Search
442 CVEs · published 2026-08-12 to 2026-08-12
CVEs (442)
Showing 126–150 of 442
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-59914 | HIGH | Patched | 7.8 | 2026-08-12 | Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with l… |
| CVE-2026-4879 | MEDIUM | Patched | 4.3 | 2026-08-12 | GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could h… |
| CVE-2026-49466 | MEDIUM | 6.5 | 2026-08-12 | Draft List is a WordPress plugin to manage and promote unpublished content. Versions 2.6.3 and below are vulnerable to stored Cross-Site Scripting (XSS) in the `[drafts]` s… | |
| CVE-2026-46731 | HIGH | Patched | 7.8 | 2026-08-12 | Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with l… |
| CVE-2026-19657 | MEDIUM | 6.1 | 2026-08-12 | ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can exe… | |
| CVE-2026-19656 | CRITICAL | 9.9 | 2026-08-12 | ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissi… | |
| CVE-2026-19643 | MEDIUM | Patched | 5.3 | 2026-08-12 | An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user to crash an application … |
| CVE-2026-19642 | MEDIUM | Patched | 5.9 | 2026-08-12 | An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authenticated user to cause a crash or heap memory corruption … |
| CVE-2026-19228 | HIGH | Patched | 8.5 | 2026-08-12 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authen… |
| CVE-2026-18679 | NONE | — | 2026-08-12 | When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled, and the … | |
| CVE-2026-18433 | MEDIUM | Patched | 4.3 | 2026-08-12 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authen… |
| CVE-2026-18150 | MEDIUM | 4.3 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition. | |
| CVE-2026-18148 | MEDIUM | 4.3 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to inject arbitrary content into Navigator log files due to improper output neutralization for logs. | |
| CVE-2026-18099 | HIGH | 8.9 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to improper neutralization of user-controlled input. | |
| CVE-2026-17642 | HIGH | 8.8 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| CVE-2026-17445 | HIGH | 8.2 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of an attacker-supplied user profile name. | |
| CVE-2026-17417 | HIGH | 8.8 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metacharacters. | |
| CVE-2026-17111 | HIGH | 7.6 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modi… | |
| CVE-2026-17083 | CRITICAL | 9.8 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow. | |
| CVE-2026-17082 | HIGH | 8.8 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of a client-supplied profile name. | |
| CVE-2026-16494 | HIGH | Patched | 7.1 | 2026-08-12 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authen… |
| CVE-2026-15217 | HIGH | Patched | 8.7 | 2026-08-12 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions coul… |
| CVE-2026-15216 | HIGH | Patched | 8.7 | 2026-08-12 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions coul… |
| CVE-2026-13361 | HIGH | Patched | 8.8 | 2026-08-12 | IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field. |
| CVE-2026-13267 | HIGH | Patched | 8.1 | 2026-08-12 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow… |