Search
616 CVEs · published 2026-08-13 to 2026-08-13
CVEs (616, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 616 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-73416 | NONE | Patched | — | 2026-08-13 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.5.0 until 4.5.10 and 4.6.2, in jupyte… |
| CVE-2026-73408 | HIGH | Patched | 7.6 | 2026-08-13 | Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName int… |
| CVE-2026-73305 | HIGH | Patched | 8.8 | 2026-08-13 | Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.a… |
| CVE-2026-73304 | MEDIUM | Patched | 4.9 | 2026-08-13 | Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id returned user objects processed by packages/server/s… |
| CVE-2026-73302 | NONE | Patched | — | 2026-08-13 | Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolved an email without getEmai… |
| CVE-2026-73039 | MEDIUM | 5.4 | 2026-08-13 | streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete other users' viewing status… | |
| CVE-2026-72857 | HIGH | Patched | 7.7 | 2026-08-13 | Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase pr… |
| CVE-2026-72856 | HIGH | Patched | 8.1 | 2026-08-13 | Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/global/users/tenant/owner (changeTenantOwnerEmail) endpoint. On self-hosted i… |
| CVE-2026-72855 | HIGH | Patched | 8.5 | 2026-08-13 | Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execution that allow authenticated builder-level users to… |
| CVE-2026-72853 | HIGH | Patched | 7.6 | 2026-08-13 | Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. At… |
| CVE-2026-72851 | CRITICAL | Patched | 10.0 | 2026-08-13 | Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-contro… |
| CVE-2026-72850 | CRITICAL | Patched | 9.1 | 2026-08-13 | Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export.… |
| CVE-2026-72849 | HIGH | Patched | 7.7 | 2026-08-13 | Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a vi… |
| CVE-2026-72842 | CRITICAL | 9.9 | 2026-08-13 | luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper au… | |
| CVE-2026-72841 | CRITICAL | 9.9 | 2026-08-13 | luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary file… | |
| CVE-2026-72840 | HIGH | 8.8 | 2026-08-13 | OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configur… | |
| CVE-2026-72839 | CRITICAL | 9.8 | 2026-08-13 | filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can r… | |
| CVE-2026-72776 | CRITICAL | 9.8 | 2026-08-13 | AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by subm… | |
| CVE-2026-56865 | HIGH | 8.4 | 2026-08-13 | A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled mo… | |
| CVE-2026-56864 | HIGH | 7.5 | 2026-08-13 | A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to … | |
| CVE-2026-56862 | HIGH | 7.5 | 2026-08-13 | Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious clien… | |
| CVE-2026-56860 | MEDIUM | 5.9 | 2026-08-13 | Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time … | |
| CVE-2026-56859 | HIGH | 7.5 | 2026-08-13 | Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. | |
| CVE-2026-56858 | MEDIUM | 6.1 | 2026-08-13 | Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS. | |
| CVE-2026-56853 | HIGH | 7.5 | 2026-08-13 | When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout… |