Search
442 CVEs · published 2026-08-12 to 2026-08-12
CVEs (442)
Showing 201–225 of 442
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-16627 | HIGH | Patched | 7.7 | 2026-08-12 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with de… |
| CVE-2026-15423 | HIGH | Patched | 8.5 | 2026-08-12 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions coul… |
| CVE-2026-73297 | NONE | Patched | — | 2026-08-12 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security.py did not block NAT64… |
| CVE-2026-73296 | CRITICAL | Patched | 9.4 | 2026-08-12 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_s… |
| CVE-2026-73295 | MEDIUM | Patched | 5.4 | 2026-08-12 | Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascript… |
| CVE-2026-73240 | CRITICAL | Patched | 9.8 | 2026-08-12 | Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to vers… |
| CVE-2026-73239 | MEDIUM | Patched | 6.5 | 2026-08-12 | Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Us… |
| CVE-2026-73238 | MEDIUM | Patched | 6.1 | 2026-08-12 | XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue. |
| CVE-2026-73237 | MEDIUM | Patched | 6.1 | 2026-08-12 | XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1. Users are recommended to upgrade to version 1.19.1, … |
| CVE-2026-48554 | HIGH | Patched | 7.5 | 2026-08-12 | Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through … |
| CVE-2026-48553 | HIGH | Patched | 7.5 | 2026-08-12 | Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote … |
| CVE-2026-48552 | MEDIUM | Patched | 5.4 | 2026-08-12 | Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored… |
| CVE-2026-48551 | HIGH | Patched | 7.4 | 2026-08-12 | Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can sup… |
| CVE-2026-48550 | MEDIUM | Patched | 6.1 | 2026-08-12 | Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote a… |
| CVE-2026-18847 | HIGH | 8.8 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i. | |
| CVE-2026-18683 | HIGH | 8.8 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands. | |
| CVE-2026-18499 | HIGH | Patched | 8.1 | 2026-08-12 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives. |
| CVE-2026-18246 | LOW | 3.0 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to an interpretation conflict in the multipart parser. | |
| CVE-2026-18144 | MEDIUM | 4.3 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization. | |
| CVE-2026-18106 | MEDIUM | 4.3 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-supplied path input. | |
| CVE-2026-18098 | HIGH | 8.1 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise system integrity due to an XML injection flaw. | |
| CVE-2026-17095 | HIGH | 8.3 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to unsafe reflection. | |
| CVE-2026-17094 | MEDIUM | 4.3 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal vulnerability. | |
| CVE-2026-16694 | MEDIUM | 6.4 | 2026-08-12 | IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI … | |
| CVE-2026-73325 | HIGH | Patched | 7.8 | 2026-08-12 | Fujitsu Research's OneCompression library before 1.2.1 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a craft… |