| CVE-2026-19837 |
Webkul Bagisto Customer Search search information disclosure |
14.08.2026 |
|
| CVE-2026-63700 |
|
14.08.2026 |
7.8 |
| CVE-2026-66271 |
|
14.08.2026 |
7.2 |
| CVE-2026-16772 |
CVE-2026-16772 |
14.08.2026 |
|
| CVE-2026-19836 |
Webkul Bagisto Backend Customer Detail Feature view authorization |
14.08.2026 |
|
| CVE-2026-19884 |
|
14.08.2026 |
|
| CVE-2026-53970 |
ZeroBrew version 0.3.1 and prior Missing Checksum Verification RCE via shim.rb |
14.08.2026 |
|
| CVE-2026-63701 |
|
14.08.2026 |
6.3 |
| CVE-2026-63702 |
|
14.08.2026 |
6.3 |
| CVE-2026-66270 |
|
14.08.2026 |
7.2 |
| CVE-2026-66272 |
|
14.08.2026 |
5.3 |
| CVE-2026-13002 |
Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing |
14.08.2026 |
|
| CVE-2026-13196 |
Out-of-bounds Write in KUNBUS piControl |
14.08.2026 |
|
| CVE-2026-13197 |
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in KUNBUS piControl |
14.08.2026 |
|
| CVE-2026-13198 |
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in KUNBUS piControl |
14.08.2026 |
|
| CVE-2026-19834 |
Webkul Bagisto Admin Customer Impersonation Feature login-as-customer authorization |
14.08.2026 |
|
| CVE-2026-19835 |
Webkul Bagisto Customer Item Deletion Endpoint access control |
14.08.2026 |
|
| CVE-2026-57469 |
Cross-Site Request Forgery (CSRF) in KUNBUS PiCtory |
14.08.2026 |
|
| CVE-2026-57471 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS RevPiPyLoad |
14.08.2026 |
|
| CVE-2026-57472 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS RevPiPyLoad |
14.08.2026 |
|
| CVE-2026-19879 |
Io.undertow/undertow: undertow: http response header integrity issue due to character truncation |
14.08.2026 |
|
| CVE-2026-58224 |
Samba: ctdb fails to do integrity checking of received packets |
14.08.2026 |
|
| CVE-2026-19880 |
Incomplete protection against CVE-2025-11226 |
14.08.2026 |
|
| CVE-2026-69101 |
Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint |
14.08.2026 |
|
| CVE-2026-19768 |
|
14.08.2026 |
|
| CVE-2026-19829 |
648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversal |
14.08.2026 |
|
| CVE-2026-19830 |
TRENDnet TEW-816DRM bftpd bftpd.conf allocation of resources |
14.08.2026 |
|
| CVE-2026-19871 |
Use of hard-coded credentials in Prospero Flow CRM employee onboarding |
14.08.2026 |
|
| CVE-2026-1621 |
Register Bypass in Universal Sotware's E-Municipality |
14.08.2026 |
5.3 |
| CVE-2026-53472 |
Migration-planner: credentialurl validator accepts javascript: urls |
14.08.2026 |
|
| CVE-2026-73633 |
Apache Struts: Unbounded read of a JSON request body |
14.08.2026 |
|
| CVE-2026-19827 |
alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversal |
14.08.2026 |
|
| CVE-2026-19828 |
648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal |
14.08.2026 |
|
| CVE-2026-19825 |
SourceCodester Simple Client Management System Master.php save_service sql injection |
14.08.2026 |
|
| CVE-2026-19826 |
alldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject deserialization |
14.08.2026 |
|
| CVE-2026-19824 |
Tenda W20E addIpMacBind ipMacBindListStore stack-based overflow |
14.08.2026 |
|
| CVE-2026-19823 |
Tenda W20E QoS Rule Deletion delQos formQOSRuleDel stack-based overflow |
14.08.2026 |
|
| CVE-2026-19870 |
IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation |
14.08.2026 |
|
| CVE-2026-73673 |
Netis NC63 V3.0.0.3327 Unauthenticated Firmware Update with Missing Cryptographic Firmware Authentication |
14.08.2026 |
|
| CVE-2025-71405 |
go-chi chi before v5.2.2 Open Redirect via RedirectSlashes |
14.08.2026 |
|
| CVE-2026-19822 |
Tenda W20E QoS Edit editQos lstAdd stack-based overflow |
14.08.2026 |
|
| CVE-2026-72810 |
SiYuan before v3.7.4 Publish-Boundary Bypass via WebSocket |
14.08.2026 |
|
| CVE-2026-72811 |
SiYuan before v3.7.4 SQL Injection via backlink search |
14.08.2026 |
|
| CVE-2026-72812 |
SiYuan before v3.7.4 Missing Authorization via refreshBacklink |
14.08.2026 |
|
| CVE-2026-72813 |
actix-files before 0.6.10 Denial of Service via empty Range header |
14.08.2026 |
|
| CVE-2026-72814 |
actix-web before 0.6.10 Information Disclosure via Files |
14.08.2026 |
|
| CVE-2026-72815 |
go-chi chi v5.2.1 IP Spoofing via X-Forwarded-For Header |
14.08.2026 |
|
| CVE-2026-72816 |
go-chi chi before 5.3.0 IP Spoofing via RealIP Middleware |
14.08.2026 |
|
| CVE-2026-72817 |
go-chi chi 0.9.0 before 5.3.0 IP Spoofing via X-Forwarded-For |
14.08.2026 |
|
| CVE-2026-72819 |
Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload |
14.08.2026 |
|
| CVE-2026-72820 |
Grav 2.0.11 Path Traversal via Backup Profile Configuration |
14.08.2026 |
|
| CVE-2026-72821 |
Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle |
14.08.2026 |
|
| CVE-2026-72822 |
Grav before 1.0.13 Authentication Bypass via disable2fa |
14.08.2026 |
|
| CVE-2026-72823 |
Grav before 1.0.13 API-key scope cap bypass via DemoController |
14.08.2026 |
|
| CVE-2026-72824 |
Grav before 1.0.13 API Key Scope Bypass via PagesController |
14.08.2026 |
|
| CVE-2026-72825 |
Grav before 1.0.13 API-key scope cap bypass via ReportsController |
14.08.2026 |
|
| CVE-2026-72826 |
Grav before 1.0.13 Scope Bypass via createApiKey |
14.08.2026 |
|
| CVE-2026-72827 |
Grav CMS before 2.0.13 Remote Code Execution via Twig |
14.08.2026 |
|
| CVE-2026-72828 |
Grav before 1.0.13 API Key Scope Bypass via InvitationsController |
14.08.2026 |
|
| CVE-2026-72829 |
Grav before 1.0.13 API Key Scope Bypass via UsersController |
14.08.2026 |
|
| CVE-2026-72830 |
Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass |
14.08.2026 |
|
| CVE-2026-72831 |
Grav through 2.0.11 Authentication Bypass via Flex Objects |
14.08.2026 |
|
| CVE-2026-72832 |
Grav before 2.0.12 Stored XSS via quoted-attribute bypass |
14.08.2026 |
|
| CVE-2026-72833 |
Grav 1.0.6 through 1.0.11 Privilege Escalation via Scoped API Keys |
14.08.2026 |
|
| CVE-2026-72834 |
filebrowser before 2.63.19 Permission Bypass via checksum |
14.08.2026 |
|
| CVE-2026-72835 |
filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization |
14.08.2026 |
|
| CVE-2026-72836 |
FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass |
14.08.2026 |
|
| CVE-2026-72837 |
File Browser before 2.63.20 Privilege Escalation via Proxy Authentication |
14.08.2026 |
|
| CVE-2026-72838 |
FileBrowser before 2.63.19 Disk Exhaustion via TUS Upload |
14.08.2026 |
|
| CVE-2026-72859 |
Budibase 3.39.4 before 3.40.0 Authorization Regression via S3 Presigned URL |
14.08.2026 |
|
| CVE-2026-73048 |
SiYuan before v3.7.4 Information Disclosure via getRefIDsByFileAnnotationID |
14.08.2026 |
|
| CVE-2026-73049 |
SiYuan before v3.7.4 Information Disclosure via getAttributeViewBacklinks |
14.08.2026 |
|
| CVE-2026-73051 |
actix-http before 3.12.1 HTTP Request Smuggling via CL.TE |
14.08.2026 |
|
| CVE-2026-73630 |
SiYuan before v3.7.4 Information Disclosure via authFilePublishAccess |
14.08.2026 |
|
| CVE-2026-19821 |
Tenda AC12 httpd web management interface SetSysAutoRebbotCfg formSetRebootTimer buffer overflow |
14.08.2026 |
|
| CVE-2026-19814 |
TOTOLINK A800R firewall.so cstecgi.cgi setMacQos stack-based overflow |
14.08.2026 |
|
| CVE-2026-19815 |
TOTOLINK A800R firewall.so cstecgi.cgi setParentalRules stack-based overflow |
14.08.2026 |
|
| CVE-2026-19813 |
TOTOLINK A800R firewall.so cstecgi.cgi setMacFilterRules stack-based overflow |
14.08.2026 |
|
| CVE-2026-19794 |
WP-Stats <= 2.56 - Unauthenticated Stored Cross-Site Scripting |
14.08.2026 |
7.2 |
| CVE-2026-19812 |
TOTOLINK A800R product.so cstecgi.cgi UploadCustomModule stack-based overflow |
14.08.2026 |
|
| CVE-2026-19811 |
TOTOLINK A800R firewall.so cstecgi.cgi setIpQosRules stack-based overflow |
14.08.2026 |
|
| CVE-2026-14290 |
Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Attribute |
14.08.2026 |
|
| CVE-2026-15205 |
Paymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Callback Pixel Lookup |
14.08.2026 |
|
| CVE-2026-16739 |
Epeken All Kurir <= 2.1.2 - Unauthenticated Order Payment Confirmation Forgery |
14.08.2026 |
|
| CVE-2026-18039 |
Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment |
14.08.2026 |
|
| CVE-2026-19617 |
Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser |
14.08.2026 |
|
| CVE-2026-12743 |
affiliate-toolkit <= 3.8.8 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter |
14.08.2026 |
4.9 |
| CVE-2026-12949 |
Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameter |
14.08.2026 |
9.8 |
| CVE-2026-16810 |
Bit Form <= 3.2.0 - Authenticated (Administrator+) SQL Injection via 'filterText' Parameter |
14.08.2026 |
6.5 |
| CVE-2025-10308 |
Astro Booking Engine <= 1.4.0 - Cross-Site Request Forgery to Settings Reset |
14.08.2026 |
4.3 |
| CVE-2026-19791 |
Tenda G0 httpd web management interface module addStaticRoute stack-based overflow |
