Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

283 CVEs · published 2026-08-04 to 2026-08-04

CVEs (283)

Showing 151–175 of 283

CVE ID Severity Patch CVSS Published Description
CVE-2026-24084 HIGH 7.5 2026-08-04 Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
CVE-2026-24083 HIGH 7.8 2026-08-04 Memory Corruption while processing IOCTL device driver requests with invalid arguments.
CVE-2026-24080 HIGH 7.8 2026-08-04 Memory Corruption when handling malformed request parameters in the fingerprint TA.
CVE-2026-24079 HIGH 8.1 2026-08-04 Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
CVE-2026-24078 MEDIUM 6.5 2026-08-04 Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVE-2026-24077 MEDIUM 6.5 2026-08-04 Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
CVE-2026-24076 MEDIUM 6.7 2026-08-04 Memory Corruption when processing registry values with incorrect types using a direct query method.
CVE-2026-21366 HIGH 7.8 2026-08-04 Memory corruption while processing a packet with a size close to the maximum allowed value.
CVE-2026-18801 NONE — 2026-08-04 OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values. An attacker who can create or update a cu…
CVE-2026-18773 MEDIUM 6.3 2026-08-04 A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the compo…
CVE-2026-10032 NONE — 2026-08-04 The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript…
CVE-2026-69251 NONE Patched — 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set …
CVE-2026-69250 NONE Patched — 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/re…
CVE-2026-68494 NONE — 2026-08-04 The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This …
CVE-2026-67618 MEDIUM Patched 6.5 2026-08-04 marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP…
CVE-2026-67200 HIGH 7.5 2026-08-04 Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesystem by including liter…
CVE-2026-67199 MEDIUM 6.5 2026-08-04 Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression con…
CVE-2026-67198 HIGH 7.5 2026-08-04 Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server proce…
CVE-2026-67196 MEDIUM 5.4 2026-08-04 Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inject arbitrary HTML and JavaScript by writing table …
CVE-2026-67195 HIGH 8.8 2026-08-04 Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted …
CVE-2026-61515 CRITICAL 9.8 2026-08-04 Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating s…
CVE-2026-61514 CRITICAL 9.8 2026-08-04 Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sendi…
CVE-2026-18770 HIGH 7.3 2026-08-04 A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the component Py…
CVE-2026-18766 MEDIUM 6.3 2026-08-04 A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of the file /Applications/…
CVE-2026-18650 HIGH Patched 8.8 2026-08-04 Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1.