| high |
CVE-2026-69222 — LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.2… |
vulnerability |
nvd |
CVE-2026-69222 |
|
2026-08-19 |
| medium |
CVE-2026-68555 — Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TUR… |
vulnerability |
nvd |
CVE-2026-68555 |
|
2026-08-19 |
| unknown |
CVE-2026-68554 — Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path att… |
vulnerability |
nvd |
CVE-2026-68554 |
|
2026-08-19 |
| high |
CVE-2026-68553 — Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticat… |
vulnerability |
nvd |
CVE-2026-68553 |
|
2026-08-19 |
| medium |
CVE-2026-68552 — Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthentic… |
vulnerability |
nvd |
CVE-2026-68552 |
|
2026-08-19 |
| high |
CVE-2026-62727 — Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… |
vulnerability |
nvd |
CVE-2026-62727 |
|
2026-08-19 |
| unknown |
CVE-2026-61556 — LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. From 10.26.0 unt… |
vulnerability |
nvd |
CVE-2026-61556 |
|
2026-08-19 |
| unknown |
CVE-2026-54743 — Lemmy is a link aggregator and forum for the fediverse. Prior to lemmy-ui 0.19.19-beta.1, LemmyNet/l… |
vulnerability |
nvd |
CVE-2026-54743 |
|
2026-08-19 |
| unknown |
CVE-2026-54741 — Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, Lemmy b… |
vulnerability |
nvd |
CVE-2026-54741 |
|
2026-08-19 |
| medium |
CVE-2026-54740 — Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, a lower… |
vulnerability |
nvd |
CVE-2026-54740 |
|
2026-08-19 |
| medium |
CVE-2026-54739 — Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, Lemmy's l… |
vulnerability |
nvd |
CVE-2026-54739 |
phishing |
2026-08-19 |
| medium |
CVE-2026-54738 — Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web… |
vulnerability |
nvd |
CVE-2026-54738 |
|
2026-08-19 |
| critical |
CVE-2026-54494 — Koel is a free, open-source music streaming solution. Prior to 9.7.1, App\Helpers\Network::isPublicH… |
vulnerability |
nvd |
CVE-2026-54494 |
ransomware |
2026-08-19 |
| high |
CVE-2026-54492 — Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible create… |
vulnerability |
nvd |
CVE-2026-54492, CVE-2026-54493 |
|
2026-08-19 |
| high |
CVE-2026-54491 — Koel is a free, open-source music streaming solution. Prior to 9.7.1, outbound podcast and radio fet… |
vulnerability |
nvd |
CVE-2026-54491 |
|
2026-08-19 |
| critical |
CVE-2026-53542 — Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa… |
vulnerability |
nvd |
CVE-2026-53542, CVE-2026-53545, CVE-2026-53546, CVE-2026-53547, CVE-2026-53548, CVE-2026-53549 |
|
2026-08-19 |
| medium |
CVE-2026-4937 — IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 throug… |
vulnerability |
nvd |
CVE-2026-4937 |
|
2026-08-19 |
| medium |
CVE-2026-4936 — IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.0… |
vulnerability |
nvd |
CVE-2026-4936 |
|
2026-08-19 |
| medium |
CVE-2026-18849 — IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update pr… |
vulnerability |
nvd |
CVE-2026-18849 |
|
2026-08-19 |
| high |
CVE-2026-18544 — IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image polic… |
vulnerability |
nvd |
CVE-2026-18544 |
|
2026-08-19 |
| low |
CVE-2026-18102 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memor… |
vulnerability |
nvd |
CVE-2026-18102 |
|
2026-08-19 |
| medium |
CVE-2026-17015 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of servic… |
vulnerability |
nvd |
CVE-2026-17015 |
|
2026-08-19 |
| medium |
CVE-2026-14978 — HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclu… |
vulnerability |
nvd |
CVE-2026-14978 |
|
2026-08-19 |
| medium |
CVE-2026-14514 — IBM Reliable Scalable Cluster Technology (RSCT) 3.0 could allow a remote attacker to cause a denial… |
vulnerability |
nvd |
CVE-2026-14514 |
|
2026-08-19 |
| medium |
CVE-2026-12634 — The NVS backend of the Zephyr settings subsystem (subsys/settings/src/settings_nvs.c) reads stored s… |
vulnerability |
nvd |
CVE-2026-12634 |
|
