Search
283 CVEs · published 2026-08-04 to 2026-08-04
CVEs (283)
Showing 1–25 of 283
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-20241 | CRITICAL | Patched | 9.8 | 2026-08-04 | Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoi… |
| CVE-2017-20242 | CRITICAL | Patched | 9.8 | 2026-08-04 | Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpo… |
| CVE-2025-29296 | CRITICAL | 9.8 | 2026-08-04 | H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100… | |
| CVE-2026-0163 | CRITICAL | 9.8 | 2026-08-04 | In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execu… | |
| CVE-2026-10032 | NONE | — | 2026-08-04 | The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript… | |
| CVE-2026-10050 | CRITICAL | Patched | 9.1 | 2026-08-04 | In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HT… |
| CVE-2026-10526 | MEDIUM | Patched | 5.8 | 2026-08-04 | The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenti… |
| CVE-2026-10709 | HIGH | 7.8 | 2026-08-04 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A m… | |
| CVE-2026-10710 | HIGH | 7.8 | 2026-08-04 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can… | |
| CVE-2026-11366 | LOW | Patched | 3.7 | 2026-08-04 | The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPres… |
| CVE-2026-11368 | HIGH | Patched | 7.1 | 2026-08-04 | The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data… |
| CVE-2026-11835 | NONE | — | 2026-08-04 | Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mode allows a compromised… | |
| CVE-2026-11836 | NONE | — | 2026-08-04 | Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to th… | |
| CVE-2026-12698 | MEDIUM | Patched | 4.3 | 2026-08-04 | The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-leve… |
| CVE-2026-13227 | NONE | Patched | — | 2026-08-04 | An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doct… |
| CVE-2026-13229 | NONE | — | 2026-08-04 | Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint. | |
| CVE-2026-14175 | CRITICAL | Patched | 9.8 | 2026-08-04 | Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell … |
| CVE-2026-14192 | MEDIUM | Patched | 5.4 | 2026-08-04 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human… |
| CVE-2026-14194 | MEDIUM | Patched | 6.5 | 2026-08-04 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resou… |
| CVE-2026-14202 | MEDIUM | Patched | 5.3 | 2026-08-04 | Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue a… |
| CVE-2026-14219 | MEDIUM | Patched | 5.4 | 2026-08-04 | URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing. This… |
| CVE-2026-14337 | NONE | — | 2026-08-04 | Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged us… | |
| CVE-2026-14465 | MEDIUM | Patched | 6.5 | 2026-08-04 | Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Re… |
| CVE-2026-14804 | CRITICAL | Patched | 9.1 | 2026-08-04 | Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within… |
| CVE-2026-14816 | MEDIUM | Patched | 6.5 | 2026-08-04 | The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices… |