14.08.2026 |
|
| CVE-2026-19792 |
Tenda G0 httpd web management interface module setPortMapping buffer overflow |
14.08.2026 |
|
| CVE-2026-19788 |
Tenda AC1206 httpd web management interface SetOnlineDevName set_device_name stack-based overflow |
14.08.2026 |
|
| CVE-2026-19789 |
Tenda AC1206 httpd web management interface WifiGuestSet set_wl_guest_iplist stack-based overflow |
14.08.2026 |
|
| CVE-2026-19790 |
Tenda G0 httpd Web Management module formSetPortMirror stack-based overflow |
14.08.2026 |
|
| CVE-2026-18109 |
W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name |
14.08.2026 |
7.2 |
| CVE-2026-19784 |
francoisjacquet RosarioSIS Referrals.php DBUpdate authorization |
14.08.2026 |
|
| CVE-2026-19785 |
francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injection |
14.08.2026 |
|
| CVE-2026-19786 |
francoisjacquet RosarioSIS Modules.php cross-site request forgery |
14.08.2026 |
|
| CVE-2026-19787 |
SourceCodester Air Cargo Management System Master.php save_cargo_type sql injection |
14.08.2026 |
|
| CVE-2026-19767 |
itsourcecode Hospital Management System viewdoctortimings.php sql injection |
14.08.2026 |
|
| CVE-2026-19770 |
feedmob fm-mcp-servers Download Endpoint index.ts downloadReport server-side request forgery |
14.08.2026 |
|
| CVE-2026-19771 |
Baicells EG3661M LuCI Web luci os command injection |
14.08.2026 |
|
| CVE-2026-19764 |
Raisecom Communication Command and Dispatch Management Platform getpwd.php sql injection |
14.08.2026 |
|
| CVE-2026-19765 |
eyaushev swagger-testcase-mcp fetch_swagger swagger-parser.ts loadSource server-side request forgery |
14.08.2026 |
|
| CVE-2026-19762 |
DTStack Taier Chunk-Check Endpoint FileChunkController.java Paths.ge path traversal |
14.08.2026 |
|
| CVE-2026-19763 |
DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirectory path traversal |
14.08.2026 |
|
| CVE-2026-19761 |
DTStack Taier Upload Controller UploadController.java MultipartFile.getOriginalFilename path traversal |
14.08.2026 |
|
| CVE-2026-19758 |
dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversal |
13.08.2026 |
|
| CVE-2026-19757 |
Dromara lamp-cloud File-Upload Controller FileAnyoneController.java path traversal |
14.08.2026 |
|
| CVE-2026-19756 |
Dromara lamp-cloud Code Generator DefGenProjectController.java path traversal |
13.08.2026 |
|
| CVE-2026-18532 |
|
13.08.2026 |
|
| CVE-2026-19753 |
Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url server-side request forgery |
14.08.2026 |
|
| CVE-2026-3883 |
|
13.08.2026 |
|
| CVE-2026-19752 |
EnzoVezzaro mcp-dominican-layer PDF Parsing index.ts parse-pdf server-side request forgery |
14.08.2026 |
|
| CVE-2026-33818 |
Enforce maximum recursion depth in encoding/asn1 |
14.08.2026 |
|
| CVE-2026-56853 |
Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http |
14.08.2026 |
|
| CVE-2026-56858 |
Fix Javascript regexp context tracking in html/template |
14.08.2026 |
|
| CVE-2026-56859 |
Add recursion depth guard during decode in encoding/xml |
14.08.2026 |
|
| CVE-2026-56860 |
Avoid quadratic complexity in resolvePath in net/url |
13.08.2026 |
|
| CVE-2026-56862 |
Limit handshake messages we are willing to accept post-handshake in crypto/tls |
14.08.2026 |
|
| CVE-2026-56864 |
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb |
13.08.2026 |
|
| CVE-2026-56865 |
Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog |
14.08.2026 |
|
| CVE-2026-72839 |
filebrowser through 2.63.16 Privilege Escalation via Signup |
13.08.2026 |
|
| CVE-2026-72840 |
OpenWrt LuCI luci-mod-system-mounts ACL Root RCE via Crontab Write |
13.08.2026 |
|
| CVE-2026-72841 |
luci-app-openvpn Path Traversal RCE via instance_name2 |
13.08.2026 |
|
| CVE-2026-72842 |
OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass |
13.08.2026 |
|
| CVE-2026-72849 |
Budibase before 3.40.0 Identity Confusion via Chat-Link Handoff CSRF |
13.08.2026 |
|
| CVE-2026-72850 |
Budibase before 3.40.0 Arbitrary File Write via Path Traversal |
13.08.2026 |
|
| CVE-2026-72851 |
Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook |
13.08.2026 |
|
| CVE-2026-72853 |
Budibase before 3.40.0 SQL Injection via Oracle connector |
13.08.2026 |
|
| CVE-2026-72855 |
Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST |
13.08.2026 |
|
| CVE-2026-72856 |
Budibase before 3.40.0 Authentication Bypass via Tenant Owner Email |
