| CVE-2026-19487 |
Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass |
13.08.2026 |
|
| CVE-2026-19744 |
Stored Cross-site Scripting in Pentestify Markdown renderer via unescaped quotes |
13.08.2026 |
|
| CVE-2026-73514 |
PostGIS address_standardizer Out-of-Bounds Write via standardize_address() |
13.08.2026 |
|
| CVE-2026-73515 |
PostGIS < 3.7.0beta2 Out-of-Bounds Read via FlatGeobuf Buffer |
13.08.2026 |
|
| CVE-2026-73670 |
CMS Admin SQL Injection via db_data.php table_name Parameter |
13.08.2026 |
|
| CVE-2026-19710 |
SourceCodester Simple Student Information System view_department.php sql injection |
13.08.2026 |
|
| CVE-2026-73559 |
vLLM: Completion prompt lists fan out into unbounded engine requests |
13.08.2026 |
6.5 |
| CVE-2026-73570 |
|
13.08.2026 |
8.9 |
| CVE-2026-73571 |
|
13.08.2026 |
3.1 |
| CVE-2026-73572 |
|
13.08.2026 |
6.1 |
| CVE-2026-73573 |
|
13.08.2026 |
3.1 |
| CVE-2026-73574 |
|
13.08.2026 |
3.1 |
| CVE-2026-73575 |
|
13.08.2026 |
3.1 |
| CVE-2026-73576 |
|
13.08.2026 |
6.3 |
| CVE-2026-12036 |
|
13.08.2026 |
|
| CVE-2026-14256 |
|
13.08.2026 |
|
| CVE-2026-15994 |
|
13.08.2026 |
|
| CVE-2026-19293 |
SMP security request |
13.08.2026 |
8.8 |
| CVE-2026-28154 |
WordPress Samex and M.Anh WordPress themes affected by Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-49820 |
Probo has an open redirect bypass via path normalization |
13.08.2026 |
4.7 |
| CVE-2026-49856 |
@jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization |
13.08.2026 |
4.3 |
| CVE-2026-49857 |
auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback |
13.08.2026 |
7.4 |
| CVE-2026-53783 |
rsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsync |
13.08.2026 |
|
| CVE-2026-53784 |
rsync < 3.5.0 Path Traversal via Symlink Module Root |
13.08.2026 |
|
| CVE-2026-53785 |
rsync < 3.5.0 Path Traversal Write Escape via --relative Mode |
13.08.2026 |
|
| CVE-2026-53786 |
rsync < 3.5.0 Filter Rule Bypass via --filter Merge Directive |
13.08.2026 |
|
| CVE-2026-53788 |
rsync < 3.5.0 Newline Injection via name-converter uid/gid mapping |
13.08.2026 |
|
| CVE-2026-53789 |
rsync < 3.5.0 Arbitrary File Deletion via Malicious File List |
13.08.2026 |
|
| CVE-2026-53790 |
rsync < 3.5.0 Command Injection via Multiple Code Paths |
13.08.2026 |
|
| CVE-2026-53791 |
rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header |
13.08.2026 |
|
| CVE-2026-53792 |
rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum Block |
13.08.2026 |
|
| CVE-2026-53793 |
rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode |
13.08.2026 |
|
| CVE-2026-53794 |
rsync < 3.5.0 Denial of Service via --max-alloc=0 Logic Error |
13.08.2026 |
|
| CVE-2026-53795 |
rsync < 3.5.0 Arbitrary File Write via --temp-dir/--link-dest |
13.08.2026 |
|
| CVE-2026-53796 |
rsync < 3.5.0 TOCTOU Race Condition via Destination Directory Handling |
13.08.2026 |
|
| CVE-2026-53797 |
rsync < 3.5.0 Symlink Race Condition Information Disclosure |
13.08.2026 |
|
| CVE-2026-53798 |
rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mapping |
13.08.2026 |
|
| CVE-2026-53799 |
rsync < 3.5.0 Symlink Race Condition via ACL/xattr Application |
13.08.2026 |
|
| CVE-2026-53800 |
rsync < 3.5.0 Symlink Race Condition via --remove-source-files |
13.08.2026 |
|
| CVE-2026-53801 |
rsync < 3.5.0 Symlink Race Condition Directory Traversal |
13.08.2026 |
|
| CVE-2026-53802 |
rsync < 3.5.0 Arbitrary File Read via Symlink Following |
13.08.2026 |
|
| CVE-2026-53803 |
rsync < 3.5.0 Symlink Following Arbitrary File Overwrite |
13.08.2026 |
|
| CVE-2026-63423 |
|
13.08.2026 |
|
| CVE-2026-63424 |
|
13.08.2026 |
|
| CVE-2026-63425 |
|
13.08.2026 |
|
| CVE-2026-63426 |
|
13.08.2026 |
|
| CVE-2026-65932 |
BT122 stops advertising |
13.08.2026 |
|
| CVE-2026-65933 |
BT122 malformed packet with increased length field causes memory leak |
13.08.2026 |
|
| CVE-2026-65934 |
BT122 plaintext pause encryption request causes DOS |
13.08.2026 |
|
| CVE-2026-65935 |
Bypassing passkey entry in legacy pairing |
13.08.2026 |
|
| CVE-2026-65936 |
RS9116W/SiWx917 malformed packet with increased length field causes memory leak |
13.08.2026 |
|
| CVE-2026-6387 |
|
13.08.2026 |
|
| CVE-2026-70452 |
rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure |
13.08.2026 |
|
| CVE-2026-70453 |
rsync < 3.5.0 Algorithmic Complexity DoS via hash_search() |
13.08.2026 |
|
| CVE-2026-70454 |
rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode |
13.08.2026 |
|
| CVE-2026-70455 |
rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion |
13.08.2026 |
|
| CVE-2026-70456 |
rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args() |
13.08.2026 |
|
| CVE-2026-70457 |
rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg() |
13.08.2026 |
|
| CVE-2026-70458 |
rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED Handling |
13.08.2026 |
|
| CVE-2026-70459 |
rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List Entry |
13.08.2026 |
|
| CVE-2026-70460 |
rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink |
13.08.2026 |
|
| CVE-2026-70461 |
rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry |
13.08.2026 |
|
| CVE-2026-70462 |
rsync 3.1.0 < 3.5.0 Signed Integer Overflow via MSG_IO_TIMEOUT |
13.08.2026 |
|
| CVE-2026-70463 |
rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing |
13.08.2026 |
|
| CVE-2026-70464 |
rsync 2.0.0 < 3.5.0 Connection Slot Exhaustion DoS via Handshake Stall |
13.08.2026 |
|
| CVE-2026-73505 |
Oh My Posh: Arbitrary command execution via template injection in the path segment |
13.08.2026 |
7.8 |
| CVE-2026-73506 |
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data |
13.08.2026 |
6.1 |
| CVE-2026-73507 |
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion |
13.08.2026 |
7.5 |
| CVE-2026-73508 |
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names |
13.08.2026 |
5.3 |
| CVE-2026-73509 |
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal |
13.08.2026 |
7.6 |
| CVE-2026-73555 |
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages |
13.08.2026 |
5.3 |
| CVE-2026-73556 |
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of CVE-2026-55574 |
13.08.2026 |
5.3 |
| CVE-2026-73557 |
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts |
13.08.2026 |
|
| CVE-2026-73558 |
vLLM: Cross-User Data Leak Vulnerability |
13.08.2026 |
5.3 |
| CVE-2026-14456 |
Unbounded Memory Growth in QUIC Server Incoming Channel Queue |
13.08.2026 |
|
| CVE-2026-16101 |
forced re-pairing with already bonded device |
13.08.2026 |
8.8 |
| CVE-2026-19291 |
Bluetooth re-pairing can use a lower security level than previous |
13.08.2026 |
8.8 |
| CVE-2026-19292 |
Bluetooth re-pairing with legitimate device can use lower security level |
13.08.2026 |
8.8 |
| CVE-2026-19734 |
IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking |
13.08.2026 |
|
| CVE-2026-66256 |
Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API) |
13.08.2026 |
|
| CVE-2026-68451 |
s390/zcrypt: Validate length for CCA ECC private key requests |
13.08.2026 |
|
| CVE-2026-68452 |
s390/zcrypt: Validate length for CCA AES cipher key requests |
13.08.2026 |
|
| CVE-2026-68453 |
s390/zcrypt: Fix buffer over-read in cca_cipher2protkey |
13.08.2026 |
|
| CVE-2026-68454 |
KVM: s390: pci: Fix handling of AIF enable without AISB |
13.08.2026 |
|
| CVE-2025-62314 |
HCL AION is affected by multiple security vulnerabilities. |
13.08.2026 |
5.6 |
| CVE-2025-62315 |
HCL AION is affected by multiple security vulnerabilities. |
13.08.2026 |
3.4 |
| CVE-2025-62318 |
HCL AION is affected by multiple security vulnerabilities. |
13.08.2026 |
3.7 |
| CVE-2026-19716 |
Stored Cross-site Scripting in Pentestify user account deletion via unescaped username |
13.08.2026 |
|
| CVE-2026-21832 |
HCL AION is affected by multiple security vulnerabilities. |
13.08.2026 |
4.3 |
| CVE-2026-27345 |
WordPress Taxi Booking Manager for WooCommerce plugin <= 2.0.3 - Broken Access Control vulnerability |
13.08.2026 |
7.5 |
| CVE-2026-27380 |
WordPress Car Rental Manager plugin <= 1.3.9 - PHP Object Injection vulnerability |
13.08.2026 |
7.2 |
| CVE-2026-27535 |
WordPress Solace Extra plugin <= 1.6.0 - Broken Access Control vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-27536 |
WordPress MailChimp Subscribe Forms plugin <= 4.3.3 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-27537 |
WordPress Popup by Supsystic plugin <= 1.11.2 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-27538 |
WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability |
13.08.2026 |
7.5 |
| CVE-2026-27539 |
WordPress Welcart e-Commerce plugin <= 2.11.31 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-27543 |
WordPress MStore API plugin <= 4.20.0 - Privilege Escalation vulnerability |
13.08.2026 |
8.1 |
| CVE-2026-27544 |
WordPress QA Analytics plugin <= 5.2.0.0 - Remote Code Execution (RCE) vulnerability |
13.08.2026 |
10 |
| CVE-2026-27999 |
WordPress Tourfic plugin <= 2.23.1 - Broken Access Control vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-28001 |
WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-28002 |
WordPress Booktics plugin 1.0.22 - SQL Injection vulnerability |
13.08.2026 |
8.5 |
| CVE-2026-28003 |
WordPress Maspik – Spam blacklist plugin <= 2.9.1 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-28004 |
WordPress Business Directory plugin <= 6.4.25 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-28008 |
WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.0.0 - Broken Authentication vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-28142 |
WordPress Web Directory Free plugin <= 1.7.13 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-28148 |
WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-28149 |
WordPress Headless Single Sign On plugin <= 1.6 - PHP Object Injection vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-28155 |
WordPress Do Lasso plugin <= 358 - Insecure Direct Object References (IDOR) vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-28156 |
WordPress Do Lasso plugin <= 358 - SQL Injection vulnerability |
13.08.2026 |
8.5 |
| CVE-2026-28157 |
WordPress Do Lasso plugin <= 358 - Path Traversal vulnerability |
13.08.2026 |
7.5 |
| CVE-2026-28158 |
WordPress Do Lasso plugin <= 358 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-28159 |
WordPress Service Finder Booking plugin <= 6.2 - Broken Access Control vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-28161 |
WordPress Service Finder Booking plugin <= 6.2 - Privilege Escalation vulnerability |
13.08.2026 |
8.8 |
| CVE-2026-28168 |
WordPress CubeWP plugin <= 1.1.30 - SQL Injection vulnerability |
13.08.2026 |
8.5 |
| CVE-2026-28170 |
WordPress Blog Floating Button plugin <= 1.4.20 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-28173 |
WordPress WP Event SOlution plugin <= 4.1.19 - Arbitrary Content Deletion vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-28174 |
WordPress WP Event SOlution plugin <= 4.1.18 - Sensitive Data Exposure vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-28175 |
WordPress Visitors Traffic Real Time Statistics plugin <= 8.11 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-28176 |
WordPress Booking Activities plugin <= 1.18.4 - PHP Object Injection vulnerability |
13.08.2026 |
8.8 |
| CVE-2026-28181 |
WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Control vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-28182 |
WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-28184 |
WordPress Form Maker by 10Web plugin <= 1.15.44 - SQL Injection vulnerability |
13.08.2026 |
8.5 |
| CVE-2026-28185 |
WordPress Log in with Google plugin <= 1.4.2 - Broken Authentication vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-28186 |
WordPress Travelfic Toolkit plugin <= 1.5.1 - Broken Access Control vulnerability |
13.08.2026 |
8.1 |
| CVE-2026-28187 |
WordPress Knowledge Base for Documentation, FAQs with AI Assistance plugin <= 17.211.0 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-28188 |
WordPress Hydra Booking plugin <= 1.2.2 - Broken Access Control vulnerability |
13.08.2026 |
7.3 |
| CVE-2026-28189 |
WordPress Participants Database plugin <= 2.7.8.4 - Arbitrary File Deletion vulnerability |
13.08.2026 |
7.4 |
| CVE-2026-48702 |
Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic |
13.08.2026 |
7.5 |
| CVE-2026-61960 |
WordPress WP Full Stripe Free plugin <= 8.5.0 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-61962 |
WordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerability |
13.08.2026 |
10 |
| CVE-2026-61965 |
WordPress GeekyBot plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-61966 |
WordPress WPJAM Basic plugin <= 7.0.1 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-61967 |
WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-61969 |
WordPress Listdom plugin <= 5.6.0 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-61974 |
WordPress Mang Board WP plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-61978 |
WordPress Secure Card Gateway for ePay Paycenter (Piraeus Bank) plugin <= 1.0.32 - Broken Access Control vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-61979 |
WordPress SAML SP Single Sign On plugin <= 5.4.3 - Privilege Escalation vulnerability |
13.08.2026 |
8.1 |
| CVE-2026-61980 |
WordPress OMGF Pro plugin <= 5.2.7 - Arbitrary File Download vulnerability |
13.08.2026 |
