| medium |
CVE-2026-55086 — Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and… |
vulnerability |
nvd |
CVE-2026-55086 |
transport |
2026-08-19 |
| critical |
CVE-2026-55085 — Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/dom… |
vulnerability |
nvd |
CVE-2026-55085 |
|
2026-08-19 |
| unknown |
CVE-2026-54742 — Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.2… |
vulnerability |
nvd |
CVE-2026-54742 |
|
2026-08-19 |
| critical |
CVE-2026-22306 — Download of code without integrity check, inclusion of functionality from untrusted control sphere,… |
vulnerability |
nvd |
CVE-2026-22306 |
|
2026-08-19 |
| unknown |
CVE-2026-19509 — Improper input validation in `ajaxSet_wireless_network_configuration.jst` in RDK-B WebUI `rdkb-2025q… |
vulnerability |
nvd |
CVE-2026-19509 |
|
2026-08-19 |
| unknown |
CVE-2026-19508 — Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-20… |
vulnerability |
nvd |
CVE-2026-19508 |
|
2026-08-19 |
| unknown |
CVE-2026-19507 — Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` all… |
vulnerability |
nvd |
CVE-2026-19507 |
|
2026-08-19 |
| unknown |
CVE-2026-19506 — Race condition in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attack… |
vulnerability |
nvd |
CVE-2026-19506 |
|
2026-08-19 |
| unknown |
CVE-2026-19505 — Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirks… |
vulnerability |
nvd |
CVE-2026-19505 |
|
2026-08-19 |
| high |
CVE-2026-18871 — IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is af… |
vulnerability |
nvd |
CVE-2026-18871 |
|
2026-08-19 |
| unknown |
CVE-2026-17590 — Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-32475. Reason:… |
vulnerability |
nvd |
CVE-2026-17590 |
|
2026-08-19 |
| high |
CVE-2026-17042 — IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.… |
vulnerability |
nvd |
CVE-2026-17042 |
|
2026-08-19 |
| medium |
CVE-2026-16883 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive infor… |
vulnerability |
nvd |
CVE-2026-16883, CVE-2026-16890, CVE-2026-16891, CVE-2026-17007 |
|
2026-08-19 |
| high |
CVE-2026-16875 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary comm… |
vulnerability |
nvd |
CVE-2026-16875, CVE-2026-16932, CVE-2026-16997 |
|
2026-08-19 |
| high |
CVE-2026-16874 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain root privileges… |
vulnerability |
nvd |
CVE-2026-16874 |
|
2026-08-19 |
| high |
CVE-2026-16873 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve local privileg… |
vulnerability |
nvd |
CVE-2026-16873 |
|
2026-08-19 |
| critical |
CVE-2026-16869 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code… |
vulnerability |
nvd |
CVE-2026-16869, CVE-2026-16914, CVE-2026-16922, CVE-2026-16936, CVE-2026-16943, CVE-2026-16944, CVE-2026-16945, CVE-2026-16996, CVE-2026-17124, CVE-2026-17422, CVE-2026-18840 |
|
2026-08-19 |
| high |
CVE-2026-16857 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to manipulate network tr… |
vulnerability |
nvd |
CVE-2026-16857 |
|
2026-08-19 |
| critical |
CVE-2026-16842 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary com… |
vulnerability |
nvd |
CVE-2026-16842, CVE-2026-16844, CVE-2026-16848, CVE-2026-16882, CVE-2026-17142 |
|
2026-08-19 |
| critical |
CVE-2026-16839 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive info… |
vulnerability |
nvd |
CVE-2026-16839, CVE-2026-16888, CVE-2026-16972, CVE-2026-17060, CVE-2026-17423 |
|
2026-08-19 |
| high |
CVE-2026-16838 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical fil… |
vulnerability |
nvd |
CVE-2026-16838 |
|
2026-08-19 |
| medium |
CVE-2026-16833 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to disclose kernel memor… |
vulnerability |
nvd |
CVE-2026-16833 |
|
2026-08-19 |
| high |
CVE-2026-16825 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain… |
vulnerability |
nvd |
CVE-2026-16825, CVE-2026-18716 |
|
2026-08-19 |
| critical |
CVE-2026-16822 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC p… |
vulnerability |
nvd |
CVE-2026-16822 |
|
2026-08-19 |
| medium |