13.08.2026 |
|
| CVE-2026-72857 |
Budibase before 3.40.0 Credential Exposure via STRING Fields |
13.08.2026 |
|
| CVE-2026-73302 |
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified |
13.08.2026 |
|
| CVE-2026-73304 |
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users |
14.08.2026 |
4.9 |
| CVE-2026-73305 |
Budibase: Privilege escalation via public role assignment API missing app-level authorization |
13.08.2026 |
8.8 |
| CVE-2026-73408 |
Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector |
13.08.2026 |
7.6 |
| CVE-2026-73416 |
jupyterlab: PyPI extension blocklist package-name canonicalization bypass |
13.08.2026 |
|
| CVE-2026-73417 |
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) |
13.08.2026 |
|
| CVE-2026-73420 |
NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass |
14.08.2026 |
|
| CVE-2026-73421 |
NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) |
13.08.2026 |
|
| CVE-2026-73428 |
Trix: Stored XSS via HTMLParser attribute injection on paste |
13.08.2026 |
4.6 |
| CVE-2026-73489 |
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records |
13.08.2026 |
4.3 |
| CVE-2026-73840 |
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) |
13.08.2026 |
5.3 |
| CVE-2026-73841 |
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints |
13.08.2026 |
8.8 |
| CVE-2026-73842 |
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation |
13.08.2026 |
9 |
| CVE-2026-73843 |
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs |
13.08.2026 |
9.6 |
| CVE-2026-19751 |
EnzoVezzaro mcp-dominican-layer parse-csv tool index.ts axios.get server-side request forgery |
13.08.2026 |
|
| CVE-2026-73039 |
streama Insecure Direct Object Reference via ViewingStatusController |
14.08.2026 |
|
| CVE-2026-73664 |
FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module |
13.08.2026 |
|
| CVE-2026-73665 |
FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection |
13.08.2026 |
|
| CVE-2026-73666 |
OpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo catalog data, scaffolder logs, and allows unauthenticated catalog write/delete |
13.08.2026 |
8.2 |
| CVE-2026-73667 |
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods |
13.08.2026 |
8.8 |
| CVE-2026-19750 |
Tenda CH/CP/TX3 SSH hard-coded password |
13.08.2026 |
|
| CVE-2026-72776 |
AgenticSeek Unauthenticated RCE via /query API Endpoint |
14.08.2026 |
|
| CVE-2026-73479 |
dua-cli Terminal Escape Sequence Injection via Marked Paths |
13.08.2026 |
|
| CVE-2026-73657 |
Trigger.dev: Cross-tenant payload poisoning via packet write + replay |
13.08.2026 |
4.2 |
| CVE-2026-73658 |
Trigger.dev: Cross-tenant object store read and write via URL path traversal |
13.08.2026 |
8.2 |
| CVE-2026-73659 |
Trigger.dev: Cross-tenant object read/write via path traversal in packet presign API |
13.08.2026 |
8.1 |
| CVE-2026-73660 |
FreePBX: Authenticated TTS AGI Command Injection Through TTS Name |
13.08.2026 |
|
| CVE-2026-73661 |
FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup |
13.08.2026 |
|
| CVE-2026-73662 |
Authenticated FreePBX Music RCE via mpg123 and Asterisk Call Files |
13.08.2026 |
|
| CVE-2026-73663 |
FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover |
13.08.2026 |
|
| CVE-2026-73480 |
gdu Terminal Injection via Unstripped Escape Sequences |
14.08.2026 |
|
| CVE-2026-17075 |
IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager |
13.08.2026 |
6.5 |
| CVE-2026-17438 |
IBM i is Affected By An Improper Privilege Management Vulnerability in LDAP [] |
13.08.2026 |
4.4 |
| CVE-2026-17468 |
IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution |
14.08.2026 |
5.3 |
| CVE-2026-17473 |
IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution |
13.08.2026 |
7.5 |
| CVE-2026-17476 |
IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Runtime |
13.08.2026 |
4.8 |
| CVE-2026-17481 |
IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution |
13.08.2026 |
8.8 |
| CVE-2026-17482 |
IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution |
13.08.2026 |
9.8 |
| CVE-2026-17502 |
IBM i is Affected By Multiple Vulnerabilities in NetServer |
14.08.2026 |
8.6 |
| CVE-2026-17649 |
IBM i is Affected By Multiple Vulnerabilities in NetServer |
13.08.2026 |
5.3 |
| CVE-2026-18020 |
IBM i is Affected By Multiple Vulnerabilities in NetServer |
13.08.2026 |
