Search
616 CVEs · published 2026-08-13 to 2026-08-13
CVEs (616, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 616 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-25765 | HIGH | 7.5 | 2026-08-13 | ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id p… | |
| CVE-2022-4993 | CRITICAL | 9.1 | 2026-08-13 | HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message t… | |
| CVE-2024-58374 | HIGH | 7.5 | 2026-08-13 | Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected … | |
| CVE-2025-52640 | MEDIUM | 4.7 | 2026-08-13 | HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the stora… | |
| CVE-2025-62314 | MEDIUM | 5.6 | 2026-08-13 | HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate r… | |
| CVE-2025-62315 | LOW | 3.4 | 2026-08-13 | HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by th… | |
| CVE-2025-62318 | LOW | 3.7 | 2026-08-13 | HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be c… | |
| CVE-2026-0289 | NONE | — | 2026-08-13 | A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls. | |
| CVE-2026-0290 | NONE | — | 2026-08-13 | An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data. | |
| CVE-2026-0291 | NONE | — | 2026-08-13 | An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged us… | |
| CVE-2026-0292 | NONE | — | 2026-08-13 | An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspecti… | |
| CVE-2026-0293 | NONE | — | 2026-08-13 | A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling … | |
| CVE-2026-0294 | NONE | — | 2026-08-13 | A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated… | |
| CVE-2026-0295 | NONE | — | 2026-08-13 | A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The… | |
| CVE-2026-0296 | NONE | — | 2026-08-13 | Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercep… | |
| CVE-2026-0297 | NONE | — | 2026-08-13 | A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system pr… | |
| CVE-2026-0298 | NONE | — | 2026-08-13 | An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices … | |
| CVE-2026-0299 | NONE | — | 2026-08-13 | Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, … | |
| CVE-2026-0301 | HIGH | Patched | 7.5 | 2026-08-13 | An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain se… |
| CVE-2026-10571 | MEDIUM | Patched | 5.7 | 2026-08-13 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative… |
| CVE-2026-11840 | HIGH | Patched | 8.8 | 2026-08-13 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection. |
| CVE-2026-11970 | NONE | — | 2026-08-13 | This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758. | |
| CVE-2026-12036 | HIGH | 7.1 | 2026-08-13 | An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user t… | |
| CVE-2026-12236 | MEDIUM | 6.5 | 2026-08-13 | The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By Type Response received from a remote GATT server du… | |
| CVE-2026-12263 | HIGH | Patched | 8.8 | 2026-08-13 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SA… |