| unknown |
CVE-2026-64850 — Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/… |
vulnerability |
nvd |
CVE-2026-64850 |
|
2026-08-19 |
| unknown |
CVE-2026-62673 — Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess… |
vulnerability |
nvd |
CVE-2026-62673 |
|
2026-08-19 |
| unknown |
CVE-2026-62672 — Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and func… |
vulnerability |
nvd |
CVE-2026-62672 |
|
2026-08-19 |
| medium |
CVE-2026-62670 — Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav… |
vulnerability |
nvd |
CVE-2026-62670 |
|
2026-08-19 |
| high |
CVE-2026-62669 — Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Gra… |
vulnerability |
nvd |
CVE-2026-62669, CVE-2026-62671 |
|
2026-08-19 |
| medium |
CVE-2026-61842 — Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offset… |
vulnerability |
nvd |
CVE-2026-61842 |
|
2026-08-19 |
| medium |
CVE-2026-61690 — Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Co… |
vulnerability |
nvd |
CVE-2026-61690 |
|
2026-08-19 |
| high |
CVE-2026-61607 — Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's cont… |
vulnerability |
nvd |
CVE-2026-61607, CVE-2026-62666, CVE-2026-62667, CVE-2026-62668, CVE-2026-63407, CVE-2026-63408, CVE-2026-64852 |
|
2026-08-19 |
| medium |
CVE-2026-53654 — Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a clie… |
vulnerability |
nvd |
CVE-2026-53654 |
phishing |
2026-08-19 |
| medium |
CVE-2026-44254 — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1… |
vulnerability |
nvd |
CVE-2026-44254 |
|
2026-08-19 |
| medium |
CVE-2026-44253 — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3… |
vulnerability |
nvd |
CVE-2026-44253 |
|
2026-08-19 |
| critical |
CVE-2026-44252 — Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4… |
vulnerability |
nvd |
CVE-2026-44252, CVE-2026-46343, CVE-2026-41424, CVE-2026-44255, CVE-2026-44256, CVE-2026-44901, CVE-2026-45798, CVE-2026-48024, CVE-2026-48162, CVE-2026-49392, CVE-2026-49441 |
|
2026-08-19 |
| unknown |
CVE-2026-19672 — The tarfile module's tar and data extraction filters created directories outside the destination for… |
vulnerability |
nvd |
CVE-2026-19672 |
|
2026-08-19 |
| unknown |
CVE-2026-18430 — HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notificat… |
vulnerability |
nvd |
CVE-2026-18430 |
|
2026-08-19 |
| high |
CVE-2026-16819 — IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of serv… |
vulnerability |
nvd |
CVE-2026-16819, CVE-2026-19653, CVE-2026-16855, CVE-2026-16897, CVE-2026-16952, CVE-2026-16980, CVE-2026-17009, CVE-2026-17195, CVE-2026-18822 |
|
2026-08-19 |
| medium |
Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware |
threat-intel |
otx |
e276bf8744f29c54…, f4769ba9e8065727… |
black hat, conference phishing, cryptocurrency theft, def con, atomic macos stealer, netsupport rat, clickfix, netsupport manager, google apps script, amos, phishing, infostealer |
2026-08-19 |
| medium |
Scammers are using fake crypto AML checkers to drain your wallet |
threat-intel |
otx |
|
fake aml checker, social engineering, crypto scam, wallet draining, fraudulent website, phishing, cryptocurrency, token theft, ghostdesk, ransomware |
2026-08-19 |
| high |
Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking |
threat-intel |
otx |
196.251.84.11 |
websocket hijacking, cryptocurrency payments, spyroid, phaas, callflow, ai vishing, mexican banking fraud, android rat, phishing |
2026-08-19 |
| unknown |
Exclusive: Linux Foundation's Akrites to Go Live in September |
news |
general-news |
|
|
2026-08-19 |
| medium |
CVE-2026-76614 — OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. Th… |
vulnerability |
nvd |
CVE-2026-76614 |
|
2026-08-19 |
| unknown |
CVE-2026-76203 — Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer… |
vulnerability |
nvd |
CVE-2026-76203 |
|
2026-08-19 |
| unknown |
CVE-2026-75956 — Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirector… |
vulnerability |
nvd |
CVE-2026-75956 |
|
2026-08-19 |
| unknown |
CVE-2026-75955 — Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - co… |
