Search
442 CVEs · published 2026-08-12 to 2026-08-12
CVEs (442)
Showing 301–325 of 442
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-66376 | MEDIUM | 4.2 | 2026-08-12 | Credentials for a deleted user may remain valid for a short period under specific conditions. | |
| CVE-2026-66375 | HIGH | 8.1 | 2026-08-12 | A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions. | |
| CVE-2026-50561 | CRITICAL | Patched | 9.4 | 2026-08-12 | Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contai… |
| CVE-2026-49349 | MEDIUM | 6.8 | 2026-08-12 | regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for… | |
| CVE-2026-49262 | LOW | 3.0 | 2026-08-12 | In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) a… | |
| CVE-2026-47234 | MEDIUM | 4.4 | 2026-08-12 | Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::setCookie()` logs full cookie values and `Session::sta… | |
| CVE-2026-47233 | MEDIUM | 6.5 | 2026-08-12 | Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `case 'item_delete':` in `modules/inventory.php`. The… | |
| CVE-2026-18171 | NONE | — | 2026-08-12 | Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sa… | |
| CVE-2026-14479 | MEDIUM | 5.5 | 2026-08-12 | A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting … | |
| CVE-2026-14478 | HIGH | 7.8 | 2026-08-12 | A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, … | |
| CVE-2025-59324 | CRITICAL | 9.1 | 2026-08-12 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped. | |
| CVE-2025-59323 | HIGH | 8.4 | 2026-08-12 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration… | |
| CVE-2025-59322 | HIGH | 7.5 | 2026-08-12 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext. | |
| CVE-2025-59321 | CRITICAL | 9.8 | 2026-08-12 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed vi… | |
| CVE-2025-59320 | MEDIUM | 4.6 | 2026-08-12 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical ac… | |
| CVE-2025-59319 | HIGH | 7.2 | 2026-08-12 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardco… | |
| CVE-2026-67285 | NONE | — | 2026-08-12 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbi… | |
| CVE-2026-47232 | MEDIUM | 4.3 | 2026-08-12 | Admidio is an open-source user management solution. Prior to version 5.0.10, the sensitive `mode=export` action in `modules/sso/keys.php` exports a PKCS#12 bundle containin… | |
| CVE-2026-47231 | HIGH | 8.1 | 2026-08-12 | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-changing modes by checking that the actor has `hasUpl… | |
| CVE-2026-47230 | MEDIUM | 6.5 | 2026-08-12 | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_rename_save` shares the same root-cause shape as the c… | |
| CVE-2026-47229 | MEDIUM | 5.4 | 2026-08-12 | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm_csrf_token` on every state-changing branch except `… | |
| CVE-2026-47228 | MEDIUM | 5.2 | 2026-08-12 | Admidio is an open-source user management solution. `modules/registration.php` mode `send_login` regenerates a random password for `user_uuid_assigned`, stores its bcrypt h… | |
| CVE-2026-47227 | MEDIUM | 6.5 | 2026-08-12 | Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`, `EVT`, `ROL`, `USF`, …) corresponds to a modu… | |
| CVE-2026-16999 | MEDIUM | Patched | 6.3 | 2026-08-12 | Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking. This issue affects… |
| CVE-2025-59327 | HIGH | 7.5 | 2026-08-12 | In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrit… |