| high |
CVE-2026-66582 — Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions. |
vulnerability |
nvd |
CVE-2026-66582 |
|
2026-08-20 |
| high |
CVE-2026-66581 — Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. |
vulnerability |
nvd |
CVE-2026-66581 |
|
2026-08-20 |
| high |
CVE-2026-28150 — Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions. |
vulnerability |
nvd |
CVE-2026-28150 |
|
2026-08-20 |
| medium |
CVE-2025-62307 — HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weak… |
vulnerability |
nvd |
CVE-2025-62307 |
|
2026-08-20 |
| medium |
CVE-2025-53999 — Unauthenticated Broken Access Control in Altair <= 5.2.2 versions. |
vulnerability |
nvd |
CVE-2025-53999 |
|
2026-08-20 |
| critical |
CVE-2025-15689 — Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. |
vulnerability |
nvd |
CVE-2025-15689 |
|
2026-08-20 |
| critical |
CVE-2025-15688 — Unauthenticated SQL Injection in Capella <= 2.5.5 versions. |
vulnerability |
nvd |
CVE-2025-15688 |
|
2026-08-20 |
| high |
CVE-2025-15637 — Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. |
vulnerability |
nvd |
CVE-2025-15637 |
|
2026-08-20 |
| unknown |
Citrix urges admins to patch new NetScaler flaws as soon as possible |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments |
news |
general-news |
|
|
2026-08-20 |
| high |
Johnson Controls Simplex Incident Manager |
advisory |
cisa-advisories, vendor-blogs |
|
phishing, ics |
2026-08-20 |
| unknown |
CISA Adds Two Known Exploited Vulnerabilities to Catalog |
advisory |
cisa-advisories |
|
|
2026-08-20 |
| medium |
Back-to-School Cyber Risks Surge as Education Remains the World's Most Attacked Sector |
threat-intel |
otx |
6d0bd9615d730b0b… |
student targeting, education sector, phishing campaigns, back-to-school, credential theft, domain registration, apac attacks, phishing |
2026-08-20 |
| medium |
Blend between Banking Malware & Spyware |
threat-intel |
otx |
feea425cde1223fe…, 2b24e1e154eb93e5… |
wi-fi mesh relay, ukraine targeted, android, spyware, device takeover, manic, banking trojan, cryptocurrency theft, botnet, infostealer |
2026-08-20 |
| unknown |
Why "Shady AI" is Security's Next Big Governance Problem |
news |
general-news |
|
|
2026-08-20 |
| unknown |
CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices |
news |
general-news |
|
|
2026-08-20 |
| unknown |
Corero brings cloud-based AI threat analysis to SmartWall ONE |
news |
general-news |
|
|
2026-08-20 |
| medium |
CVE-2026-77067 — The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied ur… |
vulnerability |
nvd |
CVE-2026-77067 |
|
2026-08-20 |
| medium |
CVE-2026-77066 — The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplie… |
vulnerability |
nvd |
CVE-2026-77066 |
|
2026-08-20 |
| unknown |
CVE-2026-77026 — Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.… |
vulnerability |
nvd |
CVE-2026-77026 |
|
2026-08-20 |
| medium |
CVE-2026-73199 — A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a n… |
vulnerability |
nvd |
CVE-2026-73199 |
|
2026-08-20 |
| high |
CVE-2026-73198 — A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `… |
vulnerability |
nvd |
CVE-2026-73198 |
|
2026-08-20 |
| high |
CVE-2026-73197 — A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by se… |
vulnerability |
nvd |
CVE-2026-73197 |
|
2026-08-20 |
| medium |
CVE-2026-73196 — A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by su… |
vulnerability |
nvd |
CVE-2026-73196 |
|
2026-08-20 |
| critical |
CVE-2026-13097 — A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos pri… |
vulnerability |
nvd |
CVE-2026-13097 |
|
2026-08-20 |
| critical |
CVE-2026-11861 — A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Dire… |
vulnerability |
nvd |
CVE-2026-11861 |
|
2026-08-20 |
| unknown |
CISA warns of hackers exploiting critical MLflow vulnerability |
news |
general-news |
|
|
2026-08-20 |
| unknown |
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands |
news |
general-news |
|
|
2026-08-20 |
| high |
ICS Operators Warned of AI-Driven Attacks on Siemens PLCs |
news |
general-news |
|
ics |
2026-08-20 |
| medium |
Fake Gemini installer delivers Vidar infostealer via Google Colab lure |
news |
general-news |
|
infostealer |
2026-08-20 |
| unknown |
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud |
news |
general-news |
|
|
2026-08-20 |
| high |
CVE-2026-18917 — A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerabil… |
vulnerability |
nvd |
CVE-2026-18917 |
|
2026-08-20 |
| unknown |
New Manic Android malware can exfiltrate data through nearby devices |
news |
general-news |
|
|
2026-08-20 |
| high |
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities |
advisory |
vendor-blogs |
|
botnet |
2026-08-20 |
| unknown |
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps |
news |
general-news |
|
|
2026-08-20 |
| critical |
Critical Zimbra RCE flaw now actively exploited in attacks |
news |
general-news |
|
rce |
2026-08-20 |
| medium |
Def Con Attendees Targeted by Persistent Phishing Campaign |
news |
general-news |
|
phishing |
2026-08-20 |
| unknown |
NIST offers resource-constrained BACS operators practical steps to address OT cybersecurity threats and risks |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| unknown |
Bitdefender traces SilkParasite cyberespionage campaign across Central Asia to seven RAT families, China-nexus tooling |
advisory |
vendor-blogs |
|
|
2026-08-20 |
| medium |
CVE-2026-77014 — A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator… |
vulnerability |
nvd |
CVE-2026-77014 |
|
2026-08-20 |
| unknown |
CVE-2026-76610 — Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment co… |
vulnerability |
nvd |
CVE-2026-76610 |
|
2026-08-20 |
| medium |
CVE-2026-14953 — A low-privileged remote attacker can enumerate all configured users and identify which accounts hold… |
vulnerability |
nvd |
CVE-2026-14953 |
|
2026-08-20 |
| high |
CVE-2026-14952 — An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the… |
vulnerability |
nvd |
CVE-2026-14952 |
transport |
2026-08-20 |
| high |
CVE-2026-14951 — An low privileged remote attacker can cause authenticated users to perform unintended actions in the… |
vulnerability |
nvd |
CVE-2026-14951 |
|
2026-08-20 |
| critical |
CVE-2026-14950 — An unauthenticated remote attacker in possession of a valid session identifier is able to continue u… |
vulnerability |
nvd |
CVE-2026-14950 |
|
2026-08-20 |
| medium |
CVE-2026-14949 — A low privileged remote attacker with a valid session can submit a request to the user creation func… |
vulnerability |
nvd |
CVE-2026-14949 |
|
2026-08-20 |
| high |
CVE-2026-14948 — A low privileged remote attacker can hijack an active administrative session without needing to know… |
vulnerability |
nvd |
CVE-2026-14948 |
|
2026-08-20 |
| high |
CVE-2026-14947 — A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal se… |
vulnerability |
nvd |
CVE-2026-14947 |
|
2026-08-20 |