5.3 |
| CVE-2026-18068 |
IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension |
13.08.2026 |
4.3 |
| CVE-2026-18077 |
IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol |
13.08.2026 |
7.5 |
| CVE-2026-18086 |
IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension |
14.08.2026 |
4.5 |
| CVE-2026-18101 |
IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty |
13.08.2026 |
8.8 |
| CVE-2026-18193 |
IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Runtime |
13.08.2026 |
8.9 |
| CVE-2026-18249 |
IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Runtime |
14.08.2026 |
8.4 |
| CVE-2026-18509 |
IBM i is Affected By A Prvilege Escalation Vulnerability [] |
14.08.2026 |
8.2 |
| CVE-2026-18511 |
IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension |
14.08.2026 |
7.3 |
| CVE-2026-18671 |
IBM i is Affected By Multiple Vulnerabilities in NetServer |
13.08.2026 |
6.5 |
| CVE-2026-18715 |
IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty |
14.08.2026 |
6.5 |
| CVE-2026-18741 |
Worksuite SaaS version prior to 6.0.14 Stored XSS via Asset Management Location and Description Fields |
13.08.2026 |
4.8 |
| CVE-2026-19297 |
Insufficient Authentication Brute Force Protection on Login Endpoint |
13.08.2026 |
9.1 |
| CVE-2026-19483 |
The following vulnerabilities that can affect IBM Storage Scale and the Management GUI are now fixed in 5.2.3.9 or higher and 6.0.1.1 or higher |
14.08.2026 |
7.1 |
| CVE-2026-19749 |
Tenda CH7 RTSP/ONVIF missing authentication |
13.08.2026 |
|
| CVE-2026-17071 |
IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager |
13.08.2026 |
2.7 |
| CVE-2026-17074 |
IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM |
13.08.2026 |
3.1 |
| CVE-2026-17076 |
IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM |
13.08.2026 |
5.3 |
| CVE-2026-17077 |
IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM |
13.08.2026 |
5.3 |
| CVE-2026-17078 |
IBM i is Affected By A Denial of Service Vulnerability in DRDA / DDM [] |
13.08.2026 |
5.3 |
| CVE-2026-17088 |
IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager |
13.08.2026 |
4.3 |
| CVE-2026-17099 |
IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
13.08.2026 |
7.3 |
| CVE-2026-17101 |
IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
14.08.2026 |
8.3 |
| CVE-2026-17212 |
IBM i is Affected By Multiple Vulnerabilities in NetServer |
13.08.2026 |
5.3 |
| CVE-2026-17216 |
IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM |
13.08.2026 |
5.3 |
| CVE-2026-17226 |
IBM i is Affected By Multiple Vulnerabilities in NetServer |
13.08.2026 |
5.4 |
| CVE-2026-17272 |
IBM i is Affected By a Denial of Service in HTTP Server [] |
13.08.2026 |
8.2 |
| CVE-2026-8715 |
Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath |
14.08.2026 |
9.6 |
| CVE-2026-19748 |
Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy |
13.08.2026 |
|
| CVE-2026-16853 |
IBM i is Affected By Multiple Vulnerabilities in NetServer |
13.08.2026 |
6.5 |
| CVE-2026-16859 |
IBM i is Affected By Multiple Vulnerabilities in NetServer |
13.08.2026 |
5.3 |
| CVE-2026-16861 |
IBM i is Affected By Multiple Vulnerabilities in NetServer |
13.08.2026 |
5.3 |
| CVE-2026-16867 |
IBM i is Affected By Multiple Vulnerabilities in NetServer |
13.08.2026 |
8.1 |
| CVE-2026-16868 |
IBM i is Affected By Multiple Vulnerabilities in NetServer |
13.08.2026 |
8.1 |
| CVE-2026-16871 |
IBM i is Affected By Multiple Vulnerabilities in NetServer |
13.08.2026 |
4.3 |
| CVE-2026-16878 |
IBM i is Affected By Multiple Vulnerabilities in NetServer |
13.08.2026 |
5.4 |
| CVE-2026-16887 |
IBM i is Affected By A Denial of Service Vulnerability DST/SST [] |
13.08.2026 |
7.5 |
| CVE-2026-16896 |
IBM i is Affected By Multiple Vulnerabilities in Network Authentication Service |
13.08.2026 |
7.1 |
| CVE-2026-16898 |
IBM i is Affected By Multiple Vulnerabilities in Network Authentication Service |
13.08.2026 |
7.8 |
| CVE-2026-16908 |
IBM i is Affected By Multiple SQL Vulnerabilities [, ] |
13.08.2026 |
8.5 |
| CVE-2026-16961 |
IBM i is Affected By SQL Injection Vulnerability in Db2 Mirror [] |
13.08.2026 |
7.6 |
| CVE-2026-16967 |
IBM i is Affected By Multiple SQL Vulnerabilities [, ] |
14.08.2026 |
8.5 |
| CVE-2026-16975 |
IBM i is Affected By A Remote Code Execution Vulnerability [] |
14.08.2026 |
8.8 |
| CVE-2026-16987 |
