Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

283 CVEs · published 2026-08-04 to 2026-08-04

CVEs (283)

Showing 176–200 of 283

CVE ID Severity Patch CVSS Published Description
CVE-2026-18401 NONE — 2026-08-04 The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An …
CVE-2026-11368 HIGH Patched 7.1 2026-08-04 The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data…
CVE-2026-70368 MEDIUM 6.5 2026-08-04 A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with netw…
CVE-2026-70367 MEDIUM 5.4 2026-08-04 A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intend…
CVE-2026-17070 HIGH Patched 8.8 2026-08-04 Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 be…
CVE-2026-14337 NONE — 2026-08-04 Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged us…
CVE-2026-70373 HIGH 8.8 2026-08-04 Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-controlled request parameters…
CVE-2026-70372 HIGH 8.8 2026-08-04 Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. An authenti…
CVE-2026-70371 HIGH 8.8 2026-08-04 Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Line …
CVE-2026-70370 HIGH 8.8 2026-08-04 Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier posit…
CVE-2026-70369 HIGH 8.8 2026-08-04 Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controlled Filter request parameters directly into WHER…
CVE-2026-63252 HIGH Patched 7.5 2026-08-04 In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote u…
CVE-2026-63248 MEDIUM Patched 6.5 2026-08-04 In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/No…
CVE-2026-62927 HIGH Patched 7.5 2026-08-04 In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an an…
CVE-2026-61387 HIGH Patched 7.5 2026-08-04 In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reser…
CVE-2026-60007 HIGH Patched 7.4 2026-08-04 In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures…
CVE-2026-58080 HIGH Patched 8.2 2026-08-04 In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct…
CVE-2026-18809 MEDIUM Patched 6.5 2026-08-04 Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153.0.3.
CVE-2026-18806 HIGH Patched 7.1 2026-08-04 External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Function…
CVE-2026-10710 HIGH 7.8 2026-08-04 A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can…
CVE-2026-10709 HIGH 7.8 2026-08-04 A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A m…
CVE-2026-66884 NONE Patched — 2026-08-04 Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module) allows an attacker to make a victim's browser c…
CVE-2026-66883 NONE Patched — 2026-08-04 Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize module) renders the user agent session binding inert, re…
CVE-2026-10050 CRITICAL Patched 9.1 2026-08-04 In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HT…
CVE-2026-18772 MEDIUM 6.5 2026-08-04 Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.