| high |
CVE-2026-14946 — A high privileged remote attacker can upload a .php file and then request it directly from /uploads/… |
vulnerability |
nvd |
CVE-2026-14946 |
|
2026-08-20 |
| unknown |
CVE-2026-76569 — Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1… |
vulnerability |
nvd |
CVE-2026-76569 |
|
2026-08-20 |
| unknown |
CVE-2026-76565 — Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Car… |
vulnerability |
nvd |
CVE-2026-76565 |
|
2026-08-20 |
| unknown |
CVE-2026-76564 — Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0… |
vulnerability |
nvd |
CVE-2026-76564 |
|
2026-08-20 |
| unknown |
CVE-2026-75948 — Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The fronten… |
vulnerability |
nvd |
CVE-2026-75948 |
|
2026-08-20 |
| unknown |
CVE-2025-14601 — An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative… |
vulnerability |
nvd |
CVE-2025-14601 |
|
2026-08-20 |
| medium |
41 deceptive download sites show a real link, then send you somewhere else |
threat-intel |
otx |
9a3f6e69c12cb814…, c0ecbd201cc92afd… |
affiliate fraud, deceptive downloads, fake software sites, bait-and-switch, grand media, download studio, javascript redirection, fakembam, ransomware |
2026-08-20 |
| unknown |
CVE-2026-71368 — F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged… |
vulnerability |
nvd |
CVE-2026-71368 |
|
2026-08-20 |
| unknown |
CVE-2026-14163 — In affected versions of Octopus Server under certain circumstances it is possible for sensitive vari… |
vulnerability |
nvd |
CVE-2026-14163 |
|
2026-08-20 |
| unknown |
CVE-2025-14602 — The application generates uploaded file names using a weak and predictable method based on the reque… |
vulnerability |
nvd |
CVE-2025-14602 |
|
2026-08-20 |
| high |
SilkParasite: Tracking a China-Nexus APT Across Central Asia |
threat-intel |
otx |
193.29.56.216 | ff22419b8ec39945…, ff33a3be2d497d93… |
dll sideloading, cookietagrat, china-nexus apt, shadowpad, deed rat, spicerat, nodeedgerat, cyberespionage, google drive c2, goginrat, nomadrat, government targeting, central asia, drivesilkrat, bloodalchemy, silkparasite, apt, phishing, botnet |
2026-08-20 |
| unknown |
Microsoft says August Windows updates may cause gaming issues |
news |
general-news |
|
|
2026-08-20 |
| high |
CVE-2026-75963 — The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up t… |
vulnerability |
nvd |
CVE-2026-75963 |
|
2026-08-20 |
| critical |
CVE-2026-75860 — The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verifica… |
vulnerability |
nvd |
CVE-2026-75860 |
|
2026-08-20 |
| medium |
CVE-2026-74992 — The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives u… |
vulnerability |
nvd |
CVE-2026-74992 |
rce |
2026-08-20 |
| low |
CVE-2026-73542 — Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle at… |
vulnerability |
nvd |
CVE-2026-73542 |
|
2026-08-20 |
| low |
CVE-2026-19699 — The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of it… |
vulnerability |
nvd |
CVE-2026-19699 |
|
2026-08-20 |
| medium |
CVE-2026-19697 — The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload… |
vulnerability |
nvd |
CVE-2026-19697 |
|
2026-08-20 |
| medium |
CVE-2026-19615 — The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG f… |
vulnerability |
nvd |
CVE-2026-19615 |
|
2026-08-20 |
| medium |
CVE-2026-17153 — The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all version… |
vulnerability |
nvd |
CVE-2026-17153 |
|
2026-08-20 |
| high |
CVE-2026-15049 — The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a… |
vulnerability |
nvd |
CVE-2026-15049 |
rce |
2026-08-20 |
| medium |
CVE-2026-13405 — The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom w… |
vulnerability |
nvd |
CVE-2026-13405 |
ransomware |
2026-08-20 |
| critical |
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code |
news |
general-news |
|
rce |
2026-08-20 |
| medium |