IBM i is Affected By An Improper Validation Vulnerability in PASE [] |
14.08.2026 |
8.8 |
| CVE-2026-17029 |
IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension |
14.08.2026 |
8.8 |
| CVE-2026-17043 |
IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager |
13.08.2026 |
3.8 |
| CVE-2026-17045 |
IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager |
13.08.2026 |
8.1 |
| CVE-2026-17069 |
IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager |
14.08.2026 |
8.1 |
| CVE-2026-19747 |
Tenda CH7 ATE Module Kylin HandleCmd command injection |
14.08.2026 |
|
| CVE-2026-73655 |
Trigger.dev: Account Takeover via Cross-Provider OAuth Email Matching in Google Login |
13.08.2026 |
7.4 |
| CVE-2026-73656 |
Trigger.dev: Cross-project deployment worker registration can modify another project's deployment state |
13.08.2026 |
9.9 |
| CVE-2026-10571 |
IBM WebSphere Application Server Liberty is affected by a denial of service |
13.08.2026 |
5.7 |
| CVE-2026-13365 |
IBM Planning Analytics Local is affected by security vulnerabilities |
13.08.2026 |
7.1 |
| CVE-2026-13460 |
The following vulnerabilities that can affect IBM Storage Scale and the Management GUI are now fixed in 5.2.3.9 or higher and 6.0.1.1 or higher |
13.08.2026 |
7.5 |
| CVE-2026-14525 |
IBM WebSphere Application Server Liberty is affected by an authenication bypass |
13.08.2026 |
9.4 |
| CVE-2026-14875 |
IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities |
13.08.2026 |
7.3 |
| CVE-2026-16674 |
IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty |
13.08.2026 |
8.8 |
| CVE-2026-16692 |
IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol |
13.08.2026 |
6.5 |
| CVE-2026-16713 |
IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution |
13.08.2026 |
4.3 |
| CVE-2026-16722 |
IBM i is Affected By An Unauthorized Privileges Vulnerability in SQL [] |
13.08.2026 |
8.8 |
| CVE-2026-16815 |
IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol |
13.08.2026 |
8.6 |
| CVE-2026-45725 |
compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal |
13.08.2026 |
|
| CVE-2026-45774 |
compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal |
13.08.2026 |
|
| CVE-2026-73654 |
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS |
13.08.2026 |
8.5 |
| CVE-2026-16929 |
IBM i is Affected By Multiple Vulnerabilities in Host Servers |
13.08.2026 |
5.3 |
| CVE-2026-16982 |
IBM i is Affected By Multiple Vulnerabilities in Host Servers |
13.08.2026 |
7.5 |
| CVE-2026-17004 |
IBM i is Affected By Multiple Vulnerabilities in Host Servers |
13.08.2026 |
7.5 |
| CVE-2026-17199 |
IBM i is Affected By Multiple Vulnerabilities in Host Servers |
13.08.2026 |
7.5 |
| CVE-2026-17206 |
IBM i is Affected By Multiple Vulnerabilities in Host Servers |
14.08.2026 |
8.1 |
| CVE-2026-17223 |
IBM i is Affected By Multiple Vulnerabilities in Host Servers |
14.08.2026 |
8.8 |
| CVE-2026-17229 |
IBM i is Affected By Multiple Vulnerabilities in Host Servers |
13.08.2026 |
7.5 |
| CVE-2026-18164 |
Flow Neuroscience FL-100 Use of Hard-coded Credentials |
13.08.2026 |
|
| CVE-2026-18846 |
IBM i is Affected By Multiple Vulnerabilities in Host Servers |
13.08.2026 |
7.5 |
| CVE-2026-19745 |
Calix GigaSpire Web Management utilities_configurationsave.cgi denial of service |
13.08.2026 |
|
| CVE-2026-19746 |
Calix GigaSpire traceroute.cmd denial of service |
13.08.2026 |
|
| CVE-2026-48099 |
WsgiDAV encoded dot segments can escape filesystem share roots |
13.08.2026 |
7.1 |
| CVE-2026-49089 |
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-49096 |
Uncaught Exception in Kibana Cases Leading to Denial of Service |
13.08.2026 |
4.3 |
| CVE-2026-49864 |
wetty vulnerable to DOM XSS via file-download filename |
13.08.2026 |
|
| CVE-2026-59714 |
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids) |
13.08.2026 |
7.1 |
| CVE-2026-72629 |
Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access to Machine Learning Trained Models |
13.08.2026 |
7.1 |
| CVE-2026-72630 |
Incorrect Authorization in Kibana Fleet Leading to Privilege Escalation |
14.08.2026 |
7.1 |
| CVE-2026-72631 |
Improper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API Keys |
14.08.2026 |
6.5 |
| CVE-2026-72632 |
Observable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearch API Keys |
13.08.2026 |
7.1 |
| CVE-2026-72636 |
