Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

442 CVEs · published 2026-08-12 to 2026-08-12

CVEs (442)

Showing 1–25 of 442

CVE ID Severity Patch CVSS Published Description
CVE-2026-9318 MEDIUM 5.4 2026-08-12 tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedd…
CVE-2026-8667 MEDIUM Patched 4.3 2026-08-12 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions cou…
CVE-2026-7427 MEDIUM Patched 5.3 2026-08-12 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions coul…
CVE-2026-7366 MEDIUM Patched 4.2 2026-08-12 IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condi…
CVE-2026-73519 CRITICAL Patched 9.8 2026-08-12 WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauth…
CVE-2026-73501 CRITICAL Patched 9.1 2026-08-12 kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil Authentic…
CVE-2026-73500 NONE Patched — 2026-08-12 etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listen…
CVE-2026-73499 NONE Patched — 2026-08-12 etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact ke…
CVE-2026-73498 HIGH Patched 7.7 2026-08-12 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplie…
CVE-2026-73495 HIGH Patched 7.4 2026-08-12 blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body trail…
CVE-2026-73493 HIGH Patched 7.5 2026-08-12 Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incom…
CVE-2026-73492 NONE Patched — 2026-08-12 Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.all…
CVE-2026-73491 NONE Patched — 2026-08-12 Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.all…
CVE-2026-73490 MEDIUM Patched 4.7 2026-08-12 Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies …
CVE-2026-73434 MEDIUM Patched 6.1 2026-08-12 A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated …
CVE-2026-73433 MEDIUM Patched 6.6 2026-08-12 A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length cou…
CVE-2026-73432 NONE — 2026-08-12 Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization functionality. Remote instance addresses were valida…
CVE-2026-73431 NONE — 2026-08-12 Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activation and recovery links were generated using sta…
CVE-2026-73430 MEDIUM Patched 5.3 2026-08-12 Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of service by sending SSH_MSG_KEX_ECDH_INIT with a 32-byte al…
CVE-2026-73429 MEDIUM Patched 5.3 2026-08-12 Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a malformed KEX_ECDH_REPLY containing a server ep…
CVE-2026-73427 NONE Patched — 2026-08-12 Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cross-site scripting when a crafted application/x-trix-…
CVE-2026-73425 LOW Patched 3.7 2026-08-12 Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remotePatterns entry into a regular expression written t…
CVE-2026-73423 NONE Patched — 2026-08-12 Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline installs security.checkOrigin only through the middleware()…
CVE-2026-73422 NONE Patched — 2026-08-12 Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS generator interpolates animation properties into an in…
CVE-2026-73419 MEDIUM Patched 6.8 2026-08-12 NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, no…