Search
442 CVEs · published 2026-08-12 to 2026-08-12
CVEs (442)
Showing 51–75 of 442
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-18888 | MEDIUM | 6.5 | 2026-08-12 | The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an applicatio… | |
| CVE-2026-18097 | MEDIUM | Patched | 5.5 | 2026-08-12 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive informat… |
| CVE-2026-18096 | LOW | 3.3 | 2026-08-12 | IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to a memory leak. | |
| CVE-2026-17616 | MEDIUM | Patched | 6.8 | 2026-08-12 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Pro… |
| CVE-2026-16695 | HIGH | Patched | 7.8 | 2026-08-12 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an … |
| CVE-2026-16480 | MEDIUM | Patched | 4.3 | 2026-08-12 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to by… |
| CVE-2026-16033 | HIGH | 8.5 | 2026-08-12 | A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD f… | |
| CVE-2026-14866 | HIGH | Patched | 7.7 | 2026-08-12 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore. |
| CVE-2026-13622 | HIGH | 8.8 | 2026-08-12 | A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launch… | |
| CVE-2026-13476 | HIGH | Patched | 7.3 | 2026-08-12 | IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to im… |
| CVE-2026-13433 | HIGH | Patched | 8.3 | 2026-08-12 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could… |
| CVE-2026-13367 | HIGH | 7.8 | 2026-08-12 | IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility. | |
| CVE-2026-13105 | HIGH | Patched | 8.8 | 2026-08-12 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration. |
| CVE-2026-13094 | HIGH | Patched | 7.8 | 2026-08-12 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configura… |
| CVE-2026-11932 | MEDIUM | Patched | 5.3 | 2026-08-12 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 is vulnera… |
| CVE-2026-10543 | HIGH | Patched | 8.2 | 2026-08-12 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query. |
| CVE-2026-73434 | MEDIUM | Patched | 6.1 | 2026-08-12 | A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated … |
| CVE-2026-73433 | MEDIUM | Patched | 6.6 | 2026-08-12 | A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length cou… |
| CVE-2026-73415 | NONE | Patched | — | 2026-08-12 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/image… |
| CVE-2026-73414 | NONE | Patched | — | 2026-08-12 | Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/win/cmd.js does not escape `(` and `)` when applicati… |
| CVE-2026-73413 | NONE | Patched | — | 2026-08-12 | Shescape is a simple shell escape library for JavaScript. From 2.1.11 until 2.1.14 and 3.0.1, the flag-protection loop in compose in src/internal/compose.js repeatedly join… |
| CVE-2026-73412 | NONE | Patched | — | 2026-08-12 | Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, this impacts users of Shescape on Unix systems that explicitly configure shell to Zsh, … |
| CVE-2026-73411 | NONE | Patched | — | 2026-08-12 | Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/unix/dash.js fails to escape ~ after : or = when appl… |
| CVE-2026-73409 | NONE | Patched | — | 2026-08-12 | Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-controlled tlsCertificateKeyFile and tlsCAFile val… |
| CVE-2026-73407 | NONE | Patched | — | 2026-08-12 | Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials from getAuthHeaders and… |