Uncontrolled Recursion in Elasticsearch Wildcard Matching Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72638 |
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72639 |
Memory Allocation with Excessive Size Value in Elasticsearch Highlighting Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72640 |
Unintended Proxy or Intermediary in Elastic Cloud on Kubernetes Leading to Cross-Namespace Secret Disclosure |
13.08.2026 |
6.5 |
| CVE-2026-72642 |
Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inference Process |
14.08.2026 |
8.8 |
| CVE-2026-72643 |
Incorrect Authorization in Kibana Agent Builder Leading to Disclosure and Tampering of Private Agents |
13.08.2026 |
7.1 |
| CVE-2026-72645 |
Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72647 |
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72648 |
Cleartext Storage of Sensitive Information in an Environment Variable in Elastic Cloud on Kubernetes Leading to Information Disclosure |
13.08.2026 |
6.5 |
| CVE-2026-72650 |
Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosure |
13.08.2026 |
4.3 |
| CVE-2026-72651 |
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72653 |
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72655 |
Improperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana Leading to Unauthorized Data Modification |
13.08.2026 |
4.3 |
| CVE-2026-72656 |
Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72657 |
Authorization Bypass Through User-Controlled Key in Fleet Server Leading to Information Disclosure |
13.08.2026 |
6.5 |
| CVE-2026-72658 |
Cross-Site Request Forgery in Kibana Leading to Privilege Escalation |
14.08.2026 |
7.3 |
| CVE-2026-72659 |
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72660 |
Uncaught Exception in Kibana Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72661 |
Missing Authorization in Kibana Leading to Information Disclosure |
13.08.2026 |
6.5 |
| CVE-2026-72663 |
Inefficient Algorithmic Complexity in Kibana Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72664 |
Missing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response Actions |
13.08.2026 |
6.5 |
| CVE-2026-72665 |
Missing Authorization in Kibana Leading to Unauthorized Execution of Host Response Actions |
13.08.2026 |
8.1 |
| CVE-2026-72666 |
Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query Execution on Managed Hosts |
13.08.2026 |
6.8 |
| CVE-2026-72667 |
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72669 |
Missing Authorization in Kibana Leading to Cross-User Information Disclosure and Data Tampering |
13.08.2026 |
7.6 |
| CVE-2026-72670 |
Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure of Fleet Proxy Credentials |
13.08.2026 |
7.7 |
| CVE-2026-72671 |
Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning Trained Model Space Assignments |
13.08.2026 |
4.3 |
| CVE-2026-72672 |
Incorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event Data |
13.08.2026 |
7.7 |
| CVE-2026-72673 |
Incorrect Authorization in Kibana Leading to Unauthorized Deletion of Synthetics Private Locations |
13.08.2026 |
5.4 |
| CVE-2026-72674 |
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72675 |
Missing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclosure and Unauthorized Data Modification |
13.08.2026 |
7.1 |
| CVE-2026-72676 |
Improper Control of Generation of Code in Fleet Server Leading to Code Injection |
13.08.2026 |
6.5 |
| CVE-2026-72677 |
Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Other Resources |
13.08.2026 |
7.3 |
| CVE-2026-72678 |
Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72679 |
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72680 |
Authorization Bypass Through User-Controlled Key in Kibana Agent Builder Leading to Unauthorized Data Modification |
13.08.2026 |
6.5 |
| CVE-2026-72681 |
Missing Authorization in Kibana Leading to Privilege Escalation and Information Disclosure |
14.08.2026 |
6.5 |
| CVE-2026-72683 |
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72684 |
Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72685 |
Inefficient Algorithmic Complexity in Elasticsearch Leading to Denial of Service |
13.08.2026 |
4.3 |
| CVE-2026-72686 |
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-72687 |
Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service |
13.08.2026 |
6.5 |
| CVE-2026-73530 |
