Search
442 CVEs · published 2026-08-12 to 2026-08-12
CVEs (442)
Showing 1–25 of 442
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9318 | MEDIUM | 5.4 | 2026-08-12 | tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedd… | |
| CVE-2026-8667 | MEDIUM | Patched | 4.3 | 2026-08-12 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions cou… |
| CVE-2026-7427 | MEDIUM | Patched | 5.3 | 2026-08-12 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions coul… |
| CVE-2026-7366 | MEDIUM | Patched | 4.2 | 2026-08-12 | IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condi… |
| CVE-2026-73519 | CRITICAL | Patched | 9.8 | 2026-08-12 | WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauth… |
| CVE-2026-73501 | CRITICAL | Patched | 9.1 | 2026-08-12 | kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil Authentic… |
| CVE-2026-73500 | NONE | Patched | — | 2026-08-12 | etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listen… |
| CVE-2026-73499 | NONE | Patched | — | 2026-08-12 | etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact ke… |
| CVE-2026-73498 | HIGH | Patched | 7.7 | 2026-08-12 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplie… |
| CVE-2026-73495 | HIGH | Patched | 7.4 | 2026-08-12 | blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body trail… |
| CVE-2026-73493 | HIGH | Patched | 7.5 | 2026-08-12 | Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incom… |
| CVE-2026-73492 | NONE | Patched | — | 2026-08-12 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.all… |
| CVE-2026-73491 | NONE | Patched | — | 2026-08-12 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.all… |
| CVE-2026-73490 | MEDIUM | Patched | 4.7 | 2026-08-12 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies … |
| CVE-2026-73434 | MEDIUM | Patched | 6.1 | 2026-08-12 | A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated … |
| CVE-2026-73433 | MEDIUM | Patched | 6.6 | 2026-08-12 | A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length cou… |
| CVE-2026-73432 | NONE | — | 2026-08-12 | Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization functionality. Remote instance addresses were valida… | |
| CVE-2026-73431 | NONE | — | 2026-08-12 | Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activation and recovery links were generated using sta… | |
| CVE-2026-73430 | MEDIUM | Patched | 5.3 | 2026-08-12 | Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of service by sending SSH_MSG_KEX_ECDH_INIT with a 32-byte al… |
| CVE-2026-73429 | MEDIUM | Patched | 5.3 | 2026-08-12 | Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a malformed KEX_ECDH_REPLY containing a server ep… |
| CVE-2026-73427 | NONE | Patched | — | 2026-08-12 | Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cross-site scripting when a crafted application/x-trix-… |
| CVE-2026-73425 | LOW | Patched | 3.7 | 2026-08-12 | Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remotePatterns entry into a regular expression written t… |
| CVE-2026-73423 | NONE | Patched | — | 2026-08-12 | Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline installs security.checkOrigin only through the middleware()… |
| CVE-2026-73422 | NONE | Patched | — | 2026-08-12 | Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS generator interpolates animation properties into an in… |
| CVE-2026-73419 | MEDIUM | Patched | 6.8 | 2026-08-12 | NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, no… |