Vulnerebility AUGUST
H
ECV
KB
KEV
|
2026()
2025()
|
Vulnerebility Calendar
Top Vulnerebility
List of Attack
CWE
Anti-Debug
Tricks
2026 January February March April May June July August September October November December
|
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
|
31.8.26 |
CVE-2026-60004 | Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. | VULNEREBILITY | VULNEREBILITY |
|
31.8.26 |
CVE-2026-6876 | ServiceNow has remediated a sandbox escape security issue that was identified in the Now Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the Now Platform, potentially leading to more access to the Now Platform than intended. ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. | VULNEREBILITY | VULNEREBILITY |
|
31.8.26 |
CVE-2026-74820 | ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data beyond what was intended. | VULNEREBILITY | VULNEREBILITY |
|
31.8.26 |
CVE-2026-18886 | ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation. | VULNEREBILITY | VULNEREBILITY |
|
31.8.26 |
CVE-2026-18885 | ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify, instance data beyond what was intended. | VULNEREBILITY | VULNEREBILITY |
|
29.8.26 |
CVE-2026-77550 | A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances. | VULNEREBILITY | VULNEREBILITY |
|
29.8.26 |
CVE-2026-77537 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. | VULNEREBILITY | VULNEREBILITY |
|
29.8.26 |
CVE-2026-20896 | Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled. | VULNEREBILITY | VULNEREBILITY |
| 28.8.26 | CVE-2026-65643 | Security: CVE-2026-65643 Vulnerability in cPanel’s Domain Parking Functionality - August 27, 2026 | VULNEREBILITY | VULNEREBILITY |
| 28.8.26 | CVE-2026-35603 | CVE-2026-35603: One Writable Folder, Every User Compromised: Exploiting Configuration Trust in AI Coding Tools | VULNEREBILITY | VULNEREBILITY |
| 28.8.26 | CVE-2026-75604 | Unauthenticated Remote Code Execution on windows-hosted servers | VULNEREBILITY | VULNEREBILITY |
| 26.8.26 | CVE-2026-60004 | Gitea Code Injection Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 25.8.26 | CVE-2026-75149 | marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a notebook. | VULNEREBILITY | VULNEREBILITY |
| 25.8.26 | CVE-2026-61979 | (CVSS score: 8.1) - An unauthenticated privilege escalation vulnerability stemming from signature algorithm confusion (Fixed in version 17.0.5 for the Standard edition) | VULNEREBILITY | VULNEREBILITY |
| 25.8.26 | CVE-2026-15981 | (CVSS score: 9.8) - An authentication bypass vulnerability stemming from accepting malformed signatures as valid (Fixed in version 17.0.6 for the Standard edition) | VULNEREBILITY | VULNEREBILITY |
| 25.8.26 | CVE-2026-21962 | VULNEREBILITY | VULNEREBILITY | VULNEREBILITY |
| 24.8.26 | CVE-2026-13757 | A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. | VULNEREBILITY | VULNEREBILITY |
| 24.8.26 | CVE-2026-17048 | A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. | VULNEREBILITY | VULNEREBILITY |
| 24.8.26 | CVE-2026-15571 | A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. | VULNEREBILITY | VULNEREBILITY |
| 24.8.26 | CVE-2026-14613 | A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific "role" can also see a list of all groups assigned to that role. | VULNEREBILITY | VULNEREBILITY |
| 24.8.26 | CVE-2026-9796 | A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. | VULNEREBILITY | VULNEREBILITY |
| 24.8.26 | CVE-2026-18963 | A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. | VULNEREBILITY | VULNEREBILITY |
| 23.8.26 | CVE-2025-55241 | Azure Entra ID Elevation of Privilege Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
23.8.26 |
CVE-2026-65770 | Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. | VULNEREBILITY | VULNEREBILITY |
| 23.8.26 | CVE-2026-65801 | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. | VULNEREBILITY | VULNEREBILITY |
|
23.8.26 |
CVE-2026-69555 | Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | VULNEREBILITY | VULNEREBILITY |
|
23.8.26 |
CVE-2026-65816 | Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | VULNEREBILITY | VULNEREBILITY |
|
23.8.26 |
CVE-2026-3055 | Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread | VULNEREBILITY | VULNEREBILITY |
|
23.8.26 |
CVE-2026-4368 | Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup | VULNEREBILITY | VULNEREBILITY |
|
22.8.26 |
CVE-2025-60710 | Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. | VULNEREBILITY | VULNEREBILITY |
| 22.8.26 | Cisco Crosswork Security Hardening Release: August 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered | VULNEREBILITY | VULNEREBILITY |
| 21.8.26 | CVE-2021-24092 | Microsoft Defender Elevation of Privilege Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
21.8.26 |
CVE-2026-69836 | Microsoft Entra ID Remote Code Execution Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
20.8.26 |
CVE-2026-19490 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. | VULNEREBILITY | VULNEREBILITY |
|
20.8.26 |
CVE-2026-19489 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. | VULNEREBILITY | VULNEREBILITY |
|
20.8.26 |
CVE-2026-73570 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. | VULNEREBILITY | VULNEREBILITY |
|
20.8.26 |
CVE-2026-69414 | Microsoft Defender Elevation of Privilege Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
20.8.26 |
CVE-2026-32475 | Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1. | VULNEREBILITY | VULNEREBILITY |
|
19.8.26 |
CVE-2025-31702 | A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user credentials could exploit the vulnerability to access certain data which are restricted to admin privileges, such as system-sensitive files through specific HTTP request. | VULNEREBILITY | VULNEREBILITY |
|
19.8.26 |
CVE-2021-33044 | The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets. | VULNEREBILITY | VULNEREBILITY |
|
19.8.26 |
CVE-2024-39943 | rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js). | VULNEREBILITY | VULNEREBILITY |
|
19.8.26 |
CVE-2026-24301 | Microsoft Copilot Information Disclosure Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
19.8.26 |
CVE-2026-64849 | (CVSS score: 9.3) - An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in MLflow that can allow an attacker who can reach the Tracking Server (mlflow server) to issue HTTP requests to arbitrary internal cloud metadata endpoints and extract sensitive data. (Affects versions < 3.15.0) | VULNEREBILITY | VULNEREBILITY |
