Search
1,425 CVEs · published 2026-08-18 to 2026-08-18
EOL hidden · Show all products
CVEs (1,425, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 1,425 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-66591 | MEDIUM | 6.5 | 2026-08-18 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS. This issue a… | |
| CVE-2026-66589 | MEDIUM | 5.4 | 2026-08-18 | Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B2BKing: from n/a … | |
| CVE-2026-27365 | MEDIUM | 5.9 | 2026-08-18 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress PublishPress Series allows Stored XSS. This issue affect… | |
| CVE-2026-73974 | MEDIUM | Patched | 5.5 | 2026-08-18 | linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing help… |
| CVE-2026-73973 | MEDIUM | Patched | 5.5 | 2026-08-18 | Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-fo… |
| CVE-2026-66603 | MEDIUM | 6.5 | 2026-08-18 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Artiss Draft List simple-draft-list allows Stored XSS. This iss… | |
| CVE-2026-66602 | HIGH | 8.8 | 2026-08-18 | Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress … | |
| CVE-2026-62377 | MEDIUM | Patched | 4.3 | 2026-08-18 | libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory() can leave the context… |
| CVE-2026-62292 | NONE | Patched | — | 2026-08-18 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed HEIF image using generic zlib unci full-item compression can cr… |
| CVE-2026-62291 | MEDIUM | Patched | 5.3 | 2026-08-18 | libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image sequence with a 2x2 primary plane and a 256x256 auxiliary alpha plane can… |
| CVE-2026-62289 | MEDIUM | Patched | 4.3 | 2026-08-18 | libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containing a clean aperture box can reduce an image dimension… |
| CVE-2026-53959 | MEDIUM | Patched | 6.5 | 2026-08-18 | 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to enumerate account information for every user throug… |
| CVE-2026-53958 | HIGH | Patched | 7.6 | 2026-08-18 | 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, sso… |
| CVE-2026-52877 | HIGH | Patched | 8.3 | 2026-08-18 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js pass… |
| CVE-2026-52876 | HIGH | Patched | 8.8 | 2026-08-18 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js acc… |
| CVE-2026-52875 | NONE | Patched | — | 2026-08-18 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js tak… |
| CVE-2026-52873 | MEDIUM | Patched | 6.9 | 2026-08-18 | Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index… |
| CVE-2026-52872 | HIGH | Patched | 8.8 | 2026-08-18 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached … |
| CVE-2026-52854 | HIGH | Patched | 8.6 | 2026-08-18 | Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the L… |
| CVE-2026-50191 | HIGH | Patched | 8.8 | 2026-08-18 | 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEna… |
| CVE-2026-50186 | HIGH | Patched | 8.8 | 2026-08-18 | 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in the filenam… |
| CVE-2026-50142 | HIGH | Patched | 7.5 | 2026-08-18 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequ… |
| CVE-2026-48796 | MEDIUM | Patched | 5.3 | 2026-08-18 | CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Presentation Foundation applications. Prior to version 148.0.90, CefSharp/… |
| CVE-2026-47699 | MEDIUM | Patched | 6.4 | 2026-08-18 | Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From 0.16.0 until 0.20.0, a crafted OCI image layer can m… |
| CVE-2026-21584 | NONE | Patched | — | 2026-08-18 | This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This Improp… |