Search
442 CVEs · published 2026-08-12 to 2026-08-12
CVEs (442)
Showing 151–175 of 442
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-12618 | HIGH | Patched | 7.2 | 2026-08-12 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow… |
| CVE-2026-12359 | HIGH | Patched | 8.1 | 2026-08-12 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow… |
| CVE-2026-12005 | HIGH | Patched | 7.2 | 2026-08-12 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a … |
| CVE-2026-12004 | HIGH | Patched | 8.7 | 2026-08-12 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a … |
| CVE-2026-11937 | LOW | Patched | 3.1 | 2026-08-12 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Sec… |
| CVE-2026-11923 | HIGH | Patched | 7.4 | 2026-08-12 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Pro… |
| CVE-2025-9486 | LOW | Patched | 3.3 | 2026-08-12 | GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could h… |
| CVE-2026-73301 | MEDIUM | Patched | 4.3 | 2026-08-12 | Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/src/api/routes/global/groups.ts omitted auth.builderO… |
| CVE-2026-19311 | HIGH | 8.1 | 2026-08-12 | Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index da… | |
| CVE-2026-18952 | HIGH | 8.1 | 2026-08-12 | Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side … | |
| CVE-2026-18678 | NONE | — | 2026-08-12 | When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverifi… | |
| CVE-2026-18677 | NONE | — | 2026-08-12 | In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-… | |
| CVE-2026-18676 | NONE | — | 2026-08-12 | The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable fr… | |
| CVE-2026-18675 | NONE | — | 2026-08-12 | The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number decodes as a float64 and triggers… | |
| CVE-2026-18673 | NONE | — | 2026-08-12 | When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to all interfaces - forwar… | |
| CVE-2026-8667 | MEDIUM | Patched | 4.3 | 2026-08-12 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions cou… |
| CVE-2026-7427 | MEDIUM | Patched | 5.3 | 2026-08-12 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions coul… |
| CVE-2026-73327 | NONE | — | 2026-08-12 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported behavior is intentional. The update process is designed to write … | |
| CVE-2026-73300 | CRITICAL | Patched | 9.6 | 2026-08-12 | Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution o… |
| CVE-2026-73299 | CRITICAL | Patched | 10.0 | 2026-08-12 | Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies… |
| CVE-2026-73298 | NONE | — | 2026-08-12 | The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service… | |
| CVE-2026-69106 | HIGH | 8.8 | 2026-08-12 | A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content. | |
| CVE-2026-49467 | HIGH | Patched | 8.8 | 2026-08-12 | Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0 allow an attacker to bypass password verification w… |
| CVE-2026-44741 | HIGH | 8.8 | 2026-08-12 | Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date f… | |
| CVE-2026-42018 | HIGH | 7.5 | 2026-08-12 | JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. |