Search
442 CVEs · published 2026-08-12 to 2026-08-12
CVEs (442)
Showing 26–50 of 442
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-18726 | MEDIUM | 6.5 | 2026-08-12 | A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By … | |
| CVE-2026-17485 | HIGH | 8.2 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow. | |
| CVE-2026-10534 | HIGH | Patched | 8.4 | 2026-08-12 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser. |
| CVE-2024-27253 | CRITICAL | 10.0 | 2026-08-12 | IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities. | |
| CVE-2026-73491 | NONE | Patched | — | 2026-08-12 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.all… |
| CVE-2026-73490 | MEDIUM | Patched | 4.7 | 2026-08-12 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies … |
| CVE-2026-73430 | MEDIUM | Patched | 5.3 | 2026-08-12 | Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of service by sending SSH_MSG_KEX_ECDH_INIT with a 32-byte al… |
| CVE-2026-73429 | MEDIUM | Patched | 5.3 | 2026-08-12 | Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a malformed KEX_ECDH_REPLY containing a server ep… |
| CVE-2026-73427 | NONE | Patched | — | 2026-08-12 | Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cross-site scripting when a crafted application/x-trix-… |
| CVE-2026-73425 | LOW | Patched | 3.7 | 2026-08-12 | Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remotePatterns entry into a regular expression written t… |
| CVE-2026-73423 | NONE | Patched | — | 2026-08-12 | Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline installs security.checkOrigin only through the middleware()… |
| CVE-2026-73422 | NONE | Patched | — | 2026-08-12 | Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS generator interpolates animation properties into an in… |
| CVE-2026-73419 | MEDIUM | Patched | 6.8 | 2026-08-12 | NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, no… |
| CVE-2026-73418 | HIGH | Patched | 7.5 | 2026-08-12 | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and… |
| CVE-2026-66898 | CRITICAL | 9.9 | 2026-08-12 | A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup a… | |
| CVE-2026-65370 | HIGH | Patched | 7.5 | 2026-08-12 | ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. This vulnerability is addressed in servicetalk version… |
| CVE-2026-64826 | MEDIUM | Patched | 6.5 | 2026-08-12 | rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal seque… |
| CVE-2026-62421 | NONE | — | 2026-08-12 | Rejected reason: Voluntarily withdrawn | |
| CVE-2026-19654 | HIGH | Patched | 7.5 | 2026-08-12 | A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an i… |
| CVE-2026-19503 | MEDIUM | 4.8 | 2026-08-12 | MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document… | |
| CVE-2026-19502 | MEDIUM | 5.5 | 2026-08-12 | MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings we… | |
| CVE-2026-19130 | MEDIUM | 5.8 | 2026-08-12 | A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a … | |
| CVE-2026-19004 | HIGH | 8.1 | 2026-08-12 | An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this is… | |
| CVE-2026-19002 | HIGH | 8.1 | 2026-08-12 | A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client applicati… | |
| CVE-2026-19001 | CRITICAL | 9.8 | 2026-08-12 | The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a… |