7.5 |
| CVE-2026-61984 |
WordPress WPMobile.App plugin <= 11.77 - Broken Access Control vulnerability |
13.08.2026 |
7.5 |
| CVE-2026-65580 |
WordPress Agrion theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-65582 |
WordPress AI Hub theme <= 1.3.10 - Arbitrary File Download vulnerability |
13.08.2026 |
7.7 |
| CVE-2026-66424 |
WordPress SMS Alert Order Notifications plugin <= 3.9.7 - Privilege Escalation vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-66426 |
WordPress WP-Stats plugin <= 2.56 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-66429 |
WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.10 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-66430 |
WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.10 - SQL Injection vulnerability |
13.08.2026 |
8.5 |
| CVE-2026-66431 |
WordPress Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin <= 1.0.7 - Broken Access Control vulnerability |
13.08.2026 |
7.5 |
| CVE-2026-66432 |
WordPress WPJAM Basic plugin <= 7.0.2.1 - Sensitive Data Exposure vulnerability |
13.08.2026 |
7.5 |
| CVE-2026-66436 |
WordPress Active Products Tables for WooCommerce plugin <= 1.1.1 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-66441 |
WordPress MultiVendorX plugin <= 5.0.10 - Broken Access Control vulnerability |
13.08.2026 |
7.5 |
| CVE-2026-66443 |
WordPress REST API Log plugin <= 1.7.1 - Sensitive Data Exposure vulnerability |
13.08.2026 |
7.5 |
| CVE-2026-66444 |
WordPress Payment Forms for Paystack plugin <= 4.0.5 - Sensitive Data Exposure vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-66446 |
WordPress If-So Dynamic Content Personalization plugin <= 1.10 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-66449 |
WordPress Geo Mashup plugin <= 1.13.18 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-66450 |
WordPress Geo Mashup plugin <= 1.13.18 - Local File Inclusion vulnerability |
13.08.2026 |
8.1 |
| CVE-2026-66453 |
WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-66454 |
WordPress WP Social Avatar plugin <= 1.5 - Broken Access Control vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-66455 |
WordPress ReactPress plugin <= 3.4.0 - Broken Access Control vulnerability |
13.08.2026 |
6 |
| CVE-2026-66456 |
WordPress Profile Extra Fields by BestWebSoft plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-66458 |
WordPress RealPress plugin <= 1.1.2 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-66459 |
WordPress AI for SEO plugin <= 2.4.2 - Broken Access Control vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-66460 |
WordPress AfterShip Tracking plugin <= 1.18.1 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-66461 |
WordPress SMEPay: UPI Gateway for WooCommerce plugin <= 1.0.5 - Payment Bypass vulnerability |
13.08.2026 |
7.5 |
| CVE-2026-66462 |
WordPress WooCommerce Appointments plugin <= 5.3.8 - Sensitive Data Exposure vulnerability |
13.08.2026 |
7.5 |
| CVE-2026-66463 |
WordPress iCARRY plugin <= 2.9 - Sensitive Data Exposure vulnerability |
13.08.2026 |
7.5 |
| CVE-2026-66464 |
WordPress Internal Link Optimiser plugin <= 5.2.7 - Broken Access Control vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-66465 |
WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-66466 |
WordPress StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin <= 2.1.1 - Broken Access Control vulnerability |
13.08.2026 |
7.5 |
| CVE-2026-66467 |
WordPress FluentCommunity plugin <= 2.7.5 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-66468 |
WordPress Local Delivery Drivers for WooCommerce plugin <= 3.0.0 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-66469 |
WordPress Arvow AI SEO Writer plugin <= 1.5.3 - Broken Access Control vulnerability |
13.08.2026 |
7.5 |
| CVE-2026-66471 |
WordPress Accordion plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-66472 |
WordPress Everest Backup plugin <= 2.3.12 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-66478 |
WordPress Church Admin plugin <= 5.1.1 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-66653 |
WordPress Barista theme <= 2.5.1 - Local File Inclusion vulnerability |
13.08.2026 |
8.1 |
| CVE-2026-66654 |
WordPress Vehica Core plugin <= 1.0.104 - Server Side Request Forgery (SSRF) vulnerability |
13.08.2026 |
6 |
| CVE-2026-66655 |
WordPress MultiParcels Shipping For WooCommerce plugin <= 1.30.36 - Reflected Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-66656 |
WordPress Foton Core plugin <= 1.1.1 - Local File Inclusion vulnerability |
13.08.2026 |
8.1 |
| CVE-2026-66657 |
WordPress Biagiotti Core plugin <= 2.1.1 - Local File Inclusion vulnerability |
13.08.2026 |
8.1 |
| CVE-2026-66658 |
WordPress Reviewer plugin <= 3.14.2 - SQL Injection vulnerability |
13.08.2026 |
8.5 |
| CVE-2026-66660 |
WordPress Contact Form 7 – PayPal & Stripe Add-on plugin <= 2.5.1 - Broken Access Control vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-66661 |
WordPress Directories Pro plugin <= 2.0.5 - Privilege Escalation vulnerability |
13.08.2026 |
7.7 |
| CVE-2026-66687 |
WordPress WpBookingly plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-66689 |
WordPress Anti Spam and list cleaner – AcyChecker plugin <= 2.0.0 - Broken Access Control vulnerability |
13.08.2026 |
6.3 |
| CVE-2026-66691 |
WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-66693 |
WordPress Motors plugin <= 1.4.113 - Broken Access Control vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-66697 |
WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.10.0 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-66698 |
WordPress SureDash plugin <= 1.10.1 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-66700 |
WordPress Smart Online Order for Clover plugin <= 1.6.1 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
7.1 |
| CVE-2026-66704 |
WordPress Gutenverse Companion plugin <= 2.5.1 - Server Side Request Forgery (SSRF) vulnerability |
13.08.2026 |
7.2 |
| CVE-2026-67986 |
|
13.08.2026 |
|
| CVE-2026-67990 |
|
13.08.2026 |
|
| CVE-2026-67991 |
|
13.08.2026 |
|
| CVE-2026-73188 |
WordPress KiviCare plugin <= 4.5.1 - Sensitive Data Exposure vulnerability |
13.08.2026 |
7.5 |
| CVE-2026-73340 |
WordPress Featured Image from URL plugin <= 5.3.3 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-73344 |
WordPress WP Data Access plugin <= 5.5.79 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
5.9 |
| CVE-2026-73346 |
WordPress MailChimp For WooCommerce plugin < 6.2 - SQL Injection vulnerability |
13.08.2026 |
7.6 |
| CVE-2026-73349 |
WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability |
13.08.2026 |
5.3 |
| CVE-2026-73353 |
