Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

442 CVEs · published 2026-08-12 to 2026-08-12

CVEs (442)

Showing 326–350 of 442

CVE ID Severity Patch CVSS Published Description
CVE-2025-59326 CRITICAL 9.8 2026-08-12 CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned code to be executed from…
CVE-2025-59325 HIGH 7.5 2026-08-12 CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline recovery of secrets and cryptographic details.
CVE-2026-71408 MEDIUM 5.3 2026-08-12 A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow a…
CVE-2026-71407 MEDIUM 5.6 2026-08-12 A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack prote…
CVE-2026-70468 HIGH 8.1 2026-08-12 A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9,…
CVE-2026-70467 LOW 3.8 2026-08-12 A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, Fo…
CVE-2026-70466 MEDIUM 5.3 2026-08-12 A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all ver…
CVE-2026-57858 HIGH 8.9 2026-08-12 Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owne…
CVE-2026-53996 HIGH 7.0 2026-08-12 NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivileged local attackers to invoke the HDAUDIO_FGRP_…
CVE-2026-47226 MEDIUM Patched 6.5 2026-08-12 Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload rights on any one folder can permanently delete fil…
CVE-2026-26035 CRITICAL 9.8 2026-08-12 An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, Fort…
CVE-2026-70560 MEDIUM 5.4 2026-08-12 Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-privileged authenticated attackers to inject arbitrary …
CVE-2026-70465 HIGH 8.1 2026-08-12 A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through …
CVE-2026-18044 LOW Patched 3.7 2026-08-12 The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property reques…
CVE-2026-17008 MEDIUM 5.3 2026-08-12 The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks an order paid on …
CVE-2026-16990 MEDIUM 5.3 2026-08-12 The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allo…
CVE-2026-16747 MEDIUM Patched 6.5 2026-08-12 The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes attacker-controlled input through shortcode executi…
CVE-2026-16621 MEDIUM Patched 5.3 2026-08-12 The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return …
CVE-2026-15213 MEDIUM Patched 5.3 2026-08-12 The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback: an unauthenticated req…
CVE-2026-15045 MEDIUM Patched 6.5 2026-08-12 The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkou…
CVE-2026-11325 HIGH Patched 8.8 2026-08-12 Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/inde…
CVE-2026-68868 MEDIUM Patched 6.5 2026-08-12 The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `tea…
CVE-2026-67284 NONE &mdash; 2026-08-12 Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform various file-related operati&hellip;
CVE-2026-64955 MEDIUM 6.1 2026-08-12 When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution.  Velociraptor fails to&hellip;
CVE-2026-64952 MEDIUM 6.5 2026-08-12 The hunt_delete() VQL function allows deleting hunts.  Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned to the "investigator" r&hellip;