Search
616 CVEs · published 2026-08-13 to 2026-08-13
CVEs (616, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 201–225 of 616 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-73037 | MEDIUM | 6.1 | 2026-08-13 | Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without escaping into HTML and … | |
| CVE-2026-72777 | HIGH | 8.6 | 2026-08-13 | Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string p… | |
| CVE-2026-18071 | HIGH | 7.8 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege management. | |
| CVE-2026-17220 | HIGH | 8.2 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow. | |
| CVE-2026-17197 | HIGH | 8.1 | 2026-08-13 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity. | |
| CVE-2026-73649 | CRITICAL | Patched | 9.8 | 2026-08-13 | Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and p… |
| CVE-2026-73648 | NONE | Patched | — | 2026-08-13 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elemen… |
| CVE-2026-73647 | MEDIUM | Patched | 5.6 | 2026-08-13 | Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursiv… |
| CVE-2026-73645 | NONE | Patched | — | 2026-08-13 | OpenZeppelin Confidential Contracts is an experimental library for developing applications on the Zama fhEVM. Prior to 0.3.1, the ERC7984 contract tracked confidential tota… |
| CVE-2026-73644 | CRITICAL | Patched | 9.6 | 2026-08-13 | OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensio… |
| CVE-2026-73643 | HIGH | Patched | 7.5 | 2026-08-13 | js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponential time when an application calls load() or loadAll(… |
| CVE-2026-73569 | NONE | Patched | — | 2026-08-13 | fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes … |
| CVE-2026-73568 | HIGH | 7.5 | 2026-08-13 | py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads … | |
| CVE-2026-73567 | CRITICAL | Patched | 9.1 | 2026-08-13 | sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() pa… |
| CVE-2026-73566 | HIGH | Patched | 7.5 | 2026-08-13 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry… |
| CVE-2026-73565 | MEDIUM | Patched | 5.3 | 2026-08-13 | @hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route with a missing or malfor… |
| CVE-2026-73564 | NONE | Patched | — | 2026-08-13 | frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by adding 4 to an attacker-… |
| CVE-2026-73563 | MEDIUM | Patched | 4.7 | 2026-08-13 | Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the… |
| CVE-2026-73562 | MEDIUM | Patched | 6.5 | 2026-08-13 | Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update su… |
| CVE-2026-73561 | HIGH | Patched | 7.5 | 2026-08-13 | Hub is a Node.js WebSocket server and client with added features. Prior to 0.2.16, every incoming unauthenticated WebSocket connection triggers loadDefaultConnectionEventLi… |
| CVE-2026-72741 | HIGH | 8.1 | 2026-08-13 | Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resou… | |
| CVE-2026-67614 | CRITICAL | Patched | 9.8 | 2026-08-13 | CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid au… |
| CVE-2026-67613 | MEDIUM | Patched | 4.9 | 2026-08-13 | CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying uns… |
| CVE-2026-19730 | MEDIUM | 4.2 | 2026-08-13 | The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (co… | |
| CVE-2026-18428 | HIGH | 8.8 | 2026-08-13 | A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbit… |