WordPress Revolut Gateway for WooCommerce plugin < 4.22.10 - Broken Access Control vulnerability |
13.08.2026 |
5.3 |
| CVE-2026-73357 |
WordPress GiveWP plugin < 4.16.6 - Cross Site Scripting (XSS) vulnerability |
13.08.2026 |
6.5 |
| CVE-2026-73401 |
WordPress InstaWP Connect plugin <= 0.1.3.7 - Broken Access Control vulnerability |
13.08.2026 |
5.3 |
| CVE-2026-73403 |
WordPress User Registration plugin <= 5.2.6 - Broken Access Control vulnerability |
13.08.2026 |
5.3 |
| CVE-2025-52640 |
HCL AION is affected by multiple security vulnerabilities. |
13.08.2026 |
4.7 |
| CVE-2026-14662 |
PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound |
13.08.2026 |
8.8 |
| CVE-2026-14663 |
PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext |
13.08.2026 |
6.5 |
| CVE-2026-14664 |
PostgreSQL regexp heap buffer overflow executes arbitrary code |
13.08.2026 |
8.8 |
| CVE-2026-14666 |
PostgreSQL row security caching disregards role modifications |
13.08.2026 |
4.2 |
| CVE-2026-14668 |
PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read |
13.08.2026 |
8.1 |
| CVE-2026-14669 |
PostgreSQL to_char heap buffer overflow executes arbitrary code |
13.08.2026 |
8.8 |
| CVE-2026-14670 |
PostgreSQL plperl tied object heap buffer overflow executes arbitrary code |
13.08.2026 |
8.8 |
| CVE-2026-14671 |
PostgreSQL refint plan cache type confusion executes arbitrary code |
13.08.2026 |
8.8 |
| CVE-2026-14672 |
PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle |
13.08.2026 |
5.3 |
| CVE-2026-14673 |
PostgreSQL amcheck does not clear untrusted search path |
13.08.2026 |
3.8 |
| CVE-2026-14676 |
PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code |
13.08.2026 |
8.8 |
| CVE-2026-14677 |
PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound |
13.08.2026 |
8.8 |
| CVE-2026-14678 |
PostgreSQL pg_trgm picksplit reads past end of buffer |
13.08.2026 |
4.3 |
| CVE-2026-14679 |
PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory |
13.08.2026 |
8.2 |
| CVE-2026-14680 |
PostgreSQL type confusion via "internal" arguments |
13.08.2026 |
8.8 |
| CVE-2026-14681 |
PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL |
13.08.2026 |
4.2 |
| CVE-2026-15741 |
PostgreSQL expression deparse allows SQL injection via EXTRACT argument |
13.08.2026 |
8.8 |
| CVE-2026-15742 |
PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound |
13.08.2026 |
8.8 |
| CVE-2026-16238 |
PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code |
13.08.2026 |
8.8 |
| CVE-2026-16239 |
PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code |
13.08.2026 |
8.8 |
| CVE-2026-16241 |
PostgreSQL ECPG integer underflow can crash the client |
13.08.2026 |
3.8 |
| CVE-2026-18024 |
PostgreSQL ascii() function reads past end of buffer |
13.08.2026 |
4.3 |
| CVE-2026-18408 |
PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client |
13.08.2026 |
8.8 |
| CVE-2026-19385 |
PostgreSQL pg_dump heap buffer overflow executes arbitrary code |
13.08.2026 |
8.8 |
| CVE-2026-49478 |
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage |
13.08.2026 |
8.7 |
| CVE-2026-49827 |
WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434) |
13.08.2026 |
9.8 |
| CVE-2026-6464 |
PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands |
13.08.2026 |
8.1 |
| CVE-2026-6469 |
PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership |
13.08.2026 |
3.8 |
| CVE-2026-6470 |
PostgreSQL fails to check type USAGE privilege |
13.08.2026 |
4.3 |
| CVE-2026-6471 |
PostgreSQL logical decoding can dlopen arbitrary file |
13.08.2026 |
7.2 |
| CVE-2026-73583 |
Sblim-sfcb: unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds memory access via malformed operationhdr |
13.08.2026 |
|
| CVE-2026-73584 |
Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure temporary file handling |
13.08.2026 |
|
| CVE-2026-73585 |
Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack |
13.08.2026 |
|
| CVE-2026-73483 |
Flowise before 3.1.3 Sandbox Escape via Puppeteer |
13.08.2026 |
|
| CVE-2026-73484 |
Flowise before 3.1.3 Sandbox Escape via Pandas Methods |
13.08.2026 |
|
| CVE-2026-73485 |
Flowise before 3.1.3 Remote Code Execution via Airtable Agent |
13.08.2026 |
|
| CVE-2026-73486 |
Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV |
13.08.2026 |
|
| CVE-2026-73487 |
Flowise before 3.1.3 Prompt Injection RCE via CSV Agent |
13.08.2026 |
|
| CVE-2026-73488 |
Flowise before 3.1.3 IDOR via customer-default-source endpoint |
13.08.2026 |
|
| CVE-2026-73601 |
Flowise before 3.1.3 Remote Code Execution via Custom MCP |
13.08.2026 |
|
| CVE-2026-73602 |
Flowise before 3.1.3 Sandbox Escape to RCE |
13.08.2026 |
|
| CVE-2026-73603 |
Flowise before 3.1.4 Credential Abuse via Text-to-Speech |
13.08.2026 |
|
| CVE-2026-73604 |
Flowise before 3.1.3 Credential Exposure via API |
13.08.2026 |
|
| CVE-2026-73605 |
SiYuan before v3.7.4 Path Traversal via getUniqueFilename |
13.08.2026 |
|
| CVE-2026-73606 |
SiYuan before v3.7.4 Information Disclosure via getRefIDs |
13.08.2026 |
|
| CVE-2026-73607 |
SiYuan before v3.7.4 Information Disclosure via getOutlineStorage |
13.08.2026 |
|
| CVE-2026-73608 |
SiYuan before v3.7.4 Authorization Bypass via getAttributeViewSearchTarget |
13.08.2026 |
|
| CVE-2026-73609 |
SiYuan before v3.7.4 Information Disclosure via getBookmarkLabels |
13.08.2026 |
|
| CVE-2026-73610 |
SiYuan before v3.7.4 Information Disclosure via Local Storage |
13.08.2026 |
|
| CVE-2026-73611 |
File Browser 2.50.0 through 2.63.21 JWT Expiration Bypass |
13.08.2026 |
|
| CVE-2026-73612 |
File Browser before v2.63.22 Authorization Bypass via Recursive Operations |
13.08.2026 |
|
| CVE-2026-73613 |
filebrowser before 2.63.19 Out-of-Scope File Deletion via Symlink |
13.08.2026 |
|
| CVE-2026-73614 |
Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation |
13.08.2026 |
|
| CVE-2026-73615 |
Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch |
13.08.2026 |
|
| CVE-2026-73616 |
OpenRemote Notification Delete Cross-Realm Insecure Direct Object Reference |
13.08.2026 |
|
| CVE-2026-73617 |
Budibase before 3.40.0 NoSQL Injection via MongoDB datasource |
13.08.2026 |
|
| CVE-2026-73618 |
Budibase Server before 3.40.0 NoSQL Injection via JSON Parameter |
13.08.2026 |
|
| CVE-2026-73619 |
GitPython before 3.1.57 Arbitrary File Read via Repo.archive() |
13.08.2026 |
|
| CVE-2026-73620 |
GitPython before 3.1.57 Arbitrary File Overwrite and Read |
13.08.2026 |
|
| CVE-2026-73621 |
GitPython before 3.1.56 Arbitrary File Truncation via Commit.count |
13.08.2026 |
|
| CVE-2026-73622 |
GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add() |
13.08.2026 |
|
| CVE-2026-73623 |
GitPython before 3.1.54 Remote Code Execution via --template |
13.08.2026 |
|
| CVE-2026-73624 |
