Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

616 CVEs · published 2026-08-13 to 2026-08-13

EOL hidden · Show all products

CVEs (616, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 616 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-3883 NONE — 2026-08-13 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-19756 MEDIUM 6.3 2026-08-13 A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the component Code Generator. Su…
CVE-2026-19753 HIGH 7.3 2026-08-13 A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the compon…
CVE-2026-18532 NONE — 2026-08-13 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-73843 CRITICAL Patched 9.6 2026-08-13 OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs o…
CVE-2026-73842 CRITICAL Patched 9.0 2026-08-13 OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api…
CVE-2026-73841 HIGH Patched 8.8 2026-08-13 OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-a…
CVE-2026-73840 MEDIUM Patched 5.3 2026-08-13 OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/opench…
CVE-2026-73667 HIGH Patched 8.8 2026-08-13 OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-st…
CVE-2026-73666 HIGH Patched 8.2 2026-08-13 OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPo…
CVE-2026-73665 NONE Patched — 2026-08-13 FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies …
CVE-2026-73664 NONE Patched — 2026-08-13 FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key …
CVE-2026-73663 NONE Patched — 2026-08-13 FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into t…
CVE-2026-73662 NONE Patched — 2026-08-13 FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed pl…
CVE-2026-73661 NONE Patched — 2026-08-13 FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value …
CVE-2026-73660 NONE Patched — 2026-08-13 FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS destination name that …
CVE-2026-73659 HIGH Patched 8.1 2026-08-13 Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app/routes/api.v1.packets.…
CVE-2026-73658 HIGH Patched 8.2 2026-08-13 Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.pres…
CVE-2026-73657 MEDIUM Patched 4.2 2026-08-13 Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp…
CVE-2026-73489 MEDIUM Patched 4.3 2026-08-13 Russh is a Rust SSH client & server library. Prior to 0.62.4, an authenticated SSH client can cause a denial of service by sending a pty-req channel request with more than …
CVE-2026-73479 MEDIUM 5.0 2026-08-13 dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attackers can craft file names containing OSC/CSI escape …
CVE-2026-73428 MEDIUM Patched 4.6 2026-08-13 Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to stored cross-site scripting when crafted HTML is pasted…
CVE-2026-73421 NONE Patched — 2026-08-13 NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the au…
CVE-2026-73420 NONE Patched — 2026-08-13 NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by the email and magic-link …
CVE-2026-73417 NONE Patched — 2026-08-13 jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLa…