| CVE-2026-75948 |
Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 |
20.08.2026 |
|
| CVE-2026-76564 |
Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7 |
20.08.2026 |
|
| CVE-2025-14601 |
vsDesk Task Scheduler OS Command Injection |
20.08.2026 |
|
| CVE-2026-76565 |
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7 |
20.08.2026 |
|
| CVE-2026-76569 |
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4 |
20.08.2026 |
|
| CVE-2025-14602 |
Weak File Name Generation in vsDesk |
20.08.2026 |
|
| CVE-2026-14163 |
|
20.08.2026 |
|
| CVE-2026-71368 |
|
20.08.2026 |
|
| CVE-2026-13405 |
Royal Elementor Addons < 1.7.1066 - Admin+ Remote Code Execution via Widget Builder |
20.08.2026 |
|
| CVE-2026-15049 |
Depicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import |
20.08.2026 |
|
| CVE-2026-19615 |
Admin and Site Enhancements < 9.0.1 - Author+ Stored XSS via SVG Upload over XML-RPC |
20.08.2026 |
|
| CVE-2026-19697 |
GutenKit < 2.5.0 - Author+ Stored XSS via SVG Upload |
20.08.2026 |
|
| CVE-2026-19699 |
GutenKit 2.4.12 - 2.4.15 - Contributor+ Mailchimp Audience Data Disclosure |
20.08.2026 |
|
| CVE-2026-74992 |
Kirki < 6.2.3 - Editor+ Stored XSS via Font Zip Upload |
20.08.2026 |
|
| CVE-2026-75860 |
JSON Options <= 0.0.4 - Unauthenticated Arbitrary Options Update |
20.08.2026 |
|
| CVE-2026-17153 |
AI Agent by SiteGround <= 1.2.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Upload via /generate-content REST Endpoint |
20.08.2026 |
5.3 |
| CVE-2026-75963 |
Events Made Easy <= 3.2.5 - Authenticated (Contributor+) Local File Inclusion via 'wp_page_template' Event Property |
20.08.2026 |
7.5 |
| CVE-2026-73542 |
|
20.08.2026 |
3.7 |
| CVE-2026-19582 |
Binutils: stack buffer overflow in gnu binutils in rsrc_print_name from an untrusted pe file |
20.08.2026 |
|
| CVE-2026-76956 |
|
20.08.2026 |
7.5 |
| CVE-2026-76957 |
|
20.08.2026 |
4.9 |
| CVE-2026-76800 |
DeDeCMS select_media_post.php unrestricted upload |
20.08.2026 |
|
| CVE-2026-76799 |
code-projects Login Registration System SQL Database Backup login_registration_system.sql file access |
20.08.2026 |
|
| CVE-2026-76795 |
AeternaLabsHQ PullMD REST API Endpoint api server-side request forgery |
20.08.2026 |
|
| CVE-2026-75628 |
Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter |
20.08.2026 |
|
| CVE-2026-76785 |
amirsanni Mini-Inventory-and-Sales-Management-System Transaction.php getAll sql injection |
20.08.2026 |
|
| CVE-2026-76783 |
DeDeCMS advancedsearch.php sql injection |
20.08.2026 |
|
| CVE-2026-76764 |
code-projects Employee Management System Admin Login Endpoint aprocess.php sql injection |
20.08.2026 |
|
| CVE-2022-4996 |
mruby bigint.c udiv floating point comparison with incorrect operator |
19.08.2026 |
|
| CVE-2026-76762 |
code-projects Assessment Management welcome.php sql injection |
19.08.2026 |
|
| CVE-2026-8619 |
Unauthenticated Denial-of-Service Vulnerability in HTTP Service in TP-Link TL-MR100, TL-MR150, TL-MR6400 and Archer MR600 |
19.08.2026 |
|
| CVE-2026-76761 |
chenhg5 cc-connect Management API engine.go shellExecCommand os command injection |
19.08.2026 |
|
| CVE-2026-76926 |
Reachable Assertion in Wireshark |
19.08.2026 |
3.1 |
| CVE-2026-76927 |
NULL Pointer Dereference in Wireshark |
19.08.2026 |
4.7 |
| CVE-2026-76928 |
NULL Pointer Dereference in Wireshark |
19.08.2026 |
7.5 |
| CVE-2026-76929 |
Out-of-bounds Read in Wireshark |
19.08.2026 |
4.7 |
| CVE-2026-76760 |
chenhg5 cc-connect webhook.go authenticate code injection |
19.08.2026 |
|
| CVE-2026-76879 |
Stack-based Buffer Overflow in Wireshark |
19.08.2026 |
7.5 |
| CVE-2026-76880 |
Out-of-bounds Write in Wireshark |
19.08.2026 |
7.5 |
| CVE-2026-76885 |
Buffer Over-read in Wireshark |
19.08.2026 |
3.1 |
| CVE-2026-76890 |
Expired Pointer Dereference in Wireshark |
19.08.2026 |
3.1 |
| CVE-2026-76891 |
Expired Pointer Dereference in Wireshark |
19.08.2026 |
3.1 |
| CVE-2026-76917 |
Heap-based Buffer Overflow in Wireshark |
19.08.2026 |
5.5 |
| CVE-2026-76918 |
Heap-based Buffer Overflow in Wireshark |
19.08.2026 |
5.5 |
| CVE-2026-76919 |
Use of Uninitialized Variable in Wireshark |
19.08.2026 |
5.3 |
| CVE-2026-76920 |
Out-of-bounds Write in Wireshark |
19.08.2026 |
4.7 |
| CVE-2026-76921 |
Use After Free in Wireshark |
19.08.2026 |
5.5 |
| CVE-2026-76922 |
NULL Pointer Dereference in Wireshark |
19.08.2026 |
5.5 |
| CVE-2026-76923 |
Out-of-bounds Read in Wireshark |
19.08.2026 |
5.5 |
| CVE-2026-76924 |
Out-of-bounds Read in Wireshark |
19.08.2026 |
5.5 |
| CVE-2026-76881 |
NULL Pointer Dereference in Wireshark |
19.08.2026 |
4.7 |
| CVE-2026-76882 |
Out-of-bounds Read in Wireshark |
19.08.2026 |
4.7 |
| CVE-2026-76883 |
Heap-based Buffer Overflow in Wireshark |
19.08.2026 |
4.7 |
| CVE-2026-76884 |
Buffer Over-read in Wireshark |
19.08.2026 |
3.1 |
| CVE-2026-76886 |
Heap-based Buffer Overflow in Wireshark |
19.08.2026 |
8.1 |
| CVE-2026-76887 |
Heap-based Buffer Overflow in Wireshark |
19.08.2026 |
3.1 |
| CVE-2026-76888 |
Heap-based Buffer Overflow in Wireshark |
19.08.2026 |
3.1 |
| CVE-2026-76889 |
Heap-based Buffer Overflow in Wireshark |
19.08.2026 |
4.7 |
| CVE-2026-18502 |
|
19.08.2026 |
|
| CVE-2026-18862 |
|
19.08.2026 |
|
| CVE-2026-19561 |
|
19.08.2026 |
|
| CVE-2026-19562 |
|
19.08.2026 |
|
| CVE-2026-19563 |
|
19.08.2026 |
|
| CVE-2026-76591 |
TRENDnet TEW-755AP ssi email.cgi log_email_server command injection |
19.08.2026 |
|
| CVE-2026-76832 |
Agno PythonTools Path Traversal via joinpath file_name argument |
19.08.2026 |
|
| CVE-2026-76878 |
|
19.08.2026 |
|
| CVE-2026-63123 |
Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root |
19.08.2026 |
6.5 |
| CVE-2026-76590 |
TRENDnet TEW-755AP ssi wan.cgi stack-based overflow |
19.08.2026 |
|
| CVE-2026-76850 |
LMDeploy Remote Code Execution via Unsafe Pickle Deserialization in the Disaggregated Serving Peer Connector |
19.08.2026 |
|
| CVE-2026-59992 |
Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters) |
19.08.2026 |
5.4 |
| CVE-2026-76251 |
Missing Authorization through REST API Endpoints in the Splunk App for Splunk Observability Cloud |
19.08.2026 |
7.1 |
| CVE-2026-76252 |
Cross-Site Scripting (XSS) through Splunk Web Message Validation in Splunk Enterprise |
19.08.2026 |
6.8 |
| CVE-2026-76253 |
Privilege Escalation through Scheduled Search Alert Action Configuration in Splunk Enterprise |
19.08.2026 |
8.8 |
| CVE-2026-76254 |
SPL Command Safeguards Bypass through Splunk Web in Splunk Enterprise |
19.08.2026 |
7.5 |
| CVE-2026-76255 |
Risky Command Safeguards Bypass through Splunk Web in Splunk Enterprise |
19.08.2026 |
6.4 |
| CVE-2026-76256 |
Information Exposure through REST API Endpoints in Splunk Secure Gateway |
19.08.2026 |
4.3 |
| CVE-2026-76257 |
Missing Authorization through REST API Endpoints in Splunk Secure Gateway |
19.08.2026 |
6.5 |
| CVE-2026-76258 |
Use of Hard-coded Cryptographic Key through Companion App Registration in Splunk Secure Gateway |
19.08.2026 |
6.5 |
| CVE-2026-76259 |
Improper Privilege Management on the Management Port in Splunk Enterprise for Windows |
19.08.2026 |
8.8 |
| CVE-2026-76260 |
Incorrect Permission Assignment for Critical Resource through the REST API in Splunk Enterprise |
19.08.2026 |
6.5 |
| CVE-2026-76261 |
Insecure Default Access Control List through the REST API in Splunk Secure Gateway |
19.08.2026 |
5.3 |
| CVE-2026-76262 |
Exposure of Sensitive Information to an Unauthorized Actor through the REST API in Splunk Enterprise |
19.08.2026 |
7.5 |
| CVE-2026-76263 |
Improper Access Control through the REST API in Splunk Enterprise |
19.08.2026 |
5.4 |
| CVE-2026-76309 |
Structured Query Language (SQL) Injection through the REST API in Splunk Enterprise |
19.08.2026 |
