Search
616 CVEs · published 2026-08-13 to 2026-08-13
CVEs (616, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 616 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-53791 | CRITICAL | Patched | 9.1 | 2026-08-13 | rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted… |
| CVE-2026-53790 | HIGH | Patched | 8.1 | 2026-08-13 | rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through … |
| CVE-2026-53789 | MEDIUM | Patched | 6.5 | 2026-08-13 | rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destinatio… |
| CVE-2026-53788 | MEDIUM | Patched | 6.5 | 2026-08-13 | rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge protocol messages by crea… |
| CVE-2026-53786 | MEDIUM | Patched | 6.5 | 2026-08-13 | rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supplying malicious --filte… |
| CVE-2026-53785 | HIGH | Patched | 7.1 | 2026-08-13 | rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relativ… |
| CVE-2026-53784 | HIGH | Patched | 7.1 | 2026-08-13 | rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the m… |
| CVE-2026-53783 | HIGH | 8.1 | 2026-08-13 | rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to… | |
| CVE-2026-49857 | HIGH | 7.4 | 2026-08-13 | auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implements SSRF protection in `assertSafeUrl()` (`src/secu… | |
| CVE-2026-49856 | MEDIUM | 4.3 | 2026-08-13 | @jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version 0.3.1, he network domain has a central SSRF authoriz… | |
| CVE-2026-49820 | MEDIUM | Patched | 4.7 | 2026-08-13 | Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `saferedirect` package validates redirect URLs us… |
| CVE-2026-28154 | HIGH | 7.1 | 2026-08-13 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and s… | |
| CVE-2026-19734 | NONE | Patched | — | 2026-08-13 | Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4.7 allows authenticated… |
| CVE-2026-19293 | HIGH | 8.8 | 2026-08-13 | SMP security request (from peripheral) does not include the maximum encryption key size supported. Using a key with less than the maximum keysize makes brute-forcing the ke… | |
| CVE-2026-19292 | HIGH | 8.8 | 2026-08-13 | Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below. | |
| CVE-2026-19291 | HIGH | 8.8 | 2026-08-13 | Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below. | |
| CVE-2026-16101 | HIGH | 8.8 | 2026-08-13 | Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below | |
| CVE-2026-15994 | HIGH | 7.0 | 2026-08-13 | During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local aut… | |
| CVE-2026-14456 | HIGH | 7.5 | 2026-08-13 | Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new … | |
| CVE-2026-14256 | MEDIUM | 4.7 | 2026-08-13 | ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a local authenticated user to cause… | |
| CVE-2026-12036 | HIGH | 7.1 | 2026-08-13 | An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user t… | |
| CVE-2026-73403 | MEDIUM | 5.3 | 2026-08-13 | Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions. | |
| CVE-2026-73401 | MEDIUM | 5.3 | 2026-08-13 | Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions. | |
| CVE-2026-73357 | MEDIUM | 6.5 | 2026-08-13 | Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions. | |
| CVE-2026-73353 | MEDIUM | 5.3 | 2026-08-13 | Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. |