|
19.8.26 |
CVE-2026-25895 | (CVSS score: 9.5) - A missing authentication for a critical function and path traversal vulnerability in FUXA that can allow an unauthenticated, remote attacker to write arbitrary files to the server file system and achieve remote code execution. (Affects versions <= 1.2.9) | VULNEREBILITY | VULNEREBILITY |
|
18.8.26 |
CVE-2026-15748 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2007-3010 | Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2016-6277 | NETGEAR Multiple Routers Remote Code Execution Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2018-14558 | Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2019-14931 | Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2020-10987 | Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2021-46422 | Telesquare SDT-CW3B1 Command Injection vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2022-37055 | D-Link Routers Buffer Overflow Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2024-29269 | Telesquare TLR-2005KSH Command Injection Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2025-10123 | D-Link DIR-823X Command Injection Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2025-55583 | D-Link DIR-868L B1 router Command Injection Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
16.8.26 |
CVE-2026-12569 | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. | VULNEREBILITY | VULNEREBILITY |
|
16.8.26 |
CVE-2019-10617 | Low privilege users can access service configuration which contains registry data that admins uses to create or delete entries in the registry in QCA6174_9377.WIN.1.0 in QCA6174_9377 | VULNEREBILITY | VULNEREBILITY |
|
15.8.26 |
CVE-2026-45659 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | VULNEREBILITY | VULNEREBILITY |
|
15.8.26 |
CVE-2026-20337 | A vulnerability in the zip archive parser of ClamAV could... | VULNEREBILITY | VULNEREBILITY |
|
15.8.26 |
CVE-2026-65400 | An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials. | VULNEREBILITY | VULNEREBILITY |
|
14.8.26 |
CVE-2026-20339 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. | VULNEREBILITY | VULNEREBILITY |
|
14.8.26 |
CVE-2026-20338 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. | VULNEREBILITY | VULNEREBILITY |
|
14.8.26 |
CVE-2026-20337 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. | VULNEREBILITY | VULNEREBILITY |
|
14.8.26 |
CVE-2026-70468 | A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here> | VULNEREBILITY | VULNEREBILITY |
|
14.8.26 |
CVE-2026-49975 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. | VULNEREBILITY | VULNEREBILITY |
|
14.8.26 |
CVE-2026-71407 | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled. | VULNEREBILITY | VULNEREBILITY |
|
14.8.26 |
CVE-2026-71408 | A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via <insert attack vector here> | VULNEREBILITY | VULNEREBILITY |
|
13.8.26 |
CVE-2026-15409 | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location. | VULNEREBILITY | VULNEREBILITY |
|
13.8.26 |
CVE-2026-15410 | Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. | VULNEREBILITY | VULNEREBILITY |
|
13.8.26 |
CVE-2025-49113 | Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization. | VULNEREBILITY | VULNEREBILITY |
|
13.8.26 |
CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-48362 | (CVSS score: 10.0) - An operating system command injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23) | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-48273 | (CVSS score: 9.9) - An eval injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23) | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-71384 | (CVSS score: 9.6) - An incorrect authorization vulnerability in ColdFusion that could lead to an application denial-of-service (Fixed in 2025.0.12 and 2023.0.23) | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-71362 | (CVSS score: 9.1) - An incorrect authorization vulnerability in Commerce that could lead to privilege escalation | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-71398 | (CVSS score: 10.0) - An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400) | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-27302 | (CVSS score: 10.0) - An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400) | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-48381 | (CVSS score: 9.0) - An SQL injection vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400) | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-33634 | Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-58231 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-44772 | (CVSS score: 9.9) - A code injection vulnerability in Manufacturing Integration and Intelligence | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-34265 | (CVSS score: 9.8) - An out-of-bounds write vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform that allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This could be exploited to disclose sensitive system information or crash the system. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-44758 | (CVSS score: 9.1) - A code injection vulnerability in Manufacturing Integration and Intelligence that could allow an attacker with high privileges to execute arbitrary commands on the underlying operating system. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-59124 | Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-62878 | Microsoft reports that CVE-2026-62878 is neither exploited in the wild nor publicly disclosed; it is a Critical Windows DNS Server remote code execution vulnerability with a CVSS score of 9.8. The flaw is a stack-based buffer overflow in Windows DNS that can be triggered remotely by an unauthenticated attacker sending a specially crafted packet to an affected service over the network, with no user interaction required, potentially allowing code execution on the target DNS server. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-72971 | This vulnerability was publicly disclosed before Patch Tuesday, making it a zero-day, but Microsoft says it has not been exploited in the wild; it is rated Important with a CVSS score of 5.5. The flaw is an improper link-resolution, or “link following,” issue in the Windows Container Isolation file system filter driver, unionfs.sys, affecting Windows 11 Version 26H1 on x64 and ARM64 systems. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-62832 | Microsoft says this vulnerability has been publicly disclosed but has not been exploited in the wild, making it a zero-day disclosure without confirmed exploitation at this time. Rated Important with a CVSS score of 7.8, this Windows User Profile Service flaw is an improper link resolution, or “link following,” issue that could allow a local authenticated attacker to elevate privileges. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-68820 | This Important-severity elevation of privilege vulnerability is listed by Microsoft as exploited in the wild but not publicly disclosed, and it has a CVSS score of 7.0. The flaw is a use-after-free issue in the Windows Ancillary Function Driver for WinSock affecting supported Windows client and server versions; a locally authenticated attacker with low privileges could run a specially crafted application to trigger a race condition and, if successful, gain SYSTEM privileges. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-62815 | This Critical Microsoft QUIC remote code execution vulnerability is not listed as exploited in the wild or publicly disclosed. It carries a CVSS score of 9.8 and is a use-after-free flaw that could allow an unauthenticated remote attacker to send a specially crafted packet to an affected service over the network and execute code on the target system, with no user interaction required. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-53415 | Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-53414 | Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-53413 | Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access. | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-63520 | Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.1 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing stack overflow. Users should upgrade to version 2.1.1 to receive a patch. No known workarounds are available. | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-55040 | Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-31431 | Linux privilege escalation (“Copy Fail”) | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-34197 | ActiveMQ Remote Code Execution | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-8512 | Use-after-free in Chrome's File System Access API on macOS | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-45185 | EXIM unauthenticated Remote Code Execution | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-22738 | SpringAI SpEL Remote Code Execution | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-20339 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-20338 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-20337 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. | VULNEREBILITY | VULNEREBILITY |
|
10.8.26 |
CVE-2026-33691 | The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ). | VULNEREBILITY | VULNEREBILITY |
|
10.8.26 |
CVE-2026-3502 | TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. | VULNEREBILITY | VULNEREBILITY |
|
9.8.26 |
Safe RET Interrupt Vulnerability | An external researcher has reported a potential vulnerability affecting AMD "Zen" architecture processors. The report claims that an attacker executing code on an affected system could inject an interrupt at a precise moment to disrupt “Safe RET,” the default Linux mitigation for Speculative Return Stack Overflow (SRSO), which could potentially weaken that protection and may result in information disclosure. | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
CVE-2026-20339 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
CVE-2026-20338 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
CVE-2026-20337 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
CVE-2026-20294 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
CVE-2023-38646 | Metabase RCE Vulnerability Explained | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
CVE-2023-38646 | Metabase RCE Vulnerability Explained | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
CVE-2026-64638 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79) | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
SCTPhantom | SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
CVE-2026-64564 | In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
CVE-2026-44613 | Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a malicious site to perform actions on the user's behalf through REST and WebSocket endpoints. | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
CVE-2026-54316 | Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools restrictions | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
CVE-2026-12537 | Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted .gemini/.env file. | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
CVE-2026-63913 | In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check An unintended behavior in the TCP conntrack state machine allows a connection to be forced into the CLOSE state using an RST packet with an invalid sequence number. | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
CVE-2026-56181 | Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
CVE-2026-64561 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
Zapscape | Zapscape (CVE-2026-64561) is a use-after-free vulnerability that occurs in the shadow MMU of KVM/x86. When an attacker-controlled guest that uses nested virtualization makes KVM recursively zap a root shadow page that is still in use during MMU page quota reclaim, KVM keeps handling the fault on a root that has already become invalid. As a result an invalid child enters the active MMU page list, and afterwards the same list link is attached to two lists at once and then freed, producing a dangling link and a post-free write. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20303 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20304 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20310 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20310 are related to improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-59. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20269 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20269 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20268 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20268 are related to issues with improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20267 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20267 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20289 | A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then collecting the system logs. A successful exploit could allow the attacker to view sensitive information like user login credentials. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20294 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20028 | Preact, a lightweight web development framework, JSON serialization protection to prevent Virtual DOM elements from being constructed from arbitrary JSON. A regression introduced in Preact 10.26.5 caused this protection to be softened. In applications where values from JSON payloads are assumed to be strings and passed unmodified to Preact as children, a specially-crafted JSON payload could be constructed that would be incorrectly treated as a valid VNode. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20308 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20311 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in the web-based management interface. An attacker could exploit this vulnerability by authenticating with a malformed certificate. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20316 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20200 | CVE-2026-20200: Cisco Cisco Unified Computing System (Standalone): A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with… | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20288 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20301 | CVE-2026-20301: Cisco: A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol,… | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20263 | GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20124 | The PhotoStack Gallery plugin for WordPress is vulnerable to SQL Injection via the 'postid' parameter in all versions up to, and including, 0.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20079 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-63077 | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability | KEV | KEV |
|
6.8.26 |
CVE-2026-18236 | A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute unauthorized tools by forging a tool confirmation response. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-18830 | Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-58073 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-58072 | A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-58067 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-58071 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
Breaking the Paperclip | Critical Vulnerabilities in AI Agent Orchestration | ||
|
5.8.26 |
CVE-2026-41679 | Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-64531 | In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guard preventing a generated nested action attribute from exceeding U16_MAX. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
OVSwrap | OVSwrap (CVE-2026-64531) local root exploit: mitigation for CloudLinux 9, 10, and CloudLinux for Ubuntu | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-60004 | . When these hook scripts are subsequently triggered during Git operations, they execute arbitrary shell commands with the privileges of the Gitea process user. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-49774 | Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-9198 | (CVSS score: 9.8) - A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. (Fixed in July 2026 with version 1.10.1) | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-34486 | (CVS score: 7.5) - A missing encryption of sensitive data vulnerability in Apache Tomcat that allows a bypass of EncryptInterceptor, a cluster component that adds pre-shared key encryption to messages sent between cluster nodes. (Fixed in April 2026 with versions 11.0.21, 10.1.54, and 9.0.117) | VULNEREBILITY | VULNEREBILITY |
|
4.8.26 |
CVE-2025-9290 | An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality. | VULNEREBILITY | VULNEREBILITY |
|
4.8.26 |
CVE-2025-9289 | A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. | VULNEREBILITY | VULNEREBILITY |
|
4.8.26 |
CVE-2026-58047 | HTTP Smuggling in cPanel allows potential leak of credentials. | VULNEREBILITY | VULNEREBILITY |
|
4.8.26 |
CVE-2026-58048 | Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. | VULNEREBILITY | VULNEREBILITY |
|
4.8.26 |
CVE-2026-18577 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
CVE-2026-17883 | Inappropriate implementation in Headless in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
CVE-2026-18577 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
CVE-2026-18556 | Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1. | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
FaceHugger | FaceHugger: Vulnerabilities in Hugging Face Diffusers Open Door to Supply Chain Attacks on Enterprise AI | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
CVE-2026-44827 | (CVSS score: 8.8) - A code injection vulnerability that allows arbitrary code to be loaded through the custom_pipeline flow from a Hub repository by means of a crafted pipeline with the name "None.py" despite passing trust_remote_code=False (or omitting it, which is the default). | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
CVE-2026-45804 | (CVSS score: 7.5) - A race condition vulnerability that allows arbitrary code to be introduced to a repository by modifying the configuration between the hf_hub_download and snapshot_download HTTP calls to the Hub, leading to code execution. | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
CVE-2026-44513 | (CVSS score: 8.8) - A code injection vulnerability that allows arbitrary code to be loaded through the custom_pipeline flow from a Hub repository despite passing trust_remote_code=False (or omitting it). | VULNEREBILITY | VULNEREBILITY |
|
2.8.26 |
CVE-2026-63077 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | VULNEREBILITY | VULNEREBILITY |
|
1.8.26 |
CVE-2026-61511 | vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. | VULNEREBILITY | VULNEREBILITY |
|
1.8.26 |
CVE-2013-4786 | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC. | VULNEREBILITY | VULNEREBILITY |
|
1.8.26 |
CVE-2026-48448 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. | VULNEREBILITY | VULNEREBILITY |
|
1.8.26 |
CVE-2026-48449 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | VULNEREBILITY | VULNEREBILITY |