4.3 |
| CVE-2026-76310 |
Improper Access Control through Embedded Report REST API Requests in Splunk Enterprise |
19.08.2026 |
9.4 |
| CVE-2026-76311 |
Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise |
19.08.2026 |
9.4 |
| CVE-2026-76312 |
Improper Access Control through Embedded Reports in Splunk Enterprise |
19.08.2026 |
9.4 |
| CVE-2026-76313 |
Remote Code Execution (RCE) through the REST API in Splunk Enterprise |
19.08.2026 |
8.8 |
| CVE-2026-76314 |
Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise |
19.08.2026 |
8.8 |
| CVE-2026-76315 |
Code Injection through Splunk Web Manager Configuration in Splunk Enterprise |
19.08.2026 |
8.8 |
| CVE-2026-76316 |
Stored SPL Injection through Deployment Server Broker Registration in Splunk Enterprise |
19.08.2026 |
8.8 |
| CVE-2026-76317 |
Path Traversal through the Lookup Configuration REST API in Splunk Enterprise |
19.08.2026 |
8.8 |
| CVE-2026-76318 |
Stored Cross-Site Scripting (XSS) through Splunk Web in Splunk Enterprise |
19.08.2026 |
5.7 |
| CVE-2026-76319 |
Remote Code Execution (RCE) through Federated Search in Splunk Enterprise |
19.08.2026 |
8.8 |
| CVE-2026-76320 |
SPL Injection through Cross-Site Request Forgery (CSRF) in the Event Type Builder in Splunk Web for Splunk Enterprise |
19.08.2026 |
5.9 |
| CVE-2026-76321 |
SPL Injection through Nearby Event Searches in Splunk Enterprise |
19.08.2026 |
7.3 |
| CVE-2026-76322 |
SPL Injection through Dashboard Studio Search Query Options in Splunk Enterprise |
19.08.2026 |
6.7 |
| CVE-2026-76323 |
SPL Risky Command Safeguards Bypass through the Job Details Dashboard in Splunk Enterprise |
19.08.2026 |
6.4 |
| CVE-2026-76324 |
Stored Cross-Site Scripting (XSS) in Splunk Web Tours in Splunk Enterprise |
19.08.2026 |
5.7 |
| CVE-2026-76325 |
Stored Cross-Site Scripting (XSS) through Splunk Web in Splunk Enterprise |
19.08.2026 |
7.3 |
| CVE-2026-76326 |
Stored Cross-Site Scripting through Dashboard Sparkline Tooltip Options in Splunk Enterprise |
19.08.2026 |
5.7 |
| CVE-2026-76327 |
SPL Injection through Splunk Web in Splunk Secure Gateway |
19.08.2026 |
6.4 |
| CVE-2026-76328 |
SPL Injection through Splunk Web in Splunk Enterprise |
19.08.2026 |
6.7 |
| CVE-2026-76329 |
SPL Injection through Monitoring Console Dashboard Inputs in Splunk Enterprise |
19.08.2026 |
6.4 |
| CVE-2026-76330 |
SPL Injection through Monitoring Console Forwarder Filters in Splunk Enterprise |
19.08.2026 |
7.1 |
| CVE-2026-76331 |
SPL Injection through the REST API in Splunk Enterprise |
19.08.2026 |
8.1 |
| CVE-2026-76332 |
SPL Injection through Splunk Web in Splunk Enterprise |
19.08.2026 |
7.1 |
| CVE-2026-76333 |
Stored Cross-Site Scripting (XSS) through Dashboard Studio Workflow Actions in Splunk Enterprise |
19.08.2026 |
7.1 |
| CVE-2026-76334 |
SPL Injection through Dashboard Studio Workflow Actions in Splunk Enterprise |
19.08.2026 |
6.4 |
| CVE-2026-76335 |
Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise |
19.08.2026 |
8.8 |
| CVE-2026-76336 |
Improper Access Control through the REST API in Splunk Enterprise |
19.08.2026 |
7.1 |
| CVE-2026-76337 |
Path Traversal through Splunk Web Static File Serving in Splunk Enterprise |
19.08.2026 |
5.3 |
| CVE-2026-76338 |
Improper Authentication through REST API Distributed Search Token Requests in Splunk Enterprise |
19.08.2026 |
8.1 |
| CVE-2026-76339 |
SPL Injection through the geostats Command in Splunk Enterprise |
19.08.2026 |
5.4 |
| CVE-2026-76340 |
Missing Authorization for Reloading Token-Signing Keys through the REST API in Splunk Enterprise |
19.08.2026 |
5.3 |
| CVE-2026-76341 |
Risky Commands Safeguards Bypass through Table Editor Dataset Initial Data in Splunk Enterprise |
19.08.2026 |
5.4 |
| CVE-2026-76342 |
Risky Commands Safeguards Bypass through Splunk Web in Splunk Enterprise |
19.08.2026 |
5.4 |
| CVE-2026-76343 |
Structured Query Language (SQL) Injection through the REST API in Splunk Enterprise |
19.08.2026 |
6.5 |
| CVE-2026-76344 |
Path Traversal through the Search Dispatch REST API in Splunk Enterprise |
19.08.2026 |
7.7 |
| CVE-2026-76345 |
Remote Code Execution (RCE) through the REST API in Splunk Enterprise |
19.08.2026 |
6 |
| CVE-2026-76346 |
Stored Cross-Site Scripting (XSS) through Splunk Web Dashboard Sparkline Format Options in Splunk Enterprise |
19.08.2026 |
5.4 |
| CVE-2026-76347 |
Server-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure Gateway |
19.08.2026 |
5.4 |
| CVE-2026-76348 |
Missing Authorization in Search Head Cluster Member Controls in Splunk Enterprise |
19.08.2026 |
3.8 |
| CVE-2026-76349 |
SPL Injection through Splunk Web Form Tokens in Splunk Enterprise |
19.08.2026 |
6.4 |
| CVE-2026-76350 |
Improper Privilege Management through PDF Attachments for Email Alert Actions in Splunk Enterprise |
19.08.2026 |
8.8 |
| CVE-2026-76351 |
Server-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secure Gateway |
19.08.2026 |
8.8 |
| CVE-2026-76352 |
Improper Authorization through the REST API in Splunk Enterprise |
19.08.2026 |
8.8 |
| CVE-2026-76353 |
Path Traversal through Knowledge Bundle Replication in Splunk Enterprise |
19.08.2026 |
5.4 |
| CVE-2026-76354 |
Path Traversal through Search Head Clustering in Splunk Enterprise |
19.08.2026 |
8.1 |
| CVE-2026-76355 |
Unauthenticated Information Disclosure through an Edge Processor Service Endpoint in Splunk Enterprise |
19.08.2026 |
7.5 |
| CVE-2026-76356 |
Authentication Bypass through IP Address Spoofing in the Automation Broker in Splunk SOAR |
19.08.2026 |
8.1 |
| CVE-2026-76357 |
Remote Code Execution (RCE) through Path Traversal in the REST API in Splunk SOAR |
19.08.2026 |
7.6 |
| CVE-2026-76358 |
Path Traversal through App Installation Tar Extraction in Splunk SOAR |
19.08.2026 |
6.5 |
| CVE-2026-76359 |
Path Traversal through Universal Forwarder Installer Archive Extraction in Splunk SOAR |
19.08.2026 |
6.5 |
| CVE-2026-76360 |
Information Disclosure through Missing Authorization in the Health REST API in Splunk SOAR |
19.08.2026 |
4.3 |
| CVE-2026-76361 |
Server-Side Request Forgery (SSRF) through the Connectivity Check REST API in Splunk SOAR |
19.08.2026 |
2.7 |
| CVE-2026-76362 |
Improper Certificate Validation through CyberArk Vault Privileged Access Manager in Splunk SOAR |
19.08.2026 |
7.4 |
| CVE-2026-76363 |
Structured Query Language Injection through the REST API in Splunk SOAR |
19.08.2026 |
6.5 |
| CVE-2026-76364 |
Structured Query Language (SQL) Injection through Custom Function Results in Splunk SOAR |
19.08.2026 |
6.5 |
| CVE-2026-76365 |
Structured Query Language (SQL) Injection through Custom Lists in Splunk SOAR |
19.08.2026 |
6.5 |
| CVE-2026-76366 |
Information Disclosure through the REST API in Splunk SOAR |
19.08.2026 |
6.5 |
| CVE-2026-76367 |
Stored Cross-Site Scripting (XSS) through Notes in Splunk SOAR |
19.08.2026 |
4 |
| CVE-2026-76368 |
Missing Authorization through Playbooks in Splunk SOAR |
19.08.2026 |
2.7 |
| CVE-2026-76369 |
Path Traversal through Automation Broker in Splunk SOAR |
19.08.2026 |
2.7 |
| CVE-2026-76370 |
Information Disclosure through the REST API in Splunk SOAR |
19.08.2026 |
4.3 |
| CVE-2026-76371 |
Incorrect Permission Assignment through Safe Mode in FireAMP for Splunk SOAR |
19.08.2026 |
2.7 |
| CVE-2026-76372 |
Incorrect Permission Assignment through Safe Mode in Nmap Scanner for Splunk SOAR |
19.08.2026 |
6.6 |
| CVE-2026-76373 |
Filter Injection through Action Parameters in AD LDAP app for Splunk SOAR |
19.08.2026 |
5.4 |
| CVE-2026-76374 |
Information Disclosure through Sensitive Data Logging in AD LDAP app for Splunk SOAR |
19.08.2026 |
4.3 |
| CVE-2026-76375 |
Information Disclosure through Environment Data Logging in AD LDAP app for Splunk SOAR |
