Search
283 CVEs · published 2026-08-04 to 2026-08-04
CVEs (283)
Showing 201–225 of 283
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-15721 | CRITICAL | Patched | 9.8 | 2026-08-04 | Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This iss… |
| CVE-2026-14838 | HIGH | Patched | 7.4 | 2026-08-04 | Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Session Hija… |
| CVE-2026-14804 | CRITICAL | Patched | 9.1 | 2026-08-04 | Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within… |
| CVE-2026-14465 | MEDIUM | Patched | 6.5 | 2026-08-04 | Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Re… |
| CVE-2026-14219 | MEDIUM | Patched | 5.4 | 2026-08-04 | URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing. This… |
| CVE-2026-14202 | MEDIUM | Patched | 5.3 | 2026-08-04 | Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue a… |
| CVE-2026-14194 | MEDIUM | Patched | 6.5 | 2026-08-04 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resou… |
| CVE-2026-14192 | MEDIUM | Patched | 5.4 | 2026-08-04 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human… |
| CVE-2026-14175 | CRITICAL | Patched | 9.8 | 2026-08-04 | Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell … |
| CVE-2026-67243 | HIGH | 7.2 | 2026-08-04 | freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product… | |
| CVE-2026-18759 | NONE | — | 2026-08-04 | The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by AES encryption. Becaus… | |
| CVE-2026-18755 | HIGH | 7.3 | 2026-08-04 | A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing a craf… | |
| CVE-2026-18754 | CRITICAL | 9.1 | 2026-08-04 | The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious act… | |
| CVE-2026-18753 | CRITICAL | 9.1 | 2026-08-04 | The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious act… | |
| CVE-2026-64565 | NONE | — | 2026-08-04 | In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() The `ims_pcu_process_data()` proce… | |
| CVE-2026-64564 | CRITICAL | 9.8 | 2026-08-04 | In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the tran… | |
| CVE-2026-64563 | HIGH | 7.8 | 2026-08-04 | In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() has two restart paths w… | |
| CVE-2026-64562 | HIGH | 8.8 | 2026-08-04 | In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR free_nested() frees the shadow VMCS while vmcs01 still… | |
| CVE-2026-64561 | HIGH | 8.8 | 2026-08-04 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page … | |
| CVE-2026-16623 | HIGH | Patched | 8.0 | 2026-08-04 | The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, allowing a multisite subs… |
| CVE-2026-16618 | CRITICAL | 9.8 | 2026-08-04 | The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supp… | |
| CVE-2026-16548 | MEDIUM | Patched | 6.5 | 2026-08-04 | The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin before 1.8.2 does not validate the type, extension, co… |
| CVE-2026-16547 | MEDIUM | Patched | 5.9 | 2026-08-04 | The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor does it check the capabilit… |
| CVE-2026-16546 | MEDIUM | Patched | 4.3 | 2026-08-04 | The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that the RSVP being r… |
| CVE-2026-16536 | MEDIUM | Patched | 5.3 | 2026-08-04 | The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unaut… |