GitPython before 3.1.54 Arbitrary File Overwrite via diff |
13.08.2026 |
|
| CVE-2026-73625 |
GitPython before 3.1.54 Remote Code Execution via kwarg value smuggling |
13.08.2026 |
|
| CVE-2026-73626 |
JupyterLab before 4.6.2 Authentication Bypass via PyPIExtensionManager |
13.08.2026 |
|
| CVE-2026-73627 |
JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass |
13.08.2026 |
|
| CVE-2026-73628 |
Serendipity 2.3.5 Reflected XSS via search clean-URL route |
13.08.2026 |
|
| CVE-2026-73629 |
Serendipity before 2.6.0 SSRF via hex IPv4 and IPv6 addresses |
13.08.2026 |
|
| CVE-2026-45819 |
|
13.08.2026 |
|
| CVE-2026-16455 |
Local privilege escalation via improper input sanitization in execl() call |
13.08.2026 |
|
| CVE-2026-18368 |
Heap buffer overflow in Modbusgwd |
13.08.2026 |
|
| CVE-2026-12263 |
Authentication Bypass |
13.08.2026 |
8.8 |
| CVE-2026-11970 |
|
13.08.2026 |
|
| CVE-2026-59501 |
Priority – CWE-284: Improper Access Control |
13.08.2026 |
8.2 |
| CVE-2026-59502 |
Priority - CWE-203: Observable Discrepancy |
13.08.2026 |
5.3 |
| CVE-2026-59503 |
Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor |
13.08.2026 |
9.1 |
| CVE-2026-59504 |
Priority – CWE-602: Client-Side Enforcement of Server-Side Security |
13.08.2026 |
9.1 |
| CVE-2026-59505 |
Priority - CWE-284: Improper Access Control |
13.08.2026 |
8.6 |
| CVE-2026-59506 |
Priority – CWE-306: Missing Authentication for Critical Function |
13.08.2026 |
9.3 |
| CVE-2026-59507 |
Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control |
13.08.2026 |
9.3 |
| CVE-2026-19484 |
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary |
13.08.2026 |
7.5 |
| CVE-2026-59499 |
Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
13.08.2026 |
8.6 |
| CVE-2026-59500 |
Priority - CWE-287: Improper Authentication |
13.08.2026 |
10 |
| CVE-2026-16458 |
Timing side-channel in RSA PKCS#1 v1.5 decryption in ocrypto |
13.08.2026 |
|
| CVE-2026-16459 |
Timing side-channel in RSA PKCS#1 v1.5 decryption in Oberon PSA Crypto |
13.08.2026 |
|
| CVE-2026-19481 |
@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header |
13.08.2026 |
7.5 |
| CVE-2026-14298 |
Denial of service via resource exhaustion in Mattermost |
13.08.2026 |
6.5 |
| CVE-2026-14332 |
Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Subscriber+ Store Disconnection via 'ec_disconnect' Action |
13.08.2026 |
5.4 |
| CVE-2026-15413 |
Link Factory - Backdoor |
13.08.2026 |
10 |
| CVE-2026-19694 |
Heap-based Buffer Overflow in Wireshark |
13.08.2026 |
4.7 |
| CVE-2026-19695 |
Stack-based Buffer Overflow in Wireshark |
13.08.2026 |
4.7 |
| CVE-2026-19696 |
Out-of-bounds Write in Wireshark |
13.08.2026 |
6.6 |
| CVE-2026-11840 |
SQL Injection |
13.08.2026 |
8.8 |
| CVE-2026-3639 |
PPWP – Password Protect Pages <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
13.08.2026 |
6.4 |
| CVE-2026-18622 |
Foxit PDF Editor/Reader's signature-validation pop-up reports modified certified documents as valid |
13.08.2026 |
4.7 |
| CVE-2026-18146 |
Fluent Forms <= 6.2.11 - Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values |
13.08.2026 |
7.2 |
| CVE-2026-13328 |
TLP Food Menu < 6.0.2 - Unauthenticated Reservation Status Modification |
13.08.2026 |
|
| CVE-2026-13610 |
KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration |
13.08.2026 |
|
| CVE-2026-14182 |
Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication Bypass |
13.08.2026 |
|
| CVE-2026-14213 |
Amelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOR |
13.08.2026 |
|
| CVE-2026-18945 |
WP Helper Premium < 4.7.6 - Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation |
13.08.2026 |
|
| CVE-2026-19088 |
ShopEngine < 4.9.3 - Customer PII Disclosure via Forced Authentication |
13.08.2026 |
|
| CVE-2026-3835 |
Prevent Direct Access – Protect WordPress Files <= 2.8.8.8 - Unauthenticated Protected File Access |
13.08.2026 |
5.3 |
| CVE-2026-19135 |
OpenNMS JEXL sandbox bypass in Measurements REST API allows ROLE_USER to load arbitrary classes |
13.08.2026 |
5.4 |
| CVE-2026-19182 |
OpenNMS v2 Alarm REST API inverted authorization check lets ROLE_REST users acknowledge alarms as any user and bypass read-only |
13.08.2026 |
4.3 |
| CVE-2026-72506 |
|
13.08.2026 |
|
| CVE-2026-18728 |
Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing |
13.08.2026 |
|
| CVE-2026-0289 |
Prisma Browser: Inappropriate Implementation in Account Protection |
13.08.2026 |
|
| CVE-2026-0290 |
Prisma Browser: Sensitive Information Disclosure Vulnerability |
13.08.2026 |
|
| CVE-2026-0291 |
Prisma Access Agent: Authenticated Limited File Deletion on Linux |
13.08.2026 |
|
| CVE-2026-0292 |
Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows |
13.08.2026 |
|
| CVE-2026-0293 |
Prisma Access Agent: Anti-Tamper Protection Bypass on Windows |
13.08.2026 |
|
| CVE-2026-0294 |
Prisma Access Agent: Local Privilege Escalation |
13.08.2026 |
|
| CVE-2026-0295 |
GlobalProtect App: Local Privilege Escalation via Race Condition on macOS |
13.08.2026 |
|
| CVE-2026-0296 |
GlobalProtect App: Improper Certificate Validation Bypass Vulnerability |
13.08.2026 |
|
| CVE-2026-0297 |
GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake |
13.08.2026 |
|
| CVE-2026-0298 |
GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP) |
13.08.2026 |
|
| CVE-2026-0299 |
GlobalProtect App: Local Privilege Escalation Vulnerabilities |
13.08.2026 |
|
| CVE-2026-0301 |
PAN-OS: Information Disclosure Vulnerability in URL Filtering |
13.08.2026 |
|
| CVE-2026-46382 |
Meeting Room Booking System has server-side request forgery in import functionality |
12.08.2026 |
|
| CVE-2026-46688 |
Meeting Room Booking System has an unauthenticated open redirect |
13.08.2026 |
|
| CVE-2026-48791 |
Sigstore Java has a vulnerability with bundle verification of integratedTime |
13.08.2026 |
2 |
| CVE-2026-16770 |
PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document |
13.08.2026 |
|
| CVE-2026-17431 |
PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for |
13.08.2026 |
|
| CVE-2026-49473 |
@cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation |
13.08.2026 |
8.8 |
| CVE-2026-49819 |
UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd |
13.08.2026 |
9.8 |
| CVE-2026-50544 |
NortheBridge/luminalshine has Incorrect Permission Assignment for Critical Resource and Creation of Temporary File in Directory with Insecure Permissions |
12.08.2026 |
6.3 |
| CVE-2026-49481 |
UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd |
12.08.2026 |
9.6 |
| CVE-2026-15141 |
Referer Validation Bypass in TL-WR820N Web Management Interface |
13.08.2026 |
|
| CVE-2026-15424 |
|
12.08.2026 |
|
| CVE-2026-47717 |
FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations |
13.08.2026 |
7.5 |
| CVE-2026-47718 |
FUXA provides guest and invalid-token access to protected read APIs in secure mode |
12.08.2026 |
|
| CVE-2026-71193 |
|
13.08.2026 |
9.6 |
| CVE-2026-71194 |
|
13.08.2026 |
6.8 |
| CVE-2026-71469 |
Acm-search-v2-api-rhel9: search-v2-api: unbounded tokenreviews cache allows unauthenticated memory-exhaustion dos |
12.08.2026 |
|
| CVE-2026-71471 |
Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container image |
13.08.2026 |
|
| CVE-2026-71473 |
Acm-search-v2-rhel9: search-v2-operator: addonfactory.getvaluesfromaddonannotation enables arbitrary helm-values override per spoke |
13.08.2026 |
|
| CVE-2026-71846 |
Insights-client: insights-client: clusterrole grants cluster-wide secrets get/list/watch beyond least privilege |
12.08.2026 |
|
| CVE-2024-27253 |
IBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete request |
12.08.2026 |
10 |
| CVE-2026-10534 |
IBM® Db2® is vulnerable to buffer overflow in the IXF IMPORT parser |
13.08.2026 |
8.4 |
| CVE-2026-17485 |
IBM i is Affected By Denial of Service Vulnerability [] |
12.08.2026 |
8.2 |
| CVE-2026-73499 |
etcd: Watch API authorization bypass via open-ended range requests |
12.08.2026 |
|
| CVE-2026-73500 |
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline |
12.08.2026 |
|
| CVE-2026-73501 |
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default |
13.08.2026 |
9.1 |
| CVE-2026-18726 |
Open-iscsi: open-iscsi: denial of service in iscsiuio router advertisement parsing |
13.08.2026 |
|
| CVE-2026-18727 |
Open-iscsi: open-iscsi: integer underflow in iscsiuio dhcpv6 parsing |
13.08.2026 |
|
| CVE-2026-18744 |
CVE-2026-18744 |
13.08.2026 |
|
| CVE-2026-18749 |
CVE-2026-18749 |
13.08.2026 |
|
| CVE-2026-18750 |
CVE-2026-18750 |
13.08.2026 |
|
| CVE-2026-19003 |
MongoDB BI Connector ODBC driver may write outside an allocated buffer when the setup dialog opens a data source with oversized path settings |
13.08.2026 |
|
| CVE-2026-73492 |
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons |
12.08.2026 |
|
| CVE-2026-73493 |
http4s-blaze-server: Unbounded WebSocket message aggregation |
12.08.2026 |
7.5 |
| CVE-2026-73495 |
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass) |
13.08.2026 |
7.4 |
| CVE-2026-73498 |
MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_attachment |
13.08.2026 |
7.7 |
| CVE-2026-73519 |
WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret |
13.08.2026 |
|
| CVE-2026-7366 |
IBM DataPower Gateway affected by HTTP request header leakage in XML-Firewall |
13.08.2026 |
4.2 |
| CVE-2026-10543 |
IBM® Db2® is vulnerable to privilege escalation with a specially crafted query |
13.08.2026 |
8.2 |
| CVE-2026-13094 |
IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities |
12.08.2026 |
7.8 |
| CVE-2026-13105 |
IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities |
13.08.2026 |
8.8 |
| CVE-2026-13367 |
IBM Informix Dynamic Server Privilege Escalation Vulnerability in oninit Utility |
12.08.2026 |
7.8 |
| CVE-2026-13433 |
IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities |
13.08.2026 |
8.3 |
| CVE-2026-13476 |
IBM Informix Wire Listener Vulnerable to Unauthenticated Remote Code Execution |
12.08.2026 |
7.3 |
| CVE-2026-13622 |
Kubevirt: virt-handler-rhel9: kubevirt: virt-handler migration proxy follows symlinks allowing container escape to host |
12.08.2026 |
|
| CVE-2026-16480 |
IBM® Db2® is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data. |
13.08.2026 |
4.3 |
| CVE-2026-16695 |
IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities |
12.08.2026 |
7.8 |
| CVE-2026-18096 |
IBM® Db2® could allow a local attacker to cause a denial of service due to a memory leak |
13.08.2026 |
3.3 |
| CVE-2026-18097 |
IBM® Db2® federated server could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files. |
12.08.2026 |
5.5 |
| CVE-2026-19130 |
Provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedfrom labels bypasses authorization |
12.08.2026 |
|
| CVE-2026-19654 |
Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd |
13.08.2026 |
|
| CVE-2026-64826 |
rConfig < 8.2.13 Path Traversal File Read via FileDownloadController |
12.08.2026 |
|
| CVE-2026-73425 |
@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped |
13.08.2026 |
3.7 |
| CVE-2026-73427 |
Trix: XSS via JSON deserialization bypass in drag-and-drop (Level0InputController) |
13.08.2026 |
|
| CVE-2026-73429 |
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) |
12.08.2026 |
5.3 |
| CVE-2026-73430 |
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) |
12.08.2026 |
5.3 |
| CVE-2026-73490 |
Loofah: SVG `href` attribute bypasses local-reference restriction |
13.08.2026 |
4.7 |
| CVE-2026-73491 |
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references |
13.08.2026 |
|
| CVE-2026-18888 |
MongoDB BI Connector ODBC driver may write outside an allocated buffer when retrieving large floating point values as character data |
13.08.2026 |
|
| CVE-2026-19001 |
MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names |
13.08.2026 |
|
| CVE-2026-19002 |
Crafted database metadata may cause memory corruption in MongoDB BI Connector ODBC Driver |
13.08.2026 |
|
| CVE-2026-19004 |
MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output Parameters |
13.08.2026 |
|
| CVE-2026-65370 |
|
13.08.2026 |
|
| CVE-2026-73419 |
NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them |
13.08.2026 |
6.8 |
| CVE-2026-73422 |
Astro: Reflected XSS via unescaped View Transition animation properties |
12.08.2026 |
|
| CVE-2026-73423 |
Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered |
12.08.2026 |
|
| CVE-2026-11932 |
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access |
12.08.2026 |
5.3 |
| CVE-2026-14866 |
IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities |
13.08.2026 |
7.7 |
| CVE-2026-16033 |
Arbitrary file read+write on host via templates/ symlink in malicious image |
13.08.2026 |
8.5 |
| CVE-2026-17616 |
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access |
12.08.2026 |
6.8 |
| CVE-2026-19502 |
Insufficient redaction of sensitive configuration values in diagnostic output of MongoDB SQL Schema Builder CLI |
13.08.2026 |
|
| CVE-2026-19503 |
Insufficient OIDC endpoint validation could invoke unintended local protocol handlers |
13.08.2026 |
|
| CVE-2026-62421 |
|
12.08.2026 |
|
| CVE-2026-66898 |
Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE |
13.08.2026 |
9.9 |
| CVE-2026-73418 |
NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers |
13.08.2026 |
7.5 |
| CVE-2026-11923 |
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access |
13.08.2026 |
7.4 |