19.08.2026 |
5 |
| CVE-2026-76376 |
Information Disclosure through Action Parameters in AWS IAM app for Splunk SOAR |
19.08.2026 |
4.3 |
| CVE-2026-76377 |
Information Disclosure through Action Parameters in Azure AD Graph app for Splunk SOAR |
19.08.2026 |
4.3 |
| CVE-2026-76378 |
Information Disclosure through Action Parameters in Cisco Secure Malware Analytics app for Splunk SOAR |
19.08.2026 |
4.3 |
| CVE-2026-76379 |
Information Disclosure through Action Parameters in Cisco Webex app for Splunk SOAR |
19.08.2026 |
4.3 |
| CVE-2026-76380 |
Information Disclosure through Action Parameters in CrowdStrike OAuth API app for Splunk SOAR |
19.08.2026 |
4.3 |
| CVE-2026-76381 |
Information Disclosure through Action Parameters in MS Graph for Active Directory app for Splunk SOAR |
19.08.2026 |
4.3 |
| CVE-2026-76382 |
Information Disclosure through Action Parameters in Phantom app for Splunk SOAR |
19.08.2026 |
4.3 |
| CVE-2026-76383 |
Information Disclosure through Action Parameters in RSA SecurID Authentication Manager app for Splunk SOAR |
19.08.2026 |
4.3 |
| CVE-2026-76384 |
Information Disclosure through Action Parameters in Splunk Attack Analyzer Connector for Splunk SOAR |
19.08.2026 |
4.3 |
| CVE-2026-76385 |
Information Disclosure through Action Parameters in Venafi app for Splunk SOAR |
19.08.2026 |
4.3 |
| CVE-2026-76386 |
Information Disclosure through Action Parameters in Zoom app for Splunk SOAR |
19.08.2026 |
4.3 |
| CVE-2026-76387 |
SPL Injection through the REST API in Splunk Enterprise Security |
19.08.2026 |
8.1 |
| CVE-2026-76388 |
Privilege Escalation through Search Macro Permissions in Splunk Enterprise Security |
19.08.2026 |
8.1 |
| CVE-2026-76389 |
Server-Side Request Forgery (SSRF) through the REST API in Cisco Talos Intelligence for Enterprise Security Cloud |
19.08.2026 |
8.8 |
| CVE-2026-76390 |
Information Disclosure through Splunk Web in Cisco Talos Intelligence for Enterprise Security Cloud |
19.08.2026 |
5.3 |
| CVE-2026-76391 |
Improper Privilege Management through Agent Run History in Splunk AI Toolkit |
19.08.2026 |
8.3 |
| CVE-2026-76392 |
Use of Hard-coded Credentials in Container Connections in Splunk AI Toolkit |
19.08.2026 |
5.4 |
| CVE-2026-76393 |
Race Condition during Model Upload through the REST API in Splunk AI Toolkit |
19.08.2026 |
5.9 |
| CVE-2026-76394 |
Missing Authorization in Container and Connection Management through the REST API in Splunk AI Toolkit |
19.08.2026 |
8.3 |
| CVE-2026-76395 |
Remote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading REST API in Splunk AI Toolkit |
19.08.2026 |
8.8 |
| CVE-2026-76396 |
Improper Access Control through Scheduled Searches in Splunk AI Toolkit |
19.08.2026 |
7.5 |
| CVE-2026-76397 |
Improper Access Control in Experiment History through the REST API in Splunk AI Toolkit |
19.08.2026 |
8.1 |
| CVE-2026-76398 |
Improper Access Control during Experiment History Deletion through the REST API in Splunk AI Toolkit |
19.08.2026 |
4.3 |
| CVE-2026-76399 |
Incorrect Permission Assignment for Scheduled Searches in Splunk AI Toolkit |
19.08.2026 |
8.1 |
| CVE-2026-76400 |
Denial of Service (DoS) through the REST API in Splunk Connect for Kafka |
19.08.2026 |
5.9 |
| CVE-2026-76401 |
Regular Expression Denial of Service (DoS) through the REST API in Splunk Connect for Kafka |
19.08.2026 |
5.9 |
| CVE-2026-76402 |
Server-Side Request Forgery (SSRF) through the REST API in Splunk Connect for Kafka |
19.08.2026 |
8.2 |
| CVE-2026-76403 |
Improper Certificate Validation through HTTP Event Collector Kerberos Authentication in Splunk Connect for Kafka |
19.08.2026 |
7.4 |
| CVE-2026-76404 |
Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app |
19.08.2026 |
9.1 |
| CVE-2026-76405 |
Information Disclosure through Cleartext Storage in the App Key Value Store in the Splunk On-Call (VictorOps) app |
19.08.2026 |
4.3 |
| CVE-2026-76589 |
TRENDnet TEW-755AP mycli FUN_401000 stack-based overflow |
19.08.2026 |
|
| CVE-2025-36254 |
DS8900F and DS8A00 Authentication Bypass |
19.08.2026 |
7.4 |
| CVE-2025-36255 |
DS8900F and DS8A00 Privilege Escalation |
19.08.2026 |
7.5 |
| CVE-2025-36398 |
DS8900F and DS8A00 Information Disclosure |
19.08.2026 |
5.4 |
| CVE-2026-69550 |
Windows App for Mac Information Disclosure Vulnerability |
19.08.2026 |
6.5 |
| CVE-2026-11617 |
Tanium addressed a compression bomb vulnerability in Findings. |
19.08.2026 |
3.1 |
| CVE-2026-14514 |
Reliable Scalable Cluster Technology Denial-of-Service |
19.08.2026 |
6.5 |
| CVE-2026-14978 |
Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions |
19.08.2026 |
5.5 |
| CVE-2026-75476 |
Tanium addressed a compression bomb vulnerability in Threat Response. |
19.08.2026 |
3.1 |
| CVE-2026-75595 |
Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext |
19.08.2026 |
|
| CVE-2026-61556 |
LiquidJS: An infinite loop vulnerability in `strip_html` filter |
19.08.2026 |
|
| CVE-2026-62727 |
Windows Telephony Service Elevation of Privilege Vulnerability |
19.08.2026 |
7 |
| CVE-2026-69222 |
LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process |
19.08.2026 |
7.5 |
| CVE-2026-75596 |
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing |
19.08.2026 |
|
| CVE-2026-76584 |
TRENDnet TV-IP751WIC alphapd set_time.cgi stack-based overflow |
19.08.2026 |
|
| CVE-2026-76827 |
Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (cross-tenant data tampering) |
19.08.2026 |
|
| CVE-2026-12522 |
Stack buffer overflow in Zephyr hl7800 modem driver parsing network-supplied +CGCONTRDP address fields |
19.08.2026 |
8.8 |
| CVE-2026-12633 |
Out-of-bounds write in IPv6 6LoWPAN Context Option handling via unauthenticated Router Advertisement |
19.08.2026 |
8.1 |
| CVE-2026-12634 |
Out-of-bounds stack write in the settings NVS backend from over-reported nvs_read length |
19.08.2026 |
5.3 |
| CVE-2026-54491 |
Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths |
19.08.2026 |
7.1 |
| CVE-2026-54492 |
Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation |
19.08.2026 |
4.3 |
| CVE-2026-54493 |
Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations |
19.08.2026 |
7.7 |
| CVE-2026-54494 |
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4 |
19.08.2026 |
|
| CVE-2026-68552 |
Coturn: uint16_t truncation overflow in STUN message length causes TCP stream framing bypass |
19.08.2026 |
5.3 |
| CVE-2026-68553 |
Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command |
19.08.2026 |
7.1 |
| CVE-2026-68554 |
Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers modify authenticated TURN requests |
19.08.2026 |
|
| CVE-2026-68555 |
coturn: Chained mobility resumes allow authenticated remote memory exhaustion |
19.08.2026 |
6.5 |
| CVE-2026-75569 |
Mce-operator-bundle: mce-operator-bundle: bundle-generation business logic fetched from mutable stolostron/release@master |
19.08.2026 |
|
| CVE-2026-75616 |
Command Injection in Router Web Management Interface |
19.08.2026 |
|
| CVE-2026-76139 |
Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@master with full build credentials |
19.08.2026 |
|
| CVE-2026-76583 |
TRENDnet TV-IP751WIC alphapd set_time.cgi command injection |
19.08.2026 |
|
| CVE-2026-17015 |
IBM i Denial of Service |
19.08.2026 |
5.4 |
| CVE-2026-18102 |
IBM i Buffer Overflow |
19.08.2026 |
3.5 |
| CVE-2026-18544 |
Portieris is vulnerable to Image Policy Bypass via Unvalidated ownerReference |
19.08.2026 |
8.1 |
| CVE-2026-53542 |
Termix: Tar option injection in file-manager archive creation allows command execution on managed SSH hosts |
19.08.2026 |
8.8 |
| CVE-2026-53545 |
Termix: Remote Code Execution via Tunnel Disconnect pkill Command Injection |
19.08.2026 |
9.8 |
| CVE-2026-53546 |