CVE-2026-76957 — libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-… |
vulnerability |
nvd |
CVE-2026-76957 |
|
2026-08-20 |
| medium |
CVE-2026-76956 — In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to ins… |
vulnerability |
nvd |
CVE-2026-76956 |
|
2026-08-20 |
| high |
CVE-2026-19582 — In binutils 2.46.1 and prior versions, a victim who opens a crafted PE file using binutils could exe… |
vulnerability |
nvd |
CVE-2026-19582 |
|
2026-08-20 |
| medium |
CVE-2026-76800 — A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of th… |
vulnerability |
nvd |
CVE-2026-76800 |
|
2026-08-20 |
| medium |
CVE-2026-76799 — A weakness has been identified in code-projects Login Registration System 1.0. This affects an unkno… |
vulnerability |
nvd |
CVE-2026-76799 |
|
2026-08-20 |
| high |
CVE-2026-76795 — A vulnerability has been found in AeternaLabsHQ PullMD 3.2.0. This impacts an unknown function of th… |
vulnerability |
nvd |
CVE-2026-76795 |
|
2026-08-20 |
| medium |
CVE-2026-76785 — A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Aff… |
vulnerability |
nvd |
CVE-2026-76785 |
|
2026-08-20 |
| high |
CVE-2026-76783 — A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown… |
vulnerability |
nvd |
CVE-2026-76783 |
|
2026-08-20 |
| unknown |
CVE-2026-75628 — Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login be… |
vulnerability |
nvd |
CVE-2026-75628 |
|
2026-08-20 |
| medium |
77 Firefox Extensions Linked to Crypto Wallet and Credential Theft |
threat-intel |
otx |
77.91.100.175 | b65143df86edd606… |
browser extension campaign, credential stealing, supabase abuse, cloudflare workers, firefox extensions, phishing, web3 impersonation, cryptocurrency wallet theft, botnet, infostealer |
2026-08-20 |
| unknown |
CVE-2026-8619 — An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150… |
vulnerability |
nvd |
CVE-2026-8619 |
|
2026-08-20 |
| high |
CVE-2026-76764 — A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an un… |
vulnerability |
nvd |
CVE-2026-76764 |
|
2026-08-20 |
| high |
CVE-2026-76762 — A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an… |
vulnerability |
nvd |
CVE-2026-76762 |
|
2026-08-20 |
| critical |
CVE-2026-72529 — TrueConf Server Missing Authentication for Critical Function Vulnerability |
vulnerability |
cisa-kev, nvd |
CVE-2026-72529 |
|
2026-08-20 |
| critical |
CVE-2026-72530 — TrueConf Server Code Injection Vulnerability |
vulnerability |
cisa-kev, nvd |
CVE-2026-72530 |
|
2026-08-20 |
| medium |
CVE-2026-76929 — Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76929 |
|
2026-08-19 |
| high |
CVE-2026-76928 — X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76928 |
|
2026-08-19 |
| medium |
CVE-2026-76927 — H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76927 |
|
2026-08-19 |
| low |
CVE-2026-76926 — BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76926 |
|
2026-08-19 |
| medium |
CVE-2026-76924 — Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76924 |
|
2026-08-19 |
| medium |
CVE-2026-76923 — Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial o… |
vulnerability |
nvd |
CVE-2026-76923 |
|
2026-08-19 |
| medium |
CVE-2026-76922 — Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of… |
vulnerability |
nvd |
CVE-2026-76922 |
|
2026-08-19 |
| medium |
CVE-2026-76920 — 3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76920 |
|
2026-08-19 |
| medium |
CVE-2026-76919 — ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76919 |
|
2026-08-19 |
| medium |
CVE-2026-76918 — SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76918 |
|
2026-08-19 |
| medium |
CVE-2026-76917 — Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial… |
vulnerability |
nvd |
CVE-2026-76917 |
|
2026-08-19 |
| low |
CVE-2026-76890 — Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
vulnerability |
nvd |
CVE-2026-76890, CVE-2026-76891 |
|
2026-08-19 |