| CVE-2026-11937 |
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access |
12.08.2026 |
3.1 |
| CVE-2026-12004 |
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access |
13.08.2026 |
8.7 |
| CVE-2026-12005 |
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access |
13.08.2026 |
7.2 |
| CVE-2026-12359 |
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access |
13.08.2026 |
8.1 |
| CVE-2026-12618 |
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access |
13.08.2026 |
7.2 |
| CVE-2026-13267 |
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access |
13.08.2026 |
8.1 |
| CVE-2026-63293 |
Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root |
13.08.2026 |
9.9 |
| CVE-2026-63294 |
Root RCE via image backup.yaml symlink |
13.08.2026 |
9.9 |
| CVE-2026-67579 |
Filter expression injection via forged keyset pagination cursor in Ash |
13.08.2026 |
|
| CVE-2026-73415 |
jupyterlab: Image viewer in JupyterLab allows XSS when opening malicious image in new browser tab |
12.08.2026 |
|
| CVE-2026-13361 |
IBM Informix Server Vulnerability in SQL Interface Handler Could Allow Remote Code Execution |
13.08.2026 |
8.8 |
| CVE-2026-17082 |
IBM i is Affected By Multiple Vulnerabilities in the Debug Server |
13.08.2026 |
8.8 |
| CVE-2026-17083 |
IBM i is Affected By Multiple Vulnerabilities in the Debug Server |
13.08.2026 |
9.8 |
| CVE-2026-17111 |
IBM i is Affected By Multiple Vulnerabilities in SQL |
12.08.2026 |
7.6 |
| CVE-2026-17417 |
IBM i is Affected By Remote Code Execution Vulnerabilities [, ] |
13.08.2026 |
8.8 |
| CVE-2026-17445 |
IBM i is Affected By Improper Validation Vulnerability in Line Printer Daemon [] |
12.08.2026 |
8.2 |
| CVE-2026-17642 |
IBM i is Affected By Remote Code Execution Vulnerabilities [, ] |
13.08.2026 |
8.8 |
| CVE-2026-18099 |
IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
12.08.2026 |
8.9 |
| CVE-2026-18148 |
IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
13.08.2026 |
4.3 |
| CVE-2026-18150 |
IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
12.08.2026 |
4.3 |
| CVE-2026-19642 |
Out-of-bounds write in the Base64 decoder in Amazon aws-sdk-cpp |
13.08.2026 |
5.9 |
| CVE-2026-19643 |
Out-of-bounds read in the Base64 decoder in Amazon aws-sdk-cpp on signed-char platforms |
13.08.2026 |
5.3 |
| CVE-2026-46731 |
|
13.08.2026 |
7.8 |
| CVE-2026-49466 |
Draft List - Contributor Stored Cross-Site Scripting via Draft Title in Custom Drafts Template Attributes |
13.08.2026 |
6.5 |
| CVE-2026-59914 |
|
13.08.2026 |
7.8 |
| CVE-2026-59917 |
|
13.08.2026 |
7.8 |
| CVE-2026-63295 |
Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated` |
13.08.2026 |
4.3 |
| CVE-2026-63296 |
Project restriction bypass via instance migration config override |
13.08.2026 |
9.9 |
| CVE-2026-63297 |
Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge |
13.08.2026 |
9.9 |
| CVE-2026-63298 |
LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration |
13.08.2026 |
8.7 |
| CVE-2026-72508 |
Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*) |
13.08.2026 |
|
| CVE-2026-73409 |
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile |
12.08.2026 |
|
| CVE-2026-73411 |
Shescape: Home-directory disclosure in assignment context on Unix with Dash |
12.08.2026 |
|
| CVE-2026-73412 |
Shescape: Path disclosure on Unix with Zsh |
13.08.2026 |
|
| CVE-2026-73413 |
Shescape: Quadratic-time denial of service in flag-protection |
13.08.2026 |
|
| CVE-2026-73414 |
Shescape: Shell injection via unescaped parentheses on Windows with CMD |
12.08.2026 |
|
| CVE-2025-9486 |
Incorrect Privilege Assignment in GitLab |
13.08.2026 |
3.3 |
| CVE-2026-15216 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab |
13.08.2026 |
8.7 |
| CVE-2026-15217 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab |
13.08.2026 |
8.7 |
| CVE-2026-16494 |
Missing Authorization in GitLab |
13.08.2026 |
7.1 |
| CVE-2026-18433 |
Incorrect Authorization in GitLab |
13.08.2026 |
4.3 |
| CVE-2026-18679 |
Kong Mesh: kuma-dp connects to the control plane without verifying the TLS certificate when no CA is configured |
13.08.2026 |
|
| CVE-2026-19228 |
Authorization Bypass Through User-Controlled Key in GitLab |
13.08.2026 |
8.5 |
| CVE-2026-19656 |
ScadaLTS Authenticated Remote Code Execution |
12.08.2026 |
9.9 |
| CVE-2026-19657 |
ScadaLTS Unauthenticated Reflected XSS |
12.08.2026 |
6.1 |
| CVE-2026-4879 |
Missing Authorization in GitLab |
13.08.2026 |
4.3 |
| CVE-2026-59916 |
|
13.08.2026 |
7.8 |
| CVE-2026-62420 |
Cross-project cluster migration bypasses project restrictions via cluster notification flag |
12.08.2026 |
9.9 |
| CVE-2026-63299 |
Storage volume cross-project move and snapshot restore bypass project disk limits |
12.08.2026 |
8.5 |
| CVE-2026-63300 |
Cross-project instance move bypasses all project restrictions allowing host command execution |
13.08.2026 |
9.9 |
| CVE-2026-6821 |
Missing Authorization in GitLab |
13.08.2026 |
4.3 |
| CVE-2026-72786 |
Craft CMS 5.0.0-RC1 before 5.10.8 Authentication Bypass via Password Reset |
13.08.2026 |
|
| CVE-2026-72787 |
Craft CMS 5.0.0-RC1 before 5.10.8 Stored XSS via Draft Name |
12.08.2026 |
|
| CVE-2026-72788 |
SiYuan before v3.7.4 Information Disclosure via UILayout Filter |
12.08.2026 |
|
| CVE-2026-72789 |
SiYuan before v3.7.4 Authentication Bypass via Encrypted Notebooks |
12.08.2026 |
|
| CVE-2026-72790 |
SiYuan before v3.7.4 Information Disclosure via getNotebookInfo |
12.08.2026 |
|
| CVE-2026-72791 |
SiYuan before v3.7.4 Information Disclosure via getAttributeViewFieldViews |
12.08.2026 |
|
| CVE-2026-72792 |
SiYuan before v3.7.4 Information Disclosure via Tag API |
12.08.2026 |
|
| CVE-2026-72793 |
SiYuan before v3.7.4 Information Disclosure via /api/system/getConf |
12.08.2026 |
|
| CVE-2026-72794 |
siyuan before v3.7.4 Session Cookie Key Disclosure via getConf |
12.08.2026 |
|
| CVE-2026-72795 |
SiYuan before v3.7.4 Information Disclosure via Embed Block |
12.08.2026 |
|
| CVE-2026-72796 |
SiYuan before v3.7.4 Access Control Bypass via Static Routes |
12.08.2026 |
|
| CVE-2026-72797 |
SiYuan before v3.7.4 Information Disclosure via getEncryptedNotebookStatus |
12.08.2026 |
|
| CVE-2026-72798 |
SiYuan before v3.7.4 Information Disclosure via renderAttributeView |
12.08.2026 |
|
| CVE-2026-72799 |
SiYuan before v3.7.4 Information Disclosure via Path Resolution |
12.08.2026 |
|
| CVE-2026-72800 |
SiYuan before v3.7.4 Information Disclosure via Unfiltered API |
12.08.2026 |
|
| CVE-2026-72801 |
SiYuan before v3.7.4 Information Disclosure via Encryption Key Material |
12.08.2026 |
|
| CVE-2026-72802 |
SiYuan before v3.7.4 Information Disclosure via resolveAssetPath |
12.08.2026 |
|
| CVE-2026-72803 |
