Search
283 CVEs · published 2026-08-04 to 2026-08-04
CVEs (283)
Showing 101–125 of 283
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-47613 | HIGH | Patched | 7.5 | 2026-08-04 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path i… |
| CVE-2026-47612 | HIGH | Patched | 7.5 | 2026-08-04 | NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A s… |
| CVE-2026-47487 | MEDIUM | Patched | 4.4 | 2026-08-04 | NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providi… |
| CVE-2026-24255 | HIGH | Patched | 7.5 | 2026-08-04 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identi… |
| CVE-2026-24254 | CRITICAL | Patched | 9.8 | 2026-08-04 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vuln… |
| CVE-2026-24253 | HIGH | Patched | 8.2 | 2026-08-04 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of se… |
| CVE-2026-18830 | HIGH | 8.1 | 2026-08-04 | Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and securi… | |
| CVE-2026-18790 | LOW | 3.3 | 2026-08-04 | A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse of the file src/ClientServer/fr… | |
| CVE-2026-18788 | HIGH | 7.3 | 2026-08-04 | A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipu… | |
| CVE-2026-69263 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx,… |
| CVE-2026-69262 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPer… |
| CVE-2026-69259 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordm… |
| CVE-2026-69258 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted a… |
| CVE-2026-69257 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IP… |
| CVE-2026-69256 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is exec… |
| CVE-2026-69255 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.… |
| CVE-2026-64634 | NONE | — | 2026-08-04 | A vulnerability allowing local privilege escalation to the Reporter service context. | |
| CVE-2026-64633 | NONE | — | 2026-08-04 | A vulnerability allowing remote unauthenticated code execution on the agent host. | |
| CVE-2026-64631 | NONE | — | 2026-08-04 | A vulnerability allowing a low-privileged user to inject SQL and extract database contents. | |
| CVE-2026-64630 | NONE | — | 2026-08-04 | A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link. | |
| CVE-2026-63456 | CRITICAL | 9.8 | 2026-08-04 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechani… | |
| CVE-2026-63455 | CRITICAL | 9.8 | 2026-08-04 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechani… | |
| CVE-2026-58075 | NONE | — | 2026-08-04 | A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally. | |
| CVE-2026-58074 | NONE | — | 2026-08-04 | A vulnerability allowing a high-privileged user to execute arbitrary code on the server. | |
| CVE-2026-58073 | NONE | — | 2026-08-04 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials. |