Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

442 CVEs · published 2026-08-12 to 2026-08-12

CVEs (442)

Showing 1–25 of 442

CVE ID Severity Patch CVSS Published Description
CVE-2024-27253 CRITICAL 10.0 2026-08-12 IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.
CVE-2026-73299 CRITICAL Patched 10.0 2026-08-12 Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies…
CVE-2026-67282 NONE &mdash; 2026-08-12 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend l&hellip;
CVE-2026-66898 CRITICAL 9.9 2026-08-12 A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup a&hellip;
CVE-2026-73268 CRITICAL 9.9 2026-08-12 A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject&hellip;
CVE-2026-73269 CRITICAL 9.9 2026-08-12 A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creatio&hellip;
CVE-2026-72508 CRITICAL 9.9 2026-08-12 A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to pe&hellip;
CVE-2026-63293 CRITICAL 9.9 2026-08-12 A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archiv&hellip;
CVE-2026-63294 CRITICAL 9.9 2026-08-12 A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup arc&hellip;
CVE-2026-63296 CRITICAL 9.9 2026-08-12 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to&hellip;
CVE-2026-63297 CRITICAL 9.9 2026-08-12 An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during&hellip;
CVE-2026-63298 CRITICAL 9.9 2026-08-12 An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configurat&hellip;
CVE-2026-63299 CRITICAL 9.9 2026-08-12 An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource lim&hellip;
CVE-2026-63300 CRITICAL 9.9 2026-08-12 An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permiss&hellip;
CVE-2026-62420 CRITICAL 9.9 2026-08-12 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When &hellip;
CVE-2026-19656 CRITICAL 9.9 2026-08-12 ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissi&hellip;
CVE-2026-16860 CRITICAL Patched 9.9 2026-08-12 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.
CVE-2026-73294 CRITICAL Patched 9.9 2026-08-12 Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option&hellip;
CVE-2026-73263 CRITICAL Patched 9.9 2026-08-12 Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config&hellip;
CVE-2026-72526 CRITICAL 9.9 2026-08-12 A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom &hellip;
CVE-2026-73519 CRITICAL Patched 9.8 2026-08-12 WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauth&hellip;
CVE-2026-18749 CRITICAL 9.8 2026-08-12 The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been mar&hellip;
CVE-2026-19001 CRITICAL 9.8 2026-08-12 The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a&hellip;
CVE-2026-17083 CRITICAL 9.8 2026-08-12 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
CVE-2026-16956 CRITICAL Patched 9.8 2026-08-12 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.