Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

616 CVEs · published 2026-08-13 to 2026-08-13

CVEs (616, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 351–375 of 616 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-53791 CRITICAL Patched 9.1 2026-08-13 rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted…
CVE-2026-53790 HIGH Patched 8.1 2026-08-13 rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through …
CVE-2026-53789 MEDIUM Patched 6.5 2026-08-13 rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destinatio…
CVE-2026-53788 MEDIUM Patched 6.5 2026-08-13 rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge protocol messages by crea…
CVE-2026-53786 MEDIUM Patched 6.5 2026-08-13 rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supplying malicious --filte…
CVE-2026-53785 HIGH Patched 7.1 2026-08-13 rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relativ…
CVE-2026-53784 HIGH Patched 7.1 2026-08-13 rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the m…
CVE-2026-53783 HIGH 8.1 2026-08-13 rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to…
CVE-2026-49857 HIGH 7.4 2026-08-13 auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implements SSRF protection in `assertSafeUrl()` (`src/secu…
CVE-2026-49856 MEDIUM 4.3 2026-08-13 @jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version 0.3.1, he network domain has a central SSRF authoriz…
CVE-2026-49820 MEDIUM Patched 4.7 2026-08-13 Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `saferedirect` package validates redirect URLs us…
CVE-2026-28154 HIGH 7.1 2026-08-13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and s…
CVE-2026-19734 NONE Patched — 2026-08-13 Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4.7 allows authenticated…
CVE-2026-19293 HIGH 8.8 2026-08-13 SMP security request (from peripheral) does not include the maximum encryption key size supported. Using a key with less than the maximum keysize makes brute-forcing the ke…
CVE-2026-19292 HIGH 8.8 2026-08-13 Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.
CVE-2026-19291 HIGH 8.8 2026-08-13 Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.
CVE-2026-16101 HIGH 8.8 2026-08-13 Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below
CVE-2026-15994 HIGH 7.0 2026-08-13 During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local aut…
CVE-2026-14456 HIGH 7.5 2026-08-13 Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new …
CVE-2026-14256 MEDIUM 4.7 2026-08-13 ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a local authenticated user to cause…
CVE-2026-12036 HIGH 7.1 2026-08-13 An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user t…
CVE-2026-73403 MEDIUM 5.3 2026-08-13 Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.
CVE-2026-73401 MEDIUM 5.3 2026-08-13 Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.
CVE-2026-73357 MEDIUM 6.5 2026-08-13 Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.
CVE-2026-73353 MEDIUM 5.3 2026-08-13 Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.