Search
283 CVEs · published 2026-08-04 to 2026-08-04
CVEs (283)
Showing 1–25 of 283
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64565 | NONE | — | 2026-08-04 | In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() The `ims_pcu_process_data()` proce… | |
| CVE-2026-11836 | NONE | — | 2026-08-04 | Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to th… | |
| CVE-2026-66884 | NONE | Patched | — | 2026-08-04 | Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module) allows an attacker to make a victim's browser c… |
| CVE-2026-18817 | LOW | 2.2 | 2026-08-04 | A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api… | |
| CVE-2026-18739 | LOW | 2.5 | 2026-08-04 | A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through … | |
| CVE-2026-16070 | LOW | Patched | 2.7 | 2026-08-04 | The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request p… |
| CVE-2026-70483 | LOW | Patched | 3.1 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks … |
| CVE-2026-18790 | LOW | 3.3 | 2026-08-04 | A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse of the file src/ClientServer/fr… | |
| CVE-2026-68744 | LOW | 3.3 | 2026-08-04 | A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet wh… | |
| CVE-2026-16068 | LOW | Patched | 3.5 | 2026-08-04 | The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data before outputting it… |
| CVE-2026-11366 | LOW | Patched | 3.7 | 2026-08-04 | The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPres… |
| CVE-2026-18569 | LOW | 3.7 | 2026-08-04 | A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authenticatio… | |
| CVE-2026-58044 | LOW | 3.7 | 2026-08-04 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` he… | |
| CVE-2026-16791 | LOW | 3.9 | 2026-08-04 | A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite o… | |
| CVE-2026-70591 | MEDIUM | Patched | 4.1 | 2026-08-04 | Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform … |
| CVE-2026-70480 | MEDIUM | Patched | 4.1 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open WebUI renders vega and vega-lite fenced code blocks in … |
| CVE-2026-18819 | MEDIUM | 4.3 | 2026-08-04 | A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation le… | |
| CVE-2026-70488 | MEDIUM | Patched | 4.3 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the know… |
| CVE-2026-70484 | MEDIUM | Patched | 4.3 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-s… |
| CVE-2026-16295 | MEDIUM | Patched | 4.3 | 2026-08-04 | The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch paths, allowing any authenticated user such as a Subs… |
| CVE-2026-16546 | MEDIUM | Patched | 4.3 | 2026-08-04 | The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that the RSVP being r… |
| CVE-2026-16035 | MEDIUM | Patched | 4.3 | 2026-08-04 | The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling us… |
| CVE-2026-16056 | MEDIUM | Patched | 4.3 | 2026-08-04 | The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscribe… |
| CVE-2026-12698 | MEDIUM | Patched | 4.3 | 2026-08-04 | The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-leve… |
| CVE-2026-18721 | MEDIUM | 4.3 | 2026-08-04 | A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file /user/sso/apiLogin of the component SSO API Login. … |