Search
283 CVEs · published 2026-08-04 to 2026-08-04
CVEs (283)
Showing 251–275 of 283
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-18721 | MEDIUM | 4.3 | 2026-08-04 | A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file /user/sso/apiLogin of the component SSO API Login. … | |
| CVE-2026-14818 | HIGH | 7.2 | 2026-08-04 | A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX serie… | |
| CVE-2026-8508 | MEDIUM | 6.5 | 2026-08-04 | An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN… | |
| CVE-2026-6837 | HIGH | 7.2 | 2026-08-04 | A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated… | |
| CVE-2026-18720 | MEDIUM | 5.3 | 2026-08-04 | A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of the component msgWarning… | |
| CVE-2026-17614 | MEDIUM | 4.4 | 2026-08-04 | A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getConfigurationFile() methods in wildfly-core/deployme… | |
| CVE-2026-18719 | MEDIUM | 6.3 | 2026-08-04 | A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the component Search. Performing a manipulation of the argume… | |
| CVE-2026-58045 | MEDIUM | 6.2 | 2026-08-04 | A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All … | |
| CVE-2026-58044 | LOW | 3.7 | 2026-08-04 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` he… | |
| CVE-2026-58042 | MEDIUM | 5.9 | 2026-08-04 | A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records. Repeated triggering of this condition can l… | |
| CVE-2026-58041 | MEDIUM | 5.3 | 2026-08-04 | A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it … | |
| CVE-2026-56846 | HIGH | 7.5 | 2026-08-04 | A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js … | |
| CVE-2026-56845 | HIGH | 7.5 | 2026-08-04 | An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the … | |
| CVE-2026-66326 | MEDIUM | Patched | 6.5 | 2026-08-04 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-66325 | MEDIUM | Patched | 6.1 | 2026-08-04 | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-66322 | HIGH | Patched | 7.1 | 2026-08-04 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-66321 | HIGH | Patched | 7.4 | 2026-08-04 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-66318 | HIGH | Patched | 8.1 | 2026-08-04 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-66317 | MEDIUM | Patched | 5.4 | 2026-08-04 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. |
| CVE-2026-66316 | MEDIUM | Patched | 5.4 | 2026-08-04 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-66315 | HIGH | Patched | 7.5 | 2026-08-04 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-66314 | MEDIUM | Patched | 6.5 | 2026-08-04 | Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-66313 | MEDIUM | Patched | 6.8 | 2026-08-04 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. |
| CVE-2026-66312 | MEDIUM | Patched | 6.5 | 2026-08-04 | Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. |
| CVE-2026-66311 | MEDIUM | Patched | 6.2 | 2026-08-04 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. |