Flyto2 Core < 2.28.0 SSRF Guard Bypass via is_private_ip() |
14.08.2026 |
|
| CVE-2026-73531 |
django-helpdesk < 2.3.3 Stored XSS via HTML Attachments |
13.08.2026 |
|
| CVE-2026-73669 |
Philips Hue Bridge Pro MQTT broker missing authentication |
13.08.2026 |
6.3 |
| CVE-2026-17197 |
IBM i is Affected By Multiple Vulnerabilities in Host Servers |
14.08.2026 |
8.1 |
| CVE-2026-17220 |
IBM i is Affected By Multiple Vulnerabilities in Host Servers |
13.08.2026 |
8.2 |
| CVE-2026-18071 |
IBM i is Affected By An Improper Management Vulnerability in HTTP Server [] |
14.08.2026 |
7.8 |
| CVE-2026-73038 |
NodeBB < 4.15.0 Stored XSS via ActivityPub emoji tag.icon.url and tag.name |
14.08.2026 |
|
| CVE-2026-73481 |
phpList < 3.7.0-RC5 Cross-Site Request Forgery via Bounce Rules |
14.08.2026 |
|
| CVE-2026-73482 |
phpList < 3.7.0-RC5 Cross-Site Request Forgery via admins.php |
14.08.2026 |
|
| CVE-2026-72777 |
Next AI Draw.io 0.4.16 SSRF via DNS Rebinding in parse-url |
14.08.2026 |
|
| CVE-2026-73037 |
Next AI Draw.io 0.2.1 - 0.4.16 Reflected XSS via unsanitized mcp query parameter |
14.08.2026 |
|
| CVE-2026-73650 |
SVGO: removeScripts plugin leaves some executable scripts intact |
13.08.2026 |
8.2 |
| CVE-2026-73651 |
TypeORM: migration:generate template-literal code injection |
13.08.2026 |
5.7 |
| CVE-2026-73652 |
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review |
13.08.2026 |
|
| CVE-2026-73653 |
Vitest: Browser Mode provider commands bypass the file-access permission gate |
13.08.2026 |
9.4 |
| CVE-2026-12908 |
|
13.08.2026 |
|
| CVE-2026-19730 |
Podman: podman: quadlet install --replace non-truncating write retains removed host-access directives |
13.08.2026 |
|
| CVE-2026-72741 |
Rainbond 6.9.7 Region API Cross-Enterprise IDOR via Tenant Access |
14.08.2026 |
|
| CVE-2026-73569 |
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits |
13.08.2026 |
|
| CVE-2026-73643 |
js-yaml: Exponential parsing time in the flow collections leads to denial of service |
13.08.2026 |
7.5 |
| CVE-2026-73644 |
OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grant |
13.08.2026 |
9.6 |
| CVE-2026-73645 |
OpenZeppelin Confidential Contracts ERC7984ERC20Wrapper: once a wrapper is filled, subsequent wrap requests do not revert and result in loss of funds. |
13.08.2026 |
|
| CVE-2026-73647 |
Quasar Framework: Prototype pollution in Quasar extend() utility |
13.08.2026 |
5.6 |
| CVE-2026-73648 |
rails-html-sanitizer: Possible XSS vulnerability with certain configurations |
13.08.2026 |
|
| CVE-2026-73649 |
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of CVE-2026-44966 fix) |
13.08.2026 |
9.8 |
| CVE-2019-25765 |
ASP-CMS SQL Injection via commentList.asp id Parameter |
14.08.2026 |
|
| CVE-2026-18428 |
SQL Query Validation Bypass in OpenSearch Direct Query |
13.08.2026 |
|
| CVE-2026-73561 |
Hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion |
13.08.2026 |
7.5 |
| CVE-2026-73562 |
Mongoose: Prototype pollution in the update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter) |
13.08.2026 |
6.5 |
| CVE-2026-73563 |
Backstage: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass in `@backstage/plugin-auth-backend` |
13.08.2026 |
4.7 |
| CVE-2026-73564 |
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow |
13.08.2026 |
|
| CVE-2026-73565 |
@hono/node-server: Unauthenticated memory-leak DoS via aborted WebSocket handshake |
13.08.2026 |
5.3 |
| CVE-2026-73566 |
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection |
13.08.2026 |
7.5 |
| CVE-2026-73567 |
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock |
13.08.2026 |
9.1 |
| CVE-2026-73568 |
py-libp2p: yamux connection DoS via oversized data frame |
13.08.2026 |
7.5 |
| CVE-2024-58374 |
Hongjing e-HR Unauthenticated SQL Injection via getSdutyTree |
13.08.2026 |
|
| CVE-2026-12236 |
Infinite loop (DoS) in Bluetooth GATT client parsing of Read-By-Type responses with zero data length |
13.08.2026 |
6.5 |
| CVE-2026-67613 |
CyberPanel < 3.0.0 Path Traversal File Read via cloudAPI ReadReport |
14.08.2026 |
|
| CVE-2026-67614 |
CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal |
14.08.2026 |
|
| CVE-2026-24059 |
Gitea runner registration-token GET endpoint performs a write under a read-only token scope |
13.08.2026 |
|
| CVE-2026-24791 |
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes |
13.08.2026 |
|