Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

283 CVEs · published 2026-08-04 to 2026-08-04

CVEs (283)

Showing 1–25 of 283

CVE ID Severity Patch CVSS Published Description
CVE-2026-11835 NONE — 2026-08-04 Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mode allows a compromised…
CVE-2026-11836 NONE — 2026-08-04 Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to th…
CVE-2026-18685 CRITICAL 9.8 2026-08-04 A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such m…
CVE-2026-18686 CRITICAL 9.8 2026-08-04 A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC W…
CVE-2026-62870 HIGH 8.8 2026-08-04 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
CVE-2026-65802 HIGH Patched 7.4 2026-08-04 External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
CVE-2026-65804 MEDIUM Patched 6.1 2026-08-04 Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66310 HIGH Patched 7.7 2026-08-04 External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
CVE-2026-66311 MEDIUM Patched 6.2 2026-08-04 Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
CVE-2026-66312 MEDIUM Patched 6.5 2026-08-04 Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
CVE-2026-66313 MEDIUM Patched 6.8 2026-08-04 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
CVE-2026-66314 MEDIUM Patched 6.5 2026-08-04 Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVE-2026-66315 HIGH Patched 7.5 2026-08-04 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-66316 MEDIUM Patched 5.4 2026-08-04 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66317 MEDIUM Patched 5.4 2026-08-04 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
CVE-2026-66318 HIGH Patched 8.1 2026-08-04 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVE-2026-66321 HIGH Patched 7.4 2026-08-04 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-66322 HIGH Patched 7.1 2026-08-04 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66325 MEDIUM Patched 6.1 2026-08-04 Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66326 MEDIUM Patched 6.5 2026-08-04 Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-56845 HIGH 7.5 2026-08-04 An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the …
CVE-2026-56846 HIGH 7.5 2026-08-04 A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js …
CVE-2026-58041 MEDIUM 5.3 2026-08-04 A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it …
CVE-2026-58042 MEDIUM 5.9 2026-08-04 A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records. Repeated triggering of this condition can l…
CVE-2026-58044 LOW 3.7 2026-08-04 A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` he…