Termix: Missing authorization in SSH host credential resolution exposes stored credentials |
19.08.2026 |
9.6 |
| CVE-2026-53547 |
Termix: Account Takeover via Global Settings Disclosure |
19.08.2026 |
8.8 |
| CVE-2026-53548 |
Termix: IDOR — Authenticated user can fetch SSH passwords for hosts owned by other users |
19.08.2026 |
9.6 |
| CVE-2026-53549 |
Termix: Server-Side Request Forgery via Proxy Connectivity Test |
19.08.2026 |
7.7 |
| CVE-2026-54738 |
Lemmy: Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfo |
19.08.2026 |
6.5 |
| CVE-2026-76582 |
TRENDnet TEW-821DAP ssi ping.cgi system command injection |
19.08.2026 |
|
| CVE-2026-18849 |
IBM OpenBMC Code Execution |
19.08.2026 |
6.8 |
| CVE-2026-4936 |
Power System Insufficient Entropy |
19.08.2026 |
5.1 |
| CVE-2026-4937 |
Power System Insufficient Entropy |
19.08.2026 |
5.3 |
| CVE-2026-54739 |
Lemmy: Login Endpoint User Enumeration via HTTP Response Code Differential |
19.08.2026 |
|
| CVE-2026-54740 |
Lemmy: Lower-ranked federated moderator can remove higher-ranked moderators |
19.08.2026 |
6.5 |
| CVE-2026-54741 |
Lemmy: Blocked users can edit private messages sent before the block |
19.08.2026 |
|
| CVE-2026-54743 |
Lemmy: Stored XSS via markdown image alt-text in lemmy-ui html5-embed |
19.08.2026 |
|
| CVE-2026-76576 |
yangzongzhuan RuoYi-Vue Common Download Endpoint CommonController.java resourceDownload path traversal |
19.08.2026 |
|
| CVE-2026-16707 |
Power System Out-of-bounds Read |
19.08.2026 |
8.2 |
| CVE-2026-54742 |
Lemmy: `CollectionAdd::Featured` does not check the post is in the community |
19.08.2026 |
|
| CVE-2026-61711 |
BuildKit: Custom frontend could bypass Seccomp/AppArmor |
19.08.2026 |
|
| CVE-2026-61712 |
BuildKit: Possible runtime DoS via unbounded group parsing |
19.08.2026 |
|
| CVE-2026-75593 |
BuildKit: Malicious client can bypass destination directory validation on local sources upload |
19.08.2026 |
|
| CVE-2026-16886 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
4.3 |
| CVE-2026-16890 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
3.6 |
| CVE-2026-16891 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
3.3 |
| CVE-2026-16894 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
9.8 |
| CVE-2026-16897 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
4.4 |
| CVE-2026-16901 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
8.8 |
| CVE-2026-16903 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
9.6 |
| CVE-2026-16909 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
8.8 |
| CVE-2026-16911 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
8.8 |
| CVE-2026-16913 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
9.8 |
| CVE-2026-16914 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
6.7 |
| CVE-2026-16917 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
9.8 |
| CVE-2026-16919 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
9.8 |
| CVE-2026-76574 |
code-projects Hospital Information System User Login UsersController.php login sql injection |
19.08.2026 |
|
| CVE-2026-16873 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
7.8 |
| CVE-2026-16874 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
7.8 |
| CVE-2026-16875 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
7.8 |
| CVE-2026-16877 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
8.8 |
| CVE-2026-16882 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
9.8 |
| CVE-2026-16883 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
5.5 |
| CVE-2026-16885 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
9.8 |
| CVE-2026-16888 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
3.7 |
| CVE-2026-17028 |
Power System Out-of-bounds Read |
19.08.2026 |
6.5 |
| CVE-2026-17091 |
Power System Integer Overflow |
19.08.2026 |
8.4 |
| CVE-2026-17097 |
Power System Improper Validation |
19.08.2026 |
7.3 |
| CVE-2026-18821 |
Power System Out-of-bounds Write |
19.08.2026 |
7.5 |
| CVE-2026-63187 |
Logto: OS command injection vulnerability exists in the Commitlint workflow |
19.08.2026 |
6.3 |
| CVE-2026-63188 |
logto-tunnel serves files outside --experience-path via path traversal |
19.08.2026 |
|
| CVE-2026-16661 |
Power System Integer Overflow |
19.08.2026 |
8.2 |
| CVE-2026-16724 |
Power System Integer Overflow |
19.08.2026 |
4.5 |
| CVE-2026-16834 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
9.8 |
| CVE-2026-16836 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
7.5 |
| CVE-2026-16837 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
7.5 |
| CVE-2026-16838 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
7 |
| CVE-2026-16839 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
9.4 |
| CVE-2026-16840 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
9.8 |
| CVE-2026-16841 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
8.8 |
| CVE-2026-16842 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
8.8 |
| CVE-2026-16844 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
8.8 |
| CVE-2026-16845 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
9.8 |
| CVE-2026-16846 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
6.5 |
| CVE-2026-16847 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
8.8 |
| CVE-2026-16848 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
8.8 |
| CVE-2026-16849 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
4.3 |
| CVE-2026-16850 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
8.8 |
| CVE-2026-16851 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
7.4 |
| CVE-2026-16852 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
7.5 |
| CVE-2026-16855 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
5.5 |
| CVE-2026-16857 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
8.2 |
| CVE-2026-16862 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
9.8 |
| CVE-2026-16864 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
9.8 |
| CVE-2026-16865 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
8.8 |
| CVE-2026-16866 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
4.8 |
| CVE-2026-16869 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
7.8 |
| CVE-2026-16872 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
9.8 |
| CVE-2026-17414 |
Power System Improper Input Validation |
19.08.2026 |
8.1 |
| CVE-2026-18871 |
Power System Buffer Overflow |
19.08.2026 |
7.3 |
| CVE-2026-55085 |
Etherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-lite |
19.08.2026 |
9.6 |
| CVE-2026-55086 |
Etherpad: Import/export use Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite |
19.08.2026 |
4.2 |
| CVE-2026-55088 |
Etherpad: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token |
19.08.2026 |
6.8 |
| CVE-2026-55089 |
Etherpad: JWT `admin` claim presence-only check lets non-admin OAuth users invoke every Etherpad HTTP API endpoint |
19.08.2026 |
9.9 |
| CVE-2026-55090 |
Etherpad: Stored XSS in HTML export via unescaped attribute-pool values |
19.08.2026 |
|
| CVE-2026-62317 |
Logto: ReDoS via unescaped user input in email subaddressing regex (blockSubaddressing) |
19.08.2026 |
7.5 |
| CVE-2026-76572 |
pkp pkp-lib XSLTransformer.php _transformPHP xml external entity reference |
19.08.2026 |
|
| CVE-2026-16822 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
9.3 |
| CVE-2026-16824 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
7.5 |
| CVE-2026-16825 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
4.2 |
| CVE-2026-16827 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
5.9 |
| CVE-2026-16829 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
5.3 |
| CVE-2026-16831 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
7.5 |
