| high |
CVE-2026-72848 — SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documente… |
vulnerability |
nvd |
CVE-2026-72848 |
|
2026-08-20 |
| medium |
CVE-2026-72846 — Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendW… |
vulnerability |
nvd |
CVE-2026-72846 |
|
2026-08-20 |
| critical |
CVE-2026-72843 — The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/m… |
vulnerability |
nvd |
CVE-2026-72843 |
|
2026-08-20 |
| high |
CVE-2026-72818 — The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and app… |
vulnerability |
nvd |
CVE-2026-72818 |
|
2026-08-20 |
| medium |
CVE-2026-70105 — Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose infor… |
vulnerability |
nvd |
CVE-2026-70105 |
|
2026-08-20 |
| high |
CVE-2026-69855 — Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to di… |
vulnerability |
nvd |
CVE-2026-69855 |
|
2026-08-20 |
| critical |
CVE-2026-69851 — Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevat… |
vulnerability |
nvd |
CVE-2026-69851 |
|
2026-08-20 |
| critical |
CVE-2026-69836 — Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute c… |
vulnerability |
nvd |
CVE-2026-69836 |
|
2026-08-20 |
| high |
CVE-2026-69558 — Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized… |
vulnerability |
nvd |
CVE-2026-69558 |
|
2026-08-20 |
| critical |
CVE-2026-69555 — Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a ne… |
vulnerability |
nvd |
CVE-2026-69555 |
|
2026-08-20 |
| high |
CVE-2026-69543 — Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevat… |
vulnerability |
nvd |
CVE-2026-69543 |
|
2026-08-20 |
| high |
CVE-2026-69519 — Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose infor… |
vulnerability |
nvd |
CVE-2026-69519 |
|
2026-08-20 |
| high |
CVE-2026-69419 — Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to exe… |
vulnerability |
nvd |
CVE-2026-69419 |
|
2026-08-20 |
| critical |
CVE-2026-69400 — Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps a… |
vulnerability |
nvd |
CVE-2026-69400 |
|
2026-08-20 |
| critical |
CVE-2026-68782 — Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Da… |
vulnerability |
nvd |
CVE-2026-68782, CVE-2026-68789 |
|
2026-08-20 |
| medium |
CVE-2026-67448 — Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/… |
vulnerability |
nvd |
CVE-2026-67448 |
|
2026-08-20 |
| medium |
CVE-2026-67447 — Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's interna… |
vulnerability |
nvd |
CVE-2026-67447 |
|
2026-08-20 |
| high |
CVE-2026-66800 — Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose… |
vulnerability |
nvd |
CVE-2026-66800 |
|
2026-08-20 |
| critical |
CVE-2026-66309 — Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges ov… |
vulnerability |
nvd |
CVE-2026-66309 |
|
2026-08-20 |
| critical |
CVE-2026-65816 — Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevat… |
vulnerability |
nvd |
CVE-2026-65816 |
|
2026-08-20 |
| critical |
CVE-2026-65801 — Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to e… |
vulnerability |
nvd |
CVE-2026-65801 |
|
2026-08-20 |
| critical |
CVE-2026-65770 — Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed… |
vulnerability |
nvd |
CVE-2026-65770 |
|
2026-08-20 |
| unknown |
CVE-2026-64773 — An attacker that can reach a container's published TCP port may be able to force the host's forwardi… |
vulnerability |
nvd |
CVE-2026-64773 |
|
2026-08-20 |
| critical |
CVE-2026-63509 — Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over… |
vulnerability |
nvd |
CVE-2026-63509 |
|
2026-08-20 |
| medium |
CVE-2026-62945 — TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions a… |
vulnerability |
nvd |
CVE-2026-62945 |
|
2026-08-20 |
| critical |
CVE-2026-62834 — Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attack… |
vulnerability |
nvd |
CVE-2026-62834 |
|
2026-08-20 |
| unknown |
CVE-2026-55893 — Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.… |
vulnerability |
nvd |
CVE-2026-55893, CVE-2026-55894 |
|
2026-08-20 |
| high |
CVE-2026-55765 — CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments.… |
vulnerability |
nvd |
CVE-2026-55765, CVE-2026-55769 |
|
2026-08-20 |
| medium |
CVE-2026-55491 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape m… |
vulnerability |
nvd |
CVE-2026-55491 |
ransomware |
2026-08-20 |
| medium |
CVE-2026-55489 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could s… |
vulnerability |
nvd |
CVE-2026-55489 |
|
2026-08-20 |
| medium |
CVE-2026-55015 — Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny servic… |
vulnerability |
nvd |
CVE-2026-55015 |
|
2026-08-20 |
| high |
CVE-2026-55013 — Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to per… |
vulnerability |
nvd |
CVE-2026-55013 |
|
2026-08-20 |
| medium |
CVE-2026-54509 — TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link… |
vulnerability |
nvd |
CVE-2026-54509 |
|
2026-08-20 |
| unknown |
CVE-2026-54508 — TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before n… |
vulnerability |
nvd |
CVE-2026-54508 |
|
2026-08-20 |
| unknown |
CVE-2026-54505 — TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK int… |
vulnerability |
nvd |
CVE-2026-54505 |
|
2026-08-20 |
| medium |
CVE-2026-54389 — Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser t… |
vulnerability |
nvd |
CVE-2026-54389 |
|
2026-08-20 |
| unknown |
CVE-2026-50192 — Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the… |
vulnerability |
nvd |
CVE-2026-50192 |
|
2026-08-20 |
| high |
CVE-2026-49436 — LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API… |
vulnerability |
nvd |
CVE-2026-49436 |
|
2026-08-20 |
| low |
CVE-2026-49245 — SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline qu… |
vulnerability |
nvd |
CVE-2026-49245 |
phishing |
2026-08-20 |
| medium |
CVE-2026-49244 — SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public we… |
vulnerability |
nvd |
CVE-2026-49244 |
|
2026-08-20 |
| high |
CVE-2026-49217 — Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorizati… |
vulnerability |
nvd |
CVE-2026-49217 |
|
2026-08-20 |
| high |
CVE-2026-46682 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authentica… |
vulnerability |
nvd |
CVE-2026-46682 |
|
2026-08-20 |
| high |
CVE-2026-46355 — BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebu… |
vulnerability |
nvd |
CVE-2026-46355 |
|
2026-08-20 |
| medium |
CVE-2026-19783 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory co… |
vulnerability |
nvd |
CVE-2026-19783 |
|
2026-08-20 |
| high |
CVE-2026-19449 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unpriv… |
vulnerability |
nvd |
CVE-2026-19449 |
|
2026-08-20 |
| medium |
CVE-2026-19448 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the… |
vulnerability |
nvd |
CVE-2026-19448 |
|
2026-08-20 |
| high |
CVE-2026-19446 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a cr… |
vulnerability |
nvd |
CVE-2026-19446 |
|
2026-08-20 |
| high |
CVE-2026-19442 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtua… |
vulnerability |
nvd |
CVE-2026-19442 |
|
2026-08-20 |
| medium |
CVE-2026-17424 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restr… |
vulnerability |
nvd |
CVE-2026-17424 |
|
2026-08-20 |
| high |
CVE-2026-17171 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary fi… |
vulnerability |
nvd |
CVE-2026-17171 |
|
2026-08-20 |