vulnerability |
nvd |
CVE-2026-75955 |
|
2026-08-19 |
| unknown |
CVE-2026-75954 — Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Se… |
vulnerability |
nvd |
CVE-2026-75954 |
|
2026-08-19 |
| unknown |
CVE-2026-75953 — Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient addres… |
vulnerability |
nvd |
CVE-2026-75953 |
|
2026-08-19 |
| unknown |
CVE-2026-75952 — Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Token… |
vulnerability |
nvd |
CVE-2026-75952 |
|
2026-08-19 |
| unknown |
CVE-2026-75951 — Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions)… |
vulnerability |
nvd |
CVE-2026-75951 |
|
2026-08-19 |
| unknown |
CVE-2026-75950 — Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory… |
vulnerability |
nvd |
CVE-2026-75950 |
|
2026-08-19 |
| unknown |
CVE-2026-75949 — Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDi… |
vulnerability |
nvd |
CVE-2026-75949 |
|
2026-08-19 |
| high |
CVE-2026-71961 — Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that a… |
vulnerability |
nvd |
CVE-2026-71961 |
|
2026-08-19 |
| critical |
CVE-2026-71960 — Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnera… |
vulnerability |
nvd |
CVE-2026-71960 |
|
2026-08-19 |
| medium |
CVE-2026-67268 — Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External… |
vulnerability |
nvd |
CVE-2026-67268 |
|
2026-08-19 |
| medium |
CVE-2026-67267 — Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Informat… |
vulnerability |
nvd |
CVE-2026-67267 |
|
2026-08-19 |
| medium |
CVE-2026-67266 — Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability… |
vulnerability |
nvd |
CVE-2026-67266 |
|
2026-08-19 |
| high |
CVE-2026-58564 — Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnera… |
vulnerability |
nvd |
CVE-2026-58564 |
|
2026-08-19 |
| high |
CVE-2026-58562 — Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A… |
vulnerability |
nvd |
CVE-2026-58562, CVE-2026-58565 |
|
2026-08-19 |
| high |
CVE-2026-56797 — Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condit… |
vulnerability |
nvd |
CVE-2026-56797 |
|
2026-08-19 |
| medium |
CVE-2026-56796 — Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File… |
vulnerability |
nvd |
CVE-2026-56796 |
|
2026-08-19 |
| medium |
CVE-2026-54793 — Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input Du… |
vulnerability |
nvd |
CVE-2026-54793 |
|
2026-08-19 |
| high |
CVE-2026-53477 — Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Rac… |
vulnerability |
nvd |
CVE-2026-53477 |
|
2026-08-19 |
| critical |
CVE-2026-53451 — Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and… |
vulnerability |
nvd |
CVE-2026-53451, CVE-2026-53452 |
|
2026-08-19 |
| critical |
CVE-2026-52889 — Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hi… |
vulnerability |
nvd |
CVE-2026-52889 |
rce |
2026-08-19 |
| high |
CVE-2026-52834 — jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a cr… |
vulnerability |
nvd |
CVE-2026-52834 |
|
2026-08-19 |
| unknown |
CVE-2026-52792 — Algernon is a small self-contained pure-Go web server. Prior to 1.17.9, Algernon on Windows selects… |
vulnerability |
nvd |
CVE-2026-52792 |
|
2026-08-19 |
| medium |
CVE-2026-50149 — Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, whe… |
vulnerability |
nvd |
CVE-2026-50149 |
|
2026-08-19 |
| high |
CVE-2026-49816 — Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vuln… |
vulnerability |
nvd |
CVE-2026-49816, CVE-2026-49817 |
|
2026-08-19 |
| high |
CVE-2026-49289 — The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20… |
vulnerability |
nvd |
CVE-2026-49289 |
|
2026-08-19 |
| high |
CVE-2026-49283 — The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions… |
vulnerability |
nvd |
CVE-2026-49283 |
|
2026-08-19 |
| high |
CVE-2026-49253 — electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3… |
vulnerability |
nvd |
CVE-2026-49253, CVE-2026-49255 |
|
2026-08-19 |
| high |
CVE-2026-48711 — SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SS… |
vulnerability |
nvd |
CVE-2026-48711 |
|
2026-08-19 |