| CVE-2026-16833 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
5.3 |
| CVE-2026-19505 |
RDK-B WebUI improper cryptographic signature verification vulnerability |
19.08.2026 |
|
| CVE-2026-19506 |
RDK-B WebUI race condition vulnerability |
19.08.2026 |
|
| CVE-2026-19507 |
RDK WebUI uncontrolled resource consumption |
19.08.2026 |
|
| CVE-2026-19508 |
RDK WebUI heap-based buffer overflow vulnerability |
19.08.2026 |
|
| CVE-2026-19509 |
RDK WebUI DOS vulnerability |
19.08.2026 |
|
| CVE-2026-22306 |
Critical flaw impacting OZOLS ERP's automatic update channel |
19.08.2026 |
|
| CVE-2026-55087 |
Etherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect) |
19.08.2026 |
6.1 |
| CVE-2026-67189 |
pfSense Plus/CE Stored XSS via Traffic Graphs PTR Record |
19.08.2026 |
|
| CVE-2026-68558 |
Wekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446) |
19.08.2026 |
8.5 |
| CVE-2026-68559 |
Wekan: Broken access control in the Excel-export route (`/api/boards/:boardId/exportExcel`) |
19.08.2026 |
6.5 |
| CVE-2026-68560 |
Wekan:hell Injection in External Antivirus Scanner Path via asyncExec |
19.08.2026 |
|
| CVE-2026-68561 |
Wekan: a low-privilege board member escalates to board admin and takes over a private board via the `sort` collection-allow rule |
19.08.2026 |
8.8 |
| CVE-2026-68899 |
Wekan: File Upload MIME Type Validation Bypass — Stored XSS via Missing System Binary Fallback |
19.08.2026 |
8.7 |
| CVE-2026-68900 |
Wekan: Stored XSS in HTML board exports through a card-title second parse |
19.08.2026 |
7.6 |
| CVE-2026-68901 |
WeKan Board Export REST Endpoints: NULL Pointer Dereference on Invalid authToken Leads to Uncaught Exception / Remote Denial of Service |
19.08.2026 |
6.5 |
| CVE-2026-74226 |
|
19.08.2026 |
|
| CVE-2026-74227 |
|
19.08.2026 |
|
| CVE-2026-74228 |
|
19.08.2026 |
|
| CVE-2026-76647 |
Leantime JSON-RPC API contains a missing authorization vulnerability |
19.08.2026 |
|
| CVE-2026-16933 |
Power System Integer Overflow |
19.08.2026 |
8.2 |
| CVE-2026-17042 |
Power System Out-of-bounds Read |
19.08.2026 |
7.3 |
| CVE-2026-17063 |
Power System Incorrect Authorization |
19.08.2026 |
7.9 |
| CVE-2026-17590 |
|
19.08.2026 |
|
| CVE-2026-63722 |
ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.php |
19.08.2026 |
|
| CVE-2026-75112 |
OTTO® Fleet Manager – Weak Password Hashing Configuration |
19.08.2026 |
|
| CVE-2026-16687 |
Power System Buffer Overflow |
19.08.2026 |
9.6 |
| CVE-2026-19198 |
Akaunting 3.1.21 - Improper authorization in BulkActions handle dispatch |
19.08.2026 |
|
| CVE-2026-16828 |
Power System Out-of-bounds Read |
19.08.2026 |
7.6 |
| CVE-2026-16832 |
Power System Buffer Overflow |
19.08.2026 |
8.4 |
| CVE-2026-16835 |
Power System Improper Certificate Validation |
19.08.2026 |
9.6 |
| CVE-2026-16930 |
Power System Missing Authorization |
19.08.2026 |
8.2 |
| CVE-2026-16938 |
Power System Missing Authorization |
19.08.2026 |
6.9 |
| CVE-2026-17429 |
Power System Incorrect Authorization |
19.08.2026 |
8.1 |
| CVE-2026-17494 |
Power System Buffer Overflow |
19.08.2026 |
8.2 |
| CVE-2026-18681 |
This Power System Buffer Overflow |
19.08.2026 |
6.8 |
| CVE-2026-18848 |
Power System Cross-Site Request Forgery (CSRF) |
19.08.2026 |
8.3 |
| CVE-2026-17093 |
Power System Buffer Overflow |
19.08.2026 |
8.2 |
| CVE-2026-17100 |
Power System Out-of-bounds Write |
19.08.2026 |
8.2 |
| CVE-2026-18315 |
TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter |
19.08.2026 |
9.8 |
| CVE-2026-19321 |
Power System Integer Overflow |
19.08.2026 |
6.7 |
| CVE-2026-55643 |
Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode |
19.08.2026 |
|
| CVE-2026-55694 |
Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover |
19.08.2026 |
|
| CVE-2026-55703 |
Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET |
19.08.2026 |
4.3 |
| CVE-2026-61807 |
Snipe-IT: Stored DOM XSS via table selected-count IDs |
19.08.2026 |
|
| CVE-2026-75618 |
RTSP Null Pointer Dereference Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101 |
19.08.2026 |
|
| CVE-2026-75619 |
RTSP Heap Buffer Overflow Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101 |
19.08.2026 |
|
| CVE-2026-49870 |
Snipe-IT: TOTP Brute-Forceable Due to Missing Rate Limiting on `POST /two-factor` |
19.08.2026 |
5.9 |
| CVE-2026-49976 |
Snipe-IT: User Account Escalation via CSV Import |
19.08.2026 |
6.5 |
| CVE-2026-50550 |
Snipe-IT: 2FA reset privilege bypass |
19.08.2026 |
5.8 |
| CVE-2026-55482 |
Snipe-IT: Multi-Tenancy Bypass via Bulk Asset Update |
19.08.2026 |
6.3 |
| CVE-2026-55483 |
Snipe-IT: Privilege Escalation via Missing admin Permission Check in User Creation |
19.08.2026 |
|
| CVE-2026-55519 |
Snipe-IT: Improper Authorization in File Deletion (IDOR) |
19.08.2026 |
5.4 |
| CVE-2026-70496 |
Search-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent via impersonate, rbac write, csr approve, and manifestwork |
19.08.2026 |
|
| CVE-2026-19234 |
Power System Buffer Overflow |
19.08.2026 |
8.2 |
| CVE-2026-63633 |
FreeRDP: Heap buffer overflow in Opus audio decode (`freerdp_dsp_decode_opus` resizes the wrong stream) — server→client |
19.08.2026 |
|
| CVE-2026-69159 |
FreeRDP: Out-of-Bounds Read in Planar RLE Decoder (planar_decompress_plane_rle / planar_decompress_plane_rle_only) |
19.08.2026 |
5.4 |
| CVE-2026-18874 |
Volsync-addon-controller: volsync-addon-controller: annotation values rendered into yaml via text/template without escaping allows yaml injection into subscription |
19.08.2026 |
|
| CVE-2026-55192 |
FreeRDP: Out-of-bounds read in H.264 YUV-to-RGB conversion due to decoder/surface dimension mismatch |
19.08.2026 |
|
| CVE-2026-55194 |
FreeRDPHeap-buffer-overflow write in TS Gateway RPC RESPONSE reassembly due to alloc_hint capacity mismatch |
19.08.2026 |
|
| CVE-2026-63117 |
FreeRDP: Denial of service through ADPCM frame size calculation |
19.08.2026 |
6.5 |
| CVE-2026-63652 |
FreeRDP: Double-free of `client_formats` in the rdpsnd server channel on a malformed Client Audio Formats PDU |
19.08.2026 |
|
| CVE-2025-14600 |
Admin Account Takeover via Path Traversal in vsDesk |
19.08.2026 |
|
| CVE-2026-19653 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
6.5 |
| CVE-2026-55191 |
FreeRDP: Heap-buffer-overflow write in AVC444 YUV buffer allocation |
19.08.2026 |
|
| CVE-2026-55193 |
FreeRDP: Heap-buffer-overflow write in TS Gateway RPC fragment receive due to uncapped bind_ack max_xmit_frag |
19.08.2026 |
|
| CVE-2026-55564 |
FreeRDP: Out-of-bounds read in glyph_cache_get via crafted glyph fragments |
19.08.2026 |
5.4 |
| CVE-2026-55648 |
FreeRDP: Integer Overflow in `freerdp_image_copy_from_icon_data` Bypasses Bounds Check |
19.08.2026 |
|
| CVE-2026-61518 |
ISPConfig Authenticated SQL Injection via Remote API primary_id Parameter |
19.08.2026 |
|
| CVE-2026-62680 |
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref |
19.08.2026 |
7.1 |
| CVE-2026-62682 |
Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification) |
19.08.2026 |
|
| CVE-2026-72717 |
Orval: Import-time RCE via schema default -> zod module-level template literal |
19.08.2026 |
|
| CVE-2026-75149 |
marimo < 0.23.15 Code Injection via MCP Server Configuration |
19.08.2026 |
|
| CVE-2026-17183 |
CVE-2026-17183 CVE Record |
19.08.2026 |
7.1 |
| CVE-2026-19875 |
Unauthenticated Registration POST Endpoint Permits Admin Email Overwrite and Outbound Relay Abuse in Langflow |
19.08.2026 |
7.5 |
| CVE-2026-62681 |
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) |
19.08.2026 |
|
| CVE-2026-66794 |
Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public route |
19.08.2026 |
|
| CVE-2026-71864 |
Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client |
19.08.2026 |
|
