| critical |
CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-17 |
| critical |
CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-17 |
| critical |
CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-17 |
| unknown |
WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover |
news |
general-news |
|
|
2026-08-17 |
| critical |
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More |
news |
general-news |
|
zeroday, supply-chain |
2026-08-17 |
| medium |
CVE-2026-75010 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin… |
vulnerability |
nvd |
CVE-2026-75010 |
|
2026-08-17 |
| medium |
CVE-2026-75007 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to inj… |
vulnerability |
nvd |
CVE-2026-75007 |
|
2026-08-17 |
| medium |
CVE-2026-75006 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS)… |
vulnerability |
nvd |
CVE-2026-75006 |
|
2026-08-17 |
| medium |
CVE-2026-75004 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to… |
vulnerability |
nvd |
CVE-2026-75004 |
|
2026-08-17 |
| medium |
CVE-2026-75003 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute… |
vulnerability |
nvd |
CVE-2026-75003 |
|
2026-08-17 |
| high |
CVE-2026-75002 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desyn… |
vulnerability |
nvd |
CVE-2026-75002 |
|
2026-08-17 |
| medium |
CVE-2026-75000 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG… |
vulnerability |
nvd |
CVE-2026-75000 |
|
2026-08-17 |
| medium |
CVE-2026-74999 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subj… |
vulnerability |
nvd |
CVE-2026-74999 |
|
2026-08-17 |
| high |
CVE-2026-74998 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style S… |
vulnerability |
nvd |
CVE-2026-74998 |
|
2026-08-17 |
| high |
CVE-2026-74997 — In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk pl… |
vulnerability |
nvd |
CVE-2026-74997 |
rce |
2026-08-17 |
| low |
CVE-2026-70412 — Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a… |
vulnerability |
nvd |
CVE-2026-70412 |
|
2026-08-17 |
| unknown |
CVE-2026-18674 — On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attribu… |
vulnerability |
nvd |
CVE-2026-18674 |
|
2026-08-17 |
| high |
CVE-2026-16467 — Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing F… |
vulnerability |
nvd |
CVE-2026-16467 |
|
2026-08-17 |
| critical |
CVE-2026-14564 — Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consul… |
vulnerability |
nvd |
CVE-2026-14564 |
|
2026-08-17 |
| critical |
CVE-2026-74843 — A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerabilit… |
vulnerability |
nvd |
CVE-2026-74843 |
|
2026-08-17 |
| unknown |
CVE-2026-40126 — OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be… |
vulnerability |
nvd |
CVE-2026-40126 |
|
2026-08-17 |
| critical |
CVE-2026-74901 — openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where… |
vulnerability |
nvd |
CVE-2026-74901 |
|
2026-08-17 |
| critical |
CVE-2026-74900 — openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsula… |
vulnerability |
nvd |
CVE-2026-74900 |
|
2026-08-17 |
| critical |
CVE-2026-74899 — openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecut… |
vulnerability |
nvd |
CVE-2026-74899 |
|
2026-08-17 |
| critical |
CVE-2026-74896 — openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPattern… |
vulnerability |
nvd |
CVE-2026-74896 |
|
2026-08-17 |
| critical |
CVE-2026-74895 — openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isol… |
vulnerability |
nvd |
CVE-2026-74895 |
|
2026-08-17 |
| critical |
CVE-2026-74894 — openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token… |
vulnerability |
nvd |
CVE-2026-74894 |
|
2026-08-17 |
| high |
CVE-2026-74893 — openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py tha… |
vulnerability |
nvd |
CVE-2026-74893 |
|
2026-08-17 |
| high |
CVE-2026-74892 — openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telem… |
vulnerability |
nvd |
CVE-2026-74892 |
|
2026-08-17 |
| critical |
CVE-2026-74891 — openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server co… |
vulnerability |
nvd |
CVE-2026-74891 |
|
2026-08-17 |
| medium |
CVE-2026-74890 — openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCiph… |
vulnerability |
nvd |
CVE-2026-74890 |
|
2026-08-17 |
| critical |
CVE-2026-74889 — openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normali… |
vulnerability |
nvd |
CVE-2026-74889 |
|
2026-08-17 |
| high |
CVE-2026-74888 — openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with ite… |
vulnerability |
nvd |
CVE-2026-74888 |
|
2026-08-17 |
| low |
CVE-2026-74887 — openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PR… |
vulnerability |
nvd |
CVE-2026-74887 |
|
2026-08-17 |
| critical |
CVE-2026-74886 — openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the Plugin… |
vulnerability |
nvd |
CVE-2026-74886 |
|
2026-08-17 |
| low |
CVE-2026-74885 — openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs mo… |
vulnerability |
nvd |
CVE-2026-74885 |
|
2026-08-17 |
| high |
CVE-2026-74884 — openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path me… |
vulnerability |
nvd |
CVE-2026-74884 |
|
2026-08-17 |
| high |
CVE-2026-74883 — openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbo… |
vulnerability |
nvd |
CVE-2026-74883 |
|
2026-08-17 |
| high |
CVE-2026-74882 — openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the enti… |
vulnerability |
nvd |
CVE-2026-74882 |
|
2026-08-17 |
| medium |
CVE-2026-74881 — openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_cr… |
vulnerability |
nvd |
CVE-2026-74881 |
|
2026-08-17 |
| critical |
CVE-2026-74880 — openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and… |
vulnerability |
nvd |
CVE-2026-74880 |
|
2026-08-17 |
| high |
CVE-2026-74879 — openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready… |
vulnerability |
nvd |
CVE-2026-74879 |
|
2026-08-17 |
| critical |
CVE-2026-74878 — openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection… |
vulnerability |
nvd |
CVE-2026-74878 |
|
2026-08-17 |
| high |
CVE-2026-74877 — openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the… |
vulnerability |
nvd |
CVE-2026-74877 |
|
2026-08-17 |
| critical |
CVE-2026-74876 — openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that cr… |
vulnerability |
nvd |
CVE-2026-74876 |
|
2026-08-17 |
| critical |
CVE-2026-74875 — openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema libra… |
vulnerability |
nvd |
CVE-2026-74875 |
|
2026-08-17 |
| high |
CVE-2026-74874 — openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographi… |
vulnerability |
nvd |
CVE-2026-74874 |
|
2026-08-17 |
| medium |
CVE-2026-74873 — openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in pro… |
vulnerability |
nvd |
CVE-2026-74873 |
|
2026-08-17 |
| critical |
CVE-2026-74872 — openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirl… |
vulnerability |
nvd |
CVE-2026-74872 |
|
2026-08-17 |
| medium |
CVE-2026-74871 — openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mo… |
vulnerability |
nvd |
CVE-2026-74871 |
|
2026-08-17 |