Search
616 CVEs · published 2026-08-13 to 2026-08-13
CVEs (616, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 616 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-16770 | CRITICAL | 9.8 | 2026-08-13 | PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, the constructo… | |
| CVE-2026-17431 | MEDIUM | 6.1 | 2026-08-13 | PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for. to_pdf read… | |
| CVE-2026-46382 | NONE | — | 2026-08-13 | The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local URI can be made to be fe… | |
| CVE-2026-46688 | NONE | — | 2026-08-13 | The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, an unauthenticated request can be made to redirect the… | |
| CVE-2026-48791 | LOW | Patched | 2.0 | 2026-08-13 | sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) a… |
| CVE-2026-49473 | HIGH | Patched | 8.8 | 2026-08-13 | @cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to … |
| CVE-2026-49819 | CRITICAL | 9.8 | 2026-08-13 | UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend… | |
| CVE-2026-50544 | MEDIUM | 6.3 | 2026-08-13 | NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at `src/… | |
| CVE-2026-0289 | NONE | — | 2026-08-13 | A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls. | |
| CVE-2026-0290 | NONE | — | 2026-08-13 | An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data. | |
| CVE-2026-0291 | NONE | — | 2026-08-13 | An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged us… | |
| CVE-2026-0292 | NONE | — | 2026-08-13 | An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspecti… | |
| CVE-2026-0293 | NONE | — | 2026-08-13 | A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling … | |
| CVE-2026-0294 | NONE | — | 2026-08-13 | A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated… | |
| CVE-2026-0295 | NONE | — | 2026-08-13 | A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The… | |
| CVE-2026-0296 | NONE | — | 2026-08-13 | Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercep… | |
| CVE-2026-0297 | NONE | — | 2026-08-13 | A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system pr… | |
| CVE-2026-0298 | NONE | — | 2026-08-13 | An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices … | |
| CVE-2026-0299 | NONE | — | 2026-08-13 | Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, … | |
| CVE-2026-0301 | HIGH | Patched | 7.5 | 2026-08-13 | An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain se… |
| CVE-2026-18728 | MEDIUM | 6.5 | 2026-08-13 | A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing,… | |
| CVE-2026-19135 | MEDIUM | Patched | 5.4 | 2026-08-13 | A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Mea… |
| CVE-2026-19182 | MEDIUM | Patched | 4.3 | 2026-08-13 | An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, o… |
| CVE-2026-72506 | MEDIUM | 5.4 | 2026-08-13 | VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnera… | |
| CVE-2026-13328 | MEDIUM | Patched | 5.3 | 2026-08-13 | The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenti… |