SiYuan before v3.7.4 Information Disclosure via getBlockAttrs |
12.08.2026 |
|
| CVE-2026-72804 |
SiYuan before v3.7.4 Authentication Bypass via Graph Endpoints |
12.08.2026 |
|
| CVE-2026-72805 |
SiYuan before v3.7.4 Information Disclosure via Block Endpoints |
12.08.2026 |
|
| CVE-2026-72806 |
SiYuan before v3.7.4 Authentication Bypass via Attribute View |
12.08.2026 |
|
| CVE-2026-72807 |
SiYuan before v3.7.4 SQL Injection via queryBlocks template |
12.08.2026 |
|
| CVE-2026-72808 |
SiYuan before v3.7.4 Information Disclosure via getFileAnnotation |
12.08.2026 |
|
| CVE-2026-72809 |
SiYuan before v3.7.4 Authentication Bypass via Localhost Trust |
12.08.2026 |
|
| CVE-2026-73268 |
Cluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows arbitrary job spec injection |
12.08.2026 |
|
| CVE-2026-73269 |
Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa |
12.08.2026 |
|
| CVE-2026-73303 |
Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session) |
12.08.2026 |
8.2 |
| CVE-2026-73306 |
Budibase: Account Enumeration via Login Lockout Response Differential |
13.08.2026 |
5.3 |
| CVE-2026-73307 |
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation |
12.08.2026 |
|
| CVE-2026-73308 |
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders |
12.08.2026 |
5.7 |
| CVE-2026-73326 |
CamaleonCMS Missing Authorization via Plugin Administration Endpoints |
12.08.2026 |
|
| CVE-2026-73329 |
CamaleonCMS Stored XSS via Draft Post Title Creation Endpoint |
12.08.2026 |
|
| CVE-2026-73330 |
CamaleonCMS 2.9.1 Server-Side Template Injection via test_email Action |
12.08.2026 |
|
| CVE-2026-73331 |
CamaleonCMS 2.9.1 Authenticated SQL Injection via Post Slug Field |
12.08.2026 |
|
| CVE-2026-73332 |
CamaleonCMS cama_contact_form Plugin Stored XSS via before_html Field |
12.08.2026 |
|
| CVE-2026-73406 |
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint |
13.08.2026 |
7.5 |
| CVE-2026-73407 |
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak (bypass of CVE-2026-48152)) |
12.08.2026 |
|
| CVE-2026-73433 |
Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd parsing leading to out-of-bounds read/write |
12.08.2026 |
|
| CVE-2026-73434 |
Gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing |
13.08.2026 |
|
| CVE-2026-18675 |
Kong Mesh: control plane denial of service via a malformed dataplane token with a non-string JWT kid |
13.08.2026 |
|
| CVE-2026-18676 |
Kong Mesh: default control plane config leaks the admin token cross-origin via a CORS wildcard and localhost admin |
13.08.2026 |
|
| CVE-2026-18677 |
Kong Mesh: a dataplane token without a workload binding can claim any workload's SPIFFE identity |
13.08.2026 |
|
| CVE-2026-18678 |
Kong Mesh: kumactl connects to the control plane without verifying the TLS certificate when no CA is configured |
13.08.2026 |
|
| CVE-2026-18952 |
Missing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics Plugin |
13.08.2026 |
|
| CVE-2026-19311 |
Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin |
13.08.2026 |
|
| CVE-2026-18673 |
Kong Mesh: the kuma-dp readiness service exposes the Envoy admin API without authentication |
13.08.2026 |
|
| CVE-2026-73301 |
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings |
12.08.2026 |
4.3 |
| CVE-2026-15423 |
Incorrect Authorization in GitLab |
13.08.2026 |
8.5 |
| CVE-2026-16627 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab |
13.08.2026 |
7.7 |
| CVE-2026-18244 |
Missing Authorization in GitLab |
13.08.2026 |
4.3 |
| CVE-2026-73300 |
Budibase: SQL Injection via `multipleStatements: true` |
12.08.2026 |
9.6 |
| CVE-2026-73327 |
Joomla 6.1.1 Zip Slip Path Traversal via com_joomlaupdate extract.php |
12.08.2026 |
|
| CVE-2026-7427 |
Allocation of Resources Without Limits or Throttling in GitLab |
13.08.2026 |
5.3 |
| CVE-2026-8667 |
Incorrect Authorization in GitLab |
13.08.2026 |
4.3 |
| CVE-2026-16856 |
IBM i is Affected By Multiple Vulnerabilities in Domain Name System |
12.08.2026 |
8.8 |
| CVE-2026-16860 |
IBM i is Affected By Remote Code Execution Vulnerability [] |
12.08.2026 |
9.9 |
| CVE-2026-16863 |
IBM i is Affected By Out-of-Bounds Read Vulnerability [] |
12.08.2026 |
7.7 |
| CVE-2026-16906 |
IBM i is Affected By Multiple Vulnerabilities in Domain Name System |
12.08.2026 |
8.8 |
| CVE-2026-16907 |
IBM i is Affected By Multiple Vulnerabilities in the Debug Server |
12.08.2026 |
7.6 |
| CVE-2026-16931 |
IBM i is Affected By A Denial of Service Vulnerability [] |
12.08.2026 |
7.5 |
| CVE-2026-16956 |
IBM Db2 Mirror for i is vulnerable to OS command injection [] |
12.08.2026 |
9.8 |
| CVE-2026-17109 |
IBM i is Affected By Multiple Vulnerabilities in SQL |
12.08.2026 |
4.3 |
| CVE-2026-17110 |
IBM i is Affected By Multiple Vulnerabilities in SQL |
12.08.2026 |
8.8 |
| CVE-2026-17218 |
IBM i is Affected By Remote Code Execution Vulnerability in Line Printer Daemon [] |
12.08.2026 |
9.8 |
| CVE-2026-17222 |
IBM i is Affected By Multiple Vulnerabilities in SQL |
12.08.2026 |
4.3 |
| CVE-2026-17248 |
IBM i is Affected By Multiple Vulnerabilities in the Debug Server |
12.08.2026 |
7.1 |
| CVE-2026-17271 |
IBM i is Affected By Multiple Vulnerabilities in the Debug Server |
12.08.2026 |
7.5 |
| CVE-2026-17420 |
IBM i is Affected By Multiple Vulnerabilities in SQL |
12.08.2026 |
6.3 |
| CVE-2026-18669 |
IBM i is Affected By A Privilege Escalation Vulnerability [] |
12.08.2026 |
8.8 |
| CVE-2026-42018 |
Anonymous user token generation exposure in JFrog Artifactory |
13.08.2026 |
7.5 |
| CVE-2026-69106 |
Potential cache poisoning in JFrog Artifactory |
13.08.2026 |
8.8 |
| CVE-2026-73298 |
Microsoft Container Migration Solution Accelerator: Authenticated IDOR allowing read/write/delete processes |
12.08.2026 |
|
| CVE-2026-73299 |
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer |
12.08.2026 |
10 |
| CVE-2026-16904 |
IBM i is Affected By improper privilege management in Navigator for i |
12.08.2026 |
8.1 |
| CVE-2026-17266 |
IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
12.08.2026 |
6.5 |
| CVE-2026-17268 |
IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
12.08.2026 |
6.8 |
| CVE-2026-17276 |
IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
12.08.2026 |
9.6 |
| CVE-2026-17418 |
IBM i is Affected By Multiple Vulnerabilities in SQL |
12.08.2026 |
8.5 |
| CVE-2026-17419 |
IBM i is Affected By Multiple Vulnerabilities in SQL |
12.08.2026 |
6.5 |
| CVE-2026-18235 |
IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
12.08.2026 |
8.3 |
| CVE-2026-18250 |
IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
12.08.2026 |
6.3 |
| CVE-2026-18713 |
IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
12.08.2026 |
8.8 |