| CVE-2026-71865 |
Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli |
19.08.2026 |
|
| CVE-2026-71866 |
Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client |
19.08.2026 |
|
| CVE-2026-71867 |
Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator |
19.08.2026 |
|
| CVE-2026-71868 |
Orval: Import-time RCE via enum-typed default -> zod module-level template literal |
19.08.2026 |
|
| CVE-2026-71869 |
Orval: Import-time RCE via array-items default -> zod module-level template literal |
19.08.2026 |
|
| CVE-2026-71871 |
Orval: Import-time RCE via header-parameter default -> zod module-level template literal |
19.08.2026 |
|
| CVE-2026-72716 |
Orval: Import-time RCE via query-parameter default -> zod module-level template literal |
19.08.2026 |
|
| CVE-2025-14603 |
Use of user input in raw SQL queries in vsDesk leading to blind SQL injection |
19.08.2026 |
|
| CVE-2026-32475 |
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability |
19.08.2026 |
9 |
| CVE-2026-67581 |
On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay |
19.08.2026 |
|
| CVE-2026-73136 |
Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay |
19.08.2026 |
|
| CVE-2026-73541 |
Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drain |
19.08.2026 |
|
| CVE-2026-73829 |
Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a concurrent race |
19.08.2026 |
|
| CVE-2026-50173 |
Flow-Like: Azure invoke presign grants app content write SAS to ExecuteEvents-only users |
19.08.2026 |
|
| CVE-2026-71470 |
Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow unsanitized into pods running impersonating sa |
19.08.2026 |
|
| CVE-2026-72529 |
|
20.08.2026 |
9.8 |
| CVE-2026-72530 |
|
20.08.2026 |
9 |
| CVE-2024-13942 |
Rockchip RK3588s Secure BootROM TOCTOU (time-of-check to time-of-use) vulnerability leading to arbitrary code execution with highest privileges |
19.08.2026 |
7.6 |
| CVE-2026-20320 |
|
19.08.2026 |
7.5 |
| CVE-2026-20327 |
Cisco Unified Intelligence Center SQL Injection Vulnerability |
19.08.2026 |
6.5 |
| CVE-2026-49392 |
Wazuh: Local SQL injection in FIM db due to path lookup interpolation in wazuh-syscheckd |
19.08.2026 |
5.3 |
| CVE-2026-75141 |
FFmpeg Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing |
19.08.2026 |
|
| CVE-2026-75142 |
FFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c |
19.08.2026 |
|
| CVE-2026-75143 |
FFmpeg Heap Buffer Overflow via RIST Protocol Reader |
19.08.2026 |
|
| CVE-2026-75144 |
FFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer |
19.08.2026 |
|
| CVE-2026-75145 |
FFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP Packetizer |
19.08.2026 |
|
| CVE-2026-75146 |
FFmpeg Out-of-Bounds Read in DASH Demuxer via dashdec.c |
19.08.2026 |
|
| CVE-2026-75147 |
FFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.c |
19.08.2026 |
|
| CVE-2026-75583 |
keeper.sh Calendar version prior to 2.18.14 SSRF Guard Bypass via DNS Rebinding |
19.08.2026 |
|
| CVE-2026-20030 |
Cisco Crosswork Security Hardening Release: August 2026 |
19.08.2026 |
10 |
| CVE-2026-20177 |
Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability |
19.08.2026 |
5.3 |
| CVE-2026-20231 |
Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Neutralization of Special Elements Vulnerabilities |
20.08.2026 |
9.9 |
| CVE-2026-20232 |
Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability |
19.08.2026 |
5.4 |
| CVE-2026-20302 |
Cisco RoomOS Stack Overflow Vulnerability |
19.08.2026 |
6.1 |
| CVE-2026-20314 |
Cisco Packaged Contact Center Enterprise & Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability |
19.08.2026 |
5 |
| CVE-2026-20315 |
Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Control Vulnerabilities |
20.08.2026 |
10 |
| CVE-2026-20317 |
Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Authentication Vulnerabilities |
19.08.2026 |
10 |
| CVE-2026-20318 |
Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Input Validation Vulnerabilities |
19.08.2026 |
9.6 |
| CVE-2026-20319 |
Cisco Secure Workload Software Security Hardening Release August 2026 - Buffer Management Vulnerabilities |
19.08.2026 |
7.5 |
| CVE-2026-20357 |
Cisco Crosswork Security Hardening Release: August 2026 |
19.08.2026 |
10 |
| CVE-2026-20358 |
Cisco Crosswork Security Hardening Release: August 2026 |
19.08.2026 |
10 |
| CVE-2026-20359 |
Cisco Crosswork Security Hardening Release: August 2026 |
19.08.2026 |
9.9 |
| CVE-2026-41424 |
Wazuh: Privilege Escalation via Admin-Protection Bypass in update-user API Endpoint |
19.08.2026 |
8.2 |
| CVE-2026-44255 |
Wazuh: Username Enumeration via Timing Side-Channel |
19.08.2026 |
5.3 |
| CVE-2026-44256 |
Wazuh: CRLF Log Injection via Unsanitized Basic-Auth Username |
19.08.2026 |
5.3 |
| CVE-2026-44901 |
Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability |
19.08.2026 |
8.4 |
| CVE-2026-45798 |
Wazuh: Pre-auth stack-buffer-overflow in compare_wazuh_versions reachable from wazuh-authd (TCP/1515) via crafted enrollment V: field |
19.08.2026 |
7.5 |
| CVE-2026-48024 |
Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh manager |
19.08.2026 |
9.1 |
| CVE-2026-48162 |
Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file path injection in Wazuh manager |
19.08.2026 |
9.1 |
| CVE-2026-49441 |
Wazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under WAZUH_PATH on Wazuh manager |
19.08.2026 |
9.1 |
| CVE-2026-44252 |
Wazuh Manager dapi RBAC Bypass Allows Privilege Escalation |
19.08.2026 |
|
| CVE-2026-44253 |
Wazuh: Cluster Protocol Memory Exhaustion (DoS) via unbounded receive_str allocation and div_msg_box accumulation |
19.08.2026 |
4.9 |
| CVE-2026-44254 |
Wazuh: Stack Out-of-Bounds Write in remoted Decompression Path |
19.08.2026 |
5.3 |
| CVE-2026-46343 |
Wazuh: Arbitrary File Deletion via Cluster Protocol – Incomplete Path Validation in end_receiving_file() |
19.08.2026 |
|
| CVE-2026-64852 |
Grav API Plugin: Missing authorization on API-key generate/revoke lets any admin.login user forge keys for any account |
19.08.2026 |
|
| CVE-2026-18430 |
HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reason |
19.08.2026 |
|
| CVE-2026-62671 |
CSRF in grav-plugin-login: anonymous attacker rotates a logged-in user's 2FA (TOTP) secret (no nonce on task=login.regenerate2FASecret) |
19.08.2026 |
5.4 |
| CVE-2026-62673 |
Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems |
19.08.2026 |
|
| CVE-2026-63407 |
Grav API Plugin: CORS 'Access-Control-Allow-Origin: *' on Authenticated API Responses |
19.08.2026 |
8.2 |
| CVE-2026-63408 |
Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter |
19.08.2026 |
7.5 |
| CVE-2026-64850 |
Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() |
19.08.2026 |
|
| CVE-2026-64851 |
Grav Shortcode Core Plugin: Stored XSS in shortcode-core attribute handlers |
19.08.2026 |
|
| CVE-2026-62666 |
Grav API Plugin: non-super api.users.write manager -> super-admin via createApiKey (incomplete fix of CVE-2026-59190); + 2FA strip of super |
19.08.2026 |
8.8 |
| CVE-2026-62667 |
Grav API Plugin : API Key 'scopes' Never Enforced - Delegated Least-Privilege Keys Carry Full User ACL |
19.08.2026 |
8.1 |
| CVE-2026-62669 |
Grav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge |
19.08.2026 |
7.4 |
| CVE-2026-62672 |
Grav: Authenticated ReDoS via regex_replace in Twig Sandbox |
19.08.2026 |
|
| CVE-2026-19672 |
tarfile extraction filter bypass allows creation of directories outside the destination |
19.08.2026 |
|
| CVE-2026-61607 |
Grav API Plugin: Stored XSS via SVG Upload - API Media Pipeline Bypasses Sanitizer |
19.08.2026 |
4.6 |
| CVE-2026-61690 |
Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits |
19.08.2026 |
6.5 |
| CVE-2026-61842 |
Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass) |
19.08.2026 |
6.5 |
| CVE-2026-62668 |
Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols |
19.08.2026 |
|
| CVE-2026-62670 |
Fail-open authorization in grav-plugin-flex-objects admin-next API: api.access user gets full CRUD on permission-less directories (requireFlexPermission missing else-deny) |
19.08.2026 |
6.3 |
| CVE-2026-16819 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
7.7 |
| CVE-2026-53654 |
Grav: Unauthenticated open redirect via login twofa_cancel _redirect |
19.08.2026 |
|
| CVE-2026-14970 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
7.5 |
| CVE-2026-16656 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
9.8 |
| CVE-2026-16686 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
8.2 |
| CVE-2026-16690 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
7.5 |
| CVE-2026-16703 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
7.8 |
| CVE-2026-16706 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
7.5 |
| CVE-2026-16814 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
8.8 |
| CVE-2026-16816 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
9.9 |
| CVE-2026-16817 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
7.5 |
| CVE-2026-16818 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
7.5 |
| CVE-2026-40509 |
OpenEMR < 8.3.0 CSRF via DICOM Viewer web_path Parameter |
19.08.2026 |
|
| CVE-2026-52834 |
jxl-oxide: Out-of-bounds writes due to integer overflow in jxl-grid on 32-bit platforms |
19.08.2026 |
7.3 |
| CVE-2026-52889 |
Formie: Server-Side Template Injection in Formie Hidden field defaults |
19.08.2026 |
9.8 |
| CVE-2026-53477 |
|
19.08.2026 |
7.8 |
| CVE-2026-58562 |
|
19.08.2026 |
7.3 |
| CVE-2026-58564 |
|
19.08.2026 |
7.8 |
| CVE-2026-58565 |
|
19.08.2026 |
8.8 |
| CVE-2026-67266 |
|
19.08.2026 |
5.5 |
| CVE-2026-67267 |
|
19.08.2026 |
5.5 |
| CVE-2026-67268 |
|
19.08.2026 |
6.5 |
| CVE-2026-76614 |
OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restore |
19.08.2026 |
|
| CVE-2026-18756 |
HumHub Community Edition 1.18.4-pl1 - Reflected XSS in Space membership request button rendering |
19.08.2026 |
|
| CVE-2026-23501 |
|
20.08.2026 |
7.2 |
| CVE-2026-40507 |
OpenEMR < 8.3.0 Reflected XSS via templateHtml Parameter in Patient Portal |
19.08.2026 |
|
| CVE-2026-40508 |
OpenEMR < 8.3.0 Stored XSS via Patient Portal Template Import Handler |
19.08.2026 |
|
| CVE-2026-45272 |
MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File |
19.08.2026 |
|
| CVE-2026-45273 |
MyBooks: Privilege Escalation via Missing Authorization on Admin Settings Endpoint |
19.08.2026 |
|
| CVE-2026-45274 |
MyBooks: Unauthenticated Registration Bypass via Missing Server-Side ALLOW_REGISTER Enforcement |
19.08.2026 |
|
| CVE-2026-47187 |
SSHFS Symlink Escape: Rogue SFTP Server → Local File Read/Write |
20.08.2026 |
9.3 |
| CVE-2026-48711 |
SSHFS: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') |
20.08.2026 |
7 |
| CVE-2026-49283 |
SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass |
19.08.2026 |
8.7 |
| CVE-2026-49289 |
SimpleSAMLphp SAML2: Possible DoS via XPath Transform |
19.08.2026 |
7.5 |
| CVE-2026-49816 |
|
19.08.2026 |
7.8 |
| CVE-2026-49817 |
|
19.08.2026 |
7.8 |
| CVE-2026-52792 |
Algernon: Server-side script source disclosure on Windows via NTFS filename |
19.08.2026 |
|
| CVE-2026-53451 |
Ground Station: Unauthenticated arbitrary file write (path traversal) in save-waterfall-snapshot leads to remote code execution |
19.08.2026 |
9.8 |
| CVE-2026-53452 |
Ground Station: Unauthenticated out-of-containment file read via `sigmfplayback` `recordingPath` |
19.08.2026 |
5.3 |
| CVE-2026-56796 |
|
19.08.2026 |
6.6 |
| CVE-2026-56797 |
|
19.08.2026 |
7.3 |
| CVE-2026-75949 |
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 |
19.08.2026 |
|
| CVE-2026-75950 |
Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 |
19.08.2026 |
|
| CVE-2026-75951 |
Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3 |
19.08.2026 |
|
| CVE-2026-75952 |
Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 |
19.08.2026 |
|
| CVE-2026-75953 |
Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 |
19.08.2026 |
|
| CVE-2026-75954 |
Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 |
19.08.2026 |
|
| CVE-2026-75955 |
Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 |
19.08.2026 |
|
| CVE-2026-75956 |
Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 |
19.08.2026 |
|
| CVE-2026-15061 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
19.08.2026 |
8.2 |
| CVE-2026-15065 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
9.1 |
| CVE-2026-15068 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
9.9 |
| CVE-2026-15078 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
8.1 |
| CVE-2026-15961 |
Power System Information Disclosure |
19.08.2026 |
5.2 |
| CVE-2026-32802 |
|
19.08.2026 |
5.3 |
| CVE-2026-44829 |
Gotenberg: Path traversal in zip entry name via Windows-style separators in upload filename |
19.08.2026 |
8.8 |
| CVE-2026-45741 |
Gotenberg: SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes |
19.08.2026 |
7.5 |
| CVE-2026-45742 |
Gotenberg: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') |
19.08.2026 |
7.5 |
| CVE-2026-49253 |
electerm: Path Traversal in Zmodem and Trzsz Download Filename Handling |
19.08.2026 |
7.1 |
| CVE-2026-49255 |
electerm: Command Injection in File System Operations (rmrf, mv, cp) |
19.08.2026 |
8.8 |
| CVE-2026-71960 |
Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT |
19.08.2026 |
|
| CVE-2026-71961 |
Cudy WR3000 2.0 OS Command Injection via Mesh MQTT Command Handler |
19.08.2026 |
|
| CVE-2026-76203 |
CSS sanitizer bypass in Pentestify report themes allows forced outbound requests |
19.08.2026 |
|
| CVE-2026-18526 |
HumHub 1.18.4 / 1.18.4-pl1 – Stored Cross-Site Scripting in oEmbed confirmation |
19.08.2026 |
|
| CVE-2026-50149 |
Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled |
19.08.2026 |
6.5 |
| CVE-2026-54793 |
|
19.08.2026 |
4.6 |
| CVE-2026-71176 |
|
20.08.2026 |
8.8 |
| CVE-2019-25766 |
Renovate before 19.38.7 Credential Exposure via Go Modules |
19.08.2026 |
|
| CVE-2020-37267 |
Renovate 19.180.0 before 23.25.1 Token Leakage via Logs |
19.08.2026 |
|
| CVE-2024-58376 |
Renovate 37.158.0 before 37.199.0 Command Injection via helmv3 |
19.08.2026 |
|
| CVE-2026-16019 |
SQL Injection in Faydam Innovation's FAYDAM Datalogger |
19.08.2026 |
9.8 |
| CVE-2026-43961 |
Vim: vimscript injection via unescaped filename in netrw s:netrwmarkfile() filter() expression allows arbitrary code execution |
19.08.2026 |
|
| CVE-2026-54794 |
|
19.08.2026 |
7.2 |
| CVE-2026-70422 |
|
19.08.2026 |
8.1 |
| CVE-2026-70423 |
|
19.08.2026 |
6.5 |
| CVE-2026-70424 |
|
19.08.2026 |
6.5 |
| CVE-2026-71694 |
|
19.08.2026 |
|
| CVE-2026-75916 |
SiYuan XSS-to-RCE via unescaped block metadata in hint popup |
19.08.2026 |
|
| CVE-2026-75917 |
SiYuan before v3.7.4 XSS-to-RCE via pathName.ts |
19.08.2026 |
|
| CVE-2026-75918 |
phpMyFAQ before 4.1.7 Authentication Bypass via Tracking File |
19.08.2026 |
|
| CVE-2026-75919 |
phpMyFAQ before 4.1.7 Authentication Bypass via Setup API |
19.08.2026 |
|
| CVE-2026-75920 |
phpMyFAQ before 4.1.6 Information Disclosure via Backup ZIP |
19.08.2026 |
|
| CVE-2026-76205 |
phpMyFAQ before 4.1.7 SQL Injection via Glossary |
19.08.2026 |
|
| CVE-2026-76206 |
phpMyFAQ before 4.1.7 Information Disclosure via PDF Export |
19.08.2026 |
|
| CVE-2026-76207 |
phpMyFAQ before 4.1.7 2FA Bypass via Remember-Me Cookie |
19.08.2026 |
|
| CVE-2026-76208 |
phpMyFAQ 3.1.0 through 4.1.6 Authentication Bypass via LDAP |
19.08.2026 |
|
| CVE-2026-76209 |
phpMyFAQ before v4.1.6 Registration Bypass via API |