CVE-2026-16724 — IBM Virtualization Management Interface FW1110.00 through FW1110.30, FW1120.00 through FW1120.00, an… |
vulnerability |
nvd |
CVE-2026-16724 |
|
2026-08-19 |
| high |
CVE-2026-16661 — IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW95… |
vulnerability |
nvd |
CVE-2026-16661, CVE-2026-16707, CVE-2026-17028, CVE-2026-17091, CVE-2026-17097, CVE-2026-17414, CVE-2026-18821 |
|
2026-08-19 |
| medium |
Backdoor delivered through software updates |
threat-intel |
otx |
cefd8928fd7411b4… |
download studio, cryptocurrency mining, software update abuse, xmrig, supply chain attack, backdoor, adblocker, torrent client, qt framework, fakembam, botnet, supply-chain |
2026-08-19 |
| unknown |
Agentic AI Presents New Insider Threat Model for Orgs |
news |
general-news |
|
|
2026-08-19 |
| unknown |
CVE-2026-75619 — Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authen… |
vulnerability |
nvd |
CVE-2026-75619 |
|
2026-08-19 |
| unknown |
CVE-2026-75618 — Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker… |
vulnerability |
nvd |
CVE-2026-75618 |
|
2026-08-19 |
| critical |
CVE-2026-70496 — A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a c… |
vulnerability |
nvd |
CVE-2026-70496 |
|
2026-08-19 |
| unknown |
CVE-2026-61807 — Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier… |
vulnerability |
nvd |
CVE-2026-61807 |
|
2026-08-19 |
| medium |
CVE-2026-55703 — Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request… |
vulnerability |
nvd |
CVE-2026-55703 |
|
2026-08-19 |
| unknown |
CVE-2026-55694 — Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /ap… |
vulnerability |
nvd |
CVE-2026-55694 |
|
2026-08-19 |
| unknown |
CVE-2026-55643 — Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS flo… |
vulnerability |
nvd |
CVE-2026-55643 |
|
2026-08-19 |
| medium |
CVE-2026-55519 — Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generi… |
vulnerability |
nvd |
CVE-2026-55519 |
|
2026-08-19 |
| unknown |
CVE-2026-55483 — Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.… |
vulnerability |
nvd |
CVE-2026-55483 |
|
2026-08-19 |
| medium |
CVE-2026-55482 — Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http… |
vulnerability |
nvd |
CVE-2026-55482 |
|
2026-08-19 |
| medium |
CVE-2026-50550 — Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users c… |
vulnerability |
nvd |
CVE-2026-50550 |
|
2026-08-19 |
| medium |
CVE-2026-49976 — Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission… |
vulnerability |
nvd |
CVE-2026-49976 |
|
2026-08-19 |
| medium |
CVE-2026-49870 — Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limi… |
vulnerability |
nvd |
CVE-2026-49870 |
|
2026-08-19 |
| unknown |
CVE-2026-19198 — Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common BulkAc… |
vulnerability |
nvd |
CVE-2026-19198 |
|
2026-08-19 |
| medium |
CVE-2026-18681 — IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.0… |
vulnerability |
nvd |
CVE-2026-18681 |
|
2026-08-19 |
| critical |
CVE-2026-18315 — The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Auth… |
vulnerability |
nvd |
CVE-2026-18315 |
|
2026-08-19 |
| high |
CVE-2026-17494 — IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability… |
vulnerability |
nvd |
CVE-2026-17494 |
|
2026-08-19 |
| high |
CVE-2026-17100 — Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00… |
vulnerability |
nvd |
CVE-2026-17100 |
|
2026-08-19 |
| high |
CVE-2026-17093 — IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW95… |
vulnerability |
nvd |
CVE-2026-17093, CVE-2026-17429, CVE-2026-16933 |
|
2026-08-19 |
| high |
CVE-2026-16930 — IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 i… |
vulnerability |
nvd |
CVE-2026-16930, CVE-2026-17063 |
|
2026-08-19 |
| critical |
CVE-2026-16687 — IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and… |
vulnerability |
nvd |
CVE-2026-16687, CVE-2026-16828, CVE-2026-16832, CVE-2026-16835, CVE-2026-16938, CVE-2026-18848 |
|
2026-08-19 |
| unknown |
Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second |
news |
general-news |
|
|
2026-08-19 |