Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

442 CVEs · published 2026-08-12 to 2026-08-12

EOL hidden · Show all products

CVEs (442)

Showing 1–25 of 442

CVE ID Severity Patch CVSS Published Description
CVE-2026-71194 MEDIUM Patched 6.8 2026-08-12 In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exis…
CVE-2026-71193 CRITICAL Patched 9.6 2026-08-12 In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authent…
CVE-2026-49481 CRITICAL 9.6 2026-08-12 UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of u…
CVE-2026-47718 NONE — 2026-08-12 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read…
CVE-2026-47717 HIGH 7.5 2026-08-12 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuratio…
CVE-2026-15424 NONE — 2026-08-12 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-15141 NONE — 2026-08-12 The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer…
CVE-2026-7366 MEDIUM Patched 4.2 2026-08-12 IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condi…
CVE-2026-73519 CRITICAL Patched 9.8 2026-08-12 WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauth…
CVE-2026-73501 CRITICAL Patched 9.1 2026-08-12 kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil Authentic…
CVE-2026-73500 NONE Patched — 2026-08-12 etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listen…
CVE-2026-73499 NONE Patched — 2026-08-12 etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact ke…
CVE-2026-73498 HIGH Patched 7.7 2026-08-12 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplie…
CVE-2026-73495 HIGH Patched 7.4 2026-08-12 blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body trail…
CVE-2026-73493 HIGH Patched 7.5 2026-08-12 Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incom…
CVE-2026-73492 NONE Patched — 2026-08-12 Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.all…
CVE-2026-71846 MEDIUM 6.5 2026-08-12 A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code…
CVE-2026-71473 HIGH 8.5 2026-08-12 A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to…
CVE-2026-71471 CRITICAL 9.0 2026-08-12 A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), c…
CVE-2026-71469 HIGH 7.5 2026-08-12 A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent …
CVE-2026-19003 HIGH 7.8 2026-08-12 A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated…
CVE-2026-18750 MEDIUM 5.3 2026-08-12 vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belong…
CVE-2026-18749 CRITICAL 9.8 2026-08-12 The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been mar…
CVE-2026-18744 MEDIUM 6.5 2026-08-12 Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func only checks _is_my_case, …
CVE-2026-18727 MEDIUM 6.5 2026-08-12 A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for …