Search
442 CVEs · published 2026-08-12 to 2026-08-12
CVEs (442)
Showing 351–375 of 442
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-64951 | LOW | 3.5 | 2026-08-12 | A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic occurs which may crash the server process. The pro… | |
| CVE-2026-18663 | MEDIUM | 5.9 | 2026-08-12 | A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without… | |
| CVE-2026-18652 | MEDIUM | 6.5 | 2026-08-12 | Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the … | |
| CVE-2026-67283 | NONE | — | 2026-08-12 | Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related opera… | |
| CVE-2026-67282 | NONE | — | 2026-08-12 | Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend l… | |
| CVE-2026-19566 | HIGH | Patched | 7.5 | 2026-08-12 | Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths. The _encode method accepts any prefix leng… |
| CVE-2026-19426 | HIGH | 8.2 | 2026-08-12 | POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system. | |
| CVE-2025-41771 | MEDIUM | 4.3 | 2026-08-12 | An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a SQLi… | |
| CVE-2025-41770 | HIGH | 7.5 | 2026-08-12 | An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client appl… | |
| CVE-2025-41769 | CRITICAL | 9.8 | 2026-08-12 | The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this… | |
| CVE-2026-66659 | CRITICAL | 9.3 | 2026-08-12 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affect… | |
| CVE-2026-19594 | HIGH | 8.1 | 2026-08-12 | Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknes… | |
| CVE-2026-19217 | MEDIUM | Patched | 5.4 | 2026-08-12 | The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, which could allow users … |
| CVE-2026-19073 | MEDIUM | Patched | 5.3 | 2026-08-12 | The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and does not verify that t… |
| CVE-2026-19052 | MEDIUM | Patched | 4.3 | 2026-08-12 | The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX actions, and the nonce they rely on is published on it… |
| CVE-2026-19050 | MEDIUM | Patched | 6.4 | 2026-08-12 | The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requester, before performin… |
| CVE-2026-18962 | MEDIUM | Patched | 4.3 | 2026-08-12 | The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload into the album they target when it processes a front-en… |
| CVE-2026-18943 | MEDIUM | Patched | 6.5 | 2026-08-12 | The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low as subscriber to read a… |
| CVE-2026-18789 | HIGH | Patched | 7.5 | 2026-08-12 | The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated attackers to trigger a serv… |
| CVE-2026-18474 | HIGH | Patched | 8.6 | 2026-08-12 | The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by un… |
| CVE-2026-18391 | CRITICAL | Patched | 9.8 | 2026-08-12 | The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, lead… |
| CVE-2026-18366 | CRITICAL | Patched | 9.8 | 2026-08-12 | The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelat… |
| CVE-2026-18230 | HIGH | Patched | 8.1 | 2026-08-12 | The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions… |
| CVE-2026-18057 | HIGH | Patched | 8.1 | 2026-08-12 | The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber … |
| CVE-2026-18049 | HIGH | Patched | 7.5 | 2026-08-12 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and builds an option name fr… |