Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

283 CVEs · published 2026-08-04 to 2026-08-04

EOL hidden · Show all products

CVEs (283)

Showing 1–25 of 283

CVE ID Severity Patch CVSS Published Description
CVE-2026-45537 CRITICAL Patched 9.1 2026-08-04 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI comp…
CVE-2026-18819 MEDIUM 4.3 2026-08-04 A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation le…
CVE-2026-18818 MEDIUM 6.3 2026-08-04 A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views.py of the component Su…
CVE-2026-70620 MEDIUM 6.8 2026-08-04 Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network re…
CVE-2026-70619 HIGH 8.8 2026-08-04 Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuratio…
CVE-2026-70594 MEDIUM Patched 6.7 2026-08-04 Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixati…
CVE-2026-70593 MEDIUM Patched 6.6 2026-08-04 Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads director…
CVE-2026-70592 MEDIUM Patched 5.5 2026-08-04 Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the dat…
CVE-2026-70591 MEDIUM Patched 4.1 2026-08-04 Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform …
CVE-2026-70590 MEDIUM Patched 4.8 2026-08-04 Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. …
CVE-2026-70589 MEDIUM Patched 4.8 2026-08-04 Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. T…
CVE-2026-67862 HIGH 7.5 2026-08-04 open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attacker to cause a denial of…
CVE-2026-67861 HIGH 7.5 2026-08-04 An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component
CVE-2026-67860 HIGH 7.5 2026-08-04 open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend.
CVE-2026-67859 HIGH 7.5 2026-08-04 Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.
CVE-2026-67858 HIGH 7.5 2026-08-04 Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauth…
CVE-2026-67857 HIGH 7.5 2026-08-04 open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.
CVE-2026-67856 HIGH 7.5 2026-08-04 An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, Tran…
CVE-2026-67855 HIGH 7.5 2026-08-04 open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker t…
CVE-2026-52370 MEDIUM 6.1 2026-08-04 A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim…
CVE-2026-51144 MEDIUM 6.1 2026-08-04 Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via the Role Name, First N…
CVE-2026-45103 HIGH Patched 7.5 2026-08-04 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Content-Length hea…
CVE-2026-45100 CRITICAL Patched 9.1 2026-08-04 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in the {s.b64encode} strin…
CVE-2026-45084 NONE Patched — 2026-08-04 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the presence module. When t…
CVE-2026-18817 LOW 2.2 2026-08-04 A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api…