| unknown |
CVE-2026-74836 — Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unaut… |
vulnerability |
nvd |
CVE-2026-74836 |
|
2026-08-20 |
| high |
CVE-2026-73137 — A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Mana… |
vulnerability |
nvd |
CVE-2026-73137 |
|
2026-08-20 |
| high |
CVE-2026-73040 — Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in va… |
vulnerability |
nvd |
CVE-2026-73040 |
|
2026-08-20 |
| critical |
CVE-2026-71485 — Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies… |
vulnerability |
nvd |
CVE-2026-71485 |
|
2026-08-20 |
| unknown |
CVE-2026-70654 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applicati… |
vulnerability |
nvd |
CVE-2026-70654 |
|
2026-08-20 |
| unknown |
CVE-2026-70653 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-s… |
vulnerability |
nvd |
CVE-2026-70653 |
|
2026-08-20 |
| unknown |
CVE-2026-70651 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips b… |
vulnerability |
nvd |
CVE-2026-70651, CVE-2026-70652 |
|
2026-08-20 |
| critical |
CVE-2026-69242 — libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted… |
vulnerability |
nvd |
CVE-2026-69242 |
rce |
2026-08-20 |
| medium |
CVE-2026-68921 — DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpola… |
vulnerability |
nvd |
CVE-2026-68921 |
|
2026-08-20 |
| critical |
CVE-2026-67567 — A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a ten… |
vulnerability |
nvd |
CVE-2026-67567 |
|
2026-08-20 |
| medium |
CVE-2026-67446 — Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-s… |
vulnerability |
nvd |
CVE-2026-67446 |
|
2026-08-20 |
| medium |
CVE-2026-67445 — Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP command… |
vulnerability |
nvd |
CVE-2026-67445 |
|
2026-08-20 |
| high |
CVE-2026-53804 — OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encry… |
vulnerability |
nvd |
CVE-2026-53804 |
|
2026-08-20 |
| unknown |
CVE-2026-52021 — An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remote attacker to obtain sensitiv… |
vulnerability |
nvd |
CVE-2026-52021 |
|
2026-08-20 |
| unknown |
CVE-2026-43798 — A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write… |
vulnerability |
nvd |
CVE-2026-43798 |
|
2026-08-20 |
| unknown |
CVE-2026-19755 — NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing a… |
vulnerability |
nvd |
CVE-2026-19755 |
|
2026-08-20 |
| high |
CVE-2026-18420 — Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards a… |
vulnerability |
nvd |
CVE-2026-18420 |
rce |
2026-08-20 |
| unknown |
New CUSTODY Framework Constrains AI Agents Inside the Network |
news |
general-news |
|
|
2026-08-20 |
| high |
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads |
news |
general-news |
|
supply-chain |
2026-08-20 |
| low |
CVE-2026-77151 — A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the func… |
vulnerability |
nvd |
CVE-2026-77151 |
|
2026-08-20 |
| medium |
CVE-2026-75910 — Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Fede… |
vulnerability |
nvd |
CVE-2026-75910 |
|
2026-08-20 |
| medium |
CVE-2026-72861 — The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inv… |
vulnerability |
nvd |
CVE-2026-72861 |
|
2026-08-20 |
| unknown |
China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware |
news |
general-news |
|
|
2026-08-20 |
| unknown |
CVE-2026-9033 — An unauthenticated attacker with network access to the captive portal service of an affected device… |
vulnerability |
nvd |
CVE-2026-9033 |
|
2026-08-20 |
| critical |
CVE-2026-77148 — A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the fi… |
vulnerability |
nvd |
CVE-2026-77148 |
|
2026-08-20 |
| medium |
CVE-2026-75514 — BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklis… |
vulnerability |
nvd |
CVE-2026-75514 |
|
2026-08-20 |
| medium |
CVE-2026-72854 — msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_… |
vulnerability |
nvd |
CVE-2026-72854 |
|
2026-08-20 |
| high |
CVE-2026-72852 — hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configur… |
vulnerability |
nvd |
CVE-2026-72852 |
|
2026-08-20 |
| critical |
CVE-2026-66788 — A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vu… |
vulnerability |
nvd |
CVE-2026-66788 |
|
2026-08-20 |
| high |
CVE-2026-66787 — A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes.… |
vulnerability |
nvd |
CVE-2026-66787 |
|
2026-08-20 |
| critical |
CVE-2026-66785 — A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect ne… |
vulnerability |
nvd |
CVE-2026-66785 |
|
2026-08-20 |
| unknown |
CVE-2026-66002 — Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-… |
vulnerability |
nvd |
CVE-2026-66002 |
|
2026-08-20 |
| unknown |
CVE-2026-66001 — Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and aut… |
vulnerability |
nvd |
CVE-2026-66001 |
|
2026-08-20 |
| medium |
CVE-2026-64777 — A malicious builder peer may be able to request an in-context file by name from the host and receive… |
vulnerability |
nvd |
CVE-2026-64777 |
|
2026-08-20 |
| unknown |
CVE-2026-63654 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted fr… |
vulnerability |
nvd |
CVE-2026-63654 |
|
2026-08-20 |
| unknown |
CVE-2026-62315 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_… |
vulnerability |
nvd |
CVE-2026-62315 |
|
2026-08-20 |
| high |
CVE-2026-53583 — libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a… |
vulnerability |
nvd |
CVE-2026-53583, CVE-2026-53584, CVE-2026-53585, CVE-2026-53586, CVE-2026-53587 |
|
2026-08-20 |
| unknown |
CVE-2026-53569 — Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted to… |
vulnerability |
nvd |
CVE-2026-53569 |
|
2026-08-20 |
| unknown |
CVE-2026-50190 — Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in… |
vulnerability |
nvd |
CVE-2026-50190 |
|
2026-08-20 |
| low |
CVE-2026-49996 — SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle s… |
vulnerability |
nvd |
CVE-2026-49996 |
|
2026-08-20 |
| medium |
CVE-2026-43678 — An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingb… |
vulnerability |
nvd |
CVE-2026-43678 |
|
2026-08-20 |
| unknown |
CVE-2026-19683 — A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During com… |
vulnerability |
nvd |
CVE-2026-19683 |
|
2026-08-20 |
| unknown |
CVE-2026-19586 — A pre-authentication OS command injection vulnerability has been identified in Omada gateways config… |
vulnerability |
nvd |
CVE-2026-19586 |
|
2026-08-20 |
| unknown |
CVE-2026-15743 — Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable… |
vulnerability |
nvd |
CVE-2026-15743 |
|
2026-08-20 |
| medium |
CVE-2026-77036 — A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailCon… |
vulnerability |
nvd |
CVE-2026-77036 |
|
2026-08-20 |
| high |
CVE-2026-77031 — A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreat… |
vulnerability |
nvd |
CVE-2026-77031 |
|
2026-08-20 |
| high |
CVE-2026-76641 — Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger me… |
vulnerability |
nvd |
CVE-2026-76641 |
|
2026-08-20 |
| medium |
CVE-2026-73259 — Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a… |
vulnerability |
nvd |
CVE-2026-73259 |
|
2026-08-20 |
| medium |
CVE-2026-73258 — Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a… |
vulnerability |
nvd |
CVE-2026-73258 |
|
2026-08-20 |
| critical |
CVE-2026-73257 — Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthentica… |
vulnerability |
nvd |
CVE-2026-73257 |
|
2026-08-20 |