19.08.2026 |
|
| CVE-2026-76210 |
phpMyFAQ before v4.1.6 Local File Disclosure via PDF Export |
19.08.2026 |
|
| CVE-2026-76211 |
phpMyFAQ before 4.1.7 Information Disclosure via Admin API |
19.08.2026 |
|
| CVE-2026-76212 |
phpMyFAQ before 4.1.7 LIKE Wildcard Injection via PostgreSQL |
19.08.2026 |
|
| CVE-2026-76213 |
phpMyFAQ before 4.1.7 2FA Brute-Force via Session-Scoped Throttle |
19.08.2026 |
|
| CVE-2026-76214 |
phpMyFAQ before 4.1.7 WebAuthn Replay Attack via Challenge |
19.08.2026 |
|
| CVE-2026-76215 |
phpMyFAQ before 4.1.7 Missing Authorization via child resources |
19.08.2026 |
|
| CVE-2026-76216 |
Vikunja through 2.4.0 Principal-Type Confusion via LinkSharing |
19.08.2026 |
|
| CVE-2026-76217 |
GitPython before 3.1.58 Arbitrary File Read via pathspec-from-file |
19.08.2026 |
|
| CVE-2026-76218 |
GitPython before 3.1.58 Remote Code Execution via Repo.init |
20.08.2026 |
|
| CVE-2026-76219 |
GitPython before 3.1.58 Arbitrary File Overwrite via read-tree |
19.08.2026 |
|
| CVE-2026-76220 |
GitPython before 3.1.58 Command Execution via split_single_char_options |
20.08.2026 |
|
| CVE-2026-76221 |
GitPython before 3.1.58 Config Injection via option-name |
20.08.2026 |
|
| CVE-2026-76222 |
GitPython before 3.1.58 Path Traversal via .gitmodules Submodule Name |
19.08.2026 |
|
| CVE-2026-76223 |
ArcadeDB before 26.8.1 Permission Bypass via DEFINE FUNCTION |
19.08.2026 |
|
| CVE-2026-76224 |
ArcadeDB before 26.8.1 Remote Code Execution via Groovy Fallback |
19.08.2026 |
|
| CVE-2026-76225 |
ArcadeDB before 26.8.1 Server-Side Request Forgery via LOAD CSV |
19.08.2026 |
|
| CVE-2026-76226 |
Renovate 43.65.0 through 43.102.11 Remote Code Execution via lockFileMaintenance |
19.08.2026 |
|
| CVE-2026-76227 |
Renovate 42.68.1 before 42.96.3 Environment Variable Exposure |
19.08.2026 |
|
| CVE-2026-76228 |
Renovate before 42.68.5 Remote Code Execution via Gradle Wrapper |
19.08.2026 |
|
| CVE-2026-76229 |
Renovate 39.218.0 before 40.33.0 Arbitrary Command Injection via kustomize |
19.08.2026 |
|
| CVE-2026-76230 |
Renovate 35.63.0 before 40.33.0 Command Injection via npm |
19.08.2026 |
|
| CVE-2026-76231 |
Renovate 32.135.0 before 40.33.0 Command Injection via hermit |
19.08.2026 |
|
| CVE-2026-76232 |
Renovate 31.51.0 before 40.33.0 Command Injection via helmv3 |
19.08.2026 |
|
| CVE-2026-76233 |
Renovate 39.53.0 before 40.33.0 Command Injection via gleam manager |
19.08.2026 |
|
| CVE-2026-76234 |
libcrux before 0.0.6 Cryptographic Implementation Bug Fixes |
19.08.2026 |
|
| CVE-2026-76236 |
stigmem before 0.9.0a12 Cross-Tenant BOLA via Tombstones |
19.08.2026 |
|
| CVE-2026-76237 |
stigmem before 0.9.0a12 Cross-Tenant BOLA via quarantine |
19.08.2026 |
|
| CVE-2026-76238 |
stigmem before 0.9.0a12 Cross-Tenant BOLA via decay sweep |
19.08.2026 |
|
| CVE-2026-76239 |
Stigmem before 0.9.0a11 SSRF via unvalidated webhook delivery_address |
19.08.2026 |
|
| CVE-2026-76240 |
stigmem Postgres SQL Injection via Schema Identifier |
19.08.2026 |
|
| CVE-2026-76241 |
stigmem Plugin Signature Enforcement Bypass via Configuration |
19.08.2026 |
|
| CVE-2026-76242 |
stigmem Federation Peer Registration Authentication Bypass |
19.08.2026 |
|
| CVE-2026-76243 |
stigmem before 0.9.0a2 Authentication Bypass via Disabled Auth |
19.08.2026 |
|
| CVE-2026-76244 |
stigmem-node Insecure Federation Transport Configuration |
19.08.2026 |
|
| CVE-2026-76245 |
stigmem Federation Peer Token Timestamp Validation Bypass |
19.08.2026 |
|
| CVE-2026-50719 |
|
19.08.2026 |
|
| CVE-2026-50720 |
|
19.08.2026 |
|
| CVE-2026-51366 |
|
19.08.2026 |
|
| CVE-2026-51367 |
|
19.08.2026 |
|
| CVE-2026-54795 |
|
20.08.2026 |
8.8 |
| CVE-2026-56088 |
|
19.08.2026 |
7.1 |
| CVE-2026-70421 |
|
20.08.2026 |
7.2 |
| CVE-2026-74803 |
Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 |
19.08.2026 |
|
| CVE-2026-74804 |
Joomla Extension - yootheme.com - Unauthenticated SQL injection in Zoo < 4.1.64 |
19.08.2026 |
|
| CVE-2026-75114 |
Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 |
19.08.2026 |
|
| CVE-2026-75148 |
cgltf 1.15 Integer Overflow via cgltf_validate() Accessor Bounds Check |
19.08.2026 |
|
| CVE-2026-54796 |
|
20.08.2026 |
7.2 |
| CVE-2026-65609 |
Out-of-bounds write in nnn |
19.08.2026 |
|
| CVE-2026-65610 |
Numeric Truncation Error in nnn |
19.08.2026 |
|
| CVE-2026-65611 |
Shell Command Injection in nnn |
19.08.2026 |
|
| CVE-2026-65612 |
Shell Command Injection in nnn |
19.08.2026 |
|
| CVE-2026-19490 |
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490 |
20.08.2026 |
|
| CVE-2026-67363 |
Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 |
19.08.2026 |
|
| CVE-2026-67364 |
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 |
19.08.2026 |
|
| CVE-2026-19489 |
|
19.08.2026 |
|
| CVE-2026-32552 |
WordPress YITH WooCommerce Membership Premium plugin <= 2.33.0 - SQL Injection vulnerability |
19.08.2026 |
8.5 |
| CVE-2026-61986 |
WordPress Contest Gallery plugin <= 30.0.5 - Cross Site Scripting (XSS) vulnerability |
19.08.2026 |
7.1 |
| CVE-2026-66596 |
WordPress Newsletter plugin <= 9.3.3 - Cross Site Scripting (XSS) vulnerability |
19.08.2026 |
7.1 |
| CVE-2026-66613 |
WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability |
19.08.2026 |
9.8 |
| CVE-2026-66668 |
WordPress Community by PeepSo plugin <= 9.0.5.2 - SQL Injection vulnerability |
19.08.2026 |
8.5 |
| CVE-2026-73182 |
WordPress BBQ Pro plugin <= 3.9 - Cross Site Scripting (XSS) vulnerability |
19.08.2026 |
7.1 |
| CVE-2026-73183 |
WordPress Maps Marker Pro plugin <= 4.32 - SQL Injection vulnerability |
19.08.2026 |
9.3 |
| CVE-2026-73184 |
WordPress Global Gallery plugin <= 11.1.2 - Cross Site Scripting (XSS) vulnerability |
19.08.2026 |
7.1 |
| CVE-2026-73185 |
WordPress NGG Smart Image Search plugin < 4.0.0 - SQL Injection vulnerability |
19.08.2026 |
9.3 |
| CVE-2026-73347 |
WordPress TrueBooker plugin <= 1.2.6 - Privilege Escalation vulnerability |
19.08.2026 |
9.8 |
| CVE-2026-73354 |
WordPress SimplyRETS Real Estate IDX plugin <= 3.2.8 - Cross Site Scripting (XSS) vulnerability |
19.08.2026 |
7.1 |
| CVE-2026-73363 |
WordPress Taxi Booking Manager for WooCommerce plugin < 2.0.8 - Broken Access Control vulnerability |
19.08.2026 |
6.5 |
| CVE-2026-73364 |
WordPress Flexible Subscriptions plugin <= 1.8.1 - PHP Object Injection vulnerability |
19.08.2026 |
9.8 |
| CVE-2026-73384 |
WordPress Pay with Contact Form 7 plugin <= 1.0.4 - Sensitive Data Exposure vulnerability |
19.08.2026 |
7.5 |
| CVE-2026-73385 |
WordPress Outranking plugin Options plugin <= 1.1.3 - Broken Access Control vulnerability |
19.08.2026 |
7.5 |
| CVE-2026-73386 |
WordPress Track Geolocation Of Users Using Contact Form 7 plugin <= 3.0.2 - Sensitive Data Exposure vulnerability |
19.08.2026 |
7.5 |
| CVE-2026-73387 |
WordPress Resido theme <= 1.5 - Local File Inclusion vulnerability |
19.08.2026 |
8.1 |
| CVE-2026-73388 |
WordPress Nikstore Core plugin <= 1.5 - SQL Injection vulnerability |
19.08.2026 |
9.3 |
| CVE-2026-73389 |
WordPress Kalles Addons plugin <= 1.0.6 - PHP Object Injection vulnerability |
19.08.2026 |
9.8 |
| CVE-2026-73390 |
WordPress Total Donations plugin <= 2.0.5 - Privilege Escalation vulnerability |
19.08.2026 |
9.8 |
| CVE-2026-73391 |
WordPress Total Donations plugin <= 2.0.5 - SQL Injection vulnerability |
19.08.2026 |
9.3 |
| CVE-2026-73394 |
WordPress Stitch Express plugin <= 1.9.0 - Broken Access Control vulnerability |
19.08.2026 |
7.5 |
| CVE-2026-76235 |
Cockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via cockpitlang cookie in send_login_html |
19.08.2026 |
|
| CVE-2026-18371 |
HTML injection in M-Files Web |
19.08.2026 |
|
| CVE-2026-18372 |
CSS injection in M-Files Web |
19.08.2026 |
|