Search
616 CVEs · published 2026-08-13 to 2026-08-13
EOL hidden · Show all products
CVEs (616, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 616 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-3883 | NONE | — | 2026-08-13 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-19756 | MEDIUM | 6.3 | 2026-08-13 | A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the component Code Generator. Su… | |
| CVE-2026-19753 | HIGH | 7.3 | 2026-08-13 | A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the compon… | |
| CVE-2026-18532 | NONE | — | 2026-08-13 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-73843 | CRITICAL | Patched | 9.6 | 2026-08-13 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs o… |
| CVE-2026-73842 | CRITICAL | Patched | 9.0 | 2026-08-13 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api… |
| CVE-2026-73841 | HIGH | Patched | 8.8 | 2026-08-13 | OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-a… |
| CVE-2026-73840 | MEDIUM | Patched | 5.3 | 2026-08-13 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/opench… |
| CVE-2026-73667 | HIGH | Patched | 8.8 | 2026-08-13 | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-st… |
| CVE-2026-73666 | HIGH | Patched | 8.2 | 2026-08-13 | OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPo… |
| CVE-2026-73665 | NONE | Patched | — | 2026-08-13 | FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies … |
| CVE-2026-73664 | NONE | Patched | — | 2026-08-13 | FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key … |
| CVE-2026-73663 | NONE | Patched | — | 2026-08-13 | FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into t… |
| CVE-2026-73662 | NONE | Patched | — | 2026-08-13 | FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed pl… |
| CVE-2026-73661 | NONE | Patched | — | 2026-08-13 | FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value … |
| CVE-2026-73660 | NONE | Patched | — | 2026-08-13 | FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS destination name that … |
| CVE-2026-73659 | HIGH | Patched | 8.1 | 2026-08-13 | Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app/routes/api.v1.packets.… |
| CVE-2026-73658 | HIGH | Patched | 8.2 | 2026-08-13 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.pres… |
| CVE-2026-73657 | MEDIUM | Patched | 4.2 | 2026-08-13 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp… |
| CVE-2026-73489 | MEDIUM | Patched | 4.3 | 2026-08-13 | Russh is a Rust SSH client & server library. Prior to 0.62.4, an authenticated SSH client can cause a denial of service by sending a pty-req channel request with more than … |
| CVE-2026-73479 | MEDIUM | 5.0 | 2026-08-13 | dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attackers can craft file names containing OSC/CSI escape … | |
| CVE-2026-73428 | MEDIUM | Patched | 4.6 | 2026-08-13 | Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to stored cross-site scripting when crafted HTML is pasted… |
| CVE-2026-73421 | NONE | Patched | — | 2026-08-13 | NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the au… |
| CVE-2026-73420 | NONE | Patched | — | 2026-08-13 | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by the email and magic-link … |
| CVE-2026-73417 | NONE | Patched | — | 2026-08-13 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLa… |