Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

616 CVEs · published 2026-08-13 to 2026-08-13

CVEs (616, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 276–300 of 616 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-42931 MEDIUM 6.5 2026-08-13 Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
CVE-2026-24791 HIGH 8.1 2026-08-13 Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
CVE-2026-24059 MEDIUM 6.5 2026-08-13 The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, y…
CVE-2026-23603 LOW 3.1 2026-08-13 Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
CVE-2026-13051 CRITICAL 9.1 2026-08-13 Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic t…
CVE-2026-13048 HIGH 8.2 2026-08-13 Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the langua…
CVE-2022-4993 CRITICAL 9.1 2026-08-13 HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message t…
CVE-2026-73671 MEDIUM 6.1 2026-08-13 Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied v…
CVE-2026-73670 HIGH 7.2 2026-08-13 A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a SHOW COLUMNS FROM stat…
CVE-2026-73576 MEDIUM Patched 6.3 2026-08-13 In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is ge…
CVE-2026-73575 LOW Patched 3.1 2026-08-13 In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (…
CVE-2026-73574 LOW Patched 3.1 2026-08-13 In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request para…
CVE-2026-73573 LOW Patched 3.1 2026-08-13 In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the…
CVE-2026-73572 MEDIUM Patched 6.1 2026-08-13 In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of …
CVE-2026-73571 LOW Patched 3.1 2026-08-13 An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality.…
CVE-2026-73570 HIGH Patched 8.9 2026-08-13 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enab…
CVE-2026-73559 MEDIUM Patched 6.5 2026-08-13 vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRequest.prompt field in vllm/entrypoints/openai/c…
CVE-2026-73533 CRITICAL 9.8 2026-08-13 Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered…
CVE-2026-73532 CRITICAL 9.8 2026-08-13 Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered …
CVE-2026-73515 HIGH Patched 8.1 2026-08-13 PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobu…
CVE-2026-73514 HIGH Patched 8.8 2026-08-13 The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ab…
CVE-2026-55401 NONE — 2026-08-13 CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet …
CVE-2026-55400 NONE — 2026-08-13 CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially crafted traffic to a se…
CVE-2026-19744 NONE Patched — 2026-08-13 Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a …
CVE-2026-19710 HIGH 7.3 2026-08-13 A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file app/admin/departments/…