Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

283 CVEs · published 2026-08-04 to 2026-08-04

CVEs (283)

Showing 1–25 of 283

CVE ID Severity Patch CVSS Published Description
CVE-2026-64633 NONE — 2026-08-04 A vulnerability allowing remote unauthenticated code execution on the agent host.
CVE-2026-70554 CRITICAL 9.8 2026-08-04 MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in …
CVE-2026-66902 CRITICAL Patched 9.8 2026-08-04 Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable subclass reads credential_…
CVE-2026-45538 CRITICAL 9.8 2026-08-04 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longer than 255 bytes causes…
CVE-2026-70553 CRITICAL 9.8 2026-08-04 MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by sub…
CVE-2026-70552 CRITICAL 9.8 2026-08-04 MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints b…
CVE-2026-69703 CRITICAL 9.8 2026-08-04 Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass sessio…
CVE-2026-49435 CRITICAL 9.8 2026-08-04 Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execut…
CVE-2026-0163 CRITICAL 9.8 2026-08-04 In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execu…
CVE-2017-20241 CRITICAL Patched 9.8 2026-08-04 Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoi…
CVE-2017-20242 CRITICAL Patched 9.8 2026-08-04 Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpo…
CVE-2026-24254 CRITICAL Patched 9.8 2026-08-04 NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vuln…
CVE-2026-63455 CRITICAL 9.8 2026-08-04 Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechani…
CVE-2026-63456 CRITICAL 9.8 2026-08-04 Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechani…
CVE-2025-29296 CRITICAL 9.8 2026-08-04 H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100…
CVE-2026-69098 CRITICAL 9.8 2026-08-04 kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary P…
CVE-2026-61514 CRITICAL 9.8 2026-08-04 Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sendi…
CVE-2026-61515 CRITICAL 9.8 2026-08-04 Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating s…
CVE-2026-15721 CRITICAL Patched 9.8 2026-08-04 Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This iss…
CVE-2026-14175 CRITICAL Patched 9.8 2026-08-04 Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell …
CVE-2026-64564 CRITICAL 9.8 2026-08-04 In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the tran…
CVE-2026-16618 CRITICAL 9.8 2026-08-04 The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supp…
CVE-2026-18685 CRITICAL 9.8 2026-08-04 A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such m…
CVE-2026-18686 CRITICAL 9.8 2026-08-04 A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC W…
CVE-2026-25289 CRITICAL 9.6 2026-08-04 Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.