Search
1,425 CVEs · published 2026-08-18 to 2026-08-18
CVEs (1,425, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 1,425 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43716 | NONE | — | 2026-08-18 | Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB. | |
| CVE-2021-43717 | NONE | — | 2026-08-18 | An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can access the projector using hard-c… | |
| CVE-2021-43718 | NONE | — | 2026-08-18 | An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malicious user cause a Denial of Service via specially cra… | |
| CVE-2024-14045 | MEDIUM | 6.3 | 2026-08-18 | A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy… | |
| CVE-2024-14046 | MEDIUM | 6.3 | 2026-08-18 | A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController of the file grails-app/controllers/org/pih/warehouse… | |
| CVE-2025-9210 | HIGH | Patched | 8.1 | 2026-08-18 | Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via t… |
| CVE-2025-9211 | MEDIUM | Patched | 6.7 | 2026-08-18 | Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges … |
| CVE-2026-11801 | HIGH | 7.5 | 2026-08-18 | The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not pro… | |
| CVE-2026-1199 | NONE | — | 2026-08-18 | Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneous… | |
| CVE-2026-12520 | MEDIUM | 6.4 | 2026-08-18 | The Sierra Wireless HL7800 cellular modem driver (drivers/modem/vendor_standalone/hl7800.c, located at drivers/modem/hl7800.c in v4.4.0 and earlier) parses AT responses wit… | |
| CVE-2026-12564 | CRITICAL | 9.6 | 2026-08-18 | A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod… | |
| CVE-2026-12631 | MEDIUM | 6.5 | 2026-08-18 | The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscall in include/zephyr/kernel.h) through thread_obj_validate() in kernel/th… | |
| CVE-2026-12632 | MEDIUM | 6.5 | 2026-08-18 | Zephyr's Precision Time Protocol receive handler ptp_msg_post_recv() in subsys/net/lib/ptp/msg.c takes the 4-bit message type straight off the wire via ptp_msg_type() (msg-… | |
| CVE-2026-15315 | NONE | — | 2026-08-18 | Tapo C200 v5 contains an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses … | |
| CVE-2026-15316 | NONE | — | 2026-08-18 | An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5. An attacker can send … | |
| CVE-2026-15371 | HIGH | 8.1 | 2026-08-18 | Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked in the GUI.The code doe… | |
| CVE-2026-15571 | HIGH | 7.3 | 2026-08-18 | A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used … | |
| CVE-2026-15585 | HIGH | Patched | 7.5 | 2026-08-18 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox… |
| CVE-2026-15748 | CRITICAL | 9.8 | 2026-08-18 | The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is d… | |
| CVE-2026-15806 | NONE | — | 2026-08-18 | The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL sch… | |
| CVE-2026-16309 | MEDIUM | Patched | 5.3 | 2026-08-18 | Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly Constrained by ACLs. … |
| CVE-2026-16732 | MEDIUM | Patched | 6.1 | 2026-08-18 | fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 added a guard on the forwarded-header reads used to derive the request host,… |
| CVE-2026-17084 | NONE | — | 2026-08-18 | The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Un… | |
| CVE-2026-17106 | NONE | — | 2026-08-18 | The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destin… | |
| CVE-2026-18392 | NONE | — | 2026-08-18 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have be… |