Search
616 CVEs · published 2026-08-13 to 2026-08-13
CVEs (616, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 616 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8715 | CRITICAL | Patched | 9.6 | 2026-08-13 | Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allo… |
| CVE-2026-73843 | CRITICAL | Patched | 9.6 | 2026-08-13 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs o… |
| CVE-2026-73842 | CRITICAL | Patched | 9.0 | 2026-08-13 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api… |
| CVE-2026-73841 | HIGH | Patched | 8.8 | 2026-08-13 | OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-a… |
| CVE-2026-73840 | MEDIUM | Patched | 5.3 | 2026-08-13 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/opench… |
| CVE-2026-73671 | MEDIUM | 6.1 | 2026-08-13 | Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied v… | |
| CVE-2026-73670 | HIGH | 7.2 | 2026-08-13 | A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a SHOW COLUMNS FROM stat… | |
| CVE-2026-73669 | HIGH | Patched | 7.3 | 2026-08-13 | The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network interfaces without authentication. An unauthenticated attacke… |
| CVE-2026-73667 | HIGH | Patched | 8.8 | 2026-08-13 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-st… |
| CVE-2026-73666 | HIGH | Patched | 8.2 | 2026-08-13 | OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPo… |
| CVE-2026-73665 | NONE | Patched | — | 2026-08-13 | FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies … |
| CVE-2026-73664 | NONE | Patched | — | 2026-08-13 | FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key … |
| CVE-2026-73663 | NONE | Patched | — | 2026-08-13 | FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into t… |
| CVE-2026-73662 | NONE | Patched | — | 2026-08-13 | FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed pl… |
| CVE-2026-73661 | NONE | Patched | — | 2026-08-13 | FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value … |
| CVE-2026-73660 | NONE | Patched | — | 2026-08-13 | FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS destination name that … |
| CVE-2026-73659 | HIGH | Patched | 8.1 | 2026-08-13 | Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app/routes/api.v1.packets.… |
| CVE-2026-73658 | HIGH | Patched | 8.2 | 2026-08-13 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.pres… |
| CVE-2026-73657 | MEDIUM | Patched | 4.2 | 2026-08-13 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp… |
| CVE-2026-73656 | CRITICAL | Patched | 9.9 | 2026-08-13 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls … |
| CVE-2026-73655 | HIGH | Patched | 7.4 | 2026-08-13 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in apps/webapp/app/services/googleAuth.serve… |
| CVE-2026-73654 | HIGH | Patched | 8.5 | 2026-08-13 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the PUT /api/v1/runs/:runId/metadata endpoint passes att… |
| CVE-2026-73653 | CRITICAL | Patched | 9.4 | 2026-08-13 | Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screensho… |
| CVE-2026-73652 | NONE | — | 2026-08-13 | vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allow… | |
| CVE-2026-73651 | MEDIUM | Patched | 5.7 | 2026-08-13 | TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server, Oracle, and other databases. Prior to versions 0.3.31 a… |