Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

283 CVEs · published 2026-08-04 to 2026-08-04

CVEs (283)

Showing 1–25 of 283

CVE ID Severity Patch CVSS Published Description
CVE-2017-20241 CRITICAL Patched 9.8 2026-08-04 Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoi…
CVE-2017-20242 CRITICAL Patched 9.8 2026-08-04 Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpo…
CVE-2025-29296 CRITICAL 9.8 2026-08-04 H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100…
CVE-2026-0163 CRITICAL 9.8 2026-08-04 In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execu…
CVE-2026-10032 NONE — 2026-08-04 The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript…
CVE-2026-10050 CRITICAL Patched 9.1 2026-08-04 In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HT…
CVE-2026-10526 MEDIUM Patched 5.8 2026-08-04 The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenti…
CVE-2026-10709 HIGH 7.8 2026-08-04 A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A m…
CVE-2026-10710 HIGH 7.8 2026-08-04 A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can…
CVE-2026-11366 LOW Patched 3.7 2026-08-04 The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPres…
CVE-2026-11368 HIGH Patched 7.1 2026-08-04 The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data…
CVE-2026-11835 NONE — 2026-08-04 Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mode allows a compromised…
CVE-2026-11836 NONE — 2026-08-04 Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to th…
CVE-2026-12698 MEDIUM Patched 4.3 2026-08-04 The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-leve…
CVE-2026-13227 NONE Patched &mdash; 2026-08-04 An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doct&hellip;
CVE-2026-13229 NONE &mdash; 2026-08-04 Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.
CVE-2026-14175 CRITICAL Patched 9.8 2026-08-04 Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell &hellip;
CVE-2026-14192 MEDIUM Patched 5.4 2026-08-04 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human&hellip;
CVE-2026-14194 MEDIUM Patched 6.5 2026-08-04 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resou&hellip;
CVE-2026-14202 MEDIUM Patched 5.3 2026-08-04 Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue a&hellip;
CVE-2026-14219 MEDIUM Patched 5.4 2026-08-04 URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing. This&hellip;
CVE-2026-14337 NONE &mdash; 2026-08-04 Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged us&hellip;
CVE-2026-14465 MEDIUM Patched 6.5 2026-08-04 Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Re&hellip;
CVE-2026-14804 CRITICAL Patched 9.1 2026-08-04 Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within&hellip;
CVE-2026-14816 MEDIUM Patched 6.5 2026-08-04 The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices&hellip;