |
| high |
CVE-2026-16139 — In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zon… |
vulnerability |
nvd |
CVE-2026-16139 |
rce |
2026-08-17 |
| high |
CVE-2026-16138 — In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of… |
vulnerability |
nvd |
CVE-2026-16138 |
|
2026-08-17 |
| high |
CVE-2026-16137 — In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credential… |
vulnerability |
nvd |
CVE-2026-16137 |
|
2026-08-17 |
| high |
CVE-2026-15218 — A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. Th… |
vulnerability |
nvd |
CVE-2026-15218 |
rce |
2026-08-17 |
| critical |
CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-17 |
| unknown |
CVE-2026-62886 .NET Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-17 |
| unknown |
CVE-2026-58612 PowerShell Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-17 |
| critical |
CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-17 |