2026-08-19 |
| high |
CVE-2026-12633 — The IPv6 neighbor-discovery code in subsys/net/ip/ipv6_nbr.c processes the 6LoWPAN Context Option (6… |
vulnerability |
nvd |
CVE-2026-12633 |
|
2026-08-19 |
| high |
CVE-2026-12522 — The HL7800 cellular modem driver's +CGCONTRDP: response handler on_cmd_atcmdinfo_ipaddr() in drivers… |
vulnerability |
nvd |
CVE-2026-12522 |
|
2026-08-19 |
| low |
CVE-2026-11617 — Tanium addressed a compression bomb vulnerability in Findings. |
vulnerability |
nvd |
CVE-2026-11617 |
|
2026-08-19 |
| medium |
Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign |
threat-intel |
otx |
fad1e9d507c7021a…, f1aed8cf2adafa86… |
sandbox evasion, grandoreiro, mexico, dll sideloading, anti-analysis, delphi, banking trojan, latin america, botnet |
2026-08-19 |
| unknown |
CVE-2026-76647 — Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JS… |
vulnerability |
nvd |
CVE-2026-76647 |
|
2026-08-19 |
| high |
CVE-2026-76574 — A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the… |
vulnerability |
nvd |
CVE-2026-76574 |
|
2026-08-19 |
| medium |
CVE-2026-76572 — A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is… |
vulnerability |
nvd |
CVE-2026-76572 |
|
2026-08-19 |
| unknown |
CVE-2026-75112 — A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insuf… |
vulnerability |
nvd |
CVE-2026-75112 |
|
2026-08-19 |
| medium |
CVE-2026-68901 — Wekan is open source kanban built with Meteor. Prior to 10.38, the /api/boards/:boardId/export, /api… |
vulnerability |
nvd |
CVE-2026-68901 |
|
2026-08-19 |
| high |
CVE-2026-68900 — Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/… |
vulnerability |
nvd |
CVE-2026-68900 |
|
2026-08-19 |
| high |
CVE-2026-68899 — Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation… |
vulnerability |
nvd |
CVE-2026-68899 |
|
2026-08-19 |
| high |
CVE-2026-68561 — Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) ru… |
vulnerability |
nvd |
CVE-2026-68561 |
|
2026-08-19 |
| unknown |
CVE-2026-68560 — Wekan is open source kanban built with Meteor. Prior to 9.75, models/fileValidation.js interpolated… |
vulnerability |
nvd |
CVE-2026-68560 |
|
2026-08-19 |
| medium |
CVE-2026-68559 — Wekan is open source kanban built with Meteor. From 9.57 until 9.74, the /api/boards/:boardId/export… |
vulnerability |
nvd |
CVE-2026-68559 |
|
2026-08-19 |
| high |
CVE-2026-68558 — Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integratio… |
vulnerability |
nvd |
CVE-2026-68558 |
|
2026-08-19 |
| medium |
CVE-2026-67189 — pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnera… |
vulnerability |
nvd |
CVE-2026-67189 |
|
2026-08-19 |
| critical |
CVE-2026-63722 — ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthentic… |
vulnerability |
nvd |
CVE-2026-63722 |
rce |
2026-08-19 |
| unknown |
CVE-2026-63188 — Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto… |
vulnerability |
nvd |
CVE-2026-63188 |
|
2026-08-19 |
| medium |
CVE-2026-63187 — Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0,… |
vulnerability |
nvd |
CVE-2026-63187 |
|
2026-08-19 |
| high |
CVE-2026-62317 — Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's… |
vulnerability |
nvd |
CVE-2026-62317 |
|
2026-08-19 |
| unknown |
CVE-2026-61711 — BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and… |
vulnerability |
nvd |
CVE-2026-61711, CVE-2026-61712, CVE-2026-75593 |
|
2026-08-19 |
| unknown |
CVE-2026-55090 — Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/Exp… |
vulnerability |
nvd |
CVE-2026-55090 |
|
2026-08-19 |
| critical |
CVE-2026-55089 — Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/AP… |
vulnerability |
nvd |
CVE-2026-55089 |
|
2026-08-19 |
| medium |
CVE-2026-55088 — Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/expr… |
vulnerability |
nvd |
CVE-2026-55088 |
|
2026-08-19 |
| medium |
CVE-2026-55087 — Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-con… |
vulnerability |
nvd |
CVE-2026-55087 |
|
2026-08-19 |